Chuyển đến nội dung chính

Keycloak from Basic to Advanced

The Keycloak course is comprehensive from basic to advanced, helping you master Identity and Access Management (IAM) from installing and configuring Realms, Users, Roles, Clients, to advanced modules such as Identity Brokering, User Federation (LDAP/AD), Authentication Flows, Authorization Services, Multi-Factor Authentication, Organizations, Workflows, Passkeys, and integrating with real applications. Updated to Keycloak 26.x (latest version 2026) running on Quarkus, including production operations, High Availability, Kubernetes Operators and enterprise security best practices.

Part 1: Keycloak Platform

Lesson 1: Introducing Keycloak - IAM and SSO in Enterprise

  • What is Keycloak? Development history (from JBoss to CNCF Incubation)

  • Why do we need Identity and Access Management (IAM)?

  • Core concepts: Realms, Clients, Users, Roles, Groups, Sessions

  • Keycloak Architecture on Quarkus (26.x)

  • Compare Keycloak vs Auth0 vs Okta vs Azure AD

  • Use cases: SSO, Social Login, LDAP Federation, MFA, API Security

Lesson 2: Installing Keycloak - Standalone, Docker and Kubernetes

  • Install Keycloak on Ubuntu/CentOS (bare metal)

  • Run Keycloak with Docker and Docker Compose

  • Kubernetes Operator deployment

  • Configure Database backend (PostgreSQL, MySQL, MariaDB)

  • HTTPS/TLS setup and hostname v2 configuration

  • Development mode vs Production mode

Lesson 3: Admin Console and creating the first Realm

  • Create the first Admin user (Admin Bootstrap & Recovery)

  • Admin Console UI Overview

  • Create and configure Realm (General, Login, Email, Themes, Keys)

  • Master Realm vs Custom Realms

  • Admin CLI (kcadm.sh) basic

  • Admin REST API overview

Lesson 4: Managing Users, Groups and User Profile

  • Create and manage Users, set credentials

  • User Profile: custom attributes, validators, annotations

  • Progressive Profiling

  • Groups and Sub-groups, group attributes, role mappings

  • User self-registration and Required Actions

  • Impersonation, account deletion, personal data

Lesson 5: Roles, Permissions and Access Control

  • Realm Roles and Client Roles

  • Composite Roles and Default Roles

  • Role Mappings for Users and Groups

  • Fine-grained Admin Permissions V2

  • Delegating Realm Administration

  • Dedicated Realm Admin Consoles

Part 2: SSO Protocols - OpenID Connect and SAML

Lesson 6: OpenID Connect Clients - Configuration from A to Z

  • Client types: Public, Confidential, Bearer-only

  • General Settings, Access Settings, Capability Config

  • OIDC Auth Flows: Authorization Code, Implicit, Client Credentials, Device Auth

  • PKCE (Proof Key for Code Exchange)

  • CIBA (Client Initiated Backchannel Authentication)

  • Integrating OIDC clients with React, Spring Boot, Node.js

Lesson 7: SAML Clients and Protocol Mappers

  • Create SAML 2.0 Clients, SAML Bindings (POST, Redirect, Artifact)

  • SAML Assertions, XML Signature and Encryption

  • Entity Descriptor Import

  • OIDC Protocol Mappers: User Attribute, Session Note, Hardcoded, Script

  • SAML Protocol Mappers

  • Lightweight Access Tokens and Pairwise Subject Identifier

Lesson 8: Client Scopes, Token Management and DPoP

  • Client Scopes: default vs optional, consent settings

  • Realm default client scopes, evaluating scopes

  • Access Token, ID Token, Refresh Token lifecycle

  • Session and Token timeout configuration

  • Offline Access, Token Revocation

  • DPoP (Demonstrating Proof-of-Possession)

Lesson 9: Client Policies and Advanced Client Configuration

  • Client Policies architecture: Policies, Profiles, Conditions, Executors

  • FAPI 2.0 Security Profile and Message Signing

  • Client Secret Rotation

  • Service Accounts and Audience support

  • Token Exchange (Standard, JWT Authorization Grant RFC 7523)

  • Keycloak as Authorization Server cho MCP servers

Part 3: Authentication, MFA and Identity Brokering

Lesson 10: Authentication Flows - Customizing authentication flow

  • Built-in flows: Browser, Direct Grant, Registration, Reset Credentials

  • Create custom Authentication Flows

  • Conditional Authenticators (sub-flow executed, client scope)

  • Step-up Authentication and ACR/LoA mapping

  • Session Limits (realm-level, client-level)

  • Dynamic Authentication Flow selection via Client Policies

Lesson 11: Multi-Factor Authentication - OTP, WebAuthn and Passkeys

  • TOTP/HOTP setup with Google Authenticator, FreeOTP

  • OTP Policy configuration and Recovery Codes

  • WebAuthn (FIDO2 Security Keys) setup

  • Passkeys integration (conditional UI, modal UI)

