Needed support for OIDC with generic Kubernetes clusters.
long-term
H
Heather Stoat
Needed support for OIDC with generic Kubernetes clusters.
The OAuth 2.0 Password Grant Type has serious security ramifications and should not be used. According to the OAuth spec on security best practices (https://datatracker.ietf.org/doc/html/draft-ietf-oauth-security-topics#name-resource-owner-password-cre): "The resource owner password credentials grant [RFC6749] MUST NOT be used. This grant type insecurely exposes the credentials of the resource owner to the client."
Need to revamp the OIDC integration with kubernetes.
Rohan Gupta
updated the status to
long-term