BuzzFeed SSO protected web services by checking a user's login before forwarding requests to them. It was useful for internal tools that had no built-in authentication, allowing several applications to share a sign-in service instead of each implementing one. The proxy sits between the user and the application, so that application must not remain reachable through an unprotected route. The public repository is no longer maintained and needs a deliberate replacement plan.
Deployment and operating notes
The upstream BuzzFeed SSO README now says that the public repository is no longer maintained and suggests modern alternatives or active forks, including Pomerium. The recovered text also describes the original bitly oauth2_proxy as unmaintained; that should not be confused with today’s separate OAuth2 Proxy project, whose documentation explains its fork history.
Before replacing an authentication proxy, inventory providers, callback URLs, allowed groups, cookie domains, session storage and the identity headers trusted by each backend. Make direct backend access impossible where the application relies on proxy authentication. Test denied users, expired sessions, logout and forwarded-header handling as well as successful login. A new proxy will not necessarily understand existing cookies, so plan a deliberate sign-in transition and retain a route rollback. Compare Pomerium and OAuth2 Proxy against the required authorization model rather than assuming either is a drop-in chart replacement. Historical statements about another company’s production use are not present-day operational evidence.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Original publication: 2019-05-10T05:51:58+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.
Heavily inspired by Buzzfeed’s example, this provides a way of protecting Kubernetes services that have no authentication layer globally from a single OAuth proxy.
Blogpost Quickstart guide SSO in Kubernetes with Google Auth Repo
Many of the Kubernetes OAuth solutions require to run an extra container within the pod using oauth2_proxy, but the project seems to not be maintained anymore. The approach used allows to have a global OAuth2 Proxy that can protect services even in different namespaces, thanks to Kube DNS.
We use this chart in production at MindDoc for protecting endpoints that have no built-in authentication (or that would require to run inner containers), like Kibana, Prometheus, etc…
The post buzzfeed sso appeared first on kubedex.com.
Sources & further reading
Spotted something that needs another look?
Help improve this page →