|
|
|
|
|
by jmorgan
1492 days ago
|
|
Tokens are verified by intercepting API server requests in-cluster against a central root of trust. This is similar to how OpenID tokens from identity providers such as Okta or Active Directory are verified by destination web applications. This works no matter where clusters are hosted (including GKE/AKS/EKS or self-hosted clusters). |
|
https://kubernetes.io/docs/reference/access-authn-authz/auth...