Sign inSign up

antstanley80/oidc-exchange

By antstanley80

•Updated about 1 month ago

Validate provider ID tokens and issue your own access/refresh JWTs

Image
0

1.5K

antstanley80/oidc-exchange repository overview

⁠oidc-exchange

Validate ID tokens from third-party OIDC providers (Google, Apple, …) and exchange them for self-issued access and refresh tokens — a single Rust binary that runs as a long-lived HTTP server (or an AWS Lambda function).

⁠Image

Multi-arch (linux/amd64, linux/arm64), published to both registries:

  • Docker Hub — antstanley80/oidc-exchange
  • GHCR — ghcr.io/antstanley/oidc-exchange

Tags: latest, X.Y.Z, X.Y, X.

The GHCR multi-arch tag has build provenance for its immutable final manifest digest (in addition to each platform digest). Verify the final GHCR manifest before running it:

gh attestation verify oci://ghcr.io/antstanley/oidc-exchange:latest \
  --repo antstanley/oidc-exchange \
  --signer-workflow antstanley/oidc-exchange/.github/workflows/release.yml
docker pull ghcr.io/antstanley/oidc-exchange:latest

This is GitHub build provenance, not a registry signature. The release is also copied to Docker Hub, but the workflow does not attach or promise a Docker Hub-verifiable attestation; use GHCR for this verification path.

⁠Run

docker run -p 8080:8080 \
  -v "$(pwd)/config.toml:/app/config.toml:ro" \
  antstanley80/oidc-exchange:latest

The server listens on the port from your config (default 8080) and exposes /token, /revoke, /keys, /.well-known/openid-configuration, and /health.

⁠Configure

Mount a config.toml (as above) and/or override values with environment variables (OIDC_EXCHANGE__{section}__{key}); ${VAR} placeholders in the TOML resolve from the environment. Minimal example:

[server]
host = "0.0.0.0"
port = 8080
issuer = "https://auth.example.com"

[providers.google]
adapter = "oidc"
issuer = "https://accounts.google.com"
client_id = "${GOOGLE_CLIENT_ID}"
client_secret = "${GOOGLE_CLIENT_SECRET}"
# Origins Google's discovery document may name beyond the issuer's origin:
endpoint_origins = ["https://oauth2.googleapis.com", "https://www.googleapis.com"]

endpoint_origins pins which origins a provider's discovery document is allowed to name; each entry must be a bare https://host[:port], and an unpinned origin logs a warning when discovered.

See the full configuration guide⁠ and the deployment guides⁠ (ECS Fargate, generic container / Kubernetes, …).

Images are built multi-arch on native runners and published from CI. MIT licensed.

Tag summary

Content type

Image

Digest

sha256:a505cdc38…

Size

49.1 MB

Last updated

about 1 month ago

docker pull antstanley80/oidc-exchange