Kubetier
  1. A federated identity credential must already exist on the managed identity, matching the cluster issuer and this namespace and ServiceAccount as subject

  2. Label the ServiceAccount azure.workload.identity/use and annotate it with the identity's client ID

  3. The workload identity webhook projects a token for that managed identity into pods using the ServiceAccount

Rights needed, any one set:

K8s docs ↗