Authentication Service provides the compatible external-identity-provider, token, identity lookup, reload, OpenID Connect, and SAML endpoints required by the preserved control-platform authentication flow.
PastureStack is an independent community effort to preserve, audit, and modernize the Rancher 1.6 ecosystem. It is not affiliated with or endorsed by Rancher Labs or SUSE.
Upstream: rancher/rancher-auth-service. This GitHub fork preserves upstream history, authorship, dates, tags, licenses, and bundled dependency notices; PastureStack maintenance is consolidated into one commit after the preserved upstream boundary.
The current compatibility release retains the existing Ubuntu 26.04, Go 1.26.5, JWT, cookie, TLS, LDAP, GitHub, Shibboleth, dependency, and build maintenance. It adds a provider-neutral OpenID Connect authorization-code client with discovery, PKCE S256, nonce validation, asymmetric ID-token verification, UserInfo subject matching, custom certificate-authority support, and a test-before-enable recovery flow. Successful staged sign-in also produces a short-lived, audience-bound, single-use signed identity proof. The control platform uses that proof for an explicit account-link or reassignment decision; profile fields are never trusted as implicit account-matching keys. Product-owned imports, executable names, CLI settings, client variables, and operator messages use PastureStack naming.
Use --platform-url, --platform-access-key, and --platform-secret-key, or their PLATFORM_* environment variables. Historical cattle-* and CATTLE_* aliases remain for migration. RSA signing keys and the encrypted authentication configuration key are required. Set PASTURESTACK_LOCALE=en-US or zh-TW for operator messages.
From a Docker-capable Linux host:
make test
make build
make packageSet VERSION_OVERRIDE=v0.4.35 for the reviewed identity-security compatibility
release. Packaging produces the deterministic, versioned
authentication-service-0.4.35-linux-amd64.tar.xz asset. The manually
dispatched release workflow runs the full test and validation suite twice,
requires byte-identical packages, verifies a fixed and attested security
scanner, publishes CycloneDX SBOMs and scan evidence, and publishes the
reviewed archive on GitHub. The build container runs without root privileges
and contains no nested Docker client or host socket. PastureStack Server
consumes that immutable release directly, so
operators do not need to host an artifact mirror.
The build image is pinned to an Ubuntu 26.04 digest and the official Ubuntu
snapshot recorded in ubuntu-apt.lock. Every directly installed APT package,
including GCC and libc development headers used only by race tests, has an
exact version. Snapshot updates and package versions must move together and
pass the manual security gate before release.
See OpenID Connect, COMPATIBILITY.md, SECURITY.md, and ORIGIN.md.
The inherited project remains licensed under Apache License 2.0. Copyright and attribution for inherited work and vendored dependencies remain with their respective authors and contributors. PastureStack contributors claim authorship only for their own changes.