6 ms·
Show HN: Oathkeeper – Cloud-Native Identity and Access Proxy
- ibuildoss 8y agoThe idea of the ory ecosystem ( https://github.com/ory https://github.com/ory / https://www.ory.am https://www.ory.am ) is to build a reliable, cloud native suite of tools which allow you to solve simple and complex IAM (identity and access management) use cases. Each service works standalone, but you can obviously combine them all. The Oathkeeper proxy is one piece of the puzzle which basically takes incoming HTTP requests, evaluates them on a set of rules (e.g. authentication of credentials used, checking if the user has the right permissions, transforming the session data to a e.g. JWT) and either grants or denies access. Other services include, for example, ORY Hydra ( https://github.com/ory/hydra https://github.com/ory/hydra ) which is an OAuth2 & OpenID Connect (certification pending) server that you can put "on top" of your existing user management. While most developers opt to build these systems (permissions, user management) themselves, it is our vision to build a reliable, broadly adopted set of OSS tools that get you started quickly and that scale well as the requirements of your organization change. Everything we do is build on top of open standards, we do not want to reinvent the wheel (unless nothing exists wrt to open standards). So everything in this ecosystem integrates well with existing systems. If you have any questions, feel free to ask. ps: New account because I lost my password and didn't set up a backup email. Stupid me.
- wsy 8y agoI really like this suite of projects, it splits the problem nicely into flexible building blocks. How do you envision integration of existing external OAuth2 or OpenID Connect servers, such as Google, GitHub, etc., or an OAuth2-compliant directory of a B2B customer?
- ibuildoss 8y agoWe're currently starting to work on ORY Hive (project name wip) which is going to be a fully functional identity management service (user registration, login, social sign in, password reset, MFA, ...) sort of along the lines of Auth0 or AWS Cognito, but as an OSS solution. As part of that service, we will add connectivity adapters for generic OAuth2/OIDC providers as well as (probably) LDAP/AD and SAML integration. We're still in prototyping phase (building a good API here is really tricky because no open standards exist to our knowledge for this) and it will take some time. But hopefully, it will be something many people can build on! And thank you so much for the positive feedback :)
- wsy 8y agoThanks for the info, looking forward to your new project!
- antoncohen 8y agoThat sounds awesome! I'd really like to see organizational management, i.e., users in orgs. It is something most B2B SaaS apps have to do, and they tend to do it differently and often very poorly. Maybe it is out of the scope of ORY Hive, but I think it would be really useful. I'm thinking it would tie into an RBAC system to give users different permissions within orgs (member, admin, owner, etc.). There are two main patterns for B2B apps: - One org per user, like G Suite. A user is a member of a single org, to be a member of another org requires another user account. This creates a challenge when it is a system where someone might be a member of multiple orgs, because it requires logging in as multiple users and having cookies that can handle that. - One user in many orgs, like GitHub. A users "owns" their user account, and is invited to one or more orgs. This makes working in multiple orgs easier, but can create challenges for companies that want to enforce things within their org, like SSO or 2FA. It also creates issues with routing of notifications (you want work notifications going to work email), and identity of users within a company (an org admin may have trouble identifying users if they aren't tied to company emails). An ecosystem like ORY obviously can't alleviate all the issues, but maybe it can help with some of them, like org membership and org friendly cookies.
- ibuildoss 8y agoGood use cases, we in fact are looking at multi-tenancy or "realms" but have not progressed very far here as it can get quite complicated. One major issue with true multi-tenancy is obviously data isolation, so usually you don't want data to "bleed" from tenant a to tenant b (think G Suite) whereas in other systems it's not truly a tenant but more of a business entity that shares users. I think in the end it boils down to what we can solve in a generic manner and what we can let developers solve for themselves. The distinction between the two use cases is definitely something we'll take a closer look at and include in our design decisions, so this won't be an afterthought but something built into the architecture! Thank you for your constructive feedback!
- jsiepkes 8y agoThis solution seems comparable to running Envoy Proxy as a reverse / frontend proxy with a JWT filter. Would you say that's a fair comparison? What would you say are the benefits of using this over such an Envoy setup with Envoy becoming so popular? Super excited to see more players move in this space btw!
