Identity and security
Identity comparison
35 / 69

Default to Pod Identity for new EKS workloads; keep IRSA where portability or Fargate demands it.

IRSAPod Identity
SetupOIDC provider per cluster, trust policy per cluster, SA annotationAdd-on plus one association, no annotation
Trust policyCluster and ServiceAccount specificCluster-agnostic, reusable
Role reuse across clustersEdit the trust policy each timeJust create another association
Where it worksEKS (incl. Fargate), and other Kubernetes via OIDCEKS EC2 nodes; not Fargate
AWS recommendationSupported, olderDefault for new setups

Migration is incremental

Both can trust the same role at once, so move workload by workload with no big bang.

create an association
$ aws eks create-pod-identity-association \
    --cluster-name shop-eu --namespace shop \
    --service-account checkout \
    --role-arn arn:aws:iam::111122223333:role/checkout-s3
1 InstallPod Identity Agent add-on.
2 TrustAdd pods.eks.amazonaws.com to the role.
3 AssociateSame namespace and ServiceAccount.
4 VerifyCheck the Pod's credentials source; upgrade SDKs if needed.
5 Clean upRemove the annotation and the OIDC trust statement.