Deep dive into the new Amazon EKS Pod Identity feature
ID: e377406e-0928-5466-987f-fa56a9369b07
STIX ID: report--e377406e-0928-5466-987f-fa56a9369b07
Feed Name: Datadog Security Labs
This report explains AWS EKS Pod Identity, detailing how it associates Kubernetes service accounts with IAM roles to deliver temporary AWS credentials via an agent (binding to 169.254.170.23) and container credential provider environment variables injected by the EKS admission webhook. It contrasts Pod Identity with IRSA for improved audibility (e.g., ListPodIdentityAssociations), notes MKAT’s support for mapping role relationships, and highlights a June 2025 enhancement enabling cross-account access through role chaining with targetRoleArn.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
