CNCF has published a guide to Kubernetes access through an identity provider. It recommends a public OIDC client, a login protocol using an identity provider, with PKCE, a protection mechanism for authorization codes, instead of a confidential client with a secret.

The kubelogin client plugin starts login, obtains a token from the identity provider, and attaches it to every API request.

Claim check:

  • CNCF has published a guide to Kubernetes access through an identity provider. (confirmed by the publication itself: evidence; «Kubernetes access via an identity provider: Public client, not confidential»)
  • CNCF recommends a public OIDC client with PKCE instead of a confidential client with a secret. (confirmed by the publication itself: evidence; «Configure it with a public OIDC client using PKCE, not a confidential client with a secret.»)
  • The kubelogin plugin starts login, obtains a token from the identity provider, and attaches it to every API request. (confirmed by the publication itself: evidence; «kubectl, with the kubelogin exec plugin. Starts the login, gets a token from the identity provider, and attaches it to every API request.»)

Primary sources:

score 66.5 · kind guide · revision 1 · stories st-1gyip38