4 ms·
feels like if keycloak had been slightly better 10 years ago, backend architecture would be way less complicated and more standardized auth system that worked
by awinter-py 2y ago
feels like if keycloak had been slightly better 10 years ago, backend architecture would be way less complicated and more standardized
auth system that worked well with static file buckets would cut like 40% of backend DB / server needs
- booi 2y agoAuth is not a simple thing to do especially with the numerous accepted methods. Is there something that you think keycloak could do better?
- mickael-kerjean 2y agoI have a couple customers who use keycloak to handle SSO integration with my product. Almost every single time we do the configuration on a screenshare it is painfull. The gist is they all seem to have different setup with various configuration and asking me how to fix it but what works for someone doesn't work for someone else. Most of the time when things don't work, they start clicking things everywhere and that either make it worse or in some case make it work. As a vendor, I would love to have a way to give them a configuration that just work on both SAML and OIDC
- KronisLV 2y agoNone of this is very specific, but also matches my experience pretty closely. Also, if you have Keycloak running behind Apache as a reverse proxy, I've had requests between those two randomly drop. I needed to change some obscure setting in the Apache config in regards to connection pooling/keep-alive or something along those lines, mentioned it in a past comment of mine. That was annoying, in addition to having to configure Keycloak in the first place. But when it works, it works pretty well!
- doctorpangloss 2y agoWhy don’t more people contribute / coalesce around Keycloak? I don’t know if it was even that “bad” per se “10 years ago.” 10 years ago, React was only open source for 1 year. Meteor was Supabase. People were still writing CoffeeScript. You are lamenting the complexity of changing authorization requirements without changing application code. I don’t know if OIDC was really set in stone back then. There was no Rego or Cedar, there were IAM policies, and that was also relatively new, and attributes-driven SAML. It’s just a lot of development has happened.