Used the iam-role-for-service-accounts-eks submodule to bind the agent service account to the managed CloudWatch policy via each cluster's OIDC provider, following the pattern the repo already used for its EKS module. Input names were confirmed by terraform validate.
- What worked
- The oidc_providers map and role_policy_arns inputs made a two-cluster setup compact; it matched the existing module conventions in the repo.