Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

Keycloak

8 Topics 109 Posts
  • Keycloak - Package Updates

    Pinned Locked
    45
    0 Votes
    45 Posts
    15k Views
    Package UpdatesP
    [1.7.1] Update keycloak to 26.7.1 Full Changelog [CVE-2026-9793] JWE request object bypasses requestObjectSignatureAlg enforcement oidc (#49429) [CVE-2026-4629] Privilege escalation via hardcoded role mapper injection in manage-clients admin/api (#50445) [CVE-2026-14209] Keycloak Admin UI Extension brute-force-user User Disclosure via search=id: under FGAP v2 admin/fine-grained-permissions (#50569) [CVE-2026-14614] Keycloak 26.6.3 Fine-Grained Admin Permissions Bypass in Client Scope Assignment admin/fine-grained-permissions (#50615) [CVE-2026-14615] FGAP v2 parent group children endpoint bypasses per-child view permission filter admin/fine-grained-permissions (#50617) WebAuthn authenticator attachment policy is bypassed when the client omits the attachment field authentication/webauthn (#50719) Kustomize cluster-wide faulty Role&RoleBinding operator (#50836) New Password is commited when multiple Password Reset is detected authentication (#50850) 500 when client requests organization scope with it already set to Default authentication (#50882) IllegalFormatConversionException in LiquibaseDBLockProviderFactory and wrong time conversion core (#50928)
  • PSA: Keycloak easy custom themes (working editor!)

    1
    2 Votes
    1 Posts
    249 Views
    No one has replied
  • Apps Compatible with Keycloak SSO

    6
    1 Votes
    6 Posts
    2k Views
    jdaviescoatesJ
    @Neiluj said in Apps Compatible with Keycloak SSO: Hi - You can find the list of Cloudron packaged app that are SSO enabled here: https://www.cloudron.io/appstatus.html While this list speaks to a SSO managed by / for Cloudron, I am under the understanding that, for each of these apps, if you leave user management to the app when installting the app on Cloudron, you should be able to configured SSO to work with your Keycloak instance. Hopefully this is a correct assumption. I hope that this helps. Yeah, I'm not certain either, but think you're right that any app that already supports Cloudron SSO could be configured to work with Keycloak SSO too. I think perhaps @Sam_uk is using Keycloak (or similar) for the SSO for his Cloudrons and so could probably chime in with actual knowledge gained from experience.
  • This topic is deleted!

    Solved
    3
    0 Votes
    3 Posts
    671 Views
  • realm email configuration

    4
    1
    1 Votes
    4 Posts
    2k Views
    aurelien-cA
    For the record, the advice was fruitful and I have a working configuration.
  • how to connect to a cloudron ldap via federation?

    12
    3
    2 Votes
    12 Posts
    4k Views
    C
    To circle back on this... I deployed Keycloak from the app store. I created a new (local) admin user and deleted the temp one (as per the instructions out of the box). I then used the "Login with Cloudron" button and was able to login to Keycloak (as the non admin user from Cloudron directory) and my Cloudron user shows up in Keycloak . I would be very interested in developing/documenting a tight integration/best practices between Cloudron/Keycloak as a way to greatly extend/enhance Cloudron user management. Setting up various tenants, self service enabling signups in those tenants etc. For example, building user on-boarding / approval workflows (where you bring on a new team member and they need to be provisioned into groups). Right now, only Cloudron Superadmins have the ability to manage groups, and that isn't a privilege I want to hand out I originally planned to have Claude build me a web app and utilize the Cloudron API to build that functionality (and was going to AGPLv3 it). However, perhaps, with Keycloak we don't have to fully re-invent the wheel? IAM is a VERY important requirement/feature to compete with AWS/Azure. It's the next thing my board wants to see as we move through go-live with Cloudron across our various projects/entities. Who would be the key people I would need to work with to get this built out/tested/integrated/streamlined? I realize that Cloudron (as I understand it) isn't currently positioned/targeting "enterprise" or those who may use AWS/Azure. I am happy todo the light/medium/(some) heavy lift work to help get it to where I need it to be. I am a founder/CTO of a company that is in the ramp up/growth phase. I steadfastly refuse to use the "big cloud" and Cloudron has been amazing at eliminating about 90% of system admin duties in a reliable way.
  • Enabling features

    26
    0 Votes
    26 Posts
    7k Views
    girishG
    @gpichler @msbt I have merged it now and published it
  • How to add a permanent admin?

    12
    0 Votes
    12 Posts
    7k Views
    S
    @joseph btw, i ended up uninstalling and reinstalling the Keycloak app and this the process went about as depicted in your video.