Identity and security
Pod Identity
34 / 69

An agent on each node hands a Pod short-lived credentials for exactly the role you associated.

No OIDC provider to manage, and the association lives in AWS, not in the ServiceAccount manifest.

checkout PodPod IdentityAgent (DaemonSet)EKS Auth APIchecks associationAWS STSS3 bucket1SDK asks the local agent endpoint2agent presents the Pod identity token3AssumeRoleForPodIdentity for the associated role4temporary credentials flow back to the Pod5Pod calls S3 with scoped, expiring credentials