Skip to content
Docs · Authentication

Clusters

Authentication

Client certificates, tokens, exec plugins, OIDC and OpenShift OAuth.

Kubyl understands the auth methods kubeconfigs use. Secrets such as tokens and refresh tokens go to the OS keychain and never into settings.json, state.json, your kubeconfig or the logs.

Supported methods

MethodNotes
Client certificate, bearer token, token file, basic authHandled directly.
Exec pluginsaws eks get-token, gke-gcloud-auth-plugin, kubelogin and others. Credentials are cached until shortly before they expire.
OIDCauth-provider: oidc or a kubelogin exec config. Browser or device-code sign-in.
OpenShift OAuth tokenssha256~… tokens. Kubyl signs in again through the cluster's OAuth server.
Legacy gcp and azure providersDetected and labelled, but not an interactive sign-in.

Exec plugins

  • On macOS and Linux Kubyl uses the PATH of your login shell, so tools installed with Homebrew, asdf or a cloud SDK are found even when you start Kubyl from the Dock.
  • The plugin timeout is 300 seconds. On failure, the plugin's stderr is shown.
  • Interactive plugins (interactiveMode: Always) get a prompt dialog with their output and a line for input. This is not a real terminal, so a plugin that checks for a TTY behaves as if it were non-interactive.
  • Kubeconfigs you paste, import or create run commands on your machine. Kubyl asks for explicit consent first: I checked these commands and trust them.

OIDC sign-in

When a context needs an OIDC login, the sign-in dialog offers:

  • Browser: authorization code with PKCE and a loopback redirect. Use Reopen browser if the tab was closed.
  • Use device code: shows a code to enter on another device.

Refresh tokens are kept in the OS keychain, so you sign in again only when they expire.

OpenShift

For OpenShift tokens (sha256~…) Kubyl offers the same three routes as the oc CLI:

  • Web login, like oc login --web.
  • Username and password, like oc login -u.
  • Pasting a token from the console's Copy login command page.

Tokens are stored per API server and user. The token in your kubeconfig is never written back.

Credential storage

Kubyl uses macOS Keychain, Windows Credential Manager or the Secret Service on Linux. Signed macOS release builds use the data-protection keychain, so there are no repeated prompts.

Something missing or wrong? Open an issue on GitHub.