Same terraform apply. The Helm provider authenticates against the now-existing cluster via its endpoint, CA cert, and a short-lived aws_eks_cluster_auth token.
terraform apply
aws_eks_cluster_auth
kubectl get pods -n monitoring