oauth2-proxy In Front Of An Upstream, Secrets In Files
oauth2-proxy from the upstream release in front of an upstream on loopback. It refuses a config with no authorization rule, and OIDC discovery happens at start, so the role waits for /ping. Secrets are root-owned files, never config values. The live test sees an anonymous request refused while the upstream answers, and a forged cookie refused. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-oauth2-proxy?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [oauth2-proxy In Front Of An Upstream, Secrets In Files](https://www.iac-bazaar.com/catalog/ansible-oauth2-proxy?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# oauth2-proxy In Front Of An Upstream, Secrets In Files: https://www.iac-bazaar.com/catalog/ansible-oauth2-proxy (download from your IaC Bazaar account)
```Preview:
Documentation
oauth2-proxy
oauth2-proxy from the upstream release (sha256-verified), in front of an upstream on loopback: anonymous requests get the sign-in page, the sign-in step hands the browser to your provider, and only identities your rules authorise get through. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
oauth2-proxy; oauth2-proxy ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the asset unless its
SHA-256 is the one in the vendor's file, then installs the binaries as
root's in /usr/local/bin, pinned by oauth2_proxy_version.
A service account, a hardened unit, a loopback listener. oauth2-proxy
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:4180 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
It refuses to authorise nobody. oauth2-proxy will not start without an
email-domain rule (measured: --config-test answers "use email-domain=* to
authorize all email addresses"). The default is example.com - no real
identity - until you set yours; * means anyone your provider vouches for,
which with GitHub is everyone on GitHub.
Discovery happens at start, not at check. With an OIDC provider,
--config-test passes even when the issuer is unreachable, and the service
then fails to start (both measured) - which is why the role waits for /ping
before it reports success. The defaults use the GitHub provider, which needs
no discovery; set oauth2_proxy_provider: oidc and the issuer for anything
else.
Secrets are files. The client secret, and a cookie secret generated once on the host and kept across runs, are root-owned files readable by the service's group, referenced from the configuration and never written into it. The live test sees an anonymous request refused with the sign-in page while the upstream itself answers, the sign-in step redirect to the provider with the client ID, a forged session cookie refused, and the secret absent from the configuration.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-suricata
Suricata from EPEL watching the default-route interface as the suricata user, ET Open fetched at install and refreshed daily, plus a canary rule that proves the sensor is alive. A root-run check left root-owned logs and a daemon recording nothing; the role prevents it. The live test raises the canary alert while a second lookup is logged, not alerted. Original role, live-tested on Rocky Linux 10.
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
ansible-389-ds
389 Directory Server from AppStream. A fresh instance listens on every interface and lets anonymous clients read the tree; this role binds both listeners to loopback and limits anonymous clients to the rootDSE. The live test adds a user who binds, sees a wrong password and an anonymous search refused, and reads the LDAPS certificate. Original role, live-tested on Rocky Linux 10.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.
ansible-bandit
bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-boundary
boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.