Kratos–Hydra consent bridge: connects Ory session auth to OAuth2 challenges in Go
1.6K
Variable Default
KRATOS_PUBLIC_URL http://localhost:4433
KRATOS_ADMIN_URL http://localhost:4434
HYDRA_ADMIN_URL http://localhost:4445
BRIDGE_PORT 3400
USER_UI_URL http://localhost:3300
Note: the /api/login routes are missing from main.go — only consent, logout, and health are registered.
# BUILD STAGE
FROM golang:1.25-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux GOARCH=arm64 go build -ldflags="-s -w" -o bridge .
# RUNTIME STAGE
FROM gcr.io/distroless/static-debian12:nonroot
COPY --from=builder /app/bridge /bridge
USER 1001:1001
EXPOSE 3400
ENTRYPOINT ["/bridge"]
go 1.25.0
require (
github.com/ory/hydra-client-go/v2 v2.2.1
github.com/ory/kratos-client-go v1.3.8
)
require golang.org/x/oauth2 v0.21.0 // indirect
version: v25.4.0
dsn: postgres://kratos:password@postgres:5432/kratos_db?sslmode=disable
serve:
public:
base_url: http://localhost:4433/
cors:
enabled: true
allowed_origins:
- http://localhost:3300
allowed_methods:
- GET
- POST
- PUT
- PATCH
- DELETE
allowed_headers:
- Content-Type
- Authorization
- Cookie
- X-Session-Token
exposed_headers:
- Set-Cookie
allow_credentials: true
admin:
base_url: http://localhost:4434/
secrets:
cookie:
- PLEASE-CHANGE-ME-I-AM-VERY-INSECURE
cipher:
- 32-LONG-SECRET-NOT-SECURE-AT-ALL
ciphers:
algorithm: xchacha20-poly1305
identity:
default_schema_id: agent
schemas:
- id: agent
url: file:///etc/config/kratos/agent.schema.json
selfservice:
default_browser_return_url: http://localhost:3300/
allowed_return_urls:
- http://localhost:3300
- http://localhost:4444
flows:
error:
ui_url: http://localhost:3300/error
registration:
enabled: false
recovery:
enabled: true
ui_url: http://localhost:3300/recovery
use: link
after:
default_browser_return_url: http://localhost:3300/settings
verification:
enabled: false
login:
ui_url: http://localhost:3300/login
lifespan: 10m
settings:
ui_url: http://localhost:3300/settings
privileged_session_max_age: 15m
logout:
after:
default_browser_return_url: http://localhost:3300/login
methods:
password:
enabled: true
link:
enabled: true
totp:
enabled: false
code:
enabled: false
webauthn:
enabled: true
config:
rp:
id: localhost
display_name: "Kratos Local Dev"
origins:
- http://localhost:3300
passwordless: true
session:
lifespan: 12h
cookie:
domain: localhost
same_site: Lax
log:
level: debug
format: text
leak_sensitive_values: true
cookies:
domain: localhost
path: /
same_site: Lax
feature_flags:
use_continue_with_transitions: true
oauth2_provider:
url: http://hydra:4445
override_return_to: true
dsn: postgres://hydra:password@postgres:5432/hydra_db?sslmode=disable
secrets:
system:
- ${HYDRA_SYSTEM_SECRET}
serve:
public:
cors:
enabled: true
allowed_origins:
- "*"
allowed_methods:
- GET
- POST
- PUT
- PATCH
- DELETE
- OPTIONS
allowed_headers:
- Authorization
- Content-Type
admin:
cors:
enabled: false
cookies:
same_site_mode: Lax
urls:
self:
issuer: http://localhost:4444
login: http://localhost:3300/login
consent: http://localhost:3300/consent
logout: http://localhost:3300/logout
error: http://localhost:3300/error
device:
verification: http://localhost:3300/device/verify
success: http://localhost:3300/device/success
# identity_provider.url intentionally not set:
# Service-level logout (UserBar) only revokes the Hydra OAuth2 session/tokens.
# The Kratos identity session remains active, enabling seamless SSO across
# services (Service B/C auto-login without re-entering credentials).
# Full logout requires using the Kratos User UI sign-out at http://localhost:3300.
strategies:
access_token: jwt
scope: exact
ttl:
access_token: 1h
id_token: 1h
refresh_token: 20h
auth_code: 10m
login_consent_request: 30m
oauth2:
pkce:
enforced: true
exclude_not_before_claim: false
allowed_top_level_claims:
- username
oidc:
subject_identifiers:
supported_types:
- pairwise
- public
pairwise:
salt: ${OIDC_SUBJECT_IDENTIFIERS_PAIRWISE_SALT:-changeme-set-this-in-production}
log:
level: info
format: json
Use At your Own risk. devs are not responsible
Content type
Image
Digest
sha256:6339d4cc5…
Size
3.5 MB
Last updated
7 months ago
docker pull 4r34n/kratos-hydra-consent-go