IAM Roles for Service Accounts (IRSA)IRSA lets Kubernetes pods assume IAM roles without storing credentials. The mechanism uses OIDC token projection.