II.
StackPart overview
Reference · livestack-part:krate-identity-engine
Krate Identity Engine overview
Handles OIDC/OAuth sign-in, maps external identities to Kubernetes users and groups via IdentityMapping CRDs, and evaluates Kubernetes RBAC policy for every API call. Issues scoped ServiceAccount tokens for CI jobs and agent dispatch attempts. Manages User, Team, Invite, AuthProvider, AgentServiceAccount, and AgentRoleBinding resources to ensure the forge never creates a parallel permission system.
Attributes
displayName
Krate Identity Engine
category
security
description
Handles OIDC/OAuth sign-in, maps external identities to Kubernetes
users and groups via IdentityMapping CRDs, and evaluates Kubernetes
RBAC policy for every API call. Issues scoped ServiceAccount tokens
for CI jobs and agent dispatch attempts. Manages User, Team, Invite,
AuthProvider, AgentServiceAccount, and AgentRoleBinding resources
to ensure the forge never creates a parallel permission system.
Outgoing edges
part_of1
- platform:krate·Platform
realizes1
- layer:6-agent-platform·LayerAgent-Platform
Incoming edges
None.