  • Kerberos Authentication

  • X.509 Client Certificate Authentication

Lesson 12: Identity Brokering and Social Login

  • Social Login: Google, Facebook, GitHub, Apple, Microsoft

  • OpenID Connect and SAML Identity Providers

  • OAuth v2 and Kubernetes Identity Providers

  • First Login Flow and Account Linking

  • Identity Provider Mappers and Sync Mode

  • Client-suggested IdP and IdP logout

Part 4: User Federation, Organizations and Authorization

Lesson 13: User Federation - LDAP and Active Directory

  • Configure LDAP/AD federation (storage mode, edit mode)

  • Connection settings: SSL, connection pool, referrals

  • LDAP Mappers: User Attribute, Full Name, Group, Role

  • MSAD User Account Control mapper

  • SSSD/FreeIPA Integration and Kerberos bridge

  • Custom User Storage SPI

Lesson 14: Organizations - Multi-tenancy and CIAM

  • Enable Organizations feature in Keycloak

  • Create/manage Organizations, Domains, Attributes

  • Member Management: managed, unmanaged, invitations

  • Associate Identity Providers with Organizations

  • Identity-first login flow

  • Mapping Organization claims into tokens

Lesson 15: Authorization Services - Detailed authorization

  • Resource Server, Resources, Scopes, Permissions, Policies

  • Policy types: Role, User, Group, Client, Time, JS, Aggregated

  • UMA 2.0 and Permission API

  • Policy Enforcer and Claim Information Points

  • Integrating Authorization into Spring Boot / Node.js

  • Evaluation API and troubleshooting permissions

Lesson 16: Workflows - Automating administration with IGA

  • Keycloak Workflows engine (preview)

  • Workflow definitions and expression language

  • Defining conditions and steps

  • Joiner-Mover-Leaver (JML) processes

  • Automated onboarding/offboarding

  • Access reviews and common use cases

Part 5: Themes, Events, Security and Vault

Lesson 17: Custom Themes - Login, Account, Admin and Email

  • Theme system: Login, Account, Admin Console, Email themes

  • Create custom themes, Freemarker templates

  • Dark mode support, internationalization

  • PatternFly 5 components

  • Hot-deploy themes, theme resources

  • Account Console v3 customization

Lesson 18: Event Auditing and Logging

  • User events and Admin events configuration

  • Event types and Event listeners

  • Custom Event Listener SPI

  • Event metrics cho monitoring

  • Logging: console, file, JSON, ECS format, syslog

  • Integration with ELK Stack / Loki

Lesson 19: Security Hardening and Brute Force Protection

  • SSL/HTTPS and Admin endpoint protection

  • Brute Force Protection (permanent, temporary, combined lockout)

  • Password Policies

  • Security Headers: CSP, X-Frame-Options, HSTS

  • reCAPTCHA setup (v2 and Enterprise)

  • Vault integration (file-based, Kubernetes Secrets)

Part 6: Integrating practical applications

Lesson 20: Integrating Keycloak with Spring Boot

  • Spring Security OAuth2 Resource Server

  • Spring Security OAuth2 Client

  • Authorization Client library

  • Role-based authorization with @PreAuthorize

  • Token relay and service-to-service communication

  • Multi-tenancy and testing strategies

Lesson 21: Integrating Keycloak with React/Angular and Node.js

  • Keycloak JavaScript adapter (standalone library)

  • React integration (keycloak-js, react-oidc-context)

  • Angular integration (angular-auth-oidc-client)

  • Node.js backend (Passport.js, express-openid-connect)

  • Token management, silent SSO, protected routes

  • Best practices cho SPA authentication

Lesson 22: Keycloak with Nginx, API Gateway and Microservices

  • Nginx reverse proxy with auth_request / OAuth2 Proxy

  • API Gateway: Kong, Traefik, APISIX with Keycloak OIDC

  • Microservices authentication patterns

  • Token introspection endpoint

  • Docker registry v2 authentication

  • Verifiable Credentials (OID4VCI) - experimental

Part 7: Production, High Availability and Kubernetes

Lesson 23: Keycloak Production Deployment and Database Tuning

  • Production readiness checklist

  • Build optimization (kc.sh build)

  • Database tuning: PostgreSQL, connection pool, additional datasources

  • Hostname v2, reverse proxy, HTTP/HTTPS settings

  • JVM tuning, Argon2 hashing, cache configuration

  • Import/Export realm data

Lesson 24: High Availability, Clustering and Multi-site Deployment

  • Keycloak clustering with Infinispan, jdbc-ping transport

  • Zero-configuration secure cluster communication

  • Session replication and persistent user sessions

  • Multi-site active-passive deployments

  • Rolling updates and non-blocking health checks

  • CPU/Memory sizing guide

Lesson 25: Kubernetes Operator, Monitoring and Admin CLI

  • Keycloak Operator: Keycloak CR, KeycloakRealmImport CR

  • Operator advanced configuration (scheduling, resources, NetworkPolicies)

  • OpenTelemetry: tracing, metrics, logging

  • Prometheus metrics and Grafana dashboards

  • Admin CLI (kcadm.sh) mastery

  • Backup/Restore strategies and troubleshooting

Part 1: Keycloak Platform

Part 2: SSO Protocols - OpenID Connect and SAML

Part 3: Authentication, MFA and Identity Brokering

Part 4: User Federation, Organizations and Authorization

Part 5: Themes, Events, Security and Vault

Part 6: Integrating practical applications

Part 7: Production, HA and Kubernetes