get_supervisor_kubeconfig
Retrieve a kubeconfig for the Supervisor Kubernetes API in a vSphere Namespace to authenticate with vCenter. Use only when explicitly requested; write to output_path to keep the token out of context.
Instructions
[WRITE] Credential access: get a kubeconfig for the Supervisor K8s API.
Call only when the user explicitly asks for this kubeconfig; never as a side step. Returns {namespace, kubeconfig} as a YAML string, or {namespace, written_to} when output_path is given. The kubeconfig embeds a Supervisor bearer token (JWT from /wcp/login) that acts as the configured vCenter account until the JWT expires (typically hours; not tied to this process) — always pass output_path so the token never enters agent context, and report only the path. The file is created owner-only (0600). Use get_tkc_kubeconfig instead to reach workloads inside a TKC cluster.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | No | vCenter in config.yaml; omit for the default. | |
| namespace | Yes | vSphere Namespace to set as the kubeconfig context. | |
| output_path | No | File to write, e.g. '~/.kube/supervisor.yaml'. Omit to return the kubeconfig inline. Creates parent directories and truncates the file. |