- ibuildoss 8y agoI have not used envoy extensively yet, but there are obviously many more options such as Apache2 + mod_oidc, Kong + oauth2 plugin, and so on. The main differentiator is that Oathkeeper is capable of performing more sophisticated permission checks (think RBAC / AWS IAM Policies) and is specifically geared towards solving authentication and authorization in front of "your" service. Most other implementations I saw (and I think this also goes a bit for envoy) is that they solve access control as one of the things in the feature set, while also focusing strongly on routing, load balancing, and other typical API gateway issues. We're explicitly not trying to build another API gateway but instead something that you deploy alongside your existing API gateway (or maybe as a sidecar) with the sole purpose of checking answering: "is the request that's coming through really allowed to perform that action?". Hope this clarifies it, if not I'm more than happy to go into more detail :)
- joeyspn 8y agoSeems like you are describing Ambassador here [0]. I think this could play nice as Ambassador's external auth service [1]. Oathkeeper looks very interesting... Congrats and best of luck! [0] https://www.getambassador.io https://www.getambassador.io [1] https://www.getambassador.io/reference/services/auth-service https://www.getambassador.io/reference/services/auth-service
- ibuildoss 8y agoNice, I have heard about Ambassador before but did not have the time to look into it in detail. It is just amazing how much OSS is being created around the k8s/container ecosystem and I truly believe that it will greatly improve our lives as developers in the future. I've added this to our internal list and we will check it out and see if any synergies are possible with our products. Our vision is that these services work so well and easy with the rest of the ecosystem, that you can get started with a new project in a day or two and have everything set up - from users, to permissions, to routing (e.g. via ambassador), to testing (there's still ton of space for this), and so on. I think the journey of software development beyond 2020 will be very exciting! ps: Sorry for slow responses, HN has a very high post wait time once you hit the limit. And thank you for the positive vibes :)
- amaccuish 8y agoCan ORY Hydra connect to an LDAP (AD) backend? We've got SAML setup here but I'd love to be able to support OpenID Connect too.
- ibuildoss 8y agoYes, ORY Hydra has a flow that allows you to integrate with any identity solution, be it AD/LDAP, SAML, or your custom database-backed app!
- deleted 8y ago[deleted]
- jiveturkey 8y ago> solve simple and complex IAM really great. please comment on the intersection with auth0. clearly there is some overlap, it would be great to have a concise explanation. > we do not want to reinvent the wheel IMHO, were I you I would not shy away from that. Existing wheels are oval in shape. Of course where you have to interoperate, you are limited. > ps: New account because I lost my password and didn't set up a backup email. Stupid me. Well you just lost me. You are developing IAM components and you can't get basic password management correct? email has nothing to do with it, we are well past the point where password managers are de rigueur, certainly for anyone involved with security matters.
- ibuildoss 8y ago> Well you just lost me. You are developing IAM components and you can't get basic password management correct? email has nothing to do with it, we are well past the point where password managers are de rigueur, certainly for anyone involved with security matters. The password in my password manager is not correct. No idea how that happened, maybe it was overwritten by accident or I copied the wrong one during account creation. Since I had to reset my FF profile it was no longer stored in the FF password manager, so I had to recover it from KeePass, which well - didn't work out so well. Since I do use a password manager, it's impossible to recover it as I have no idea what the password is.
- mderazon 8y agoA bit extreme don't you think ? He's human and people lose access to old accounts from time to time... Has nothing to do with the fact he's developing auth software. Besides, HN does not do oauth. If it did and he would still lose access then it's a different story ;-)
- NateDad 8y agoGetting the wrong password in your password manager happens occasionally. Usually from password resets that somehow don't make it into your password manager. The fact that HN allows accounts without email addresses is the real problem. Also, maybe he just doesn't value his HN account all that much.
- dcosson 8y agoThis is a cool project, I'll definitely keep an eye on it. I've long wished that something framework & language agnostic like this existed. One suggestion for the docs, especially since the tagline is that this is a cloud-native solution, would be examples of how to run it in common cloud setups. For instance I'm looking at the deployment page and it mentions that in the gateway configuration you'll want to run it behind a load balancer but in front of the API router. But if you're using an ELB, which as far as I'm aware is still part of basically the default way to run web apps on AWS, the load balancer and router are combined and there's no way to hook something like this in. So it would be cool to see some examples involving specific tools like ELBs, maybe a note on other ways to run it if using Kubernetes, etc.
- ibuildoss 8y agoThat's a really good point! I've tracked this as https://github.com/ory/docs/issues/29 https://github.com/ory/docs/issues/29 We're a very small team, so it might take a while for us to tackle this (especially because we mostly use k8s with oathkeeper proxy as a sidecar), but that does make this not lesser of an issue!
