Kubyl understands the auth methods kubeconfigs use. Secrets such as tokens and refresh tokens go to the OS keychain and never into settings.json, state.json, your kubeconfig or the logs.
Supported methods
| Method | Notes |
|---|---|
| Client certificate, bearer token, token file, basic auth | Handled directly. |
| Exec plugins | aws eks get-token, gke-gcloud-auth-plugin, kubelogin and others. Credentials are cached until shortly before they expire. |
| OIDC | auth-provider: oidc or a kubelogin exec config. Browser or device-code sign-in. |
| OpenShift OAuth tokens | sha256~… tokens. Kubyl signs in again through the cluster's OAuth server. |
Legacy gcp and azure providers | Detected and labelled, but not an interactive sign-in. |
Exec plugins
- On macOS and Linux Kubyl uses the
PATHof your login shell, so tools installed with Homebrew, asdf or a cloud SDK are found even when you start Kubyl from the Dock. - The plugin timeout is 300 seconds. On failure, the plugin's stderr is shown.
- Interactive plugins (
interactiveMode: Always) get a prompt dialog with their output and a line for input. This is not a real terminal, so a plugin that checks for a TTY behaves as if it were non-interactive. - Kubeconfigs you paste, import or create run commands on your machine. Kubyl asks for explicit consent first: I checked these commands and trust them.
OIDC sign-in
When a context needs an OIDC login, the sign-in dialog offers:
- Browser: authorization code with PKCE and a loopback redirect. Use Reopen browser if the tab was closed.
- Use device code: shows a code to enter on another device.
Refresh tokens are kept in the OS keychain, so you sign in again only when they expire.
OpenShift
For OpenShift tokens (sha256~…) Kubyl offers the same three routes as the oc CLI:
- Web login, like
oc login --web. - Username and password, like
oc login -u. - Pasting a token from the console's Copy login command page.
Tokens are stored per API server and user. The token in your kubeconfig is never written back.
Credential storage
Kubyl uses macOS Keychain, Windows Credential Manager or the Secret Service on Linux. Signed macOS release builds use the data-protection keychain, so there are no repeated prompts.