diff --git a/README.md b/README.md
index 370715a..603838e 100644
--- a/README.md
+++ b/README.md
@@ -29,3 +29,9 @@ cluster.
The JWKS file must contain only public key material for the k3s ServiceAccount
token signing key. Never commit the private signing key, AWS credentials, KMS key
IDs, kubeconfigs, or decrypted SOPS values here.
+
+This static issuer is for Kubernetes ServiceAccount tokens used by AWS STS; it
+is not the human kubectl login provider and does not expose the cluster API.
+Maintainer kubectl access uses Cloudflare Access plus ArgoCD Dex as documented
+in the
+[`kustomize-cluster` README](https://github.com/makeitworkcloud/kustomize-cluster#kubectl-access).
diff --git a/makeitwork.cloud/index.html b/makeitwork.cloud/index.html
index 2d9425c..c7d0ad6 100644
--- a/makeitwork.cloud/index.html
+++ b/makeitwork.cloud/index.html
@@ -5,11 +5,11 @@
@@ -26,7 +26,7 @@
/>
MAKE IT WORK
-
-
-
-
Headlamp
-
kubectl get pods
-
-
-