Looking at various examples of how to implement kube2iam, I am struggling to understand why the trust relationship of the policy to be assumed by the worker node needs to ha