Introduction


If you're running apps on Amazon EKS, you've faced this challenge: your pods need to talk to AWS services (S3, DynamoDB, SQS), and you must provide credentials securely without baking long-lived access keys into a Kubernetes Secret.

For years, the standard was IRSA (IAM Roles for Service Accounts). It's secure, but setting it up...