---
title: Charmhub | Deploy Oathkeeper using Charmhub - The Open Operator Collection
description: Deploy the latest version of Oathkeeper as a Kubernetes Operator on any
  cloud.
url: https://charmhub.io/oathkeeper/libraries/auth_proxy
---

# Oathkeeper

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

stable 39

```
juju deploy oathkeeper
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/oathkeeper/libraries/auth_proxy#drawer)

## charms.oathkeeper.v0.auth\_proxy

* [*Docstrings*Docstrings](https://charmhub.io/oathkeeper/libraries/auth_proxy)
  [*Code*Source code](https://charmhub.io/oathkeeper/libraries/auth_proxy/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.oathkeeper.v0.auth_proxy
    ```

    [Download auth\_proxy.py](https://charmhub.io/oathkeeper/libraries/auth_proxy/download)
  + *Last updated* 18 Apr 2024
  + *Revision* Library version 0.6

Interface library for providing Oathkeeper with downstream charms' auth-proxy information.

It is required to integrate a charm into an Identity and Access Proxy (IAP).

##### Getting Started

To get started using the library, you need to fetch the library using `charmcraft`.
**Note that you also need to add `jsonschema` to your charm's `requirements.txt`.**

```
cd some-charm
charmcraft fetch-lib charms.oathkeeper.v0.auth_proxy
```

To use the library from the requirer side, add the following to the `metadata.yaml` of the charm:

```
requires:
  auth-proxy:
    interface: auth_proxy
    limit: 1
```

Then, to initialise the library:

```
from charms.oathkeeper.v0.auth_proxy import AuthProxyConfig, AuthProxyRequirer

AUTH_PROXY_ALLOWED_ENDPOINTS = ["welcome", "about/app"]
AUTH_PROXY_HEADERS = ["X-User", "X-Some-Header"]

class SomeCharm(CharmBase):
    def __init__(self, *args):
        # ...
        self.auth_proxy = AuthProxyRequirer(self, self._auth_proxy_config)

        @property
        def external_urls(self) -> list:
            # Get ingress-per-unit or externally-configured web urls
            # ...
            return ["https://example.com/unit-0", "https://example.com/unit-1"]

        @property
        def _auth_proxy_config(self) -> AuthProxyConfig:
            return AuthProxyConfig(
                protected_urls=self.external_urls,
                allowed_endpoints=AUTH_PROXY_ALLOWED_ENDPOINTS,
                headers=AUTH_PROXY_HEADERS
            )

        def _on_ingress_ready(self, event):
            self._configure_auth_proxy()

