Follow the latest coverage, related explainers and connected technology stories.
A CNCF article proposes replacing client certificates and long-lived tokens in self-hosted Kubernetes clusters with an OIDC integration based on a public client and PKCE. This approach ties permissions to identity and group membership, simplifies revocation, and improves the accuracy of audit logs without requiring the cluster to be rebuilt.