What it is: How a Pod gets permissions to call AWS APIs (S3, DynamoDB, etc.).
What it’s for:
Two common models:
1) Node IAM Role (EC2 Instance Profile)
2) IRSA (Recommended)
Pod uses a specific Kubernetes Service Account.
That service account is mapped to an IAM Role.
Pod receives temporary credentials via STS and can only do what that role allows.
Exam cues:
Hard words:
*inherit* /ɪnˈherɪt/: thừa hưởng
*temporary credentials* /ˈtɛmpəˌrɛri krəˈdɛnʃəlz/: thông tin tạm thời
*mapped* /mæpt/: ánh xạ
*least privilege* /liːst ˈprɪvəlɪdʒ/: cấp đúng quyền cần thiết