GSA/ansible-https-proxy

FEATURE: Oauth/SAML based Reverse Proxy Module

Opened this issue · 0 comments

As a system owner of a proxy, I would like to optionally integrate an added layer of authentication/authorization to restrict access to only those privileged users/groups. For a GSA system, it makes sense to offer the following:

Oauth based

  • Google (w/ whitelisted domains - @gsa.gov account only)
  • Github (w/ whitelisted orgs/groups - @GSA or @18F members or specific teams within)

SAML based (may be more appropriate to link to another repo as a standalone component)

Example:
https://github.com/bitly/oauth2_proxy