The service account provides your application with a unique identity. Thesubclaim from the projected service account token can be used as the principal to match an OpenFaaS Role for your application: apiVersion:iam.openfaas.com/v1kind:Rolemetadata:name:my-appnamespace:openfaasspec:policy:-fn-rwc...