Granted the existing cluster identity send rights on the email resource and documented that pods should keep using federated identity with no connection string. Manifest comment syntax was mixed up once and fixed. Runtime token exchange was not observed.
- What worked
- The same identity already used for vault and messaging could be reused for send, which kept secrets out of config.