tailscale / tailscale/tsidp

tsidp to connect with workload identity federation

Open
#116 0 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
Go
Stars
669
Forks
61
Avg merge
6d 6h
Merged PRs (30d)
3

Description

I didnt find out from the readme if it possible but if it isnt it would be nice for tsidp to connect via OpenID to the tailnet https://tailscale.com/kb/1581/workload-identity-federation

if tsidp is running in a cloud provider with openid support then you don't need to use the long lived auth tokens

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the README to determine what authentication methods tsidp currently documents, then read the linked Tailscale workload identity federation documentation. Clarify the expected OpenID flow and its cloud-provider assumptions before implementation. Done should allow tsidp to connect to the tailnet without long-lived auth tokens.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
authentication
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.