-
Epic
-
Resolution: Obsolete
-
Critical
-
None
-
None
-
None
-
Document Audience for external OIDC Providers
-
False
-
None
-
False
-
Not Selected
-
To Do
-
0
-
0
-
0
Goal
Find a way to configure external OIDC clients (e.g., AAD) so that they request tokens with an additional claim audience that’s going to be the same for every client in the cluster.
Defintion of Done
Drafted technical How-to document describing configuration of the specific OIDC providers e.g., AAD
Related references / Previous Work
- This upstream K8s PR which is closed as "rotten": https://github.com/kubernetes/kubernetes/issues/71162
- Potential solution: https://github.com/kubernetes/enhancements/pull/3332.