With this plugin Gerrit can use OAuth2 protocol for authentication. Supported OAuth providers:
- AirVantage
- Azure (previously named Office365)
- Bitbucket
- CAS
- CoreOS Dex
- Discovery — any generic OpenID Connect provider, via Well-Known Discovery
- GitHub
- GitLab
- Keycloak
- Phabricator
- SAP Cloud Identity Services (IAS)
Auth0, Authentik, Amazon Cognito, LemonLDAP::NG and Tuleap were previously shipped as dedicated providers. They are standard OpenID Connect providers, so they have been removed in favour of the generic Discovery provider; see Documentation/config-discovery.md for how to migrate their configuration.
See Documentation/providers.md for a per-provider capability matrix, and the Wiki for what it can do for you.
Prebuilt binary artifacts are available on release page. Make sure to pick the right JAR for your Gerrit version.
This plugin is built with Bazel inside the Gerrit
source tree. Clone or link it into Gerrit's plugins directory, link its
dependency fragment over the placeholder, and build it from the Gerrit tree:
git clone https://gerrit.googlesource.com/gerrit
git clone https://gerrit.googlesource.com/plugins/oauth
cd gerrit/plugins
ln -s ../../oauth .
rm external_plugin_deps.MODULE.bazel
ln -s oauth/external_plugin_deps.MODULE.bazel .
cd ..
bazel build plugins/oauth
Besides the default oauth.jar, the plugin can also be built as slim,
single-provider artifacts that bundle just one provider plus the shared core.
Each registers as the same gerrit-oauth-provider plugin and ships its own init
step; see Documentation/build.md
for the target list. SAP IAS is shipped only as the oauth-sapias artifact.
Copy the bazel-bin/plugins/oauth/oauth.jar to
$gerrit_site/plugins and re-run init to configure it:
java -jar gerrit.war init -d <site>
[...]
*** OAuth Authentication Provider
***
Use Bitbucket OAuth provider for Gerrit login ? [Y/n]? n
Use Google OAuth provider for Gerrit login ? [Y/n]?
Application client id : <client-id>
Application client secret :
confirm password :
Link to OpenID accounts? [true]:
Use GitHub OAuth provider for Gerrit login ? [Y/n]? n
Make sure to read the FAQ before reporting issues.
Apache License 2.0