# Is GitHub the only authentication?

**URL:** <https://forums.suse.com/t/is-github-the-only-authentication/185>\
**Category:** Rancher 1.x\
**Created:** [July 29, 2015, 9:59pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185 "2015-07-29T21:59:15Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [July 29, 2015, 9:59pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/1 "2015-07-29T21:59:15Z")

</div>

I set up an instance of Rancher, got it working, really like it. Looking forward to putting it in front of the Ops team later this week to early next.

But is there no authentication other than github? That would be a real showstopper with this team. A production environment running in our own data centre with sensitive data… no way they will agree to let authentication go outside. We would handle LDAP, although we would be perfectly fine with user/pass with a local user database (which is simplest).

Is there no easy way to secure it for enterprise environments?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 29, 2015, 10:17pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/2 "2015-07-29T22:17:02Z")

</div>

We are working on LDAP/AD support right now. The only other option today is GitHub Enterprise, which you could run on-premise.

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [July 30, 2015, 6:07am UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/3 "2015-07-30T06:07:43Z")

</div>

I love GitHub, use it extensively, but for the right projects. I think GitHub is fabulous for your development, and your cycle, and even your deploy. But that cycle is not production. Production is what you get once you have done all of those and deployed… and Rancher is built to manage those servers and containers, so depending on an external service is a really tough sell, except in GitHub-centric environments.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 30, 2015, 7:02am UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/4 "2015-07-30T07:02:47Z")

</div>

I understand, and this is why we’re adding LDAP. But we started with Github because:

- Most people don’t want to maintain an extra source of truth, passwords, etc for users and group membership just for Rancher.
- Most dev & ops types have GitHub accounts already.
- A lot of them already use it to manage their code and have teams defined.
- Smaller companies, startups, and individuals testing Rancher don’t have LDAP servers.
- Bigger companies often have GitHub Enterprise on-premise instead, configured to support LDAP, SAML, or whatever else they use internally. So we get integration into their auth for free if they use GHE.

Not trying to change your mind or anything, but FYI on the way it works:

- We are using OAuth to GitHub to get user and team/org membership info and associating those to accounts and environments in Rancher.
- It does not give GitHub any control over Rancher (other than not being able to login if they are down/unresponsive).
- It does not give Rancher any control over your GitHub account (we request read-only access to the minimal basic user profile and team info).
- It does not give us (Rancher Labs, the company) any info about you.
- It does not mean your rancher/server has to be exposed to the inbound public internet.

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [July 30, 2015, 1:54pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/5 "2015-07-30T13:54:55Z")

</div>

I get what you are saying. IMHO this is one of those cases where Docker’s development-side roots come through, even when trying to do something operations.

Authenticating against GitHub is fine in one of two cases:

1. You are doing something development - after all, GH is part of your dev cycle
2. You are in an extremely small team

The moment those are not true - you have multiple teams with separate responsibilities, e.g. development and ops, let alone you are working in the operational space - relying on GitHub to manage your internal production operations, not development or new deployments, makes many people very nervous and completely breaks their actual flows and processes.

How would I tell an ops team of 5 people to go set up github (or bitbucket or …) accounts so they can manage their operational environment? They would laugh me out of the room. The developers? They would love it. But the ops? Never.

So, yeah, LDAP works for a team that has enterprise infrastructure and authentication, but that makes the initial setup and integration curve much higher. I am setting up a basic structure for a team, let them choose among multiple orchestrators… and I have no easy way to just get them going. I am not going to get them github accounts (for production use or for testing), nor would they agree, and setting up an LDAP server just for this is kind of crazy.

---

<div class="post-metadata">

**Author:** ![willchan](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/willchan/32/2856_2.png) [@willchan](https://forums.suse.com/u/willchan)\
**Post date:** [July 30, 2015, 2:45pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/6 "2015-07-30T14:45:39Z")

</div>

You are not the only person to ask for local auth. As part of the LDAP feature we are developing, we have also created an Identity API that we can use to plug any type of backend auth system without any major code refactoring. We will add local auth fairly soon, most likely in a couple of weeks. I’ve added a feature bug to track this and added it to our next milestone so we can talk about it and get it started as soon as possible.

