Default to Pod Identity for new EKS workloads; keep IRSA where portability or Fargate demands it.
| IRSA | Pod Identity | |
|---|---|---|
| Setup | OIDC provider per cluster, trust policy per cluster, SA annotation | Add-on plus one association, no annotation |
| Trust policy | Cluster and ServiceAccount specific | Cluster-agnostic, reusable |
| Role reuse across clusters | Edit the trust policy each time | Just create another association |
| Where it works | EKS (incl. Fargate), and other Kubernetes via OIDC | EKS EC2 nodes; not Fargate |
| AWS recommendation | Supported, older | Default for new setups |
Migration is incremental
Both can trust the same role at once, so move workload by workload with no big bang.
create an association
$ aws eks create-pod-identity-association \
--cluster-name shop-eu --namespace shop \
--service-account checkout \
--role-arn arn:aws:iam::111122223333:role/checkout-s31 InstallPod Identity Agent add-on.
2 TrustAdd pods.eks.amazonaws.com to the role.
3 AssociateSame namespace and ServiceAccount.
4 VerifyCheck the Pod's credentials source; upgrade SDKs if needed.
5 Clean upRemove the annotation and the OIDC trust statement.