A federated identity credential must already exist on the managed identity, matching the cluster issuer and this namespace and ServiceAccount as subject
Label the ServiceAccount azure.workload.identity/use and annotate it with the identity's client ID
The workload identity webhook projects a token for that managed identity into pods using the ServiceAccount
Rights needed, any one set:
· any one; the label and annotation are the same write
· any one; the label and annotation are the same write
