GHOSTby AlphaBravo
CatalogWhy GhostContactAccount
Ghost Container Registry — Secure, signed, FIPS-ready images·Built by AlphaBravo
Catalog/aws-eks-pod-identity-agent

aws eks pod identity agent

FIPS 140-3Integration & delivery

The AWS EKS Pod Identity Agent runs on Amazon EKS nodes and exchanges Kubernetes service account tokens for temporary AWS IAM credentials, providing pods with IAM roles without using IRSA or instance profiles.

OverviewGuidesTags
Signed
SBOM
FIPS
CIS

Pull this image

About

About AWS EKS Pod Identity Agent

The AWS EKS Pod Identity Agent is a Kubernetes node agent that delivers temporary AWS IAM credentials to pods running on Amazon EKS clusters. It exchanges projected Kubernetes service account tokens for short-lived AWS credentials by calling the EKS Auth API, then serves those credentials to pods via a local credential proxy.

The agent runs as a DaemonSet on each EKS node and exposes a local HTTP endpoint that the AWS SDKs and CLI inside workload pods can use to obtain credentials. The Pod Identity association mapping (which IAM role each service account maps to) is configured in EKS rather than annotated on the service account, which simplifies cross-account access and removes the need for the OIDC provider configuration required by IRSA.

Recently pushed

View all →
0.1.20-debian13-55318d2b5d93Debian
24 CVEs11 MBSep 19
0.2.2-debian13-ed31e206539dDebian
24 CVEs17 MBSep 19
0.1.20-debian13-cb2dc13804f6Debian
0 CVEs6 MBSep 19
0.2.2-debian13-382d3d328d07Debian
0 CVEs13 MBSep 19
0.1.20-debian13-9ea3c041d77aDebian
0 CVEs6 MBSep 9

Image details

Distribution
Debian
Architecture
amd64
Latest size
11 MB
Variants
Base + FIPS
Last pushed
Sep 19, 2026
Last scanned
Sep 19, 2026 · Trivy

Resources

Documentation ↗
Available tags
18 tags
View tags →
Latest digest
sha256:1b4cbc8db9c1…