Configure the EKS Pod Identity Agent add-on so pods obtain credentials without an OIDC provider
A company is using Amazon Elastic Kubernetes Service (Amazon EKS) to run its applications. The EKS cluster is successfully running multiple pods. The company stores the pod images in Amazon Elastic Container Registry (Amazon ECR). The company needs to configure Pod Identity access for the EKS cluster. The company has already updated the node IAM role by using the permissions for Pod Identity access. Which solution will meet these requirements?
Community Votes
83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Pod Identity replaces the IRSA mechanism, and IRSA is precisely what requires an IAM OpenID Connect provider; the question states Pod Identity access is being configured, so option A's OIDC provider belongs to the IRSA approach and is not needed here (B rather than A). The Pod Identity Agent add-on is the component that performs the credential exchange with EKS Auth, so adding and configuring it, together with node reachability to the EKS Auth API, is what completes the setup (B). Option C's API_AND-CONFIG_MAP authentication mode concerns Kubernetes API authentication, not Pod Identity, and option D configures an STS endpoint for a service account, which is an IRSA-oriented concern.
EKS Pod Identity gives pods AWS credentials without storing any IAM credentials in Kubernetes Secrets and without the instance metadata service. Because the node IAM role has already been updated with the permissions Pod Identity requires, the remaining steps are to make sure the nodes can reach the EKS Auth API and to add and configure the EKS Pod Identity Agent add-on, which handles the credential exchange. Unlike IAM roles for service accounts, Pod Identity does not require an OIDC provider.
Creating an IAM OpenID Connect provider for the EKS cluster (A) — OIDC providers exist to support IAM roles for service accounts, and Pod Identity deliberately removes that dependency; CHRIS12722222 noted the question is not about IRSA and that Pod Identity does not need OIDC. Configuring an access entry with the API_AND-CONFIG_MAP cluster authentication mode (C) — that mode governs how Kubernetes authenticates to the API server, not how pods obtain AWS credentials. Configuring the AWS STS endpoint for the Kubernetes service account (D) — service-account-based STS configuration is part of the IRSA pattern that Pod Identity replaces.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
EKS Pod Identity is the mechanism that lets pods receive AWS credentials without an OIDC provider, because it does not rely on IAM roles for service accounts and web identity federation. Given that the node IAM role has already been updated with the permissions Pod Identity requires, the work that remains is to ensure the nodes can reach the EKS Auth API, which the agent calls, and to add and configure the EKS Pod Identity Agent add-on so that it performs the credential exchange and delivers credentials to the pods (B). This is the documented sequence for enabling Pod Identity on an existing cluster.Why the Other Options Are Wrong
A creates an IAM OpenID Connect provider for the EKS cluster. OIDC providers are required for IAM roles for service accounts, not for Pod Identity; CHRIS12722222 and gildzeee both noted the question concerns Pod Identity, which needs no OIDC provider, and teo2157's citation of the IRSA documentation describes the mechanism Pod Identity was designed to replace. C creates an EKS access entry using the API_AND-CONFIG_MAP cluster authentication mode, which governs how the cluster authenticates to the Kubernetes API server and has no relationship to how pods obtain AWS credentials. D configures the AWS STS endpoint for the Kubernetes service account the pods use, which is part of the IRSA-oriented configuration that Pod Identity supersedes. B is the correct answer.Community Comment Notes
Community voted B (83), with A a 17 percent minority. Srikantha noted that EKS Pod Identity is the newer, simpler alternative to IRSA and that with the node role already updated, the add-on is the remaining step. CHRIS12722222 and gildzeee both emphasized that Pod Identity does not require OIDC because the question is not about IRSA. teo2157 favored A based on the IRSA documentation, which is the mismatched mechanism for this scenario.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →