Same terraform apply. This phase adds an IRSA-based IAM role (OIDC-federated trust policy, scoped to the ebs-csi-controller-sa service account), the aws-ebs-csi-driver EKS addon, and a gp3 StorageClass.
kubectl get storageclass
kubectl get pvc -n monitoring
Expect both Grafana's and Prometheus's PVCs showing Bound