- stedaniels 8y agoWhere is the ORY Security Console hidden? I can't see it on GitHub and all links lead to a running instance of it? Is this how you're hoping to monetise all your hard work? I don't begrudge that at all :-) It's just a little unclear? If there's going to be a security console, I wouldn't want it hosted by anyone else. Especially if I'm the type of person to deploy all the other components I'll undoubtedly want to deploy the console myself. [EDIT] There's also some on by default telemetry.. and the link for details is 404'ing: https://github.com/ory/oathkeeper#telemetry https://github.com/ory/oathkeeper#telemetry -> https://www.ory.sh/docs/guides/latest/9-telemetry https://www.ory.sh/docs/guides/latest/9-telemetry I might not mind this, but I can't tell if the links don't go anywhere. I don't want to sound negative, other than these queries the ORY ecosystem looks lovely and something I might implement. Cheers
- codeisawesome 8y agoThanks for bringing this up, I would not have looked for it.
- danielcb 8y agoanything regarding this? Would also be interested if you plan releasing the console, i.e. allow a fully self-hosted usage.
- wvh 8y agoI just wrote a simple proxy myself that takes an OIDC authenticated user and forwards the request to backend servers if their session is valid. It only took me two days to get this proxy functionality up and running, but of course the main application itself was handling all of the authentication, authorisation and session stuff already. It's good to know there's an option to do this in the future for projects that don't have all that groundwork done already, if this is easy to set up – at least initally – without having to include all the parts of the ecosystem.
- SauciestGNU 8y agoAre you aware that this project shares a name with an extremist group[0]? I'm not sure how concerned you are about that, especially if you're not American, but I'd want to know if it were one of my projects. [0]https://www.splcenter.org/fighting-hate/extremist-files/group/oath-keepers https://www.splcenter.org/fighting-hate/extremist-files/grou...
- ibuildoss 8y agoIt is extremely important to be sensitive to extremism of any kind, condemn extremist practices, beliefs, and views and take a stance against extremist ideologies. We do not share nor endorse extremist views nor "values", nor have anything to do with extremist groups whatsoever. We have not heard about them (Oath Keepers) before. We'll discuss a name change internally & with the community. ps: It also shares the name of the sword from Game of Thrones and is a wordplay on OAuth :) edit:// Forgot to thank you for raising awareness on this.
- andymockli 8y agoJust to clarify, are you speaking for the team to condemn extremism in general, or the specific belief in upholding the U.S. Constitution within the U.S., or something else? Maybe I should pay attention to the discussion with the community when that occurs, but I'm interested in which "values" you take issue with. Care to share here?
- wereHamster 8y agoI'm currently looking how to protect internal websites used within our company behind github oauth (we're a small company and we all have a github account connected to the company's github organization). Would this or one of the other tools that are part of the ory ecosystem work for this?
- ibuildoss 8y agoYes, this could definitely solve that. Another service which might be well suited for this specific task is: https://github.com/bitly/oauth2_proxy https://github.com/bitly/oauth2_proxy
- matthew-wegner 8y agoCloudFlare has a product for this, at $3/person/month: https://www.cloudflare.com/products/cloudflare-access/ https://www.cloudflare.com/products/cloudflare-access/
- avitzurel 8y agoI built this [1] exactly for what you are describing [1] https://github.com/KensoDev/micro-auth-proxy https://github.com/KensoDev/micro-auth-proxy
- Rain4CNCF 8y agoCoreOS's Dex would work for that: https://github.com/coreos/dex https://github.com/coreos/dex
- ibuildoss 8y agoThe day is coming to an end here, I'll try to monitor this thread but in case you don't get an answer from me any more, you will definitely get one in the community forums or chat by tomorrow: - Forums: https://community.ory.am/ https://community.ory.am/ - Chat: https://discord.gg/PAMQWkr https://discord.gg/PAMQWkr Thank you all for the awesome discussions!
- youdontknowtho 8y agoI'm really excited to try this out. Microsoft's Azure App Proxy is a great technology, but it has licensing constraints that make it difficult to use with all user personas.
- colemickens 8y agoDo you have a Slack? I'm interested in OIDC and have some questions and interest in the user management component that is mentioned to be in the works.
- romanminkin 8y agoThey have Discord https://discord.gg/PAMQWkr https://discord.gg/PAMQWkr
- WilliG 8y agoWas useful to read, tnx. I started using this proxy https://buy.fineproxy.org/eng/usa-proxy.html https://buy.fineproxy.org/eng/usa-proxy.html recently and I have no complaints at all. It has the highest posible speed and competitive prixe. It's probably best proxy I ever used.