16 ms·
Keycloak with PostgreSQL on Kubernetes
- vxxzy 3y agoAh nice! I use Keycloak in conjunction with NetMaker. It seems to work well! I’d like to figure out a way to somehow get ssh authentication with keycloak. I’ve read of oauth + ssh certs, but all of it seems so cumbersome. It would be cool to have an open source alternative to StrongDM.
- bebop 3y agoSuper roughly, but you might be able to implement an Authentication SPI[0] and wire that into an Authorization Code flow. [0] - https://www.keycloak.org/docs/latest/server_development/#_auth_spi https://www.keycloak.org/docs/latest/server_development/#_au...
- hotpotamus 3y agoI've been down this road a bit, though actually in Docker Swarm. One aspect I spend a lot of time digging into was running multiple keycloak containers with shared cache. On metal or a VM with multicast, they'll find each other no problem, and it works beautifully, but I'm not aware of any container orchestration that brings multicast out of the box (and I don't think AWS does either). Keycloak has a built in Kubernetes DNS discovery mechanism to find its peer containers and share cache which also worked quite well on Swarm, though I lost a day or two tweaking it.
- rad_gruchalski 3y agoAWS supports multicast in VPCs.
- hotpotamus 3y agoCurious - I've seen several references that it doesn't support it, and that keycloak has a dedicated ec2 cache discovery option. But I don't use AWS anyway, so I'm far from knowledgable about it.
- rad_gruchalski 3y agohttps://aws.amazon.com/blogs/networking-and-content-delivery/running-multicast-enabled-containers-on-aws/ https://aws.amazon.com/blogs/networking-and-content-delivery...
- vbezhenar 3y agoYes, Keycloak cluster works fine on Kubernetes. It takes some time to read all the docs and understand things, but nothing outrageous, that was my experience at least.
- xupybd 3y agoI've just started using Keycloak to provide OpenID for F# Safe stack applications. Wow the learning curve was steep on that one. Not having ever touched OpenID or anything other than forms based authentication and not knowing ASP.Net very well. But it's neat to get it all up and running. Still a few issues with getting Keycloak to redirect to HTTPS but we will get there.
- rad_gruchalski 3y agoMaybe this will be helpful? https://gruchalski.com/posts/2022-02-20-keycloak-1700-with-tls-behind-envoy/ https://gruchalski.com/posts/2022-02-20-keycloak-1700-with-t.... I’m the author.
- xupybd 3y agoThank you! That looks like the exact problem I'm facing. I'll try it out today! Thanks again!
- andix 3y agoThat’s exactly what needs to be done. It is also in the keycloak documentation, but not as easy to find as in your post.
- rad_gruchalski 3y agoThanks. I have recently rolled out Keycloak on k8s with Istio and ACME cert-manager. I’m going to write an article about it and post here when I find some time.
- andix 3y agoThe most disappointing problem with asp.net for me was, that there is no backchannel logout. So you can’t easily force-logout users from oidc/keycloak. Everything else was going pretty smooth, although the authentication documentation for asp.net really sucks.
- 3y ago
- photonios 3y agoIf there's anyone reading this that is planning on deploying Keycloak in a high availability environment, I would highly recommend that you persist all sessions in the database as offline sessions. At work, I ran 9 Keycloak clusters in production, handling tens of millions of sessions where the cost of losing sessions was high. The amount of time we wasted on getting it to work reliably with its default configuration of storing the sessions in its distributed, in-memory cache (Infinispan) is insane. It just isn't designed to handle such a work load reliably. Unless you're willing to spent months tuning it for every possible scenario, you WILL lose sessions. If you are in this situation, shoot me an email. I have been through this pain and it took a lot of painstaking work to get to a highly reliable set up at scale.
- ArchOversight 3y agoDo you have a blog post or something detailing what you did and how you did it?
- rad_gruchalski 3y agoI found this: https://www.janua.fr/offline-sessions-and-offline-tokens-within-keycloak/ https://www.janua.fr/offline-sessions-and-offline-tokens-wit.... janua.fr is a very solid Keycloak resource. The write up is for a pretty aged Keycloak version but there are probably some decent pointers in there.
