kubectl as
you — no shared admin credential, and every action is attributed to your
identity. To run that sign-in, kubectl needs the oidc-login credential
plugin (kubelogin).
Install the kubelogin plugin
kubectl oidc-login plugin, which is what the
downloaded kubeconfig uses — so any of them works. Homebrew and Chocolatey also
install a standalone kubelogin binary; Krew installs only the plugin form
(invoked as kubectl oidc-login). Krew is the most portable option — it works
anywhere kubectl does, including Windows and ARM. For manual binaries or other
package managers, see the project’s install guide.
int128/kubelogin on GitHub
Source, releases, and full installation options for the kubelogin (
oidc-login) plugin.Verify the install with
kubectl oidc-login --version (works for every install
method; kubelogin --version also works for Homebrew and Chocolatey).Connect to your cluster
1
Download the kubeconfig
Open your cluster from the Kubernetes page in the
dashboard and download its kubeconfig
(
<cluster>.yaml).2
Point kubectl at it
3
Run any command — your browser opens
kubectl runs as you and the command completes.Access tokens are short-lived — when one expires,
kubectl reopens the browser
to sign in again. Confirm who you’re acting as with kubectl auth whoami.
