Arbitrary issuers and claims for federated credentials [GA]
- 主要语言
- 没有语言数据
- 星标
- 8.9k
- 派生
- 1.8k
- PR 合并指标
- 30 天内没有已合并 PR
描述
### Value Prop
You can now authenticate GitHub Apps using any compatible identity provider — including SPIFFE, Okta, GCP, AWS, Kubernetes clusters, and more — instead of managing private keys. Configure any issuer and claims that fit your infrastructure, and use federated credentials to mint installation tokens for your app's installations. This gives every team, regardless of their technology stack, a secure and flexible alternative to long-lived private keys.
### Expected Outcome
Developers and platform teams can eliminate the operational burden of storing, rotating, and securing GitHub App private keys by integrating directly with the identity providers already powering their infrastructure. By extending federated credential support to any compatible issuer, GitHub Apps fit naturally into modern zero-trust and cloud-native environments. The result is a more secure authentication model that reduces credential sprawl and scales with the diversity of real-world infrastructure setups.
贡献指南
调研方向
此路线图条目没有指出应首先检查的仓库文件、测试或实现入口点。以 GitHub App 联合凭据身份验证领域作为起始范围;当兼容的任意 issuer 和 claims 无需私钥即可签发 installation tokens 时,这项工作就完成了。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- github
- 领域
- authentication, security
- Issue 类型
- 功能
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 30/100