<@U011D3UQKNY> <@U01MTU9E4CF> <@U02U9MSKL9X> <@U04...
# talk-oathkeeper
c
@magnificent-energy-493 @proud-plumber-24205 @damp-sunset-69236 @refined-kangaroo-48640 @thousands-vase-40385 @high-optician-2097 @gentle-thailand-50068 @narrow-van-43826 @fast-lunch-54279 Okay... I know I've tagged a lot of Ory staff in this message, but we need to talk about this. You guys are publishing open-source software, I'm migrating my entire company's infrastructure over to Ory Cloud using Ory Oathkeeper as our proxy. I'm hitting serious bugs, lack of documentation, and worst of all lack of support. I'm gone through a few of these channels, git discussions, and git issues and I'm staggered by the lack of support you offer, even to the general community. If you're looking to expand your Ory Cloud service then you guys really have to start helping the people here, these are your future customers (including myself). I know it's a weekend, but I've been in this chat for months, I'm no further now than I was months ago. The worst part about all this is that you guys are in an awesome position to deliver something great, I've looked at the alternatives and nothing fits our needs quite like Ory. Please please please start taking support seriously. I know you guys have updated your website 4 times in the last 6 months, but what good is that if your customers can't integrate their software? I'm sorry for this public rant, but I just can't get anywhere here. Please understand I am technically a disgruntled future customer.
h
Hi Kieron, sorry to hear that you are having troubles, you clearly come from a place of frustration. Please help me set some expectations: The slack community is not an official bug tracker, and it’s a place where developers help other developers. I see that you have created 4 issues / and one discussions in Ory ( https://github.com/search?q=org%3Aory+author%3AKieronWiltshire&amp;type=issues ), one of which is resolved and two of those are within the last 48 hours. Ory’s engineering is less than 10 people, and we already have to support paying customers, fix bugs, advance the roadmap, keep the system alive, … - and we can’t offer real time support on Slack for free. We try to help people as best as we can, but it’s not a guarantee. Please also respect that we need to regenerate from a weeks of intense work on the weekend, and it can’t be the expectation that someone is helping during the downtime. Regarding Oathkeeper, it’s a bit of Ory’s problem child. The reason for that is that we are not super happy how the system works and there are many rough edges. However, fixing that requires, in our mind, a complete refactor (or rewrite) of the product. That’s why we do not have Oathkeeper as the highest priority in development right now. I do agree though, that there is a need for such a product. There is a clone of Oathkeeper that is improved a lot by dadrus, it’s this one: https://github.com/dadrus/heimdall Maybe this does what you need? Dadrus has been an active Ory contributor for some time. I hope this helps understand expectations and limitations, but still provides a bit of help.
c
First of all, let me just start by saying thanks for the response, I didn’t believe I’d get a response. Second, let me apologize for my bad attitude, although I’m under huge amounts of stress, it was no excuse for little outburst. How come the Ory team is so small? I was I under the impression the company was a lot bigger supporting big corporations?
h
It is, we’re simply a very efficient engineering team :)
Accepted, no problem!
c
I’m also willing to contribute to the projects and documentation if it helps
But I’m also going to need a direct communication channel with the team to be able to do that, whether that be just asking questions here, or whatever
But firstly, my immediate noticeable changes from the ory oathkeeper docs is that it doesn’t seem that the oauth2 introspect pre authorization supports the client credentials grant and that you have to supply the ory cloud api key, which imo is bad security, if an attacker gets into my proxy, they have access to kratos/keto, they could technically make themselves and admin user etc
I’m not sure if this is just a documentation thing, or if oathkeeper generally lacks support for this
i
Since Aeneas put the rabit out of the hat 😉 (thank you for advertisement @high-optician-2097. I appreciate that a lot!!)... @creamy-fall-97349: Unfortunately this is not just a documentation thing. oathkeeper does indeed not support client credentials grant for accessing apis.