{"repo":"truster-dev/truster","free":true,"listed":false,"github":"https://github.com/truster-dev/truster","clone":"git clone https://github.com/truster-dev/truster.git","description":"Truster is an open source OIDC issuer for authenticating users and services to your apps or Kubernetes clusters, using an upstream auth provider you trust","language":"Go","stars":36,"topics":["kubernetes","oauth","oauth2","oidc","oidc-server"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Truster Truster is designed to make setting up and operating an OIDC server straightforward: - Supports Google/GitHub/other OIDC providers, or OTP email login. - No passwords stored in its database. - Stores state in SQLite (default), or an external PostgreSQL database for horizontal scaling. - Policy configuration (like mapping users to groups) can be in a config file, or queried from any PostgreSQL database (even when SQLite is used for state). - Can be used for Kubernetes control plane auth, simplifying RBAC. - All HTML page and email templates can be customised without rebuilding the binary. - Can run on a single VM instance for minimal cost. Use Truster if you: - want users to sign in with accounts they already have; - want to manage email-to-group mapping policies in config files in git, or a database; - want a small, self-hosted login service; and - use Kubernetes RBAC to decide what each group can do, or just need an OIDC service for your app. Official OpenTofu/Terraform modules are available for AWS and Google Cloud, and an OCI Helm chart is published for each release. See Why Truster? for its intended scope and operational limits. Try it locally You can see the complete email-code sign-in flow without a cloud account. You need Go, kubelogin, and three terminals. Start Mailpit in the first terminal. It captures the demo email instead of sending it for real: Start Truster in the second terminal: Then begin a login: Your browser will ask for an email address. Enter any","default_branch":null,"files":null,"tree":[],"storefront":"/r/truster-dev","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/truster-dev/truster/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}