Same terraform apply. The Helm provider authenticates against the now-existing cluster via its endpoint, CA cert, and a short-lived aws_eks_cluster_auth token.

kubectl get pods -n monitoring

monitoring.png