401 Unauthorized on Kubeflow dashboard after OIDC token revocation
In a Kubeflow environment utilizing Istio for authentication, the auth-proxy validates OIDC tokens at the request level. While Kubernetes RBAC manages permissions based on OIDC groups, there is a discrepancy between the identity provider's state and the active Istio session. When a user is deactivated or their credentials are rotated in the OIDC provider, th