3 ms·
Keycloak is a non-brain solution for my enterprise, in-house friends. Would like to cheerlead for fully opensource Zitadel project here however. https://zitad
by adeptima 3y ago
Keycloak is a non-brain solution for my enterprise, in-house friends.
Would like to cheerlead for fully opensource Zitadel project here however.
https://zitadel.com/ https://zitadel.com/
https://zitadel.com/team https://zitadel.com/team
Main repo https://github.com/zitadel/zitadel https://github.com/zitadel/zitadel
Zitadel team clearly understand OpenID, Auth0, Keypass, etc specs and have all previous experience to implement identity management right for SaaS, B2C and B2B project scenarios.
SaaS Product with Authentication and Authorization https://zitadel.com/docs/guides/solution-scenarios/saas https://zitadel.com/docs/guides/solution-scenarios/saas
Simplify Your SaaS: Multi-Tenancy and Delegated Access Management with ZITADEL Organizations https://www.youtube.com/watch?v=Cx_WgyY4TOo https://www.youtube.com/watch?v=Cx_WgyY4TOo
ZITADEL Roadmap
https://github.com/orgs/zitadel/projects/6/views/1 https://github.com/orgs/zitadel/projects/6/views/1
Zitadel took a very good direction into allowing to "build my own login and register ui"
Sprint Demo - ZITADEL 2.28.0 https://www.youtube.com/watch?v=hpQ4zrV48LY https://www.youtube.com/watch?v=hpQ4zrV48LY
[Epic] Login API and improvement of Register API #5015
https://github.com/zitadel/zitadel/issues/5015 https://github.com/zitadel/zitadel/issues/5015
https://github.com/zitadel/typescript https://github.com/zitadel/typescript
Previously had a look at Ory, Keycloak and many others.
Found those solutions either to be more "enterprisy" and over-engineered rather than something which can co-exist in my small team brain.
- adeptima 3y agoThank you for downvoting, guys ...
- nine_k 3y agoWe are upvoting just to spite you! B-D
- eastbound 3y agoThis is an ad?
- adeptima 3y agoNope. Just a note from my own research. I’m heavily relying on HN comments to weight in alternatives.
- dikei 3y agoI just wish Keycloak has an easier way of building customized login/registration UI. Zitadel is currently not much better in this aspect either, but they're working on it. Only the Ory stack currently has full API supports for fully customized login/registration screen.
- adeptima 3y agoSame observation. Hope Zitadel can do it right with zitadel/typescript repo. Huge respect to Ory for showing how it can be done.
- iimpact 3y agonot the author, but when I was facing the same issue with customization, I came across: https://www.keycloakify.dev/ https://www.keycloakify.dev/
- smashed 3y agoWhat exactly are you saying here? Keycloak is not open source enough? It's fine to talk about alternative solutions but you could at least compare and contrast the solutions together and provide some insight into why you are plugging another product...
- adeptima 3y agoKeyclock is a great project. Much welcomed by all my friends from bloody enterprise caused 1. it’s written in Java and 2. well tested by their cyberops teams.
- pharmakom 3y agoWhat’s the problem with keycloak then?
- michaelt 3y agoWhen adeptima says "Keycloak is a non-brain solution" I believe that is intended as an endorsement. Americans use the term 'no-brainer' as a positive thing - a decision so good, easy and obvious that even someone with no brain would make it. That's in contrast to a most colloquialisms about decisions made without brain power - calling a decision 'thoughtless' or 'dumbass' would instead be a negative thing.
- adeptima 3y agoAppreciate intend capture, michaelt! Suntory Time! - Lost in Translation https://www.youtube.com/watch?v=FiQnH450hPM https://www.youtube.com/watch?v=FiQnH450hPM
- danmur 3y agoThat looks really good, thank you.
- dodyg 3y agoThanks for the info. TIL.
- mrklol 3y agoI currently use Firebase auth for a couple of projects where I don’t want to implement auth. because of 2fa etc. There I just have one project for each … project because they are separated. I just saw that something like that works in Zitadel too, so I only have to run one instance. But is this meant to work like that? Or should I rather spin up one instance per project?
- ffo 3y agoZitadel co-founder here. We support multiple approaches for multi-tenancy. In a typical setup you will only need an instance (a virtual Zitadel system). This already supports B2C and B2B deployments. If you want to host multiple customers, fully isolated, you could create an instance for each customer. However this is only necessary if you want to become a Zitadel service provider in most cases ;-) Some docs for this: Organization vs Instance: https://zitadel.com/blog/multi-tenancy-with-organizations https://zitadel.com/blog/multi-tenancy-with-organizations Instance: https://zitadel.com/docs/concepts/structure/instance https://zitadel.com/docs/concepts/structure/instance Organization: https://zitadel.com/docs/concepts/structure/organizations https://zitadel.com/docs/concepts/structure/organizations Hope this helps!
- ffo 3y agoZitadel co-founder here. Thanks for the kind words! As you already pointed out we are currently working on two major improvements. A new resource based API which allows creating your own login/register and many more things (1) and a login/register sdk for typescript (2). This decision was definitely influenced by our great community and helps us shape the product. We dearly believe the market needs a modern open source identity platform that can replace Auth0 Personal opinion, do not fight me for this ;-) I often think of what we do as GitLab vs. GitHub. Going with an open core/source product against a well established cloud only/closed source player. From Keycloak we took inspiration in the ability to self-host. We think it is important to allow people to control their critical user data. [1] i.e https://github.com/zitadel/zitadel/tree/main/proto/zitadel/session/v2alpha https://github.com/zitadel/zitadel/tree/main/proto/zitadel/s... [2] https://github.com/zitadel/typescript https://github.com/zitadel/typescript