get_tkc_kubeconfig
Retrieve a kubeconfig for a specific Tanzu Kubernetes Cluster (TKC) to authenticate and access it. Provide the cluster name and namespace; optionally save to a file.
Instructions
[WRITE] Credential access: get a kubeconfig for one TKC cluster.
Call only when the user explicitly asks for this kubeconfig; never as a side step. Returns {cluster, kubeconfig}, or {cluster, written_to} when output_path is given. The kubeconfig embeds a Supervisor bearer token (JWT from /wcp/login) that acts as the configured vCenter account until the JWT expires (typically hours; not tied to this process) — always pass output_path so the token never enters agent context, and report only the path. Nothing in the managed cluster changes, but output_path creates parent directories and truncates the named file (owner-only, 0600), so output_path='~/.kube/config' replaces the user's own kubeconfig. Run list_tkc_clusters first for name and namespace; use get_supervisor_kubeconfig instead for Supervisor-level access.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | TKC cluster name. | |
| target | No | vCenter in config.yaml; omit for the default. | |
| namespace | Yes | Namespace holding it. | |
| output_path | No | File to write, e.g. '~/.kube/my.yaml'. Omit to return the kubeconfig inline. |