Show HN: An OIDC issuer for GitHub Actions pull_request workflows
github.com
github.com
But we needed a way to authenticate our CLI within those public workflows. This OIDC issuer is the result of that need, and works like so:
1. The pull_request workflow makes a "claim request" to the OIDC issuer, claiming certain details about the workflow like the ID, run ID, repository, etc.
2. The OIDC issuer responds with a "challenge code" that the workflow must periodically print to its logs
3. The OIDC issuer connects to the GitHub Actions websocket endpoint for log streaming, validates that the challenge code is being printed, then returns a new OIDC token to the workflow
This is working well for us, and lets us acquire an OIDC token similar to the GitHub Actions native OIDC token. The issuer itself runs as a Cloudflare Worker.
Happy to answer questions and I'd love any feedback you may have!