No video

KEYCLOAK REALMS - what they really are & how to use them for Multi-Tenancy | Niko Köbler (@dasniko)

  Рет қаралды 10,702

Niko Köbler (@dasniko) - Keycloak Expert

Niko Köbler (@dasniko) - Keycloak Expert

Күн бұрын

Пікірлер: 28
@tharindunishada
@tharindunishada Жыл бұрын
Thanks for the videos. Appreciate your contribution towards Keycloak community.
@roscode96
@roscode96 Жыл бұрын
Thanks for posting this! It gave me confidence that I chose the right approach for my use case! (1 realm per tenant) 😄👍
@dempile
@dempile Жыл бұрын
hi, im planning to do the same think , I want to know if it worked well for you , and if you managed to make same user to login in multiple realms, tnx
@balaji3229
@balaji3229 Ай бұрын
Great explanation ! Thanks you very much. Option 3 looks like an over-engineering , introducing additional complexities.
@dasniko
@dasniko Ай бұрын
It always depends on the requirements. What looks like overengineering for you might be the proper solution for someone else.
@PranayHira
@PranayHira Жыл бұрын
Thank you very much, coming across your videos helped me and keeps helping me to gain more profound knowledge on Keycloak!
@davidtheprogrammer
@davidtheprogrammer 2 ай бұрын
New subscriber here. Thanks for the information, your a lifesaver
@PK-xv7oi
@PK-xv7oi 11 ай бұрын
Hey, thank you very much for your explanation. Do you have some resource references for the "n Tenant Realms + 1 Application Realm" scenario? I can't find any example how to set this up.
@emersonstori
@emersonstori Жыл бұрын
I'm trying to implement this situation right now and it's really confusing to choose the best way, since I don't have previous experiences with keycloack and multi-tenant
@Juanchi_AR
@Juanchi_AR Жыл бұрын
Nice!
@florianmayerhofer3215
@florianmayerhofer3215 2 ай бұрын
@dasniko Have you also videos about using Keycloak as a resource server?
@dasniko
@dasniko 2 ай бұрын
Keycloak is an IdP, not a resource server!
@smktutor
@smktutor 4 ай бұрын
Could you please share any design documents on the KeyCloack-multi-tenancy implementation?
@dasniko
@dasniko 4 ай бұрын
A link to the repo is in the description.
@user-nn2bv4zx5w
@user-nn2bv4zx5w 10 ай бұрын
Hello, I would like to assign the role "LDAP administrator of a realm" to a user who could administer the OU corresponding to the realm, so the user would be "base DN" in the LDAP settings and create the groups, roles and users with rights on this realm.
@dankogulsoy
@dankogulsoy Жыл бұрын
good job
@user-zf7gs5dr4l
@user-zf7gs5dr4l 11 ай бұрын
2 users A and B under same profile and Role. How can I restrict records of A to B and Vise versa in keycloak Can you please let me know about this
@binaryfire
@binaryfire Жыл бұрын
Great video mate. I need 1 realm per tenant but saw several posts about performance issues with large numbers of realms. Will the new JPA storage solve that? We'll eventually have many thousands of realms with a small number of users each. Using Postgres as the db.
@dasniko
@dasniko Жыл бұрын
Don't know. ¯\_(ツ)_/¯
@markkennethsantos2172
@markkennethsantos2172 Жыл бұрын
Thanks for the explanation. I just have one question when it comes to one realm and adding some custom SPI for organization/tenant feature. Is there any possibility to have a custom implementation for "access token life span" at tenant level? Currently, it can only be configured by realm and client level so I'm thinking about the use-case if client belongs to many tenants and they wanted to have different "access token lifespan". Thanks
@dasniko
@dasniko Жыл бұрын
AFAIK that's not possible without modifying core classes of Keycloak.
@Mr.Selast
@Mr.Selast Жыл бұрын
Very nice Vidéo! Some points notice fo the next one: - include some graphs: Looking at one person just talking is fun (kind of?) but a good graph a is worth a thousant explanation - For the option 3, qhat if we're using one UserStorage SPI for every realms ? 😂😂😂😂
@souravkumar-ue8uj
@souravkumar-ue8uj Жыл бұрын
Thanks Niko, I have one question though in one of my requirements is that different tenants should have different databases as well (one of the arch decisions other than the option of having single database with tenant identifier , here realmId) , is that possible in Keycloak ?
@dasniko
@dasniko Жыл бұрын
no
@dempile
@dempile Жыл бұрын
Thanks Niko for the explanation, Iam choosing Option 2 , but I want to know if its possible to make cross realms login for users , ir order to access clients in different realms, thanks
@dasniko
@dasniko Жыл бұрын
As I mentioned in the video, realms are level of isolation, there is no cross-anything! The only option would be identity brokering from one realm to another.
@dempile
@dempile Жыл бұрын
@@dasniko Its a fair solution for me , but we want to make selective login between realms
KEYCLOAK Implementing Custom User Storage Provider (in-depth) | Niko Köbler (@dasniko)
39:29
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 32 М.
KEYCLOAK Magic Login Link for Passwordless Authentication | Niko Köbler (@dasniko)
14:12
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 7 М.
КАКУЮ ДВЕРЬ ВЫБРАТЬ? 😂 #Shorts
00:45
НУБАСТЕР
Рет қаралды 3 МЛН
ПОМОГЛА НАЗЫВАЕТСЯ😂
00:20
Chapitosiki
Рет қаралды 28 МЛН
Harley Quinn's revenge plan!!!#Harley Quinn #joker
00:59
Harley Quinn with the Joker
Рет қаралды 18 МЛН
KEYCLOAK Upgrading and Migration - Frequently Asked Questions | Niko Köbler (@dasniko)
15:21
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 5 М.
KEYCLOAK Step-Up Authentication explained | Niko Köbler (@dasniko)
14:01
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 5 М.
KEYCLOAK Update Email Feature | Niko Köbler (@dasniko)
3:38
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 2,6 М.
KEYCLOAK Home IdP Discovery (w/ Sven-Torben Janus) | Niko Köbler (@dasniko)
17:27
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 3,4 М.
KEYCLOAK Enforce User Re-Authentication (e.g. before Updating Password) | Niko Köbler (@dasniko)
5:38
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 5 М.
KEYCLOAK Restrict Client Auth (w/ Sven-Torben Janus) | Niko Köbler (@dasniko)
12:48
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 3 М.
KEYCLOAK Recovery Authentication Codes | Niko Köbler (@dasniko)
15:19
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 2,1 М.
#Keycloak DevDay 2024:  Multi-Tenancy in Keycloak (GR Patil, phase two)
38:35
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 3,3 М.
Keycloak Tutorial: Creating Realms and Clients
24:52
K S Techno World
Рет қаралды 2 М.
#Keycloak DevDay 2024:  Flexible Access Management w/ Keycloak & OPA (Thomas Darimont, codecentric)
48:36
Niko Köbler (@dasniko) - Keycloak Expert
Рет қаралды 1 М.