---
title: Charmhub | Deploy Oathkeeper using Charmhub - The Open Operator Collection
description: Deploy the latest version of Oathkeeper as a Kubernetes Operator on any
  cloud.
url: https://charmhub.io/oathkeeper/libraries/forward_auth
---

# Oathkeeper

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

stable 39

```
juju deploy oathkeeper
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/oathkeeper/libraries/forward_auth#drawer)

## charms.oathkeeper.v0.forward\_auth

* [*Docstrings*Docstrings](https://charmhub.io/oathkeeper/libraries/forward_auth)
  [*Code*Source code](https://charmhub.io/oathkeeper/libraries/forward_auth/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.oathkeeper.v0.forward_auth
    ```

    [Download forward\_auth.py](https://charmhub.io/oathkeeper/libraries/forward_auth/download)
  + *Last updated* 18 Apr 2024
  + *Revision* Library version 0.4

Interface library for providing API Gateways with Identity and Access Proxy information.

It is required to integrate with Oathkeeper (Policy Decision Point).

##### Getting Started

To get started using the library, you need to fetch the library using `charmcraft`.
**Note that you also need to add `jsonschema` to your charm's `requirements.txt`.**

```
cd some-charm
charmcraft fetch-lib charms.oathkeeper.v0.forward_auth
```

To use the library from the requirer side, add the following to the `metadata.yaml` of the charm:

```
requires:
  forward-auth:
    interface: forward_auth
    limit: 1
```

Then, to initialise the library:

```
from charms.oathkeeper.v0.forward_auth import AuthConfigChangedEvent, ForwardAuthRequirer

class ApiGatewayCharm(CharmBase):
    def __init__(self, *args):
        # ...
        self.forward_auth = ForwardAuthRequirer(self)
        self.framework.observe(
            self.forward_auth.on.auth_config_changed,
            self.some_event_function
            )

