Arbitrary issuers and claims for federated credentials [GA]
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 8.9k
- Fork
- 1.8k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Descrizione
### Value Prop
You can now authenticate GitHub Apps using any compatible identity provider — including SPIFFE, Okta, GCP, AWS, Kubernetes clusters, and more — instead of managing private keys. Configure any issuer and claims that fit your infrastructure, and use federated credentials to mint installation tokens for your app's installations. This gives every team, regardless of their technology stack, a secure and flexible alternative to long-lived private keys.
### Expected Outcome
Developers and platform teams can eliminate the operational burden of storing, rotating, and securing GitHub App private keys by integrating directly with the identity providers already powering their infrastructure. By extending federated credential support to any compatible issuer, GitHub Apps fit naturally into modern zero-trust and cloud-native environments. The result is a more secure authentication model that reduces credential sprawl and scales with the diversity of real-world infrastructure setups.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
This roadmap entry does not identify repository files, tests, or implementation entry points to inspect first. Use the GitHub App federated-credential authentication area as the starting scope; the work is done when compatible arbitrary issuers and claims can mint installation tokens without private keys.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- github
- Ambito
- authentication, security
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Tranquilla
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 30/100