How to setup a Workload Identity token access on AKS to allow keycloak access on Azure?

How to setup a Workload Identity token access on AKS to allow keycloak access on Azure ?

I wan to implement: