# ECK AWS Pod Identity instead of iam user/secret key pair

**URL:** <https://discuss.elastic.co/t/eck-aws-pod-identity-instead-of-iam-user-secret-key-pair/386418>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [May 20, 2026, 5:21am UTC](https://discuss.elastic.co/t/eck-aws-pod-identity-instead-of-iam-user-secret-key-pair/386418 "2026-05-20T05:21:57Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![khteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khteh/32/147573_2.png) [@khteh](https://discuss.elastic.co/u/khteh)\
**Post date:** [May 20, 2026, 5:21am UTC](https://discuss.elastic.co/t/eck-aws-pod-identity-instead-of-iam-user-secret-key-pair/386418/1 "2026-05-20T05:21:57Z")

</div>

I used to add the AWS credentials into elasticsearch (ECK) keystore to backup to AWS S3. And then I was told that this is not a recommended good practice but should use pod identity or environment variables injected by it. How to configure the ECK to use this instead of using iam user/secret key pair?
