
Keycloak
Use Keycloak as the identity provider for Pomerium through OpenID Connect.
Overview
Keycloak is an open-source identity and access management system. It manages users, groups, roles, sessions, and application clients inside realms. Keycloak supports OpenID Connect. Pomerium can use a Keycloak realm as the identity provider for protected applications and services.
A central identity provider gives users one sign-in flow across many private services. Each service does not need a separate authentication system. Pomerium uses identity claims from Keycloak when it evaluates the policy for each route.
This is a documented Keycloak integration. Keycloak authenticates the user. Pomerium applies route access policy. It does not add a separate Keycloak authorization engine inside Pomerium.
How it works
Create an OpenID Connect client in the correct Keycloak realm. Enable the standard authorization flow and client authentication. Add the Pomerium Authenticate callback as an exact valid redirect URI.
Configure Pomerium with the realm provider URL, client ID, and client secret. Select only the scopes and claims that the access policy needs. Keep client secrets outside source control and use HTTPS for production traffic.
Pomerium Enterprise can synchronize Keycloak directory data. Directory sync is a separate step and is not required for the standard OpenID Connect sign-in flow.
Example
A platform team runs Keycloak and several private engineering tools. The team registers Pomerium as one Keycloak OpenID Connect client. Each tool has a Pomerium route. A route policy permits members of an approved engineering group. Users sign in through Keycloak. Pomerium then permits or denies each route request.
Considerations
- Keycloak remains responsible for user authentication and identity data.
- OpenID Connect claims depend on Keycloak client scopes and protocol mappers.
- Directory sync is separate and needs Pomerium Enterprise.
- Pomerium does not create Keycloak users or manage the Keycloak user lifecycle.
