Use an OIDC public client (PKCE) for kubectl access — don’t distribute a client secret
Replace static kube credentials with an identity provider and a public OpenID Connect client so access follows user accounts and group membership rather than distributed files or long-lived tokens.