    def some_event_function(self, event: AuthConfigChangedEvent):
        if self.forward_auth.is_ready():
            # Fetch the relation info
            forward_auth_data = self.forward_auth.get_forward_auth_data()
            # update ingress configuration
            # ...
```

---

Index

* [class ForwardAuthConfigError](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthconfigerror)
* [class DataValidationError](https://charmhub.io/oathkeeper/libraries/forward_auth#datavalidationerror)
* [class ForwardAuthRelation](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrelation)
* [class ForwardAuthConfig](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthconfig)
* + [def from\_dict(
    cls,
    dic)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthconfig-from_dict)
* + [def to\_dict(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthconfig-to_dict)
* [class ForwardAuthRequirerConfig](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirerconfig)
* + [def to\_dict(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirerconfig-to_dict)
* [class AuthConfigChangedEvent](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigchangedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    decisions\_address,
    app\_names,
    headers,
    relation\_id,
    relation\_app\_name)](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigchangedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigchangedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigchangedevent-restore)
* [class AuthConfigRemovedEvent](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigremovedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigremovedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigremovedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/forward_auth#authconfigremovedevent-restore)
* [class ForwardAuthRequirerEvents](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirerevents)
* [class ForwardAuthRequirer](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer)
* + [def \_\_init\_\_(
    self,
    charm)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer-__init__)
* + [def update\_requirer\_relation\_data(
    self,
    ingress\_app\_names,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer-update_requirer_relation_data)
* + [def get\_provider\_info(
    self,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer-get_provider_info)
* + [def get\_remote\_app\_name(
    self,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer-get_remote_app_name)
* + [def is\_ready(
    self,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer-is_ready)
* + [def is\_protected\_app(
    self,
    app)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrequirer-is_protected_app)
* [class ForwardAuthProxySet](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthproxyset)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthproxyset-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthproxyset-restore)
* [class InvalidForwardAuthConfigEvent](https://charmhub.io/oathkeeper/libraries/forward_auth#invalidforwardauthconfigevent)
* + [def \_\_init\_\_(
    self,
    handle,
    error)](https://charmhub.io/oathkeeper/libraries/forward_auth#invalidforwardauthconfigevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#invalidforwardauthconfigevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/forward_auth#invalidforwardauthconfigevent-restore)
* [class ForwardAuthRelationRemovedEvent](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrelationremovedevent)
* + [def \_\_init\_\_(
    self,
    handle,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrelationremovedevent-__init__)
* + [def snapshot(
    self)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrelationremovedevent-snapshot)
* + [def restore(
    self,
    snapshot)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthrelationremovedevent-restore)
* [class ForwardAuthProviderEvents](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthproviderevents)
* [class ForwardAuthProvider](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthprovider)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name,
    forward\_auth\_config)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthprovider-__init__)
* + [def update\_forward\_auth\_config(
    self,
    forward\_auth\_config,
    relation\_id)](https://charmhub.io/oathkeeper/libraries/forward_auth#forwardauthprovider-update_forward_auth_config)

#### class ForwardAuthConfigError

Description

Emitted when invalid forward auth config is provided. None

#### class DataValidationError

Description

Raised when data validation fails on relation data. None

#### class ForwardAuthRelation

Description

A class containing helper methods for forward-auth relation. None

Methods

#### class ForwardAuthConfig

Description

Helper class containing configuration required by API Gateway to set up the proxy. None

Methods

ForwardAuthConfig.
from\_dict(

cls

,
dic: Dict
)

Description

Generate ForwardAuthConfig instance from dict. None

ForwardAuthConfig.
to\_dict(

*self*
)

Description

Convert object to dict. None

#### class ForwardAuthRequirerConfig

Helper class containing configuration required by Oathkeeper.

Description

Its purpose is to evaluate whether apps can be protected by IAP.

Methods

ForwardAuthRequirerConfig.
to\_dict(

*self*
)

Description

Convert object to dict. None

#### class AuthConfigChangedEvent

Description

Event to notify the requirer charm that the forward-auth config has changed. None

Methods

AuthConfigChangedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
decisions\_address: str

,
app\_names

,
headers

,
relation\_id: int

,
relation\_app\_name: str
)

AuthConfigChangedEvent.
snapshot(

*self*
)

Description

Save event. None

AuthConfigChangedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class AuthConfigRemovedEvent

Description

Event to notify the requirer charm that the forward-auth config was removed. None

Methods

AuthConfigRemovedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
relation\_id: int
)

AuthConfigRemovedEvent.
snapshot(

*self*
)

Description

Save event. None

AuthConfigRemovedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class ForwardAuthRequirerEvents

Description

Event descriptor for events raised by `ForwardAuthRequirer`. None

#### class ForwardAuthRequirer

Description

Requirer side of the forward-auth relation. None

Methods

ForwardAuthRequirer.
\_\_init\_\_(

*self*

,
charm: CharmBase
)

ForwardAuthRequirer.
update\_requirer\_relation\_data(

*self*

,
ingress\_app\_names

,
relation\_id
)

Description

Update the relation databag with app names that can get IAP protection. None

ForwardAuthRequirer.
get\_provider\_info(

*self*

,
relation\_id
)

Description

Get the provider information from the databag. None

ForwardAuthRequirer.
get\_remote\_app\_name(

*self*

,
relation\_id
)

Description

Get the remote app name. None

ForwardAuthRequirer.
is\_ready(

*self*

,
relation\_id
)

Checks whether ForwardAuth is ready on this relation.

Description

Returns True when Oathkeeper shared the config; False otherwise.

ForwardAuthRequirer.
is\_protected\_app(

*self*

,
app
)

Description

Checks whether a given app requested to be protected by IAP. None

#### class ForwardAuthProxySet

Description

Event to notify the charm that the proxy was set successfully. None

Methods

ForwardAuthProxySet.
snapshot(

*self*
)

Description

Save event. None

ForwardAuthProxySet.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class InvalidForwardAuthConfigEvent

Description

Event to notify the charm that the forward-auth configuration is invalid. None

Methods

InvalidForwardAuthConfigEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
error: str
)

InvalidForwardAuthConfigEvent.
snapshot(

*self*
)

Description

Save event. None

InvalidForwardAuthConfigEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class ForwardAuthRelationRemovedEvent

Description

Event to notify the charm that the relation was removed. None

Methods

ForwardAuthRelationRemovedEvent.
\_\_init\_\_(

*self*

,
handle: Handle

,
relation\_id: int
)

ForwardAuthRelationRemovedEvent.
snapshot(

*self*
)

Description

Save event. None

ForwardAuthRelationRemovedEvent.
restore(

*self*

,
snapshot: Dict
)

Description

Restore event. None

#### class ForwardAuthProviderEvents

Description

Event descriptor for events raised by `ForwardAuthProvider`. None

#### class ForwardAuthProvider

Description

Provider side of the forward-auth relation. None

Methods

ForwardAuthProvider.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str

,
forward\_auth\_config
)

ForwardAuthProvider.
update\_forward\_auth\_config(

*self*

,
forward\_auth\_config: ForwardAuthConfig

,
relation\_id
)

Description

Update the forward-auth config stored in the object. None
