Generated kubeconfig structure
Managed Auth generates kubeconfig files for your CKS clusters from the Cloud Console. These files follow the permissions configured for their related tokens and embed the API access token. The following example shows a kubeconfig file generated by Managed Auth:Authentication errors
The following errors can occur when you use a Managed Auth kubeconfig file. For help choosing an authentication method, see Introduction to authentication and access control.The managed endpoint returns
403 Forbidden for token problems, not 401 Unauthorized. A 401 on a CKS cluster points to an OIDC or unmanaged authentication issue instead. If several users share one token, its expiration or revocation blocks all of them at once. Give each user their own token.