7 ms·
A detailed guide to SSO on Kubernetes
- gsjjsjsbsb 5y agoDoes anybody have a good, comprehensive guide to Keycloak? I looked at it a while back and it seemed like a giant web UI with a million poorly documented knobs, but I keep seeing people who claim to be using it. I've used Auth0, Okta, Dex, and ORY and none of them seemed quite as incomprehensible
- rad_gruchalski 5y agoThe thing with Keycloak is: when you know what you are looking for, it's all self descriptive. Server administration documentation is awesome: https://www.keycloak.org/docs/latest/server_admin/index.html https://www.keycloak.org/docs/latest/server_admin/index.html I've written more about Authorization Services: https://gruchalski.com/posts/2020-09-05-introduction-to-keycloak-authorization-services/ https://gruchalski.com/posts/2020-09-05-introduction-to-keyc... And can recommend these resources: https://www.janua.fr/tag/technical-blog/ https://www.janua.fr/tag/technical-blog/
- candiddevmike 5y agoKeycloak is designed to be super flexible and support almost every combination of auth methods out there. A lot of companies don't need this kind of complexity though, which is where something like Dex may be more appropriate--it's quite a bit simpler.
- streetcat1 5y agoI think that keycloak is based on JBoss, which is GPL? Hence I am not sure that you want it for commercial projects. But I might be wrong.
- nurgasemetey 5y agoThere are many commercial projects using Keycloak as I know. Are they in danger?
- jeroenhd 5y agoEdit: Keycloak is licensed with the Apache 2.0 license, so none of this is relevant for Keycloak. GPL is only a problem if you import or change the source code. If you just run it in the backend, as a service, you're most likely fine. If you customise Keycloak through code, you're probably in GPL violation territory. With the customisability of Keycloak, I doubt that this is something many projects will ever run into.
- pricechild 5y agoI don't think this is true. The GPL allows you to copy & modify code for your own desires very generously. The limitations you fear apply if you distribute the code (in source or other forms) or modifications yourself.
- jeroenhd 5y agoThat's true; assuming you run the software on your own premises, GPL won't hurt you at all. If you sell premium software packages to be run over at your clients' hardware this can be a problem, though. However, after looking into Keycloak more closely, the software seems to be licensed with the Apache 2 license, so none of this is a concern.
- jabiko 5y agoKeycloak is licensed under Apache 2.0
- varispeed 5y agoMy dream is to one day create an SSO solution for companies. I've been doing research for a time being, but I am worried that I wouldn't find any clients, because who would trust an SSO created by one guy in his basement? I think the first step to overcome that would be having a completely Open Source solution, but how to avoid other companies grabbing it and selling as their own? Or do you think it is better to develop it anyway and then worry about customers later?
- saberdancer 5y agoThere is already Keycloak and various vendor solutions. I feel you'll struggle to break through.
- herodoturtle 5y ago> because who would trust an SSO created by one guy in his basement? If you think you've got a good idea and a unique proposition - and your technical skills are up to scratch - then don't worry about starting out from your basement. Have a look at Thawte Consulting - a certificate authority founded by Mark Shuttleworth in his parents' garage - which he later sold to Verisign for $575 million dollars: https://en.wikipedia.org/wiki/Thawte https://en.wikipedia.org/wiki/Thawte Starting a "high trust" business from one's basement is perfectly fine. That being said, a far more important point is testing / validating the existence of an actual market for your product. Whether you build your solution out of your basement or a lavish penthouse office is irrelevant. The best and brightest team working out of swank office space will still fail if the market for their product doesn't exist. Hope that helps :-)
- martin-adams 5y agoPersonally, I think the answer has to come from your customers. If the pain you're solving is great enough that they want it, but the only showstopper is future-proofing, then you might be able to work with them to find a solution. It might be a case that you deploy into their infrastructure and give them a licence to use the source code should you shut down.
- 3np 5y agoThe current business players in the space all range across the spectrum of closed blackbox Saas (Auth0) to open core / open source (HC Boundary, arguably) Before you can answer that - how do you differentiate from the existing competition? What's your target customer?
- halfmatthalfcat 5y agoI've leveraged nginx-ingress's OAuth annotations to great success: https://kubernetes.github.io/ingress-nginx/examples/auth/oauth-external-auth/ https://kubernetes.github.io/ingress-nginx/examples/auth/oau...
- talkingquickly 5y agoYup agree, that's exactly what's being used here, along with some tweaks to make it easier to do things like passing the auth JWT's back to the underlying app etc
- cpdean 5y agoI read the headline, "A detailed guide to SSO on Kubernetes", as "A detailed guide to Single-Stage to Orbit on Kerbalnetes" and was thoroughly disappointed after clicking.