3 ms·
I have been using Keycloak for the past couple of years in my homelab for SSO. It works really well, but there's a bit of a learning curve.
by d4a 4y ago
I have been using Keycloak for the past couple of years in my homelab for SSO. It works really well, but there's a bit of a learning curve.
- mooreds 4y agoWhat would you say have been the positives and negatives of it? Is the learning curve above and beyond OIDC/OAuth? How much did you have to customize it?
- sascha_sl 4y agoKeycloak just assumes you know OIDC terminology, and it has some quirks that you might not expect (e.g. until recently, client credential grants created a refresh token). It also, concerningly, uses some OIDC terminology outside of OIDC. There are two kinds of scopes in Keycloak. OIDC scopes (that are a set of mappers and represent permissions) and which client and realm roles can be included in a token (including the famous "Full Scope allowed" option that'll dump all roles into your token if you use the default OIDC scope). A lot of behavior is also just implicit. Particularly in the Authentication Flow Editor. You just gotta know what you want if you want to customize them. The Audience mapper is another tricky one, relying on the (not OIDC) scope to figure out which client to put into the "aud" claim.