- Setup IAM-auth Postgres and blob storage Use cloud IAM roles instead of static credentials. - Validate Materialize can authenticate with them Test IAM roles from pods using Workload Identity or IRSA.