Kubernetes on GKE, Vault on VMs, auth fails?

Is there some way to configure a GKE (google kubernetes engine) cluster so that it provides the “aud” field in JWTs? I’m trying to set up multiple GKE clusters to contact a Vault managed instance group (VMs) in Google Cloud Platform, but k8s auth keeps complaining about this missing field.