SSO-Backed kubectl Access Across Many Clusters
TL;DR: If your development, staging, and production API servers all trust the same OIDC issuer and audience, Kubernetes will accept the same cached kubectl token across all of them. You should use separate audiences in your API.