Four names that look like four different things. Really, they are two real objects and two portal views. Here is the short version — what each one actually is, and which one to use in which situation.
Workload Identity gives every pod its own Azure identity. So why are we still passing connection strings around? Here is how I dropped them for SQL, Storage, and Service Bus — using DefaultAzureCredential and a single pattern.
Every tutorial teaches you the pieces — pods, modules, charts, dashboards. Almost no one teaches the connective tissue between them. That gap is what this blog is about.