The kubeconfig sprawl problem
Shared cluster-admin kubeconfigs, long-lived service account tokens, and vendor VPN paths into prod clusters are difficult to revoke and nearly impossible to audit command-by-command. Gateways replace standing kubeconfig access with session grants tied to identity.
Kubeconfig sprawl
Shared cluster-admin · vendor VPN · long-lived tokens
Session grants
Identity-bound · revocable · command-level audit