Arbitrary issuers and claims for federated credentials [GA]
- Vorherrschende Sprache
- Keine Sprachdaten
- Sterne
- 8.9k
- Forks
- 1.8k
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### Value Prop
You can now authenticate GitHub Apps using any compatible identity provider — including SPIFFE, Okta, GCP, AWS, Kubernetes clusters, and more — instead of managing private keys. Configure any issuer and claims that fit your infrastructure, and use federated credentials to mint installation tokens for your app's installations. This gives every team, regardless of their technology stack, a secure and flexible alternative to long-lived private keys.
### Expected Outcome
Developers and platform teams can eliminate the operational burden of storing, rotating, and securing GitHub App private keys by integrating directly with the identity providers already powering their infrastructure. By extending federated credential support to any compatible issuer, GitHub Apps fit naturally into modern zero-trust and cloud-native environments. The result is a more secure authentication model that reduces credential sprawl and scales with the diversity of real-world infrastructure setups.
Beitragsleitfaden
Rechercherichtung
This roadmap entry does not identify repository files, tests, or implementation entry points to inspect first. Use the GitHub App federated-credential authentication area as the starting scope; the work is done when compatible arbitrary issuers and claims can mint installation tokens without private keys.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- github
- Bereich
- authentication, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Ruhig
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 30/100