{"repo":"openkube-hub/KubeUser","free":true,"listed":false,"github":"https://github.com/openkube-hub/KubeUser","clone":"git clone https://github.com/openkube-hub/KubeUser.git","description":"Kubernetes-native user management operator","language":"Go","stars":98,"topics":["authentication","authorization","certificate-management","crd","csr","kubeconfig","kubernetes","rbac","user-management","x509"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"KubeUser KubeUser is a Kubernetes-native way to manage users, certificates, RBAC, and kubeconfigs declaratively — without running an external identity provider. --- Overview Managing Kubernetes access often means manually creating kubeconfigs, handling certificates, and keeping RBAC in sync. This quickly becomes error-prone, hard to audit, and unfriendly to GitOps workflows. KubeUser solves this by managing Kubernetes users through declarative custom resources. It automatically generates and rotates certificates, applies RBAC bindings, and produces ready-to-use kubeconfigs using native Kubernetes APIs. Designed for small teams and self-managed clusters that want Kubernetes-native, GitOps-friendly access control without a full IAM or OIDC stack. Not a replacement for enterprise identity providers. Architecture --- Quickstart Try KubeUser in a few commands on any cluster with a working kubectl context: For production installs, see Installation below. --- Features ✅ Implemented - [x] Declarative User CRD — status tracking, conditions, and finalizers for clean resource lifecycles - [x] Automatic Certificate Generation — seamless integration with the Kubernetes CSR API - [x] Stateful Rotation Engine — resumable, multi-step rotation via the Shadow Secret pattern; survives controller restarts - [x] Atomic Secret Updates — zero-downtime credential flip with rollback on failure - [x] Dynamic RBAC Reconciliation — automatic RoleBinding and ClusterRoleBinding management - [x] Mutating &","default_branch":null,"files":null,"tree":[],"storefront":"/r/openkube-hub","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/openkube-hub/KubeUser/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}