Interview · Cloud Native Compass

Kubernetes Security with Identity & OIDC

§ Overview

About this video

What You'll Learn

  1. Why long-lived kubeconfig certificates should be reserved for break-glass access
  2. How OIDC impersonation maps GitHub workflow identities to Kubernetes RBAC
  3. Why supply chain signing depends on trusted identities, not just cryptographic keys

Marc Boorshtein, CTO of Tremolo Security, explains why long-lived kubeconfig certificates are an anti-pattern, how OIDC and impersonation deliver revocable cluster access, and how workflow identity via OIDC JWTs replaces static service account tokens in CI/CD pipelines.

§ Technologies featured

Meet the Cast

Weekly Cloud Native insights

Stay ahead in cloud native

Tutorials, deep dives, and curated events. No fluff.

More from Cloud Native Compass

View all 23 episodes
Kubernetes

More about Kubernetes

View all 172 videos

More about OpenUnison

View technology