        def _configure_auth_proxy(self):
            self.auth_proxy.update_auth_proxy_config(auth_proxy_config=self._auth_proxy_config)
```

---

Index

* [class AuthProxyConfigError](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigerror)
* [class DataValidationError](https://charmhub.io/oathkeeper/libraries/auth_proxy#datavalidationerror)
* [class AuthProxyRelation](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrelation)
* [class AuthProxyConfig](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfig)
* + [def validate(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfig-validate)
* + [def to\_dict(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfig-to_dict)
* [class AuthProxyConfigChangedEvent](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigchangedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    protected\_urls,
    headers,
    allowed\_endpoints,
    relation\_id,
    relation\_app\_name)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigchangedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigchangedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigchangedevent-restore)
* + [def to\_auth\_proxy\_config(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigchangedevent-to_auth_proxy_config)
* [class AuthProxyConfigRemovedEvent](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigremovedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigremovedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigremovedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyconfigremovedevent-restore)
* [class AuthProxyProviderEvents](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyproviderevents)
* [class AuthProxyProvider](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyprovider)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyprovider-__init__)
* + [def get\_headers(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyprovider-get_headers)
* + [def get\_app\_names(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyprovider-get_app_names)
* [class InvalidAuthProxyConfigEvent](https://charmhub.io/oathkeeper/libraries/auth_proxy#invalidauthproxyconfigevent)
* + [def \_\_init\_\_(
    self,
    handle,
    error)](https://charmhub.io/oathkeeper/libraries/auth_proxy#invalidauthproxyconfigevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#invalidauthproxyconfigevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/auth_proxy#invalidauthproxyconfigevent-restore)
* [class AuthProxyRelationRemovedEvent](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrelationremovedevent)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrelationremovedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrelationremovedevent-restore)
* [class AuthProxyRequirerEvents](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrequirerevents)
* [class AuthProxyRequirer](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrequirer)
* + [def \_\_init\_\_(
    self,
    charm,
    auth\_proxy\_config,
    relation\_name)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrequirer-__init__)
* + [def update\_auth\_proxy\_config(
    self,
    auth\_proxy\_config,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/auth_proxy#authproxyrequirer-update_auth_proxy_config)

#### class AuthProxyConfigError

Description

Emitted when invalid auth proxy config is provided. None

#### class DataValidationError

Description

Raised when data validation fails on relation data. None

#### class AuthProxyRelation

Description

A class containing helper methods for auth-proxy relation. None

Methods

#### class AuthProxyConfig

Description

Helper class containing a configuration for the charm related with Oathkeeper. None

Methods

AuthProxyConfig.
validate(

*self*
)

Description

Validate the auth proxy configuration. None

AuthProxyConfig.
to\_dict(

*self*
)

Description

Convert object to dict. None

#### class AuthProxyConfigChangedEvent

Description

Event to notify the Provider charm that the auth proxy config has changed. None

Methods

AuthProxyConfigChangedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
protected\_urls

,
headers

,
allowed\_endpoints

,
relation\_id: int

,
relation\_app\_name: str
)

AuthProxyConfigChangedEvent.
snapshot(

*self*
)

Description

Save event. None

AuthProxyConfigChangedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

AuthProxyConfigChangedEvent.
to\_auth\_proxy\_config(

*self*
)

Description

Convert the event information to an AuthProxyConfig object. None

#### class AuthProxyConfigRemovedEvent

Description

Event to notify the provider charm that the auth proxy config was removed. None

Methods

AuthProxyConfigRemovedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
relation\_id: int
)

AuthProxyConfigRemovedEvent.
snapshot(

*self*
)

Description

Save event. None

AuthProxyConfigRemovedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class AuthProxyProviderEvents

Description

Event descriptor for events raised by `AuthProxyProvider`. None

#### class AuthProxyProvider

Description

Provider side of the auth-proxy relation. None

Methods

AuthProxyProvider.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

AuthProxyProvider.
get\_headers(

*self*
)

Description

Returns the list of headers from all relations. None

AuthProxyProvider.
get\_app\_names(

*self*
)

Description

Returns the list of all related app names. None

#### class InvalidAuthProxyConfigEvent

Description

Event to notify the charm that the auth proxy configuration is invalid. None

Methods

InvalidAuthProxyConfigEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
error: str
)

InvalidAuthProxyConfigEvent.
snapshot(

*self*
)

Description

Save event. None

InvalidAuthProxyConfigEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class AuthProxyRelationRemovedEvent

Description

Custom event to notify the charm that the relation was removed. None

Methods

AuthProxyRelationRemovedEvent.
snapshot(

*self*
)

Description

Save event. None

AuthProxyRelationRemovedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class AuthProxyRequirerEvents

Description

Event descriptor for events raised by `AuthProxyRequirer`. None

#### class AuthProxyRequirer

Description

Requirer side of the auth-proxy relation. None

Methods

AuthProxyRequirer.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
auth\_proxy\_config

,
relation\_name: str
)

AuthProxyRequirer.
update\_auth\_proxy\_config(

*self*

,
auth\_proxy\_config: AuthProxyConfig

,
relation\_id
)

Description

Update the auth proxy config stored in the object. None
