CNCF has published a guide to Kubernetes access through an identity provider. It recommends a public OIDC client, a login protocol using an identity provider, with PKCE, a protection mechanism for authorization codes, instead of a confidential client with a secret.
The kubelogin client plugin starts login, obtains a token from the identity provider, and attaches it to every API request.
Claim check:
- CNCF has published a guide to Kubernetes access through an identity provider. (confirmed by the publication itself: evidence; «Kubernetes access via an identity provider: Public client, not confidential»)
- CNCF recommends a public OIDC client with PKCE instead of a confidential client with a secret. (confirmed by the publication itself: evidence; «Configure it with a public OIDC client using PKCE, not a confidential client with a secret.»)
- The kubelogin plugin starts login, obtains a token from the identity provider, and attaches it to every API request. (confirmed by the publication itself: evidence; «kubectl, with the kubelogin exec plugin. Starts the login, gets a token from the identity provider, and attaches it to every API request.»)
Primary sources:
score 66.5 · kind guide · revision 1 · stories st-1gyip38