An IAM role must already exist whose trust policy names the cluster OIDC provider plus this namespace and ServiceAccount
Add the eks.amazonaws.com/role-arn annotation naming that role to the ServiceAccount
Pods using the ServiceAccount receive credentials for the role, bounded by whatever that role grants
Rights needed, any one set:
· any one; the annotation is the same write
· any one; the annotation is the same write