- photonios 3y agoThis article gets pretty close, but it misses a very critical piece. If you're running Keycloak 16 or older, you'll explicitly want to enable lazy offline session loading [0]. Otherwise, Keycloak will attempt to load ALL offline sessions in memory during startup. Keycloak 17 made offline sessions lazily loaded by default. [0] https://www.keycloak.org/docs/16.1/server_admin/#offline-sessions-preloading https://www.keycloak.org/docs/16.1/server_admin/#offline-ses...
- deleted 3y ago[deleted]
- vsviridov 3y agoAs a possible alternative, I've recently started using Zitadel (https://zitadel.com/ https://zitadel.com/) which is a very full-fledged open source IDP, in active development.
- upcoming-sesame 3y agoOry Hydra / Kratos is another good one https://www.ory.sh https://www.ory.sh
- vsviridov 3y agoI guess with Zitadel they don't paywall any features, and with self-hosted option you get essentially the same thing as with hosted. I think you can probably even do multi-instance, however maybe without a management interface for that part of it... When I read Ory language, it says to me "you can try it out locally and itegrate, but we want you in our hosted solution right after" (I could be wrong, I was just glancing casually...)
- rad_gruchalski 3y agoThe Ory stack doesn’t hide any features behind a paywall. Their documentation is subpar, for sure. It’s a decent product but setting things up can be a bit dull. One has to thread multiple Github repos and their incomplete scattered documentation together. But once it works, it works.
- vbezhenar 3y agoIs there solid documentation or tutorial on deploying hydra + kratos? That's what stopped me last year. I've found some subtle pointers in some buried github issues, but nothing definitive. Which surprised me because one would thought that's the main use-case for many people and should be documented well.
- whilenot-dev 3y agothere's the repository with examples: https://github.com/ory/examples https://github.com/ory/examples
- ahachete 3y agoThis is good and interesting recipe to get Keycloak and Postgres on Kubernetes. There is an important improvement, though: the Postgres deployed here is not production ready (high availability, backups, monitoring, etc). We run Keycloak on StackGres [1] which gives us production-ready Postgres setup (disclaimer: it's dogfooding). Happy to share the YAML manifests used to deploy Keycloak with StackGres. Maybe we will write a blog post as a follow-up to this one, for completeness. [1]: https://stackgres.io https://stackgres.io
- Turbots 3y ago[dead]
- deleted 3y ago[deleted]
- rad_gruchalski 3y ago> There is an important improvement, though: the Postgres deployed here is not production ready (high availability, backups, monitoring, etc). Another omission is that one could use a Keycloak operator instead of rolling custom YAML.
- ahachete 3y agoYes, absolutely.
- bbu 3y agoI gotta say the (new) keycloak operator is super basic and doesn't really support changes in image tag. it always assumes a keycloak upgrade and will automatically scale down your keycloak to 1 instance to do an "upgrade". of course this will overload that one node, it will crash, and all your sessions are gone. I'm not sure if anybody is actually using keycloak & kc-operator in production on kubernetes. the state of the documentation and guides make it look like it's an abandoned product.
- slig 3y agoHow do you compare StackGres to CrunchyData's `postgres-operator`?
- hsn915 3y agoAm I the only one for whom this kind of thing is painful to read? I am kinda curious though about the kind of personality type that enjoys this kind of stuff. Of course, I have never heard of "Keycloak" before, so I checked their homepage: "No need to deal with storing users or authenticating users." Wait a second, is dealing with storing users and authenticaing them _so much pain_ that you rather inflict yourself with the pain of setting up and managing a k8s cluster? I seriously don't get it.
- rad_gruchalski 3y agoNo. The article talks about setting up Keycloak in Kubernetes (and it does that poorly because it’s not a production setup) but you don’t need Kubernetes: https://gruchalski.com/posts/2022-02-20-keycloak-1700-with-tls-behind-envoy/ https://gruchalski.com/posts/2022-02-20-keycloak-1700-with-t....
- hsn915 3y agoI find that equally triggering
- rad_gruchalski 3y agoCan’t appeal to everyone. Tell me what triggers you. I’m the author and I’m looking forward to your feedback.
