Arbitrary issuers and claims for federated credentials [GA]
- Langage dominant
- Aucune donnée de langage
- Étoiles
- 8.9k
- Forks
- 1.8k
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
### Value Prop
You can now authenticate GitHub Apps using any compatible identity provider — including SPIFFE, Okta, GCP, AWS, Kubernetes clusters, and more — instead of managing private keys. Configure any issuer and claims that fit your infrastructure, and use federated credentials to mint installation tokens for your app's installations. This gives every team, regardless of their technology stack, a secure and flexible alternative to long-lived private keys.
### Expected Outcome
Developers and platform teams can eliminate the operational burden of storing, rotating, and securing GitHub App private keys by integrating directly with the identity providers already powering their infrastructure. By extending federated credential support to any compatible issuer, GitHub Apps fit naturally into modern zero-trust and cloud-native environments. The result is a more secure authentication model that reduces credential sprawl and scales with the diversity of real-world infrastructure setups.
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
This roadmap entry does not identify repository files, tests, or implementation entry points to inspect first. Use the GitHub App federated-credential authentication area as the starting scope; the work is done when compatible arbitrary issuers and claims can mint installation tokens without private keys.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- github
- Domaine
- authentication, security
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- Calme
- Clarté
- À clarifier
- Accessibilité débutants
- 30/100