Project reference ↗

Dex acts as a bridge between an application and the organization's existing login systems. The application speaks OpenID Connect to Dex; Dex uses a connector to authenticate the user with a provider such as a directory or another identity service. It is useful when several applications need a consistent login interface despite different upstream providers. Login establishes identity, while each application must still decide what the signed-in user is allowed to do.

Deployment and operating notes

Dex remains an OpenID Connect identity service that connects applications to upstream identity providers. Its project-owned Helm chart and current connector documentation supersede the archived stable package and the old table of alpha, beta and claim support. Connector behavior, especially groups and refresh tokens, must be checked for the chosen connector and version.

Inventory issuer URL, client IDs, redirect URIs, signing-key storage and upstream provider configuration before migration. Preserve persistent storage where it contains keys or sessions, and avoid changing the issuer URL casually because relying applications validate it. Test authorization-code login, token refresh, group changes, denied users and expiry with the actual client applications. A memory-backed demonstration setup is not evidence of durable multi-replica operation. Keep TLS and cookie behavior consistent through the ingress path, and restrict administrative interfaces. A successful authentication response does not prove the application applies the intended authorization policy; verify a low-privilege identity before switching all clients.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2018-10-07T08:28:42+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Dex is an identity service that uses OpenID Connect to drive authentication for other apps.

Dex acts as a portal to other identity providers through “connectors.” This lets dex defer authentication to LDAP servers, SAML providers, or established identity providers like GitHub, Google, and Active Directory. Clients write their authentication logic once to talk to dex, then dex handles the protocols for a given backend.

Dex implements the following connectors:

 

Name supports refresh tokens supports groups claim status notes
LDAP yes yes stable
GitHub yes yes stable
SAML 2.0 no yes stable
GitLab yes yes beta
OpenID Connect yes no (#1065) beta Includes Google, Salesforce, Azure, etc.
LinkedIn yes no beta
Microsoft yes yes beta
AuthProxy no no alpha Authentication proxies such as Apache2 mod_auth, etc.

The post Dex appeared first on kubedex.com.

Sources & further reading

  1. Dex documentation and connectors
  2. Dex project Helm chart
  3. Recovered historical source

Spotted something that needs another look?

Help improve this page →