Server Identity introduced to enhance security

If I have 3 Environments for MFT (Prod, DR and Non Prod), all environments with paired servers behind a Load Balancer.

Would I create a server identity for each environment (3) or would I create 1 server identity accross my entire suite of MFT.?

ie Prod Load balancer has 2 MFT nodes, DR LB has 2 Nodes and Non Prod has 2 nodes.
Please advise