{"id":22479126,"url":"https://github.com/jsiebens/tskeyservice","last_synced_at":"2025-08-02T14:32:06.097Z","repository":{"id":65194399,"uuid":"563294165","full_name":"jsiebens/tskeyservice","owner":"jsiebens","description":"A lightweight service exchanging OIDC tokens for Tailscale Auth Keys","archived":false,"fork":false,"pushed_at":"2023-04-28T14:29:14.000Z","size":37,"stargazers_count":22,"open_issues_count":0,"forks_count":1,"subscribers_count":4,"default_branch":"main","last_synced_at":"2024-06-19T13:41:11.432Z","etag":null,"topics":["oidc","tailscale"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jsiebens.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-11-08T10:10:12.000Z","updated_at":"2024-02-20T15:56:21.000Z","dependencies_parsed_at":"2024-06-19T13:27:31.204Z","dependency_job_id":"1b33b918-3406-408e-bd6d-6f56c15a674d","html_url":"https://github.com/jsiebens/tskeyservice","commit_stats":{"total_commits":5,"total_committers":1,"mean_commits":5.0,"dds":0.0,"last_synced_commit":"aff3f1818c650bc49574c24a9e03f89ae3cc1fe3"},"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsiebens%2Ftskeyservice","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsiebens%2Ftskeyservice/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsiebens%2Ftskeyservice/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jsiebens%2Ftskeyservice/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jsiebens","download_url":"https://codeload.github.com/jsiebens/tskeyservice/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":228483617,"owners_count":17927363,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["oidc","tailscale"],"created_at":"2024-12-06T15:13:07.689Z","updated_at":"2024-12-06T15:13:08.170Z","avatar_url":"https://github.com/jsiebens.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# tskeyservice\n\nThis lightweight service exchanges OIDC token from trusted issuer for a short-lived, one-time use [Tailscale](https://tailscale.com) [Auth Token](https://tailscale.com/kb/1085/auth-keys/).\n\n## Why?\n\nThe idea for this service was born when connecting a GitHub Action to my Tailscale network.\nWhile this is typically done by creating an ephemeral auth key, add it to the secrets of the workflow.\nAlthough such Tailscale auth keys have an expiration by default, I always try to avoid \"static\" secrets.\n\n## How?\n\nGitHub Actions has support for OpenID Connect (OIDC) tokens, allowing your workflows to exchange short-lived tokens from e.g. your cloud provider.\nThis service is such an implementation and creates ephemeral, short-lived, one-time auth keys for your Tailscale network.\n\n## Configuration\n\nConfiguration is done by settings environment variables:\n\n- TS_TAILNET: the name of your tailnet\n- TS_API_KEY: a Tailscale API key\n- TS_KEYS_ISSUER: a trusted OIDC Issuer url (e.g. https://token.actions.githubusercontent.com)\n- TS_KEYS_TAGS: comma-separated list of ACL tags\n- TS_KEYS_BEXPR: a boolean expression to filter OIDC tokens (based on claims) when creating auth keys\n\nThe last setting is quit important as it allows you to filter OIDC tokens and only creating auth keys when the token has some certain claims.\n\nExample:\n\nIn case of GitHub Action, the issued token has a `repository` claim.\nThe following expression will only create auth keys for a workflow from this repository:\n\n```shell\nexport TS_KEYS_BEXPR='repository == \"jsiebens/tskeys-example\"'\n```\n\nThe boolean expression is implemented using the [HashiCorp go-bexpr](https://github.com/hashicorp/go-bexpr) library\n\n## Deployment\n\nWhen using in GitHub Actions, this service should be publicly available. E.g. on Google Cloud Run or [fly.io](https://fly.io).\n\nA Docker image is available at `ghcr.io/jsiebens/tskeyservice`\n\n## Example workflow\n\n```yaml\nname: GitHub Action Sample\n\non:\n  workflow_dispatch:\n\npermissions:\n  id-token: write\n\njobs:\n  sample:\n    runs-on: ubuntu-latest\n    steps:\n\n      - name: Get Tailscale key\n        shell: bash\n        env:\n          TSKEYSERVICE_URL: \"\u003cyour tskeservice url e.g. https://tskeys.example.com/key\u003e\"\n        run: |\n          OIDC_TOKEN=$(curl -sLS \"${ACTIONS_ID_TOKEN_REQUEST_URL}\u0026audience=tskeyservice\" -H \"User-Agent: actions/oidc-client\" -H \"Authorization: Bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN\" | jq -j '.value')\n          TS_KEY=$(curl -sLS $TSKEYSERVICE_URL -H \"User-Agent: actions/oidc-client\" -H \"Authorization: Bearer $OIDC_TOKEN\" | jq -j '.key')\n          echo \"TAILSCALE_AUTHKEY=$TS_KEY\" \u003e\u003e $GITHUB_ENV\n          \n      - name: Tailscale\n        uses: tailscale/github-action@main\n        with:\n          authkey: ${{ env.TAILSCALE_AUTHKEY }}\n```\n\n## Alternatives\n\n- [vault-plugin-tailscale](https://github.com/davidsbond/vault-plugin-tailscale)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsiebens%2Ftskeyservice","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjsiebens%2Ftskeyservice","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjsiebens%2Ftskeyservice/lists"}