Chuyển đến nội dung chính

Lesson 1: Introducing Keycloak - IAM and SSO in Enterprise

Learn what Keycloak is, why do you need IAM, core concepts (Realms, Clients, Users, Roles, Groups, Sessions), Keycloak architecture on Quarkus, comparison with Auth0/Okta/Azure AD, and real use cases in the enterprise. Keycloak 26.x version overview.

1. What is Keycloak?

Keycloak is an open source Identity and Access Management (IAM) solution, originally developed by Red Hat and now a CNCF Incubation (Cloud Native Computing Foundation) project. Keycloak provides Single Sign-On (SSO), identity management, and application security for web systems and RESTful web services.

Keycloak's goal is to make security simple — security features that developers would typically have to write themselves are available out-of-the-box and customizable to organizational requirements.

Development history

  • 2014: Keycloak was born as a JBoss/Red Hat project

  • 2018: Keycloak 4.0 — supports Authorization Services, UMA 2.0

  • 2020: Keycloak.X (Quarkus-based) preview

  • 2022: Keycloak 20 — WildFly distribution removed, officially switched to Quarkus

  • 2024: Keycloak becomes CNCF Incubation project

  • 2026: Keycloak 26.5.x — current version with Workflows, Passkeys, MCP support

2. Why do we need Identity and Access Management?

In modern enterprise systems, identity and access management becomes complicated when:

  • Multiple apps need shared authentication (SSO)

  • Requires integration with external Identity Providers (Google, Azure AD, LDAP)

  • Needs Multi-Factor Authentication (MFA) for high security

  • Complicated permission management (RBAC, ABAC, fine-grained permissions)

  • Compliant with security standards (OAuth 2.0, OIDC, SAML 2.0, FAPI 2.0)

  • Multi-tenancy cho SaaS applications

Keycloak IAM/SSO Overview

Keycloak IAM/SSO Overview: Apps → Keycloak → Identity Providers

3. Keycloak

Key Features
  • Single Sign-On (SSO) and Single Sign-Out for browser applications

  • OpenID Connect and OAuth 2.0 support

  • SAML 2.0 support

  • Identity Brokering — authenticate via external OIDC or SAML Identity Providers

  • Social Login — sign in with Google, GitHub, Facebook, Apple, Microsoft

  • User Federation — synchronize users from LDAP and Active Directory

  • Kerberos bridge — automatically authenticates users logged into the Kerberos server

  • Admin Console — centralized management of users, roles, clients, configuration

  • Account Console — allows users to manage their own accounts

  • Theme support — customize login, account, admin, email interface

  • Two-factor Authentication — TOTP/HOTP, WebAuthn, Passkeys

  • Authorization Services — detailed authorization with policies and permissions

  • Organizations — multi-tenancy cho CIAM (B2B, B2B2C)

  • Workflows — administrative automation (IGA)

  • Token Mappers — customize claims in tokens

  • Events & Auditing — audit logging and event listeners

4. Core concepts

Realms

Realm manages a collection of users, credentials, roles and groups. Each user belongs to and is logged into a realm. Realms are isolated from each other — only users belonging to that realm can be managed and authenticated.

Clients

Clients are entities (applications, services) that require Keycloak to authenticate users. Clients can be web apps, mobile apps, REST APIs, or services that need tokens to call other services.

Users

Users are entities that can log into the system. Users have attributes (email, username, phone, etc.), belong to groups and are assigned roles.

Roles

Roles identifies the type or category of the user (Admin, User, Manager). The application assigns access rights based on roles instead of individual users.

Groups

Groups manages user groups. Groups have attributes and role mappings. Users inherit attributes and role mappings from group.

Sessions

When a user logs in, a session is created to manage the login session, including information about the login time and applications that participated in SSO.

5. Keycloak Architecture on Quarkus

From version 20+, Keycloak runs entirely on the Quarkus framework, providing:

  • Ultra-fast startup time — suitable for containers and serverless

  • Small memory footprint — optimized for cloud-native deployments

  • Build-time optimization — precompiled configuration

  • Native image support — ability to run GraalVM native

Keycloak Architecture on Quarkus

Keycloak Architecture: Quarkus Runtime, Infinispan Cache, Hibernate ORM, Admin/Account Console

Component Description
Quarkus Runtime Application server (replaces WildFly)
Infinispan Distributed cache cho sessions, tokens
Hibernate ORM ORM layer cho database persistence
Database PostgreSQL (recommended), MySQL, MariaDB, Oracle, MSSQL
Admin Console React-based SPA (PatternFly 5)
Account Console React-based SPA cho user self-service

6. Compare Keycloak vs Auth0 vs Okta vs Azure AD

Criteria Keycloak Auth0 Okta Azure AD
License Apache 2.0 (FOSS) Commercial Commercial Commercial
Deployment Self-hosted Cloud SaaS Cloud SaaS Cloud SaaS
Cost Free (self-operated) From $35/month From $2/user/month From $6/user/month
Customization Very high (open source) Average Average Low
OIDC/OAuth2 Full Full Full Full
SAML Full Yes Full Full
LDAP/AD Full Enterprise Full Native
MFA TOTP, WebAuthn, Passkeys Full Full Full

7. Actual use cases

  • Enterprise SSO: Single sign-on for all internal applications

  • Customer IAM (CIAM): Managing customer identities with Organizations

  • API Security: Secure REST APIs with OAuth 2.0 tokens

  • Microservices Authentication: Service-to-service authentication with client credentials

  • Social Login: Allows users to log in with Google, Facebook, GitHub

  • LDAP/AD Federation: Integrate existing directory system

  • MFA for Compliance: Meets PCI-DSS, HIPAA, SOC requirements 2

8. Course overview

The course includes 25 lessons divided into 7 parts, covering all modules of Keycloak 26.x:

  • Part 1: Platform (Realms, Users, Groups, Roles, Permissions)

  • Part 2: SSO Protocols (OIDC, SAML, Client Scopes, Tokens, DPoP)

  • Part 3: Authentication & MFA (Flows, OTP, WebAuthn, Passkeys, Identity Brokering)

  • Part 4: Federation & Authorization (LDAP/AD, Organizations, Authorization Services, Workflows)

  • Part 5: Security & Customization (Themes, Events, Hardening, Vault)

  • Part 6: Practical Integration (Spring Boot, React/Angular, Node.js, API Gateway)

  • Part 7: Production Operations (Deployment, HA, Kubernetes, Monitoring)