What it is: The relationship between a Pod and the Kubernetes Service Account (SA) it uses.
What it’s for:
Key ideas:
A Pod specifies `serviceAccountName`.
If not set, it uses the namespace default service account.
Best practice: create a dedicated SA per microservice that needs distinct permissions.
Exam cues:
Hard words: