Configure the EKS Pod Identity Agent add-on so pods obtain credentials without an OIDC provider

Answer Correct answer: B — ensure nodes can reach the EKS Auth API and add the EKS Pod Identity Agent add-on; no OIDC provider is needed.

A company is using Amazon Elastic Kubernetes Service (Amazon EKS) to run its applications. The EKS cluster is successfully running multiple pods. The company stores the pod images in Amazon Elastic Container Registry (Amazon ECR). The company needs to configure Pod Identity access for the EKS cluster. The company has already updated the node IAM role by using the permissions for Pod Identity access. Which solution will meet these requirements?

  1. Create an IAM OpenID Connect (OIDC) provider for the EKS cluster.
  2. Ensure that the nodes can reach the EKS Auth API. Add and configure the EKS Pod Identity Agent add-on for the EKS cluster. Correct Answer
  3. Create an EKS access entry that uses the API_AND-CONFIG_MAP cluster authentication mode.
  4. Configure the AWS Security Token Service (AWS STS) endpoint for the Kubernetes service account that the pods in the EKS cluster use.

Community Votes

B
83%
A
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Pod Identity replaces the IRSA mechanism, and IRSA is precisely what requires an IAM OpenID Connect provider; the question states Pod Identity access is being configured, so option A's OIDC provider belongs to the IRSA approach and is not needed here (B rather than A). The Pod Identity Agent add-on is the component that performs the credential exchange with EKS Auth, so adding and configuring it, together with node reachability to the EKS Auth API, is what completes the setup (B). Option C's API_AND-CONFIG_MAP authentication mode concerns Kubernetes API authentication, not Pod Identity, and option D configures an STS endpoint for a service account, which is an IRSA-oriented concern.

EKS Pod Identity gives pods AWS credentials without storing any IAM credentials in Kubernetes Secrets and without the instance metadata service. Because the node IAM role has already been updated with the permissions Pod Identity requires, the remaining steps are to make sure the nodes can reach the EKS Auth API and to add and configure the EKS Pod Identity Agent add-on, which handles the credential exchange. Unlike IAM roles for service accounts, Pod Identity does not require an OIDC provider.

Creating an IAM OpenID Connect provider for the EKS cluster (A) — OIDC providers exist to support IAM roles for service accounts, and Pod Identity deliberately removes that dependency; CHRIS12722222 noted the question is not about IRSA and that Pod Identity does not need OIDC. Configuring an access entry with the API_AND-CONFIG_MAP cluster authentication mode (C) — that mode governs how Kubernetes authenticates to the API server, not how pods obtain AWS credentials. Configuring the AWS STS endpoint for the Kubernetes service account (D) — service-account-based STS configuration is part of the IRSA pattern that Pod Identity replaces.

Community Discussion (8 comments)

Srikantha 👍 1 Selected: B
The company wants to configure EKS Pod Identity (a newer and simpler alternative to IAM Roles for Service Accounts / IRSA). Since they already updated the node IAM role to allow Pod Identity access, the next essential step is to: Install the EKS Pod Identity Agent add-on to the cluster. Ensure that the nodes can reach the EKS Auth API, which the agent uses to request temporary credentials. This is exactly what Option B outlines.
CHRIS12722222 👍 3 Selected: B
Question is not talking about IRSA Pod identities do not need OIDC
tubtab 👍 2 Selected: B
IT BBBB
gildzeee 👍 2 Selected: B
question doesnt state the pods are using irsa so the eks addon should work just fine with pod identity
teo2157 👍 1 Selected: A
It's A based on this: https://docs.aws.amazon.com/eks/latest/userguide/iam-roles-for-service-accounts.html
pma17 👍 2 Selected: B
Pod Identity is a "new" way to provide Pod access to AWS services and does not rely on OIDC. Instead you have to setup the EKS Pod Identity Agent and must ensure kubernetes nodes can reach the EKS Auth API endpoint. https://docs.aws.amazon.com/eks/latest/userguide/pod-identities.html
f4b18ba 👍 1 Selected: A
This is the necessary first step to set up IRSA. Without the IAM OIDC provider, IAM cannot trust tokens from the EKS cluster, and service accounts cannot assume IAM roles. Enables the establishment of trust between Kubernetes service accounts and IAM roles, allowing pods to securely access AWS resources.
uncledana 👍 1
The best and most accurate solution is A. Create an IAM OpenID Connect (OIDC) provider for the EKS cluster.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

EKS Pod Identity is the mechanism that lets pods receive AWS credentials without an OIDC provider, because it does not rely on IAM roles for service accounts and web identity federation. Given that the node IAM role has already been updated with the permissions Pod Identity requires, the work that remains is to ensure the nodes can reach the EKS Auth API, which the agent calls, and to add and configure the EKS Pod Identity Agent add-on so that it performs the credential exchange and delivers credentials to the pods (B). This is the documented sequence for enabling Pod Identity on an existing cluster.

Why the Other Options Are Wrong

A creates an IAM OpenID Connect provider for the EKS cluster. OIDC providers are required for IAM roles for service accounts, not for Pod Identity; CHRIS12722222 and gildzeee both noted the question concerns Pod Identity, which needs no OIDC provider, and teo2157's citation of the IRSA documentation describes the mechanism Pod Identity was designed to replace. C creates an EKS access entry using the API_AND-CONFIG_MAP cluster authentication mode, which governs how the cluster authenticates to the Kubernetes API server and has no relationship to how pods obtain AWS credentials. D configures the AWS STS endpoint for the Kubernetes service account the pods use, which is part of the IRSA-oriented configuration that Pod Identity supersedes. B is the correct answer.

Community Comment Notes

Community voted B (83), with A a 17 percent minority. Srikantha noted that EKS Pod Identity is the newer, simpler alternative to IRSA and that with the node role already updated, the add-on is the remaining step. CHRIS12722222 and gildzeee both emphasized that Pod Identity does not require OIDC because the question is not about IRSA. teo2157 favored A based on the IRSA documentation, which is the mismatched mechanism for this scenario.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide