{"repo":"dadrus/heimdall","free":true,"listed":false,"github":"https://github.com/dadrus/heimdall","clone":"git clone https://github.com/dadrus/heimdall.git","description":"A cloud native Identity Aware Proxy and Access Control Decision service","language":"Go","stars":253,"topics":["api-gateway","authentication","authorization","golang","oauth2","openid-connect","policy-enforcement","access-control","access-management","auth-api"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Heimdall Background Heimdall is inspired by the Zero Trust idea and also by Pomerium and Ory's OAthkeeper. Some experience with both and my inability to update the latter one to include the desired functionality and behavior was Heimdall's born hour. What is heimdall Heimdall authenticates and authorizes incoming HTTP (HTTP 1.x and HTTP 2.0) requests as well as enriches these with further contextual information and finally transforms resulting subject information into a format, required by the upstream services. It can do so: Standalone as a proxy in front of your service or web server that rejects unauthorized requests and forwards authorized ones to your end points, or Integrated into any other proxy, ingress controller or API gateway, like Kong, NGNIX, Envoy, Traefik, Contour, Ambassador and many more. Here that other proxy will forward the incoming request to heimdall and depending on its response either forward the original request, verified and updated by heimdall to your upstream service, or reject it with the information provided by heimdall. In both cases it acts as a Policy Enforcement and to some degree a Policy Decision Point according to NIST Zero Trust Architecture (SP 800-207) How does authentication, authorization and transformation work The decision-making and transformation processes in Heimdall are governed by rules or respectively rule sets. These rule sets can be independently configured and managed by each upstream service. Heimdall dynamically loads the","default_branch":null,"files":null,"tree":[],"storefront":"/r/dadrus","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dadrus/heimdall/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}