On your RBAC integration, syncing OIDC groups is the correct first step, but we found the real challenge was maintaining consistent namespace-level role bindings across three clouds. We built a small reconciler that audits them weekly against a central manifest, which caught several configuration drifts. It's a simple script, but it prevents those "why can't I access the logs?" tickets.
For performance, test your specific service-to-service traffic patterns before committing. The latency addition might be negligible for your batch jobs but could break synchronous API calls. We logged the RTT for a week and created a simple decision matrix: if the service SLA is under 50ms, we skip the gateway.
TrustScore is still a black box. We defined three concrete device posture tiers (managed corporate, enrolled personal, unknown) and mapped those directly to coarse-grained roles, which gave us 90% of the benefit without tuning an opaque algorithm.
Measure twice, buy once.