On IRSA
I did not copy-paste a blog post. I enabled the OIDC provider, wrote the trust policy with the service-account condition, scoped the IAM policy to a specific table ARN, annotated the ServiceAccount, and verified it by exec-ing into the pod and checking env | grep AWS. I know it works because I know why it works.