17 ms·
Keycloak – Open-source identity and access management interview
- roboben 3y agoI don’t get it. Keycloak feels like some clunky 90s enterprise software and I mean it only in a bad way. Had to run it on openshift and it was hell. It’s not really made for containers, clustering is basically impossible, it needs to know it’s default route and I can’t remember the exact issue but found myself patching some obscure startup scripts which templated some XML to start that thing. Can’t recommend but I’d be happy to hear alternatives which are actually modern.
- Glyptodon 3y agoIt's on my list of things that assumes out of the box that you know waaaaaay more about dozens of details than you actually are likely to unless you've already used it for 10 years. To the point that I don't even know what the benefit of using it vs. other options is at all.
- roboben 3y agoI can’t understand your first sentence even after reading it ten times. Maybe it is too long for me. To the second sentence: I don’t know what the benefit is either but in some environments you are not able to use any cloud provider or other external service to realize the auth layer so you are stuck with things like keycloak. Hope this thread discusses some other solutions which you can self host.
- vxNsr 3y agoI know the two main competitors that have been adopted by the self hosted community are authentik and authelia, they’re both somewhat under developed for enterprise but at the same time still difficult to grasp for non-full time devOps people. At least in my opinion.
- jsmith99 3y agoI use authentik for self hosted - it's great but still too powerful and configurable for me or most people who are not auth experts to customise. Just creating a password reset flow requires integrating a dozen moving parts. The only explanation how to do it is a yaml file or a YouTube tutorial. Setting up basic forward auth or OIDC was super easy though.
- Lacerda69 3y agouse cases that require _everything_ "on-premise" are often government/military, big healthcare, or just huge enterprises that want to control everything (and can afford a team that only runs their auth service). I mentioned Ory above but you get both options - either as a managed service or run on your own infra
- p_l 3y agoOr just places that don't want to give data to external, VC-funded or worse, vendors. I have clients that definitely prefer combination of open source + owner-controlled + lower costs ;)
- saynay 3y agoYep, this is why I have been evaluating it recently. Have a customer that wants SAML 2.0 support, others that want LDAP support, 2FA support, and multi-tenancy support, while being something we can self-host. The other main suggestions I have seen - ORY or Zitadel - tend to be missing at least one of those (from what I can tell). Keycloak looks like a big complicated monster, so I would prefer to stay away except that it looks like I will be required to have all that complexity to support all the use-cases we are looking at.
- selcuka 3y agoCurious. I'm not using Zitadel yet, but we are planning to. It seems to support all of those features. What was the missing part for you? https://zitadel.com/docs/apis/saml/endpoints https://zitadel.com/docs/apis/saml/endpoints https://zitadel.com/docs/guides/integrate/identity-providers/ldap https://zitadel.com/docs/guides/integrate/identity-providers... https://zitadel.com/docs/concepts/features/selfservice#mfa--2fa https://zitadel.com/docs/concepts/features/selfservice#mfa--... https://zitadel.com/docs/guides/migrate/introduction#multi-tenancy-architecture https://zitadel.com/docs/guides/migrate/introduction#multi-t... https://zitadel.com/blog/zitadel-as-sso-provider-for-selfhosting https://zitadel.com/blog/zitadel-as-sso-provider-for-selfhos...
- saynay 3y ago
- nebulousthree 3y agoThey mean that the software relies on the user understanding its, or the industry-it-serves's, jargon, to be used effectively.
- _cenw 3y agoWhich is extra funny when Keycloak is sticking to jargon out of RFCs that nobody else in the SaaS identity space is using. Hooking up Keycloak to a SAML consumer that only documents SaaS configuration is a fun game of try until it works most of the time.
- Lacerda69 3y agoHave you had a look at Ory (Kratos)? Its a "cloud-native"/modern alternative to Keycloak: https://github.com/ory/kratos https://github.com/ory/kratos
- dijit 3y agoI have, and we went back to keycloak- everything the parent says is true, however Ory/Kratos is a lesson in half finished solutions and poor documentation. we really tried quite hard, since it was backed by CNCF, but it could just be a case of being a tad too immature for prime time. it seems keycloak is now CNCF though
- rad_gruchalski 3y agoOry Kratos is nowhere near Keycloak. First of all, one needs at least Kratos+Hydra (there’s an integration method now out of the box yay) but Keycloak still has a flexibility advantage. Keycloak has many more features out of the box comparing to the complete Ory stack. The only thing nicer in Kratos from Keycloak is the standalone self-service UI with JSON identity declaration. If someone from the Keycloak team is reading this, please, let’s have a talk about bringing that feature to Keycloak, then Keycloak will be perfect. The template approach is a bit of a hassle. Source: deployed both stacks in production systems.
- mnming 3y agoAnother significant advantage of Kratos is that it's written in Golang, so it takes little to none resources for simple use cases. Also my experience with Keycloak in the past was that you can't do zero downtime deployment, or true configuration as code.
- adeptima 3y agoFound Ory (Kratos) customised registration flow as something over-engineered for my personal use cases. Very impressive ecosystem nevertheless. Show HN: Ory Kratos https://news.ycombinator.com/item?id=31679811 https://news.ycombinator.com/item?id=31679811 Most HN comments are still relevant
- 3y ago
- tecleandor 3y agoWere you using Keycloak also as the identity provider? IIRC, if you're using an external identity provider, and you want clustering, you can just deploy Keycloak containers and load balance between them. You can then load a shared cache if you want (or need). My memory is fuzzy right now, but although it isn't the leanest solution, I don't remember it as terrible. Ours wasn't a very custom solution anyway, we just hit an LDAP in the back and that was all.
- Delotono 3y agoThey completely reworked the code base and made it k8s compatible
- rad_gruchalski 3y agoMost of those issues have been sorted out in recent versions. It’s all container-ready now with pretty solid k8s story.
- jeroenhd 3y agoI just docker-compose up'd the server and configured it. I don't know when you last needed to mess with it, but the containerised version seems quite easy. Configuration sucked, but that's because Keycloak can do an awful lot.
- ownagefool 3y agoWhilst I agree keycloak is a lil clunky, I had it working clustered in k8s ~8 years ago. I do recall the gossip protocol presenting problems back then, but now I believe the helm chart just works.
- ashtonmeuser 3y agoBC gov?
- xnyanta 3y agoAre we using the same piece of software? I have it deployed in production on kubernetes using the bitnami helm chart and everything works like a charm, clustering etc. No need to modify any XML or care about network routes.
- ponyous 3y agoHow do you handle backups? I was considering doing the same, but found that backing up different systems inside k8s can be difficult.
- seletz 3y agoWe use KC with PostgreSQL as backend data store. Backup is done by backing up the PostgreSQL database. If you actually want to transport configuration across environments (DEV, QA, PROD), then you want to export realms and have it load by KC on startup or import it using the UI.
- jdsleppy 3y agoThere's a good Terraform provider for consistent configuration across environments, too.
- mooreds 3y agoDisclosure: I work for FusionAuth. We've had a number of folks migrate from Keycloak due to some of this clunkiness, but I do know they've done some major overhauls recently (moving to Quarkus amongst other things). It also used to be super resource intensive if you have a large number of realms (which is what Keycloak calls tenants and Cognito calls user pools). From this 2022 link, more than 100-200 can cause issues: https://github.com/keycloak/keycloak/discussions/11074 https://github.com/keycloak/keycloak/discussions/11074
- Lucasoato 3y agoI’m a bit newbie in this exact field but when Keycloak is used to autenticate an external client, wouldn’t revealing that you’re using Keycloak itself be a security concern? Giving that information to a possible attacker could be dangerous, is it possible to make it totally impossible to understand if someone is using Keycloak or not?
- Lacerda69 3y agoI dont quite get why you think it would be a security concern? The alterntive to using a tried and tested solution is to build it yourself - but are you really confident you will do a better job than professionals in the field?
- paulmd 3y agoServer information leakage is generally viewed as a security vulnerability, eg by scanning tools utilizing the OWASP guidelines, because it assists in server fingerprinting. https://www.ibm.com/docs/en/control-desk/7.6.1.x?topic=checklist-vulnerability-server-leaks-information https://www.ibm.com/docs/en/control-desk/7.6.1.x?topic=check... https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/01-Information_Gathering/02-Fingerprint_Web_Server https://owasp.org/www-project-web-security-testing-guide/lat... The general problem is that if you just go and blab about what software you're running, if you ever have a version with a known vulnerability (or a zero-day) then the attacker immediately knows what payload to run against you, in fact you can potentially be programmatically attacked from Shodan/etc. Obviously it's better to simply never run any insecure software, but forcing them to run a search for payloads against you will hopefully create an opportunity for them to trip alarms and generally increase the attack time. I am not super duper concerned about leaking what the gateway app is in general, as a sibling mentions it's pretty unavoidable that an attacker is going to fingerprint a server if they really want to, I generally agree (without knowing which is which) that there are clearly a couple of them that have distinctive UI looks lol. On the other hand, leaking version info is probably a bridge too far in my opinion - if you do ever end up with a vulnerable JVM/library/appserver/gateway, now it can be programmatically identified by an attacker. Things like log4shell or the Jakarta Struts vuln have a long long tail of shit that's gonna be vulnerable forever. It's not the end of the world, but honestly I really, really dislike the way "security by obscurity!" tends to be used (more often than not) as a thought-terminating cliche. The line is supposed to be that "obscurity as the only method is not security" and that's true, but, obscurity is generally an important part of defense-in-depth. There's no reason to hand an adversary more information about the system than necessary, them blundering around your obscurity and triggering security alerts for patched attack payloads/etc or weird errors that don't normally crop up increases the chance of detection. People treat it as "anything that increases obscurity is a bad thing" and no, actually that's generally a good thing (as OWASP acknowledges). Just not if your system is designed such that it doesn't work if obscurity fails. Building a secure system and then adding obscurity is a net increase over a secure system without the obscurity. Should your application be secure if you hand them a classfile list? Sure. Is it a good idea to actually hand them one? No. Same for network maps/IP ranges/etc. Is it something they could figure out eventually? Sure, but make them work for it, and hope they try to connect somewhere that isn't allowed for that container/VLAN and alarms go off. Security and obscurity are two great tastes that go great together, because obscurity increase the chances that an attacker trip alarms in a way that catches attention.
- croo 3y agoI worked on a project which used Keycloak for authentication and SSO module between like 10+ java services with a custom UI and custom 2fa solution. I really liked it. Setting up and using it with LDAP was easy, Google and other sso integration was a search and some settings away, it ran on docker without problems. There were some problems with caching and refreshing user data but that arose from the complex architecture. The keycloak UI was at times a little clunky but the documentation was good. I would recommend it to anyone.
- rad_gruchalski 3y ago> the documentation was good There’s also a book now which I can highly recommend: https://www.amazon.com/Keycloak-Management-Applications-protocols-applications-ebook/dp/B092KP135B https://www.amazon.com/Keycloak-Management-Applications-prot.... It has some holes in the installation section because it does not cover the most recent containerisation story but it’s pretty good for Keycloak configuration for various purposes.
- mooreds 3y agoAwesome, just ordered! Thanks for sharing.
- beachy 3y agoKeycloak is awesome. It does 10 x what you likely need, but when some enterprise customer asks you to for support for their baroque idp setup or for their crazy password complexity requirements, with Keycloak you can always Just Say Yes.
- p_l 3y ago... and when it does, it gives you the tools to whack the system till it works. Been there, done that, AWS can never claim their documentation is correct to me anymore.
- deleted 3y ago[deleted]
- kurante 3y agoWhat do folks think about authentik[0]? I tried to set up Keycloak but after fiddling with it for awhile before giving up and trying something else. It felt really weird that I was just extracting a tar and running a jar instead of some pre-packaged solution, but that might just be me. authentik was pretty easy to set up for my homelab, but maybe I'm missing something given all the positive recommendations for Keycloak? [0]: https://goauthentik.io/ https://goauthentik.io/
- Jnr 3y agoI set up Keycloak using Docker and it was very simple to do. I did not really try authentik yet since all the advanced features I needed worked with Keycloak, but I do have it running in a container to play with at some point in time.
- miduil 3y agoI was considering using authentik, but I'm not very keen towards having a Django application taking over SSO authentication.
- risson 3y agoAuthentik dev here, AMA
- axutio 3y agoUsing Authentik as a part of my selfhosted setup, mostly positive things to say. I tried with Keycloak first but had too much trouble getting the Docker image to work, so switched to Authentik. I also checked out some other options along the way, and ultimately realized that pretty much all of the options come with enterprise-oriented features that are just added complexity for the self-hosting use case. Ultimately, I've gotten at least somewhat familiar with all the complexities of Authentik, so I'd have a hard time switching off. Would definitely love to see a solution geared towards selfhosting that's more barebones, though.
- golemiprague 3y ago[dead]
- adeptima 3y agoKeycloak is a non-brain solution for my enterprise, in-house friends. Would like to cheerlead for fully opensource Zitadel project here however. https://zitadel.com/ https://zitadel.com/ https://zitadel.com/team https://zitadel.com/team Main repo https://github.com/zitadel/zitadel https://github.com/zitadel/zitadel Zitadel team clearly understand OpenID, Auth0, Keypass, etc specs and have all previous experience to implement identity management right for SaaS, B2C and B2B project scenarios. SaaS Product with Authentication and Authorization https://zitadel.com/docs/guides/solution-scenarios/saas https://zitadel.com/docs/guides/solution-scenarios/saas Simplify Your SaaS: Multi-Tenancy and Delegated Access Management with ZITADEL Organizations https://www.youtube.com/watch?v=Cx_WgyY4TOo https://www.youtube.com/watch?v=Cx_WgyY4TOo ZITADEL Roadmap https://github.com/orgs/zitadel/projects/6/views/1 https://github.com/orgs/zitadel/projects/6/views/1 Zitadel took a very good direction into allowing to "build my own login and register ui" Sprint Demo - ZITADEL 2.28.0 https://www.youtube.com/watch?v=hpQ4zrV48LY https://www.youtube.com/watch?v=hpQ4zrV48LY [Epic] Login API and improvement of Register API #5015 https://github.com/zitadel/zitadel/issues/5015 https://github.com/zitadel/zitadel/issues/5015 https://github.com/zitadel/typescript https://github.com/zitadel/typescript Previously had a look at Ory, Keycloak and many others. Found those solutions either to be more "enterprisy" and over-engineered rather than something which can co-exist in my small team brain.
- lordofgibbons 3y agoWhen I was building a website and companion app, I researched a lot of the open-source options for auth. My primary requirement was ease of setup and operation. I didn't want to mess around with JVM dependencies and 100% didn't want to start messing around with k8s for such a small project. I was also very intimidated by the ORY stack. I didn't know how all the pieces fit together. And to self-host you pretty much need to run and orchestrate it on k8s. I'm not an auth expert, I just want a login thingy for my website/app. I'm not affiliated with it in any way, but I really liked what ZITADEL[1] is doing, in case anyone else is researching their options. It has a very simple interface to get started with, but also a ton of features. It being written in Go is a huge benefit since that makes it much easier for me to throw it up on my vps and calling it a day. 1. https://zitadel.com/ https://zitadel.com/
- adeptima 3y agoSame experience with ZITADEL and Ory. Posted more details on ZITADEL below in this discussion.
- faangsticle 3y ago> I didn't want to mess around with JVM dependencies and 100% didn't want to start messing around with k8s for such a small project. That's what the docker image is for: https://www.keycloak.org/getting-started/getting-started-docker https://www.keycloak.org/getting-started/getting-started-doc... docker run -p 8080:8080 -e KEYCLOAK_ADMIN=admin -e KEYCLOAK_ADMIN_PASSWORD=admin quay.io/keycloak/keycloak:21.1.1 start-dev And off you go
- lordofgibbons 3y agoI've only used docker for local dev environments, so I'm curious what happens if the process crashes? Does the docker daemon perform health checks to restart it, or is that the domain of k8s? It's pretty simple to do with systemd.
- vbezhenar 3y agoDocker and kubernetes are different things. But both systems can restart crashed containers. That's not an issue at all. Kubernetes does it automatically. Docker does not do it automatically but you just need to supply proper option for `run` (or just in docker-compose.yaml).
- vbezhenar 3y agoMy biggest problem with Keycloak is its configuration. It stores its configuration in the database. It means that I can't just configure it in some yaml configmaps. There's no easy supported way to test some changes on test server and then move those changes to production. You need to click around in its UI and you better do it well, it's a security tool after all. There's adorsys/keycloak-config-cli which is third-party solution which is supposed to somewhat mitigate this issue (you supply a config and it'll try to adjust keycloak instance to this config), but it's absolutely not first-party solution and does not work as well. Please just store users in the database. Let me specify everything in config yamls, so I can change it and restart the server and that's about it. That's how gitops is supposed to work.
- horsawlarway 3y agoI feel this problem (I also find configuring keycloak clunky) - but I understand their problem. OIDC allows an arbitrary number of identity providers to register themselves - so there's not really a clear way to distinguish "config" vs "data" here. That said - They've recently improved importing and exporting realms, and it really solved a lot of my pain. Mainly - you can now directly import/export realms in the UI, and the server doesn't need to be stopped. Still a little more finicky than I'd like, but way less risky than having to reconfigure by hand.
- deleted 3y ago[deleted]
- xnyanta 3y agoJust use the terraform provider.
- liamkinne 3y agoThe Terraform provider[1] unfortunately is 3rd party and as such doesn't bring and guarantees of correctness other than that of the maintainer. It would be nice to see Keycloak provide an official solution for configuration management other than the K8s operator which is missing a lot of features. [1] https://github.com/mrparkers/terraform-provider-keycloak https://github.com/mrparkers/terraform-provider-keycloak
- tendant 3y agoWe used keycloak for openid identity provider as well. It is fine to setup keycloak once. But it is painful share the setup with other engineers. For local development, we end up using dex (https://dexidp.io https://dexidp.io). When we need support group/role, we use dex and glauth(https://glauth.github.io https://glauth.github.io). Both dex and glauth can be configured with yaml files. We just created a few yaml files and a docker compose file, every engineer can be brought up the whole environment in a few seconds. Also https://www.authelia.com https://www.authelia.com and https://github.com/goauthentik/authentik https://github.com/goauthentik/authentik look pretty promising, if you need more advanced features from them.
- mooreds 3y agoGlauth looks pretty cool, thanks for sharing! Amazing to me that LDAP was invented in 1993 and is still relevant today.
- throwawaaarrgh 3y agoEverything made since is simultaneously more complicated and less useful, and LDAP just does one thing well, so it's here to stay
- tannhaeuser 3y agoLDAP (the odd CN=x, OU=y, ... recipient/originator addressing format) is based on even older (1980's) ITU-T OSI X.400/X.500 ...
- koevet 3y agoIt's actually very easy to share a realm configuration. In my team, we docker-compose-up KC and the realm gets configured at boot time, by passing the path to a previously exported configuration, which we store in got. The configuration holds realm data and users.
- okeuro49 3y ago> But it is painful share the setup with other engineers. We used keycloak-config-cli [1] it compares a config file stripped of IDs to your Keycloak installation and makes the relevant updates through the REST API. [1] https://github.com/adorsys/keycloak-config-cli https://github.com/adorsys/keycloak-config-cli
- joshgermon 3y agoThis is timely. I am stuck on simple authentication for my small apps. Everyone tells me - "Don't roll your own auth EVER!!!!", and then tells me about some easy-to-use Auth as a service. Ok, great. Well if I'm buying my auth I at the very least need some kind of 2FA, MFA or something. I don't care about anything other than user/pass and MFA. But every service wants to charge you well over $100/mth for any kind of MFA. Why can't they just forward the transactional SMS/Email charges on? Or better yet just give the authenticator app options. I feel like user/pass + MFA isn't asking for the world and not including any kind of MFA to me feels like potentially worse security than "rolling my own" simple bcrypt + regular old sessions and then can add on MFA too using well defined standards and libraries. Now I do like these open-source options but again, they seem faaaar too complex for what I want. I could definitely implement simple session and hashing auth much quicker than setting up any of these. Which I completely understand as this is complicated enterprise identity systems here. I don't need that though! Anyway rant over. Anyone else have this experience or am I alone?
- nine_k 3y agoAs mentioned in multiple comments, https://zitadel.cloud/ https://zitadel.cloud/ It's free for 25k requests / mo, then you either earn enough to pay, or self-host :)
- joshgermon 3y agoAppreciate the call out, will definitely check this out. I haven't seen them mentioned much before.. Very interesting to have a per request model, instead of MAUs. I think I prefer that too.
- Volundr 3y agoI'm curious whose telling you not to roll your own auth. I've worked on far more software that handles its own auth than integrates with Okta/Keycloak/Whatever. In fact the general advice I've heard is "just use bcrypt"
- joshgermon 3y ago
- throwawaaarrgh 3y agoKeycloak: RedHat Engineering at its usual piss-poor level, plus the mediocrity of Java projects, mixed with the complexity of every enterprise customer. Result: "hey, you can get it to work eventually!"
- seletz 3y agoThat's not at all our experience. We use KC for all our auth/auth needs and it basically "just works". The UI might look a little outdated, but that's a admin ui anyhow. Lately even that got better. Cannot recommend KC enough. Even kenning locally on our dev boxen, it never failed on us.
- stevefan1999 3y agoI've been using Keycloak for my free Oracle DB. I have the option to use OCI but I don't want my customer (or players, actually) data to be directly stored on Oracle side because they are not that flexible. Other than that I find Keycloak super easy to use with Kubernetes nowadays though it was such a pain in the ass in the past, because the use of EJB and WildFly. Now they switched to Quarkus and you have a much better environment
- gabereiser 3y agoWe used keycloak at the Accelerator I worked for. I used it to provide auth and SAML SSO to enterprises while giving our devs an easy to integrate module. It worked great. Theming the login/signup/forgot password pages was simple and easy but would have been easier for the teams if it was React. Nevertheless we built some amazing B2B SaaS software using Keycloak as our identity provider. I would use it again for sure.
- iimpact 3y agowith Keycloakify, you can create themes in React: https://www.keycloakify.dev/ https://www.keycloakify.dev/
- gabereiser 3y agoNice! Thanks for sharing.
- brabel 3y agoWhy the hell you need React for a login page?
- gabereiser 3y agoJust because of consistency with our design components. You don’t need react for a login page. If your app is already using react and has a lot of custom components, it would have been easier for the dev teams vs having to learn Freemarker.
- hsluoyz 3y agoCasdoor is another promising open-source IAM solution: https://casdoor.org/ https://casdoor.org/ , written in Go and React. All features like OIDC, OAuth 2.0, SAML, CAS, LDAP, WebAuthn and 2FA are all supported. Compared to Keycloak, Casdoor has: 1. Support high-concurrency and use less memory (Go v.s. Java) 2. More modern SPA-style web UI (with React and Ant Design), more CDN friendly 3. full-fledged RESTful API 4. Support a lot of provider types: OAuth, SMS, Email, CAPTCHA 5. More powerful authorization (powered by Casbin), Casbin is a popular authorization solution with a lot of integrations for DBs and applications: https://casbin.org/ https://casbin.org/ SaaS hosting is also provided at: https://casdoor.com/ https://casdoor.com/ for anyone who don't want to self-host
- bboygravity 3y ago2. More modern SPA-style web UI (with React and Ant Design), Is this a feature or an anti-feature?
- hsluoyz 3y agoSSO doesn't need SEO. So SPA is OK. The good point is RESTful API is fully exposed without any extra dev work.
- rickette 3y agoThe website/docs are in Chinese. This will be a major blocker for folks outside that region.
- koevet 3y agoThis is from the GitHub page of the project: An open-source Identity and Access Management (IAM) / Single-Sign-On (SSO) platform powered by Casbin and AI gateway with web UI supporting OAuth 2.0, OIDC, SAML and OpenAI ChatGPT Why would an IAM/Oauth2 platform need Chatgpt? Is this just buzzword bingo?
- jsiepkes 3y ago> 1. Support high-concurrency and use less memory (Go v.s. Java) In the context of Go vs Java this is a kind of weird unsubstantiated claim. For example if you think a garbage collector leads to higher memory use; Go uses a garbage collector, just like Java. There are loads of applications which support high concurrency in Java. Such as Elasticsearch and Apache Kafka.
- ninjaoxygen 3y agoAs a user of Keycloak on a production project, I'm a little sad there is currently no support for opaque tokens. Sure, you can treat the access token as an opaque token... but at the end of the day it could be a lot smaller. Discussed here https://github.com/keycloak/keycloak/discussions/9713 https://github.com/keycloak/keycloak/discussions/9713 and https://stackoverflow.com/questions/75082532/keycloak-support-for-jwe-opaque-for-access-token-and-refresh-token https://stackoverflow.com/questions/75082532/keycloak-suppor... We also experience a few front-end issues, like when a token expires, the browser tab goes back to the login page. If you leave the tab a while then press login, the token it is using will have expired. Rather than automatically retrieving a new token and posting the login again, the user gets an error message and has to authenticate again. If you have two tabs in that state, you log one back in, switch to the other tab, if you refresh that tab, all is well, login proceeds automatically. If you press "login" instead, you get an error page telling you "already logged in" rather than just redirecting you back to the app... it also loses the redirect url so you have to press "back" instead. Will see if we can fix these when we have time, it would be nice to contribute back.
- kioleanu 3y agoWe use Keycloak _a lot_ at work, with many public and private instances. It is an amazing product and I keep discovering features every day. But as I somehow ended up being the de-facto responsible person for all things related frontend, I find that Keycloak is lacking some stuff there. My biggest problem at the moment is that you can’t add an endpoint + new page next to your login/registration process. For example, I now need to add a page that explains what data protection measures we take. My only easy option is to add a normal HTML page and link to it, but then it doesn’t inherit from my template and I have to maintain this file separately. Otherwise I have to extend Keycloak’s functionality to register an endpoint myself and then point this endpoint to a method that reads my ftl template and parses it. Apart from that, I’ve been struggling with UI changes that made once straight forward functionality hard to work with. For example role assigning inside a client, which is now hidden behind multiple screens, where before it was a matter of picking a user and client and just arranging the roles. I feel like there’s a good need for a UX expert in the team because it seems that Keycloak is becoming one of those pieces of software we pay consultants to come and explain to us, because it is cheaper than us doing it by reading the manual and trying different combinations
- actidoo 3y agoYou can add custom pages to your login and registration flows by implementing an SPI and customizing your flows in the admin interface. ( We offer consultancy for this..., info@actidoo.com )
- kioleanu 3y agoThis proves my point from the last paragraph. I’ve also found this solution in the past, but it is too complex for me. Just to define a page, I would write an SPI, do a config in the admin panel and the corresponding documentation I would need to write for my colleagues. One of those is bound to get forgotten and not get updated, which brings me to square one, keeping a HTML file updated. That’s why I would prefer a solution in which I register the endpoint programmatically and make it parse the template. I do it once and I don’t need to config the instances afterwards (we have dev, staging and prod)
- 3y ago
- actidoo 3y ago[dead]
- elevation 3y agoMy LDAP server is the source of truth for my org's user/password (authentication) and user-group membership (authorization) data. I'd like upgrade to an IdP like Keycloak. It seems straightforward to have Keycloak proxy the authentication via OIDC but it's less clear to me how to get apps to check with Keycloak to determine if user X is in group Y and is therefore allowed to access resource Z. The main benefit in a setup like this is the ability to query a single source of truth when it's necessary to audit a user's capabilities within the org. Is this an achievable or reasonable use case for keycloak? Or should I integrate my apps around a different Zanzibar clone which is designed to quickly serve granular permissions?
- rad_gruchalski 3y agoYes, it’s possible. You can do this with Authorisation Services. Not an exact example but it’s close: https://gruchalski.com/posts/2020-09-05-introduction-to-keycloak-authorization-services/ https://gruchalski.com/posts/2020-09-05-introduction-to-keyc.... I’m the author.
- jgrodziski 3y agoI use Keycloak a lot for authentication and authorisation and I like its flexibility and richness of features. Running it in production is a no-brainer, the only problem we got was some bad behaviours of some clients that issue a token for every API call as it can put some stress on Keycloak, has to implements some rate limiting in front ok Keycloak to avoid that. I try to ease its usage with Clojure with https://github.com/jgrodziski/keycloak-clojure https://github.com/jgrodziski/keycloak-clojure I wrote some documentation about Keycloak concepts here: https://cljdoc.org/d/keycloak-clojure/keycloak-clojure/1.30.0/doc/security-concepts https://cljdoc.org/d/keycloak-clojure/keycloak-clojure/1.30....
- swapsCAPS 3y agoHeh! I just started using keycloak y'day in combination with oauth2-proxy to give me a way of completely delegating authentication. This way I don't have to worry about auth _in_ any of my apps. Really nice experience so far and fantastic documentation.
- RedlineTriad 3y agoI tried Keycloak for my homelab, but I found the resource usage especially on startup to be too high (3 GB memory or something) and since I wanted minimal sever footprint I went with lldap[1] as the user store and authelia[2] to do forward auth using traefik. Pretty happy with this setup, though it has less features than Keycloak, it's easier to administrate from code. [1] https://github.com/lldap/lldap https://github.com/lldap/lldap [2] https://www.authelia.com/ https://www.authelia.com/
- chromanoid 3y agoDid you try the "new" version powered by Quarkus? I think it has a much smaller footprint. edit: BTW authelia looks very promising. Thank you for the link! The bus factor seems a bit low for such a mission critical application, at least when evaluating it as an alternative for production. But I really like how open the core team is about that.
- RedlineTriad 3y agoI tried the Quarkus version, but it does some kind of build step at container startup, and that is what used the most memory. You can apparently build an "optimized" image[1] so it doesn't do it at runtime, but I didn't want to build a custom image, and I felt like the KeyCloak philosophy didn't align with my own. In general I found myself avoiding Java applications because of their memory footprint. [1] https://www.keycloak.org/server/containers#_creating_a_customized_and_optimized_container_image https://www.keycloak.org/server/containers#_creating_a_custo...
- brabel 3y agoI understand your reluctance to use Java, but it's actually pretty good if the developers use small libraries instead of the giant frameworks most Java servers use... a Java server for this kind of stuff will run within 200MB+ comfortably and with very high performance when written properly. Anything using 3GB for this stuff is doing something terribly wrong.
- pharmakom 3y agoOverall, I have enjoyed using Keycloak. However, the docs were poor and I had to spend lots of time scouting the internet to get it configured right. This is quite uncomfortable for a piece of security infrastructure.
- RamblingCTO 3y agoKeycloak is the bane of my existence. We use it and I absolutely regret it, although we didn't have any alternative at the time. Bloated and overly complex java stuff with lots and lots of undocumented behaviour. And they are still missing proper devops etiquette.
- Tainnor 3y agoUnfortunately, Keycloak currently fails to properly scale for a large-ish (a couple of hundred) number of realms, which can be an issue for use cases with a large number of tenants (as not unusual in a B2B setting): https://github.com/keycloak/keycloak/discussions/11074 https://github.com/keycloak/keycloak/discussions/11074 This leads among other things to the Admin UI becoming basically unusable: https://github.com/keycloak/keycloak/issues/20453 https://github.com/keycloak/keycloak/issues/20453 We currently have to implement a workaround where we create multiple Keycloak clusters and will have to write some glue to manually route to the correct one based on the realm, but that seems like unnecessary overhead.
- proctrap 3y agoI still have open issues on github for keycloak. One of them is for example, that you can use whitespaces for names, where keycloak can't actually accept whitespaces. So you find that out after you set the global name.. The upgrade path for keycloak is also similarly broken in my experience. Especially the total change in one of the recent versions broke a lot of things, which they are still fixing. Add no visible LTS or security patching on top, and you end up with something, that isn't usable for any enterprise rollout.
- samkuel 3y agoIs it possible to use keycloack with .NET ? Or is it better to implement auth myself with Identity Management ?