AL2023 + Karpenter requires a hybrid authentication setup.
Keep an EKS Access Entry of type EC2_LINUX (gives system:nodes)
Enable authentication_mode = "API_AND_CONFIG_MAP"
Add an aws-auth ConfigMap role mapping that includes both:
system:bootstrappers
system:nodes