Currently spilo supports instance profile and IRSA style AWS role variables. If AWS_CONTAINER_CREDENTIALS_FULL_URI and AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE are added to the standard WAL-G environment, then the native aws sdk integration used in WAL-G will allow normal operations up and down to S3 when poid identity is assigned to the service account.