Identity and security
Module infographic
40 / 69

Revision poster: workload identity and hardening.

Infographic: the five-step Pod Identity credential flow, IRSA comparison note and a layered hardening checklist for nodes, data, control plane and network
Click the poster to enlarge it

Left: how a Pod gets short-lived AWS credentials. Right: the hardening checklist grouped by layer.

  1. 1Pods get temporary credentials via the Pod Identity Agent and STS, scoped to the associated role.
  2. 2An association links cluster, namespace and ServiceAccount to an IAM role.
  3. 3IRSA needs an OIDC provider per cluster; Pod Identity does not.
  4. 4Require IMDSv2 and use a minimal node OS.
  5. 5Encrypt Secrets with KMS and keep no long-lived AWS keys in the cluster.
  6. 6Enable audit logs, restrict the endpoint, default-deny network policy and Pod Security Standards.

Self-check: cover the poster and answer

  • Why is the Pod Identity trust policy reusable across clusters?
  • Which control stops a Pod stealing the node role through metadata?

Short-lived credentials and layered hardening beat long-lived keys.