Repository navigation
Burrow v0.1.0
Burrow v0.1.0
Burrow's first release is a lightweight, single-organization OpenID Connect
identity provider. The Go backend and React interface ship together. Licensed
under MIT. This is an early release; future configuration, API and database
changes may require migration.
Features
- Shared SSO with Burrow passwords and mandatory TOTP for every user.
- Temporary-password changes, first-login authenticator binding, administrator
MFA reset and operator recovery. - Users, groups, custom roles, permissions, personal profiles and application
portals, with transactional authorization and auditing. - Authorization Code with PKCE S256; confidential Web and public SPA clients.
Administrators may enable an explicit no-PKCE exception for an individual Web
application; SPA clients always require PKCE. - Persistent signing keys, key rotation, exact callback/origin matching and
revalidation of access at authorization and code exchange. - English and Simplified Chinese, with light, dark and system themes.
- PostgreSQL production storage; SQLite development and test storage.
Install
Linux amd64 container images:
ghcr.io/arkgravity/burrow:v0.1.0
docker.io/logic3579/burrow:v0.1.0
Attachments include the Linux amd64 binary with embedded UI (glibc 2.36+), a
Compose deployment archive, INSTALL.md, IMAGES.txt with registry digests and
SHA256SUMS. Containers are the recommended deployment method. See the attached
installation guide for credentials, TLS, configuration and startup order.
Upgrading development versions
Back up the database and preserve its original master key. Run migration and
seed before starting the server. Schema v5 revokes old Burrow sessions/tokens
and unfinished authorizations; users sign in again and bind TOTP. Accounts,
passwords, grants, application configuration and signing keys are preserved.
Older Provider-based databases must first satisfy the password-only migration
requirements. Rollback requires a compatible database backup, configuration and
master key; replacing the image alone does not reverse migrations.
Scope and verification
The release workflow requires successful full CI for the exact main-branch
commit, then runs browser regression tests against the packaged binary and
production-mode PostgreSQL startup checks against the release container.
Workflow results are available under the repository's Actions tab.
The user reported local Grafana, Nightingale and Harbor web-login acceptance on
2026-10-01, and MFA browser acceptance on 2026-10-02. These are historical user
checkpoints, separate from this release's automated checks and production
validation. The local integration environment has since been removed.
Refresh Tokens, upstream identity providers, external account linking, machine
clients, dynamic registration and cross-application logout are outside this
release. Downstream applications own their sessions. Burrow has not claimed
OpenID Foundation certification.
中文说明
Burrow 首个版本提供单组织 OIDC 身份服务:密码与全员强制 TOTP、共享 SSO、
用户/组/角色/权限管理、个人资料及应用门户。支持 Web/SPA 授权码流程,默认要求
PKCE S256;提供中英双语及浅色、深色、系统主题,采用 MIT 许可证。
推荐使用 Linux amd64 容器部署;独立二进制要求 glibc 2.36 或更新版本。
附件包含部署包、安装说明、镜像 digest 和 SHA256 校验文件。生产使用 PostgreSQL、
独立密钥与初始管理员密码,并配置 HTTPS。首次登录需修改临时密码并绑定认证器。
旧开发版升级前请备份数据库并保留原 master key;迁移到 schema v5 会使旧 Burrow
会话与 Token 失效,用户重新登录后绑定 MFA。回滚需要兼容的数据库备份,不能仅
退回旧镜像。早期版本的配置、API 和数据库可能继续演进。工程互通及人工验收记录
不代表官方 OIDC 认证或生产验证。