{"repo":"int128/kubelogin","free":true,"listed":false,"github":"https://github.com/int128/kubelogin","clone":"git clone https://github.com/int128/kubelogin.git","description":"kubectl plugin for Kubernetes OpenID Connect authentication (kubectl oidc-login)","language":"Go","stars":2345,"topics":["kubernetes","kubectl","openid-connect","oidc","golang","kubectl-plugins"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"kubelogin This is a kubectl plugin for Kubernetes OpenID Connect (OIDC) authentication, also known as kubectl oidc-login . Here is an example of Kubernetes authentication with the Google Identity Platform: Kubelogin is designed to run as a client-go credential plugin. When you run kubectl, kubelogin opens the browser and you can log in to the provider. Then kubelogin gets a token from the provider and kubectl access Kubernetes APIs with the token. Take a look at the diagram: Getting Started Setup Install the latest release from Homebrew, Krew, Chocolatey or GitHub Releases. If you install via GitHub releases, save the binary as the name kubectl-oidc login on your path. When you invoke kubectl oidc-login , kubectl finds it by the naming convention of kubectl plugins. The other install methods do this for you. You need to set up the OIDC provider, cluster role binding, Kubernetes API server and kubeconfig. Your kubeconfig looks like this: See the setup guide for more. Run Run kubectl. Kubectl executes kubelogin before calling the Kubernetes APIs. Kubelogin automatically opens the browser, and you can log in to the provider. After the authentication, kubelogin returns the credentials to kubectl. Kubectl then calls the Kubernetes APIs with the credentials. Kubelogin stores the ID token and refresh token to the cache. If the ID token is valid, it just returns it. If the ID token has expired, it will refresh the token using the refresh token. If the refresh token has expired, it wi","default_branch":null,"files":null,"tree":[],"storefront":"/r/int128","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/int128/kubelogin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}