Kuadrant/authorino

K8s-native AuthN/AuthZ service to protect your APIs.

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 5 minutes ago
Added to GitGenius on January 24th, 2025
Created on December 22nd, 2020
Open Issues & Pull Requests: 48 (+0)
Number of forks: 53
Total Stargazers: 266 (+0)
Total Subscribers: 7 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 4.9 days
Mean response time: 194.6 days
90th percentile: 655.0 days
Tracked items: 55

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 43% of open issues come from outside the core team, a mix of external reports and the maintainers' own roadmap. Only 7% of issues opened in the past year have been closed. Three people close 78% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 30
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 645 days
Stale 30+ days: 28
Stale 90+ days: 23

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • kind/enhancement (17)
  • participation/good first issue (16)
  • area/api (10)
  • size/medium (9)
  • size/small (9)
  • area/implementation (7)
  • area/tooling (5)
  • kind/bug (5)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

Authorino is a Kubernetes-native authorization service designed to protect APIs through external authorization enforcement with Envoy Proxy. Written in Go, it functions as a lightweight external authorization server that is fully manageable via Kubernetes Custom Resources, eliminating the need for application code changes or rebuilds to implement authentication and authorization policies.

The service implements Envoy Proxy's external authorization gRPC protocol and is part of the Red Hat Kuadrant architecture. It operates on Kubernetes Custom Resource Definitions and the Operator pattern, allowing users to define authorization policies through an AuthConfig custom resource. Authorino supports multiple authentication methods including JWT authentication, API keys, mutual TLS, Kubernetes service account tokens, and integrates with external identity providers through OpenID Connect Discovery.

For authorization, Authorino provides pattern-matching rules against JSON data structures, Open Policy Agent Rego policies, and Kubernetes RBAC enforcement through the SubjectAccessReview API. The service can fetch additional metadata from external sources during the authorization process and supports injecting authentication data back into requests via HTTP headers, Wristband tokens, and rate-limit metadata. It can also function as a ValidatingWebhook service for Kubernetes control plane protection.

The authentication and authorization workflow follows a multi-phase pipeline. When a request arrives at the Envoy ingress, Authorino performs identity verification through at least one authentication method, optionally fetches external metadata, evaluates user-defined authorization policies against a composed JSON object containing context data and identity information, and returns either approval or denial along with optional dynamic metadata.

The service is designed as multi-tenant and cloud-native, supporting hybrid API security models where organizations can combine their preferred authentication standards and authorization policies without requiring application modifications. Deployment can follow various topologies including centralized gateways, centralized authorization services, or sidecar patterns depending on organizational needs.