ExternalIdentityMapsTo

An external/workload identity resolves to a concrete internal principal (guest->member, IdP subject->role, k8s SA->IAM role).

cross_boundary AUTHORIZATION nature: explicit walkable weight 1
ExternalIdentity, FederatedIdentity, WorkloadIdentity  ── ExternalIdentityMapsTo ──▸  Identity, Role, ServiceAccount

Target types

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureexplicit

Rules that emit ExternalIdentityMapsTo 11

A Kubernetes ServiceAccount annotated with eks.amazonaws.com/role-arn maps to that IAM role; the mapping is realized when the role trust allows the cluster OIDC issuer + sub for this SA.
awsexplicit
An EKS Pod Identity Association explicitly maps a namespace:SA pair to an IAM role; the mapping is backed by the role trust trusting pods.eks.amazonaws.com.
awsexplicit
azureexplicit
move · open · esc close