4 ms·
I tried Keycloak for my homelab, but I found the resource usage especially on startup to be too high (3 GB memory or something) and since I wanted minimal sever
by RedlineTriad 3y ago
I tried Keycloak for my homelab, but I found the resource usage especially on startup to be too high (3 GB memory or something) and since I wanted minimal sever footprint I went with lldap[1] as the user store and authelia[2] to do forward auth using traefik.
Pretty happy with this setup, though it has less features than Keycloak, it's easier to administrate from code.
[1] https://github.com/lldap/lldap https://github.com/lldap/lldap
[2] https://www.authelia.com/ https://www.authelia.com/
- chromanoid 3y agoDid you try the "new" version powered by Quarkus? I think it has a much smaller footprint. edit: BTW authelia looks very promising. Thank you for the link! The bus factor seems a bit low for such a mission critical application, at least when evaluating it as an alternative for production. But I really like how open the core team is about that.
- RedlineTriad 3y agoI tried the Quarkus version, but it does some kind of build step at container startup, and that is what used the most memory. You can apparently build an "optimized" image[1] so it doesn't do it at runtime, but I didn't want to build a custom image, and I felt like the KeyCloak philosophy didn't align with my own. In general I found myself avoiding Java applications because of their memory footprint. [1] https://www.keycloak.org/server/containers#_creating_a_customized_and_optimized_container_image https://www.keycloak.org/server/containers#_creating_a_custo...
- brabel 3y agoI understand your reluctance to use Java, but it's actually pretty good if the developers use small libraries instead of the giant frameworks most Java servers use... a Java server for this kind of stuff will run within 200MB+ comfortably and with very high performance when written properly. Anything using 3GB for this stuff is doing something terribly wrong.
- RedlineTriad 3y agoYeah I know, nothing except maybe the JIT that requires java programs to use more memory than Go, but in practice Java apps are almost always significantly worse. C# is also pretty bad, but not quite as bad I think. I can only assume it's a cultural thing since reflection and abstraction is used so much. Rust apps are always nice since they are generally <20MB or something.
- dikei 3y agoProbably not small enough for a home lab setup, between a 50MB Golang App and 500MB Java App I'd choose the Golang App every time for my home lab, because memory is precious and probably less than 10 people will use it. However, it's a different story when picking the solution for my day job, where RAM is abundant, but developer time is in short supply.
- radomir_cernoch 3y agoAs I'm also running a homelab, I was curious, what's your overall experience with IAM in this context? What was your original goal? Which services are linked to your lldap? How many users? Does it simplify things or make it more complex?
- RedlineTriad 3y agoIt's been pretty good, I never really used LDAP before so I had a bit of a learning curve, but it's not too complicated. 1. My original goal was not having 5 different passwords for my own server because although I have a password manager it's still a bit annoying. Also just for learning. 2. You can see the services here[1], since my entire setup is provisioned from GitHub with Terraform and Ansible. 3. I have about 5 users. 4. I would say simplify so far, but it depends on what kind of complexity you care about, and which services you want to integrate. [1] https://github.com/RedlineTriad/private_server/tree/master/software/roles/docker_compose_apps/templates https://github.com/RedlineTriad/private_server/tree/master/s...
- ilyt 3y ago> My original goal was not having 5 different passwords for my own server because although I have a password manager it's still a bit annoying. I "solved" that problem by having configuration management deploy same password (hash) on all of my servers. Requires keeping the repo with password hashes relatively safe and of course changing them is a bit of a process but extremely easy and low tech if there is already CM in place.
- RedlineTriad 3y agoAuthelia actually supports a yaml file with password hashes as the user database. I thought about using that, but decided to try lldap instead. But I wouldn't want to figure out how to write the password hash into the databases of each application like grafana, or grocy.
- nitnelave 3y agoLLDAP author here, I'm glad to see it's useful! A homelab is exactly the use case it was built for, and low resources is among the goals.
- nitnelave 3y agoNote that if you want to use KeyCloak for the OpenID but want to still have a LDAP source of truth, you can use LLDAP + KeyCloak together, with LLDAP as the source of truth and KeyCloak giving you the fancy features: https://github.com/lldap/lldap/blob/main/example_configs/keycloak.md https://github.com/lldap/lldap/blob/main/example_configs/key...
- RedlineTriad 3y agoThank you for the help on GitHub with running it as a read only image BTW. Since I try to keep my deployments clean and mostly stateless getting that to work was very nice. The lldap config I use is here if you want it for any examples or something: https://github.com/RedlineTriad/private_server/tree/master/software/roles/docker_compose_apps/templates/lldap https://github.com/RedlineTriad/private_server/tree/master/s...
- ilyt 3y agoDamn, if I found it 6 months ago it would have saved me a lot of time...
- hsluoyz 3y agoWhy not use Casdoor? https://casdoor.org https://casdoor.org From their system info page: https://door.casdoor.com/sysinfo https://door.casdoor.com/sysinfo, it only consumes about 10MB memory and with no less features (more features actually) than Keycloak
- deleted 3y ago[deleted]
- RedlineTriad 3y agoI just never heard of it, I went through reddit and looked at what people were using, and awesome-xyz lists, and then went through docs and pages to see which projects had the same priorities as me. And Authelia looked like the best match. I think I looked at: - Keycloak - Zitadel - Authelia - Authentik And maybe a few more, but I never heard of Casdoor before today, and even now there are few Reddit references to it.
- hsluoyz 3y agoIt's worth a try. Their Casbin is more popular among Go devs. Casdoor is their fairly new project but looks promising
- lmz 3y agoLooking at your username, it would be nice to mention that you are one of the main developers behind the tool instead of making it sound like you are unrelated: https://github.com/casbin/casbin/graphs/contributors https://github.com/casbin/casbin/graphs/contributors https://github.com/casdoor/casdoor/graphs/contributors https://github.com/casdoor/casdoor/graphs/contributors
- rad_gruchalski 3y agoWhat’s your thought on OPA Rego?
- madduci 3y agoThe newer versions (19.0+) don't need more than 1 GB RAM for many scenarios
- lionkor 3y agoAny reason for it to use as much RAM as full operating systems, with games, programs, databases, ...? 1 GB is still ridiculous, no?
- dikei 3y agoNot really, it's still way less than a web browser or an electron app, and it can server a heck lot of customers with 1GB of RAM. JVM programs have high initial memory usage, but they scale up very well.
- lionkor 3y agoI understand that it's the way it is, and it could be worse, but man is 1 GB absolutely crazy usage.