Same terraform apply. This phase adds an IRSA-based IAM role (OIDC-federated trust policy, scoped to the ebs-csi-controller-sa service account), the aws-ebs-csi-driver EKS addon, and a gp3 StorageClass.

kubectl get storageclass
kubectl get pvc -n monitoring

Expect both Grafana's and Prometheus's PVCs showing Bound