Sign inSign up

4r34n/kratos-hydra-consent-go

By 4r34n

•Updated 7 months ago

Kratos–Hydra consent bridge: connects Ory session auth to OAuth2 challenges in Go

Image
Security
Integration & delivery
API management
0

1.6K

4r34n/kratos-hydra-consent-go repository overview

Variable Default

KRATOS_PUBLIC_URL http://localhost:4433⁠

KRATOS_ADMIN_URL http://localhost:4434⁠

HYDRA_ADMIN_URL http://localhost:4445⁠

BRIDGE_PORT 3400

USER_UI_URL http://localhost:3300⁠

Note: the /api/login routes are missing from main.go — only consent, logout, and health are registered.

⁠Dockerfile

# BUILD STAGE
FROM golang:1.25-alpine AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux GOARCH=arm64 go build -ldflags="-s -w" -o bridge .

# RUNTIME STAGE
FROM gcr.io/distroless/static-debian12:nonroot
COPY --from=builder /app/bridge /bridge
USER 1001:1001
EXPOSE 3400
ENTRYPOINT ["/bridge"]

⁠go.mod


go 1.25.0

require (
	github.com/ory/hydra-client-go/v2 v2.2.1
	github.com/ory/kratos-client-go v1.3.8
)

require golang.org/x/oauth2 v0.21.0 // indirect

⁠possible config

⁠kratos.yaml
version: v25.4.0

dsn: postgres://kratos:password@postgres:5432/kratos_db?sslmode=disable

serve:
  public:
    base_url: http://localhost:4433/
    cors:
      enabled: true
      allowed_origins:
        - http://localhost:3300
      allowed_methods:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
      allowed_headers:
        - Content-Type
        - Authorization
        - Cookie
        - X-Session-Token
      exposed_headers:
        - Set-Cookie
      allow_credentials: true
  admin:
    base_url: http://localhost:4434/

secrets:
  cookie:
    - PLEASE-CHANGE-ME-I-AM-VERY-INSECURE
  cipher:
    - 32-LONG-SECRET-NOT-SECURE-AT-ALL

ciphers:
  algorithm: xchacha20-poly1305

identity:
  default_schema_id: agent
  schemas:
    - id: agent
      url: file:///etc/config/kratos/agent.schema.json

selfservice:
  default_browser_return_url: http://localhost:3300/
  allowed_return_urls:
    - http://localhost:3300
    - http://localhost:4444

  flows:
    error:
      ui_url: http://localhost:3300/error

    registration:
      enabled: false

    recovery:
      enabled: true
      ui_url: http://localhost:3300/recovery
      use: link
      after:
        default_browser_return_url: http://localhost:3300/settings

    verification:
      enabled: false

    login:
      ui_url: http://localhost:3300/login
      lifespan: 10m

    settings:
      ui_url: http://localhost:3300/settings
      privileged_session_max_age: 15m

    logout:
      after:
        default_browser_return_url: http://localhost:3300/login

  methods:
    password:
      enabled: true
    link:
      enabled: true
    totp:
      enabled: false
    code:
      enabled: false
    webauthn:
      enabled: true
      config:
        rp:
          id: localhost
          display_name: "Kratos Local Dev"
          origins:
            - http://localhost:3300
        passwordless: true

session:
  lifespan: 12h
  cookie:
    domain: localhost
    same_site: Lax

log:
  level: debug
  format: text
  leak_sensitive_values: true

cookies:
  domain: localhost
  path: /
  same_site: Lax

feature_flags:
  use_continue_with_transitions: true

oauth2_provider:
  url: http://hydra:4445
  override_return_to: true
⁠hydra.yaml
dsn: postgres://hydra:password@postgres:5432/hydra_db?sslmode=disable

secrets:
  system:
    - ${HYDRA_SYSTEM_SECRET}

serve:
  public:
    cors:
      enabled: true
      allowed_origins:
        - "*"
      allowed_methods:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
        - OPTIONS
      allowed_headers:
        - Authorization
        - Content-Type
  admin:
    cors:
      enabled: false
  cookies:
    same_site_mode: Lax

urls:
  self:
    issuer: http://localhost:4444
  login: http://localhost:3300/login
  consent: http://localhost:3300/consent
  logout: http://localhost:3300/logout
  error: http://localhost:3300/error
  device:
    verification: http://localhost:3300/device/verify
    success: http://localhost:3300/device/success
  # identity_provider.url intentionally not set:
  # Service-level logout (UserBar) only revokes the Hydra OAuth2 session/tokens.
  # The Kratos identity session remains active, enabling seamless SSO across
  # services (Service B/C auto-login without re-entering credentials).
  # Full logout requires using the Kratos User UI sign-out at http://localhost:3300.

strategies:
  access_token: jwt
  scope: exact

ttl:
  access_token: 1h
  id_token: 1h
  refresh_token: 20h
  auth_code: 10m
  login_consent_request: 30m

oauth2:
  pkce:
    enforced: true
  exclude_not_before_claim: false
  allowed_top_level_claims:
    - username

oidc:
  subject_identifiers:
    supported_types:
      - pairwise
      - public
    pairwise:
      salt: ${OIDC_SUBJECT_IDENTIFIERS_PAIRWISE_SALT:-changeme-set-this-in-production}

log:
  level: info
  format: json

Use At your Own risk. devs are not responsible

Tag summary

Content type

Image

Digest

sha256:6339d4cc5…

Size

3.5 MB

Last updated

7 months ago

docker pull 4r34n/kratos-hydra-consent-go