[https://github.com/rancher/rancher/issues/1687](https://github.com/rancher/rancher/issues/1687)

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [July 30, 2015, 3:03pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/7 "2015-07-30T15:03:01Z")

</div>

Got it. Rancher really is quite impressive… but sometimes it is the simplest things that it needs.

---

<div class="post-metadata">

**Author:** ![gregory](https://avatars.discourse-cdn.com/v4/letter/g/e56c9b/32.png) [@gregory](https://forums.suse.com/u/gregory)\
**Post date:** [August 6, 2015, 4:34pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/8 "2015-08-06T16:34:41Z")

</div>

would be awesome to get an authentication service based on jwt just like they did with the docker registry:

> **[Token Authentication Specification](https://docs.docker.com/registry/spec/auth/token/)**
>
> Docker Registry v2 authentication via central service This document outlines the v2 Docker registry authentication scheme: Attempt to begin a push/pull operation with the registry. If the registry requires authorization...

that way, anyone could implement their own system: no more complain.

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [August 6, 2015, 5:45pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/9 "2015-08-06T17:45:18Z")

</div>

I was not overly enamoured of the auth token based system for the docker registry, but maybe because I was just expecting something simpler.

Is there an open-source “runs in an image” auth server that works for it? Hmm, you know, if an auth token server could serve both rancher and a registry (and other things) and be easy to run (in docker), well, that would be interesting

---

<div class="post-metadata">

**Author:** ![gregory](https://avatars.discourse-cdn.com/v4/letter/g/e56c9b/32.png) [@gregory](https://forums.suse.com/u/gregory)\
**Post date:** [August 10, 2015, 3:34pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/10 "2015-08-10T15:34:35Z")

</div>

I’ll use [https://github.com/SUSE/Portus](https://github.com/SUSE/Portus) for the authentication of my private registry. This could be patched if needed to work with rancher.

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [August 10, 2015, 6:24pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/11 "2015-08-10T18:24:16Z")

</div>

You got Portus to work? I found its documentation to be terrible. Sure, it has a compose file for the whole thing in dev mode, but getting its two containers (web & db) set up an initialized is a pain. I didn’t want to read the source code to figure it out.

I was looking at going with [https://github.com/cesanta/docker\_auth](https://github.com/cesanta/docker_auth) despite its mixing auth/auth and config file, and despite its rigid model, just to get something that works easily.

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [August 26, 2015, 6:50am UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/12 "2015-08-26T06:50:23Z")

</div>

Where do we stand on either LDAP/AD or local auth? I can live with either, but I would say this is the major thing holding up a team looking to deploy in both IT and Production.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [August 26, 2015, 9:08am UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/13 "2015-08-26T09:08:25Z")

</div>

LDAP is in yesterday’s 0.34 release.

---

<div class="post-metadata">

**Author:** ![forums](https://avatars.discourse-cdn.com/v4/letter/f/ed8c4c/32.png) [@forums](https://forums.suse.com/u/forums)\
**Post date:** [August 26, 2015, 2:55pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/14 "2015-08-26T14:55:18Z")

</div>

I highly recommend going to to the Announcements section of our Forums, [http://forums.suse.com/c/announcements](http://forums.suse.com/c/announcements) and setting it to “Watching” so that you will be automatically notified of new releases which include summaries of the release notes.

![](https://us1.discourse-cdn.com/flex022/uploads/suse/original/1X/0b40184c508259cfc2a577558049f23e3f3f78a7.png)

---

<div class="post-metadata">

**Author:** ![deitch](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/deitch/32/40_2.png) [@deitch](https://forums.suse.com/u/deitch)\
**Post date:** [August 30, 2015, 9:24am UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/15 "2015-08-30T09:24:31Z")

</div>

Good idea, thanks. I did it.

---

<div class="post-metadata">

**Author:** ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)\
**Post date:** [September 1, 2015, 4:51pm UTC](https://forums.suse.com/t/is-github-the-only-authentication/185/16 "2015-09-01T16:51:38Z")

</div>


