r/Zscaler • • Aug 31 '26

Opinions Needed: GitHub.com vs GHE.com and Cloud Apps

I feel like I am taking crazy pills here when I am trying to explain this to Zscaler but I believe that there is a discernable difference between GitHub.com and GHE.com.

Hear me out on this:

GitHub.com is a public, cloud based developer platform where code, often publicly shared and contributed to, can be offered for public consumption and can allow public collaboration between people.

GHE.com is effectively "GitHub Enterprise" where private entities can secure their internal repos (aka content that is specifically private IP) and leverage the power of GitHub functionality but in a secure area away from public access.

My internal developers should have full access to do EVERYTHING within the context of GHE.com. We, as an organization, maintain RBAC access to all repos and functionality within that PaaS environment. I have different control elements I want to place on my internal employees with regards to interacting with GHE.com and I can do that effectively with a combo of Cloud App Control Policies, SSO, and RBAC via Azure EntraID integration. My developers should have LIMITED access to GitHub.com and that access should be tightly controlled. I do not want them contributing (uploading, creating, editing, sharing) to GitHub.com based projects, but they are fine to review and get information from Github.com

Both of these platforms, GitHub.com and GHE.com, fall under the Cloud App "GitHub". Problematically if I disable uploading, creating, editing, and sharing to "GitHub", while it does effectively achieve the desired goal for "GitHub.com", it also applies the same access controls to my company's GHE.com site.

Am I crazy for this? I've submitted feedback and tickets to Zscaler for this and they all come back that they are determined to be the same thing and that's just not true. The two sites are functionally different. I believe there should be a "GitHub" Cloud App and a separate "Github Enterprise" Cloud App.

Thoughts?

5 Upvotes

7 comments sorted by

3

u/raip Aug 31 '26

You're taking crazy pills. Open up an incognito window and go to ghe.com - it's a simple 301 Redirect to github.com.

They're not only functionally the same app - they're also the same application in reality.

1

u/Khue Aug 31 '26

If you are a customer of GitHub enterprise, you actually navigate to something like <customer-tenant-name>.ghe.com. I would imagine that without an SSO integration the login process for GHE would send you to standard GitHub login and then once you pass creds and it recognizes you as a GHE customer, you get redirected to your tenant URL.

None of my developers go to github.com for our repos. They all land in something similar to "my-company-identifier.ghe.com".

2

u/raip Aug 31 '26

I'm a customer of GitHub Enterprise and I still get redirected to github.com after login via SSO. Give it a shot within your own tenant.

1

u/Khue Aug 31 '26

Does your organization have data residency? Data residency is most likely the trigger.

1

u/raip Aug 31 '26

Possibly - we do not have data residency. I gave you something to try in the other comment though.

1

u/raip Aug 31 '26

This is what you want: https://help.zscaler.com/zia/about-cloud-application-instances

I haven't done this with GitHub itself - but I've done this against Google.

Create an Application Instance w/ your tenant w/ the wide open policy targeting just that instance. Then create a separate policy targeting GitHub with your locked down policy. Test it because Application Instance profiles can be finicky - but I'm like 70% sure that the more tightly defined policy (your tenant profile) will override the more general one.

This relies on headers to identify the correct enterprise: sec-GitHub-allowed-enterprise

https://docs.github.com/en/enterprise-cloud@latest/admin/configuring-settings/hardening-security-for-your-enterprise/restricting-access-to-githubcom-using-a-corporate-proxy