My dream is to one day create an SSO solution for companies. I've been doing research for a time being, but I am worried that I wouldn't find any clients, because who would trust an SSO created by one guy in his basement? I think the first step to overcome that would be having a completely Open Source solution, but how to avoid other companies grabbing it and selling as their own? Or do you think it is better to deve…
A detailed guide to SSO on Kubernetes
21–30 of 33 posts
Re: A detailed guide to SSO on Kubernetes
#22Earlier quoted context omitted.
Edit: Keycloak is licensed with the Apache 2.0 license, so none of this is relevant for Keycloak. GPL is only a problem if you import or change the source code. If you just run it in the backend, as a service, you're most likely fine. If you customise Keycloak through code, you're probably in GPL violation territory. With the customisability of Keycloak, I doubt that this is something many projects will ever run into…
I don't think this is true. The GPL allows you to copy & modify code for your own desires very generously. The limitations you fear apply if you distribute the code (in source or other forms) or modifications yourself.
However, after looking into Keycloak more closely, the software seems to be licensed with the Apache 2 license, so none of this is a concern.
Re: A detailed guide to SSO on Kubernetes
#23My dream is to one day create an SSO solution for companies. I've been doing research for a time being, but I am worried that I wouldn't find any clients, because who would trust an SSO created by one guy in his basement? I think the first step to overcome that would be having a completely Open Source solution, but how to avoid other companies grabbing it and selling as their own? Or do you think it is better to deve…
The smaller scale homelab/selfhosting people really need a better solution. I think open source developers do as well. What we really need is a small easy to set up solution that provides a clear way for us to integrate our app into it. My ideal would be something that * Supports ldap and OIDC * Can be deployed to docker using one compose file * Only needs to support hundreds of users (keep it simple, easy to deploy,…
Perhaps you could enlighten us with a few key differentiators of your ideal solution to other common ones?
Re: A detailed guide to SSO on Kubernetes
#24Earlier quoted context omitted.
The smaller scale homelab/selfhosting people really need a better solution. I think open source developers do as well. What we really need is a small easy to set up solution that provides a clear way for us to integrate our app into it. My ideal would be something that * Supports ldap and OIDC * Can be deployed to docker using one compose file * Only needs to support hundreds of users (keep it simple, easy to deploy,…
I think Keycloak ticks all those boxed rather nicely. While it does support more than a few hundred users, I doubt that this will be a serious issue. Perhaps you could enlighten us with a few key differentiators of your ideal solution to other common ones?
Re: A detailed guide to SSO on Kubernetes
#25My dream is to one day create an SSO solution for companies. I've been doing research for a time being, but I am worried that I wouldn't find any clients, because who would trust an SSO created by one guy in his basement? I think the first step to overcome that would be having a completely Open Source solution, but how to avoid other companies grabbing it and selling as their own? Or do you think it is better to deve…
In the meantime people are already offering managed keycloak instances as a service.
Re: A detailed guide to SSO on Kubernetes
#26My dream is to one day create an SSO solution for companies. I've been doing research for a time being, but I am worried that I wouldn't find any clients, because who would trust an SSO created by one guy in his basement? I think the first step to overcome that would be having a completely Open Source solution, but how to avoid other companies grabbing it and selling as their own? Or do you think it is better to deve…
The smaller scale homelab/selfhosting people really need a better solution. I think open source developers do as well. What we really need is a small easy to set up solution that provides a clear way for us to integrate our app into it. My ideal would be something that * Supports ldap and OIDC * Can be deployed to docker using one compose file * Only needs to support hundreds of users (keep it simple, easy to deploy,…
I have it in production at work. Three instances, clustered (infinispan), running in docker containers orchestrated by kubernetes.
Each instance (pod) is upper-limited to 2gb ram (or 3, can't recall the details now).
It works very well and very reliably, serving about 750 users (as in, real people).
If you have 2GB to spare and a physical core, you can run keycloak with no problems at all.
After all, it all depends on the amount of traffic. Little traffic = little cpu load.
Don't dismiss keycloak because it's written in Java... Quite the contrary, you can tune the JVM to work with little memory (-Xms -Xmx iirc).
Ten years ago it was very common to see tips and tricks to make grails web apps work on as little as 64mb of ram on chap VPSes.
Re: A detailed guide to SSO on Kubernetes
#27Earlier quoted context omitted.
The smaller scale homelab/selfhosting people really need a better solution. I think open source developers do as well. What we really need is a small easy to set up solution that provides a clear way for us to integrate our app into it. My ideal would be something that * Supports ldap and OIDC * Can be deployed to docker using one compose file * Only needs to support hundreds of users (keep it simple, easy to deploy,…
Uhm, keycloak does all the things you name and more. I have it in production at work. Three instances, clustered (infinispan), running in docker containers orchestrated by kubernetes. Each instance (pod) is upper-limited to 2gb ram (or 3, can't recall the details now). It works very well and very reliably, serving about 750 users (as in, real people). If you have 2GB to spare and a physical core, you can run keycloak…
Re: A detailed guide to SSO on Kubernetes
#28Earlier quoted context omitted.
Uhm, keycloak does all the things you name and more. I have it in production at work. Three instances, clustered (infinispan), running in docker containers orchestrated by kubernetes. Each instance (pod) is upper-limited to 2gb ram (or 3, can't recall the details now). It works very well and very reliably, serving about 750 users (as in, real people). If you have 2GB to spare and a physical core, you can run keycloak…
Can you provide an example docker compose to deploy keycloak+ldap in docker (not kubernetes)?
https://github.com/ivangfr/springboot-keycloak-openldap/blob...
Re: A detailed guide to SSO on Kubernetes
#29Earlier quoted context omitted.
I think Keycloak ticks all those boxed rather nicely. While it does support more than a few hundred users, I doubt that this will be a serious issue. Perhaps you could enlighten us with a few key differentiators of your ideal solution to other common ones?
Wait, does keycloak have an integrated LDAP server?
Re: A detailed guide to SSO on Kubernetes
#30Earlier quoted context omitted.
Can you provide an example docker compose to deploy keycloak+ldap in docker (not kubernetes)?
I googled that for you, first result: https://github.com/ivangfr/springboot-keycloak-openldap/blob...
So now I need to look up the default values for
Vendor, Username LDAP attribute, RDN LDAP attribute, UUID LDAP attribute, User Object Classes, Connection URL, Users DN, Custom User LDAP Filter, Search Scope, Bind Type, Bind DN, Bind Credential
If I knew what vendor openldap was considered setting the Vendor would fill a bunch of of those in. Well let's try following through this this random blog post and hope it works: https://geek-cookbook.funkypenguin.co.nz/recipes/keycloak/au...
Compare that to the experience of deploying say, wordpress. And hey look, it already comes with an authentication backed!
Sure, you can build something that does more or less the same thing but you have to do a fair bit of work to get to that point. Realistically if you haven't done it before, and if you don't have any ldap experience, you're looking at a solid couple of hours to get that set up.
And it's still apparently going to use 100s of MB of ram.
Where as wordpress goes up in a few minutes, handles user account but uses less ram, I don't really need to do any extra work, and I'm confident it's going to work.
I'm not looking to build a skill, I'm looking to just have an auth server I can use and that I can link my own apps against easily.
As an aside I had seen that one before and it is workable, it's just a lot of work to get from there to an actual working deployment I can use on my home server.