The operator writes each renewed service account token into WasmPlugin.spec.pluginConfig.cache_token (coraza-kubernetes-operator/internal/controller/engine_controller_wasm_driver.go). Envoy includes the plugin configuration in the plugin key (envoy/source/extensions/common/wasm/plugin.cc), so a new token creates a new plugin root. Istio 1.30.3 strips its changing resource-version VM variable before forwarding the configuration, and Envoy keys the VM by its VM configuration and WASM bytes. With unchanged code and VM settings, successive roots share one worker VM.
The Coraza guest fixes are already deployed. The remaining fixes must release root-owned state without destroying state still used by another root on that VM. This plan is based on source inspection only; no process was run or measured.