The following sets up an oidc flow using kubelogin aka oidc-login. Make sure to install the tool before continuing.
First set up a bunch of variables
# We're using an email claim, but it should be possible to get other claims to work
# See
export AAD_USER_IDENTIFICATION=mads@reload.dk