---
title: Charmhub | Deploy Request Authentication Configurator using Charmhub - The
  Open Operator Collection
description: Deploy the latest version of Request Authentication Configurator on any
  cloud. A charm configurator to have `RequestAuthentication.security.istio.io` custom
  resources created
url: https://charmhub.io/request-authentication-configurator
---

# Request Authentication Configurator

[Kubeflow Charmers](https://charmhub.io/publisher/ckfbot "View all packages from Kubeflow Charmers")

* [Kubeflow Charmers](https://charmhub.io/publisher/ckfbot "View all packages from Kubeflow Charmers")

Platform:

24.04

edge 22

```
juju deploy request-authentication-configurator --channel edge
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

---

[Add docs to a charm](https://juju.is/docs/sdk/add-docs-to-your-charmhub-page)

#### A charm configurator to have `RequestAuthentication.security.istio.io` custom resources created

A charm configurator to have `RequestAuthentication.security.istio.io` custom resources created.

This charm exposes a config option to define the desired claim-to-header mapping for JWT tokens
validated by `RequestAuthentication`s, integrates with Hydra to obtain the JWT issuer of employed
identities, and integrates with two separate Istio charms managing K8s Gateways to have them
create a `RequestAuthentication` each, attached to the respective K8s Gateway, one for UI-based
access and the other for programmatic-based access, both sharing the collected JWT issuer and
claim-to-header mapping.

This charm encompasses the common logic to have such custom `RequestAuthentication`s set up so
that it can be reused for different product solutions and easily maintained in a unified place.

This charm meets the need of having two different `RequestAuthentication`s targeting two separate
K8s Gateways when sharing all other fields, including JWT issuer and claim-to-header mapping.
