{"repo":"banzaicloud/jwt-to-rbac","free":true,"listed":false,"github":"https://github.com/banzaicloud/jwt-to-rbac","clone":"git clone https://github.com/banzaicloud/jwt-to-rbac.git","description":"JWT-to-RBAC lets you automatically generate RBAC resources based on JWT tokens","language":"Go","stars":113,"topics":["kubernetes","rbac","jwt","dex","authn","authz"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"JWT-to-RBAC JWT-to-RBAC lets you automatically generate RBAC resources based on JWT token. Context For authentication we use Dex with the LDAP and GitHub connectors. The users in LDAP have group memberships, GitHub users can be members of a team in an organization and Dex issues a JWT token containing these memberships. The JWT-to-RBAC project can create ServiceAccount , ClusterRoles and ClusterroleBindings based on JWT tokens. When we create a new ServiceAccount K8s automatically generates a service account token . For more information and context please read the Provider agnostic authentication and authorization in Kubernetes post. JWT-to-RBAC is a core part of Banzai Cloud Pipeline, a Cloud Native application and devops platform that natively supports multi- and hybrid-cloud deployments with multiple authentication backends. Check out the developer beta: Requirements: There are some pre-requirements to kick this of for your own testing. Configured Dex server as OIDC provider which issues JWT tokens. If you want to issue tokens with Dex you have to configure it with LDAP connector. You can use the Banzai Cloud Dex chart. GitHub account assigned for an organization or configured LDAP server - you can use the openldap Docker image Authentication application which uses Dex as an OpenID connector (in our case is Pipeline. Dex acts as a shim between a client app and the upstream identity provider. The client only needs to understand OpenID Connect to query Dex. The issued ID tok","default_branch":null,"files":null,"tree":[],"storefront":"/r/banzaicloud","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/banzaicloud/jwt-to-rbac/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}