- hsn915 3y agoYou proposed it as an alternative to the complexity in the OP, but it's more or less the same thing: edit a bunch of config files and run some cryptic commands
- rad_gruchalski 3y agoIt’s not an alternative. It’s a different technology stack altogether. I posted it as a response to show you that one does not need Kubernetes to run Keycloak. What would you expect to see instead of a bunch of configuration files and cryptic commands?
- rubentanlz 3y agoHopefully this doesn't come across as off-topic but the "smooth scrolling" or whatever that is that hijacks the normal scroll behavior is throwing off my scrollwheel, making the website nigh impossible to navigate. Only way I can scroll properly is by clicking on the scroll bar and dragging it up and down manually.
- toomanydoubts 3y agoYes. As a rule of thumb, unless you're making some kind of experiment/poc/artistic work please don't hijack the native browser scroll ever. Hate that this still has to be said in 2023. We like and (maybe) configured the scroll on the OS to our own taste, it's pointless to try and impose an slower, inferior and bug-ridden non-native implementation of the scroll just to add some kind of "smoothness".
- brakmic 3y agoHi, OP here. Thanks for the hint. I just disabled smooth scrolling. Sorry, not a sophisticated designer guy, using wordpress plus some UI themes. Regards,
- rubentanlz 3y agoThanks, the article content is very useful for me as we're using k8 and keycloak together right now.
- boris-ning-usds 3y agoI've been reading up on Keycloak recently, and had questions for hosting keycloak in prod. How do people in the field handle configuration updates with code? For example, if I want to set it up as an identity broker to an idp, I would want that configuration backed by code, reviewed by my team. Is anybody using the keycloak terraform provider https://registry.terraform.io/providers/mrparkers/keycloak/latest/docs https://registry.terraform.io/providers/mrparkers/keycloak/l... in production? Do people diff the realm json configuration as code and use that instead?
- vbezhenar 3y agoSame pain here. I've tried terraform and it works, but I just hate it because of state management. We're doing things manually, like someone changes stuff on test server, writes everything down and then at deploy hour repeats those changes on production server. This is not nice.
- skhro87 3y agoyou can try keycloak-config-cli https://github.com/adorsys/keycloak-config-cli https://github.com/adorsys/keycloak-config-cli we've been using it in production for 2 years and it works well! we are running it as part of our CICD, to sync settings to all Keycloak realms. As the tool supports variable substitution, it makes it quite flexible. The config file it uses is basically the same realm.json you can export from Keycloak, so it doesn't re-invent the wheel.
- vbezhenar 3y agoWhy postgres is running as privileged?
- brakmic 3y agoHi, Many thanks for the hint. It must have been a leftover setting from one of the other variants I am using locally. Yes, postgres doesn't need to run as privileged. I changed it to "false" and updated the github repo. Regards,
- vbezhenar 3y agoI miss the ability to use some kind of GitOps with Keycloak. There's Terraform plugin, but I hate it (because of state). I wish there was some kind of config file which Keycloak would read at startup and create/update/delete its resources according to it. I know that I can initialize realm with JSON (with unreadable structure), but I can't maintain realm with config file.
- pat2man 3y agoHave you tried the operator? https://www.keycloak.org/operator/advanced-configuration https://www.keycloak.org/operator/advanced-configuration
- vbezhenar 3y agoI looked at it but I don't see the features I'm talking about. I can configure pod myself, so I don't understand why would I need this operator.
- skhro87 3y agoyou can try keycloak-config-cli https://github.com/adorsys/keycloak-config-cli https://github.com/adorsys/keycloak-config-cli we've been using it in production for 2 years and it works well! we are running it as part of our CICD, to sync settings to all Keycloak realms. As the tool supports variable substitution, it makes it quite flexible. The config file it uses is basically the same realm.json you can export from Keycloak, so it doesn't re-invent the wheel.
- vbezhenar 3y agoIt looks promising, thanks!
- Too 3y agoI may be wrong but is it not preferable to use StatefulSet for databases, rather than PV, PVC and Deployments? You will not be able to scale anything up anyway since it’s a single instance mounting the same data.
- brakmic 3y agoHi, I don't think you're wrong. StatefulSets are simply on a "higher level" than raw Deployments and manually provided PersistentVolumes/Claims. I am thinking about writing another article that shows how to use StatefulSets in similar scenarios. Regards,