Give Pods identities through ServiceAccounts, projected tokens, and external workload identity systems. Separate human credentials from workload credentials and reduce reliance on long-lived secrets.