4 ms·
So, first, congrats on launching your product. :) Personally, I don't have a need for it, and if I did, I'd be very reluctant to use a proprietary service, but
by jerrac 6y ago
So, first, congrats on launching your product. :) Personally, I don't have a need for it, and if I did, I'd be very reluctant to use a proprietary service, but I'm sure there are companies out there who will be happy to use you. Good luck!
------------
That said, maybe the HN community can answer something I've wondered about... Why isn't there an Open Source, standardized, self-hosted, version of this kind of service? Or, why hasn't one, or two, options emerged that everyone uses and I would have heard of by now?
User management, authentication, and authorization, are all problems that have been solved in many apps, and there are plenty of best practices. So, just like you shouldn't roll your own hashing algorithm, I'd think we'd want to do the same with this. It would make sense for one of the open source companies or organizations like Canonical, RedHat, Apache or Mozilla to have at least tried to do this.
The closest I can think of to an attempt is Persona...
Anyway, just been wondering about this for a while, and thought I'd take the opportunity to ask.
- SahAssar 6y agoI haven't tried it but https://www.keycloak.org/ https://www.keycloak.org/ (by redhat) seems close to what you describe.
- digaozao 6y agoI have been using it for a year. No problems so far, and found it to be really flexible
- TedDoesntTalk 6y agoKeycloak FTW. Been using it for 18 months now in production.
- afrodc_ 6y agoKeycloak is great and pretty extensible on a per basis need.
- mamcx 6y agoI have found confusing then support for multi-tenants and your own auth tables (ie: put the auth tables in the schema of each tenant?) across the board. Exist one project where I can do both?
- znpy 6y agokeycloak is great, it's very flexible and fairly lightweight (all things considered). it can get a bit complex, but to be fair the whole oauth/oauth2.0/openid/openid-connect/saml is quite messy in general.
- aryamaan 6y agoVery tangent question but someone could help as the discussion is about Keycloak. In particular, I am trying to solve the problem of how I can share client secrets (so they can generate access token using it) with the respective clients. I don't want to share them over email/ password protected doc. I tried making one client for each realm and adding one user to it. When I login via user account using GUI, I am unable to see any info related to clients. What am I doing wrong here? What are the good practices around this? Thanks kind folks
- jineshshah36 6y agoCheck out the [org](https://www.ory.sh/hydra/ https://www.ory.sh/hydra/) family of projects
- jokethrowaway 6y agoI second ory, that's pretty much a solved problem in my book. Fast self contained binaries, easy to interface with Kubernetes. Adding some UI around them and managing them via api is nice enough. The only incognita is whether they're going to handle scaling (I hope I'll have this problem one day). Hydra is for OpenId though, I'd point to Kratos + Oathkeeper.
- eins1234 6y agoI've been looking into SuperTokens lately. It's very new, but super promising imo: https://supertokens.io/ https://supertokens.io/
- advaitruia 6y agoThanks! Cofounder of SuperTokens here - please let us know if you have any feedback or questions. I can be reached at advait @ supertokens.io
- deleted 6y ago[deleted]
- keerthiko 6y agoever since facebook acquired, then liberated Parse [0], it kind of fulfills this role. You can roll any subsystem of it and use off-the-shelf providers for other subsystems (we pay a service to host the server, but we run our own dashboard server to poke into it, others run their own database and use just the API server, etc), but I suppose it's easiest if you run the whole parse backend as a whole. [0]: https://parseplatform.org/ https://parseplatform.org/
- vineyardmike 6y agoI’ve always wondered why parse was never more popular as a backend for people hosting personal and small scale stuff?
- 3np 6y agoMaybe one of these fit your bill: keycloak, freeipa, gluu - they all have a bit of different scope and approach
- sssk 6y agohttps://www.userfrosting.com/ https://www.userfrosting.com/ is a good open source solution in this space actually.
- robertlagrant 6y agoI'm keeping a close eye on ory.sh - it's an open source auth as a service that plugs into k8s etc nicely as well.
- franciscop 6y ago"Why isn't there an Open Source, standardized, self-hosted, version of this kind of service? Or, why hasn't one, or two, options emerged that everyone uses and I would have heard of by now?" Because it is a lot of hard, strict and continuous work. Specially if you want - and you kinda need to, if you want anyone to use you - to provide customization for: styling, different databases, languages (both programming and natural), login methods (SSO, email, etc), email delivery systems, user fields, etc. So people building open source generally will just solve their own problem and might share that, not solve a problem space one up with all of these combination complexity mess. The most "standard" open source I know is Passport.js, but it only solves the problem of login methods.
- necovek 6y agoCanonical Identity Provider (https://launchpad.net/canonical-identity-provider https://launchpad.net/canonical-identity-provider) behind Ubuntu SSO is free software, but the documentation is lacking (it's an openid provider with oauth support for application tokens; not sure if it's been moved to openid connect). To get proper users and groups, you'd needed to extract Launchpad Registry from Launchpad itself (https://launchpad.net/launchpad https://launchpad.net/launchpad), though I think some "teams" functionality was added to Identity Provider itself. In general, if more sites grew proper OpenID auth vs justa subset of providers, we'd see more people run their own OpenID servers to authenticate against external services. Basically, for an open source/free software service to succeed in this area, it needs to allow both federated and SaaS model because that's how free software people are :) And federated is hard because nobody accepts pure OpenID anymore (and it's funny: you'll trust an email address but not a URL as a unique identifier). But it's probably how hard it was to get working that's the issue.
- jerrac 6y agoThanks for all the replies. Sorry I'm a bit late responding. So, there are options, some I now remember hearing of before. I'm still interested in more of you thoughts on why they don't have a wider adoption rate.
- silexia 6y agoLaravel (php) and Django (python) both have easy open source user and auth management.