{"repo":"AndriyKalashnykov/authentik-k8s","free":true,"listed":false,"github":"https://github.com/AndriyKalashnykov/authentik-k8s","clone":"git clone https://github.com/AndriyKalashnykov/authentik-k8s.git","description":"Provision a multi-org Authentik hierarchy (groups, users, OAuth tokens) via its Go client, then gate an app with forward-auth; KinD or Compose","language":"Go","stars":12,"topics":["authentication","authentik","go","golang","oauth","oauth2","oauth2-authentication","oauth2-client","token","traefik"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Authentik Provisioning with the Go Client Provision a multi-org Authentik hierarchy — per-org groups, users, passwords, OAuth tokens — programmatically with the Go client, plus opt-in forward-auth application access. Deploy on Kubernetes (KinD) or Docker Compose. A proof-of-concept that drives Authentik programmatically via its Go client library goauthentik.io/api/v3 . The core flow creates groups, users, passwords and OAuth tokens, then re-authenticates as a created user to read its group membership. An optional second demo extends the same client from provisioning identities to controlling application access — it configures an Authentik proxy provider, application, and embedded-outpost binding so that Traefik's forwardAuth middleware gates a sample app behind Authentik login. It ships with two ways to stand up Authentik (Docker Compose or KinD) plus the Go POC that runs against it. On the delivery side it carries hermetic httptest API-contract tests plus live Compose/KinD and Playwright browser e2e layers, a distroless container image, a composite security gate (Trivy filesystem + image scans, gitleaks, hadolint, govulncheck), a mise-pinned toolchain, and Renovate-tracked pins — all enforced in GitHub Actions CI. Overview The repo has two halves: - Deploy Authentik — locally via Docker Compose (lightweight) or on a full Kubernetes cluster via KinD (with cloud-provider-kind for LoadBalancer support and OSS PostgreSQL datastore). - provisioner/ — a Go program that provisions ","default_branch":null,"files":null,"tree":[],"storefront":"/r/AndriyKalashnykov","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/AndriyKalashnykov/authentik-k8s/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}