User Tools

Site Tools


hosts:enclave:keycloak

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
hosts:enclave:keycloak [2022/09/27 00:27] – created tcmalhosts:enclave:keycloak [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1
Line 1: Line 1:
-====== Keycloak ====== 
- 
-^ Port(s) | 443 | 
-^ Publicly Accessible?   | Yes (through proxy) | 
-^ Upstream       | [[https://www.keycloak.org/|Keycloak]] | 
- 
-Provides [[https://www.onelogin.com/learn/how-single-sign-on-works|OpenID (Single Sign-On)]]. User information is federated from [[hosts:enclave:ldap|LDAP]], and password authentication is done through [[hosts:enclave:kerberos|Kerberos]]. 
- 
-Because it misbehaves otherwise, this uses SSL with a certificate issued by [[hosts:enclave:step-ca|Step CA]]. 
- 
-===== Data directories ===== 
- 
-  * ''/var/lib/postgresql/'' 
- 
-===== Configuration locations ===== 
- 
-Handled declaratively through [[https://git.tardisproject.uk/tardis/nix/-/blob/main/profiles/services/keycloak.nix|Nix]]. 
  
hosts/enclave/keycloak.1664238427.txt.gz · Last modified: 2022/09/27 00:27 by tcmal