How do you avoid configuring the API server to support OIDC?
https://kubernetes.io/docs/reference/access-authn-authz/auth...
https://kubernetes.io/docs/reference/access-authn-authz/auth...
Infra runs a lightweight process in-cluster that intercepts requests and verifies them - and yes, this process intercepts requests and then impersonates the correct users and groups.