How to Tie Kubernetes Audit Logs to Individual Engineers
Kubernetes audit logs may show multiple engineers as one user and do not capture what is typed after a kubectl exec session starts. Assign each engineer a unique identity, make sure it stays consistent through proxies and cloud IAM, and use a session recorder if you need to review terminal activity.