4 ms·
The best part is when you start chaining Keycloak instances together. We've had a couple cases where customers have wanted their own identity management, so we
by realdavidops 6y ago
The best part is when you start chaining Keycloak instances together. We've had a couple cases where customers have wanted their own identity management, so we use an instance of Keycloak to connect to our central keycloak instances and to their solution of choice (Google, AzureAD, etc), and allows everyone to use their preferred identity platform.
- pm90 6y agoI’m a bit confused...are you federating user management of those customers to their IDP? Or running separate keycloack instances for each of them? Or something else?
- 411111111111111 6y agothey could also just let them run their own keycloak instance and use that as the provider for the realm so customers can more easily debug it themselves. it doesnt need much maintenance, so it doesnt really get easier than that.
- benjaminwai 6y agoThink it would be using brokering, the instance of Keycloak would be an external identity provider. Each customer would have their own instance of Keycloak that could then be configured to broker their choice of identity provider. I think this might be achievable at the realm level in a smaller scale deployment, i.e., using a separate realm for each customer but still chaining them back to the central realm through brokering, rather than spawning off new instances of Keycloak. Just a thought..