{"repo":"gardener/oidc-webhook-authenticator","free":true,"listed":false,"github":"https://github.com/gardener/oidc-webhook-authenticator","clone":"git clone https://github.com/gardener/oidc-webhook-authenticator.git","description":"Kubernetes Webhook Authenticator that allows for dynamic registration of OpenID Connect providers","language":"Go","stars":60,"topics":["kubernetes","oidc","webhook","authentication","authenticator","openid-connect","k8s","crd","controller"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"OpenID Connect Webhook Authenticator for Kubernetes Table of content - OpenID Connect Webhook Authenticator for Kubernetes - Table of content - Overview - Background - Use cases - How it works - Registration of a new OpenID Connect provider - End-user authentication via new OpenIDConnect IDP - Docker images - Local development Overview The OpenID Connect Webhook Authenticator allows Kubernetes cluster administrators to dynamically register new OpenID Connect providers in their clusters to use for kube-apiserver authentication. Note: This repository still in alpha stage and in active development. It should not be used in production. The API can change without any backwards compatibility. Background In Kubernetes, only a single OpenID Connect authenticator can be used for end-users to authenticate. To workaround this limitations, a Webhook Token Authentication can be configured. The Kube APIServer then sends the Bearer Tokens (id token) to an external webhook for validation: Where upon verification, the remote webhook returns the identity of the user (if authentication succeeds): This repository is the out-of tree implementation of Dynamic Authentication KEP. Use cases - Establish trust relationship between different Kubernetes clusters using Service Account Token Volume Projection and Service Account Issuer Discovery. - Offer cluster admins the option to dynamically allow users from other OIDC IDPs to authenticate against their kube-apiserver . How it works This webhook is a K","default_branch":null,"files":null,"tree":[],"storefront":"/r/gardener","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gardener/oidc-webhook-authenticator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}