Skip to content

Open ID Connect (OIDC) for GHEC Audit Log Streaming to Azure Blob Storage #581

Description

@github-product-roadmap

Summary

Today, GitHub’s audit log streaming feature requires storage of cloud secrets in GitHub when configuring your stream. Going forward, the audit log feature will support OpenID Connect (OIDC) for streaming partners. OIDC allows for the use of short-lived tokens that are automatically rotated for each configuration.

Intended Outcome

  • With the new OpenID Connect (OIDC) support, you can stream to one of our five streaming partners
  • OpenID token exchange eliminates the need for storing any long-lived cloud secrets in GitHub
  • Enterprise owners can use the security mechanisms of their cloud provider to ensure minimal access to cloud resources

How will it work?

OIDC will establish an identity layer between GitHub and Azure for the purposes of authenticating GitHub to stream audit log events to a specified Azure blob. Enterprise owners will establish trust with the GitHub audit log application and assign audit log a role with write permissions to the Azure blob. When streaming GitHub events via audit log streaming, GitHub will authenticate the cloud role and the Github audit log identity using short lived tokens.

Activity

  1. locked and limited conversation to collaborators on Sep 14, 2022
  2. moved this to Q4 2022 – Oct-Dec in GitHub Public Roadmapon Sep 14, 2022
  3. moved this from Q4 2022 – Oct-Dec to Q1 2023 – Jan-Mar in GitHub Public Roadmapon Oct 19, 2022
  4. ankneis commented on Nov 20, 2024

    @ankneis
    Contributor

    This issue is being closed as outdated. For more information, please check out this Discussion post. Stay tuned for new additions to our refreshed public roadmap!

  5. ankneis commented on Dec 17, 2024

    @ankneis
    Contributor

    We wanted to provide more details on why we removed this from the roadmap. We do intend to bring OIDC for GHEC Audit Log Streaming to Azure Blob Storage, but we're removing it from this roadmap for now until we have more certainty on our timeline for a public preview.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    EnterpriseProduct SKU: GitHub EnterprisePreviewFeature phase: Previewaudit logsFeature: Github audit logs

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions