4 ms·
I don’t get it. Keycloak feels like some clunky 90s enterprise software and I mean it only in a bad way. Had to run it on openshift and it was hell. It’s not r
by roboben 3y ago
I don’t get it. Keycloak feels like some clunky 90s enterprise software and I mean it only in a bad way.
Had to run it on openshift and it was hell. It’s not really made for containers, clustering is basically impossible, it needs to know it’s default route and I can’t remember the exact issue but found myself patching some obscure startup scripts which templated some XML to start that thing. Can’t recommend but I’d be happy to hear alternatives which are actually modern.
- Glyptodon 3y agoIt's on my list of things that assumes out of the box that you know waaaaaay more about dozens of details than you actually are likely to unless you've already used it for 10 years. To the point that I don't even know what the benefit of using it vs. other options is at all.
- roboben 3y agoI can’t understand your first sentence even after reading it ten times. Maybe it is too long for me. To the second sentence: I don’t know what the benefit is either but in some environments you are not able to use any cloud provider or other external service to realize the auth layer so you are stuck with things like keycloak. Hope this thread discusses some other solutions which you can self host.
- vxNsr 3y agoI know the two main competitors that have been adopted by the self hosted community are authentik and authelia, they’re both somewhat under developed for enterprise but at the same time still difficult to grasp for non-full time devOps people. At least in my opinion.
- jsmith99 3y agoI use authentik for self hosted - it's great but still too powerful and configurable for me or most people who are not auth experts to customise. Just creating a password reset flow requires integrating a dozen moving parts. The only explanation how to do it is a yaml file or a YouTube tutorial. Setting up basic forward auth or OIDC was super easy though.
- Lacerda69 3y agouse cases that require _everything_ "on-premise" are often government/military, big healthcare, or just huge enterprises that want to control everything (and can afford a team that only runs their auth service). I mentioned Ory above but you get both options - either as a managed service or run on your own infra
- p_l 3y agoOr just places that don't want to give data to external, VC-funded or worse, vendors. I have clients that definitely prefer combination of open source + owner-controlled + lower costs ;)
- saynay 3y agoYep, this is why I have been evaluating it recently. Have a customer that wants SAML 2.0 support, others that want LDAP support, 2FA support, and multi-tenancy support, while being something we can self-host. The other main suggestions I have seen - ORY or Zitadel - tend to be missing at least one of those (from what I can tell). Keycloak looks like a big complicated monster, so I would prefer to stay away except that it looks like I will be required to have all that complexity to support all the use-cases we are looking at.
- selcuka 3y agoCurious. I'm not using Zitadel yet, but we are planning to. It seems to support all of those features. What was the missing part for you? https://zitadel.com/docs/apis/saml/endpoints https://zitadel.com/docs/apis/saml/endpoints https://zitadel.com/docs/guides/integrate/identity-providers/ldap https://zitadel.com/docs/guides/integrate/identity-providers... https://zitadel.com/docs/concepts/features/selfservice#mfa--2fa https://zitadel.com/docs/concepts/features/selfservice#mfa--... https://zitadel.com/docs/guides/migrate/introduction#multi-tenancy-architecture https://zitadel.com/docs/guides/migrate/introduction#multi-t... https://zitadel.com/blog/zitadel-as-sso-provider-for-selfhosting https://zitadel.com/blog/zitadel-as-sso-provider-for-selfhos...
- saynay 3y ago
- nebulousthree 3y agoThey mean that the software relies on the user understanding its, or the industry-it-serves's, jargon, to be used effectively.
- _cenw 3y agoWhich is extra funny when Keycloak is sticking to jargon out of RFCs that nobody else in the SaaS identity space is using. Hooking up Keycloak to a SAML consumer that only documents SaaS configuration is a fun game of try until it works most of the time.
- Lacerda69 3y agoHave you had a look at Ory (Kratos)? Its a "cloud-native"/modern alternative to Keycloak: https://github.com/ory/kratos https://github.com/ory/kratos
- dijit 3y agoI have, and we went back to keycloak- everything the parent says is true, however Ory/Kratos is a lesson in half finished solutions and poor documentation. we really tried quite hard, since it was backed by CNCF, but it could just be a case of being a tad too immature for prime time. it seems keycloak is now CNCF though
- rad_gruchalski 3y agoOry Kratos is nowhere near Keycloak. First of all, one needs at least Kratos+Hydra (there’s an integration method now out of the box yay) but Keycloak still has a flexibility advantage. Keycloak has many more features out of the box comparing to the complete Ory stack. The only thing nicer in Kratos from Keycloak is the standalone self-service UI with JSON identity declaration. If someone from the Keycloak team is reading this, please, let’s have a talk about bringing that feature to Keycloak, then Keycloak will be perfect. The template approach is a bit of a hassle. Source: deployed both stacks in production systems.
- mnming 3y agoAnother significant advantage of Kratos is that it's written in Golang, so it takes little to none resources for simple use cases. Also my experience with Keycloak in the past was that you can't do zero downtime deployment, or true configuration as code.
- adeptima 3y agoFound Ory (Kratos) customised registration flow as something over-engineered for my personal use cases. Very impressive ecosystem nevertheless. Show HN: Ory Kratos https://news.ycombinator.com/item?id=31679811 https://news.ycombinator.com/item?id=31679811 Most HN comments are still relevant
- 3y ago
- tecleandor 3y agoWere you using Keycloak also as the identity provider? IIRC, if you're using an external identity provider, and you want clustering, you can just deploy Keycloak containers and load balance between them. You can then load a shared cache if you want (or need). My memory is fuzzy right now, but although it isn't the leanest solution, I don't remember it as terrible. Ours wasn't a very custom solution anyway, we just hit an LDAP in the back and that was all.
- Delotono 3y agoThey completely reworked the code base and made it k8s compatible
- rad_gruchalski 3y agoMost of those issues have been sorted out in recent versions. It’s all container-ready now with pretty solid k8s story.
- jeroenhd 3y agoI just docker-compose up'd the server and configured it. I don't know when you last needed to mess with it, but the containerised version seems quite easy. Configuration sucked, but that's because Keycloak can do an awful lot.
- ownagefool 3y agoWhilst I agree keycloak is a lil clunky, I had it working clustered in k8s ~8 years ago. I do recall the gossip protocol presenting problems back then, but now I believe the helm chart just works.
- ashtonmeuser 3y agoBC gov?
- xnyanta 3y agoAre we using the same piece of software? I have it deployed in production on kubernetes using the bitnami helm chart and everything works like a charm, clustering etc. No need to modify any XML or care about network routes.
- ponyous 3y agoHow do you handle backups? I was considering doing the same, but found that backing up different systems inside k8s can be difficult.
- seletz 3y agoWe use KC with PostgreSQL as backend data store. Backup is done by backing up the PostgreSQL database. If you actually want to transport configuration across environments (DEV, QA, PROD), then you want to export realms and have it load by KC on startup or import it using the UI.
- jdsleppy 3y agoThere's a good Terraform provider for consistent configuration across environments, too.
- mooreds 3y agoDisclosure: I work for FusionAuth. We've had a number of folks migrate from Keycloak due to some of this clunkiness, but I do know they've done some major overhauls recently (moving to Quarkus amongst other things). It also used to be super resource intensive if you have a large number of realms (which is what Keycloak calls tenants and Cognito calls user pools). From this 2022 link, more than 100-200 can cause issues: https://github.com/keycloak/keycloak/discussions/11074 https://github.com/keycloak/keycloak/discussions/11074