Documentation
Documentation
Truster lets people sign in to your app or Kubernetes cluster with an existing account or a code sent by email. These guides take you from a quick local demonstration to a persistent deployment and Kubernetes access.
Start here
- Getting Started - Try Truster locally or choose a deployment target
- Why Truster? - Decide whether its scope fits your team
- OIDC Primer - Learn how OAuth2 and OIDC work with Truster
- Concepts and terminology - Look up the practical identity and protocol terms used in these guides
Set up Truster
- Sign-in Providers - Configure Google, GitHub, generic OAuth2/OIDC, or email codes
- Deployment - Deploy to AWS or Google Cloud using the official OpenTofu/Terraform modules
- Kubernetes Integration - Configure your cluster
- kubelogin - Authenticate with kubectl
- Application Integration - Connect a browser or server application
Reference
- Configuration Reference - Connectors, email verification, secrets, clients, and templates
- System Specification - Architecture, security properties, and protocol behavior
- State Database - Store login and token state in SQLite or PostgreSQL
- Policy Database - Supply clients, users, groups, and trust policy from PostgreSQL
- DPoP Integration - Sender-constrained clients, BFFs, and resource servers
- Troubleshooting - Common issues and solutions