[anyscale/terraform-provider-anyscale]: the Operator runs as a pod, not an EC2 instance, so it cannot reuse the node group's IAM role: that role's trust policy only allows ec2.amazonaws.com to assume it, not pods.eks.amazonaws.com. The fix is an EKS Pod Identity association with a dedicated role trusted by pods.eks.amazonaws.com, bound to the Operator's namespace and service account. That role also needs permission to read and write the object storage bucket the cloud registers, because the Operator checks it during its own startup verification.

Context: The Anyscale Operator fails to start with an IMDS or credentials error that has nothing obviously to do with IAM trust policies.