GitHub
Use GitHub as an OAuth 2.0 identity provider for Pomerium-protected applications with a registered callback, client ID, and client secret.
Overview
GitHub is a source-code hosting and development platform. Pomerium can use GitHub.com as an OAuth 2.0 identity provider. This route is separate from GitHub Enterprise Server.
GitHub sign-in gives development teams a familiar identity path for private tools. Pomerium keeps application access policy separate from GitHub repository authorization.
GitHub authenticates the user through OAuth 2.0. Pomerium uses the returned identity for route policy and then sends approved application traffic to the protected service.
How it works
Register a GitHub OAuth app with the Pomerium homepage and exact /oauth2/callback URL.
Configure Pomerium with the github provider key, client ID, and client secret. Keep the secret outside source control.
Pomerium Enterprise directory sync can use a personal access token with read:org and user:email when policy needs GitHub organization data.
Example
A team registers one GitHub OAuth app for Pomerium. Users sign in with GitHub. Pomerium uses the returned identity and route policy before it sends approved traffic to private applications.
Considerations
- GitHub OAuth apps do not issue OpenID Connect ID tokens.
- A GitHub OAuth app accepts one callback URL.
- This route supplies login identity. It does not protect GitHub or replace repository permissions.
