{"repo":"sorah/sts-cat","free":true,"listed":false,"github":"https://github.com/sorah/sts-cat","clone":"git clone https://github.com/sorah/sts-cat.git","description":"Yet another GitHub STS, aims to allow easy self-host and be cloud-agnostic","language":"Rust","stars":12,"topics":[],"license":"Apache-2.0","category":"self-hosted-apps","readme_excerpt":"sts-cat OIDC-to-GitHub-token exchange service. A Rust reimplementation of octo-sts designed for easy self-hosting and being cloud-agnostic. Currently supports AWS (Lambda, KMS) natively, or any environment with a plain HTTP server binary and private keys on flat files. sts-cat accepts OIDC ID tokens from any identity provider, validates them against trust policies stored in GitHub repositories, and returns scoped GitHub installation access tokens. Setup Prerequisites - A GitHub App with the desired permissions, and installed on target repositories - The GitHub App's private key Configuration All configuration is via environment variables: Variable Required Description --- --- --- STS CAT GITHUB APP ID Yes GitHub App ID STS CAT IDENTIFIER Yes Identifier used as default audience (e.g. https://sts.example.com ) STS CAT GITHUB API URL No GitHub API base URL (default: https://api.github.com ) HOST No Listen host (default: 0.0.0.0 ). Ignored in Lambda mode. PORT No Listen port (default: 8080 ). Ignored in Lambda mode. STS CAT LOG JSON No Enable JSON-formatted logging STS CAT KEY SOURCE Yes Signing key source: file , env , or aws-kms STS CAT KEY FILE When file Path to the GitHub App PEM private key STS CAT KEY ENV When env Name of env var containing the PEM private key STS CAT AWS KMS KEY ARN When aws-kms ARN of the AWS KMS asymmetric signing key STS CAT POLICY PATH PREFIX No Path prefix within repos for trust policy files (default: .github/sts-cat ) STS CAT POLICY FILE EXTENSION No","default_branch":null,"files":null,"tree":[],"storefront":"/r/sorah","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sorah/sts-cat/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}