ExternalIdentityMapsTo
An external/workload identity resolves to a concrete internal principal (guest->member, IdP subject->role, k8s SA->IAM role).
ExternalIdentity, FederatedIdentity, WorkloadIdentity
── ExternalIdentityMapsTo ──▸
Identity, Role, ServiceAccount
Source types
Target types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | explicit |
|---|
Rules that emit ExternalIdentityMapsTo 11
awsexplicit
awsexplicit
awsexplicit
A Kubernetes ServiceAccount annotated with eks.amazonaws.com/role-arn maps to that IAM role; the mapping is realized when the role trust allows the cluster OIDC issuer + sub for this SA.
awsexplicit
An EKS Pod Identity Association explicitly maps a namespace:SA pair to an IAM role; the mapping is backed by the role trust trusting pods.eks.amazonaws.com.
awsexplicit
awsexplicit
azureexplicit
azureexplicit
azureexplicit
azureexplicit
gcpexplicit