Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Keycloak & Cloudron

Keycloak & Cloudron

Scheduled Pinned Locked Moved Discuss
105 Posts 15 Posters 28.8k Views 17 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • BrutalBirdieB BrutalBirdie

    I could build, install and use the https://github.com/njsubedi/cloudron-keycloak master branch with no problems.

    girishG Offline
    girishG Offline
    girish
    Staff
    wrote on last edited by
    #49

    @BrutalBirdie thanks for testing, will prioritize getting this published.

    Sam_ukS 2 Replies Last reply
    4
    • girishG girish

      @BrutalBirdie thanks for testing, will prioritize getting this published.

      Sam_ukS Offline
      Sam_ukS Offline
      Sam_uk
      wrote on last edited by Sam_uk
      #50

      @girish Great stuff! We're a bit stuck on this one at the moment: https://github.com/njsubedi/cloudron-keycloak/issues/7#issuecomment-1384001649

      Sam_ukS 1 Reply Last reply
      2
      • Sam_ukS Sam_uk

        @girish Great stuff! We're a bit stuck on this one at the moment: https://github.com/njsubedi/cloudron-keycloak/issues/7#issuecomment-1384001649

        Sam_ukS Offline
        Sam_ukS Offline
        Sam_uk
        wrote on last edited by
        #51

        Any updates on this one please?

        luckowL 1 Reply Last reply
        1
        • Sam_ukS Sam_uk

          Any updates on this one please?

          luckowL Offline
          luckowL Offline
          luckow
          translator
          wrote on last edited by
          #52

          @Sam_uk besides Keycloak - have you tried the new OpenID Connect Provider feature in Cloudron v. 7.4?

          Pronouns: he/him | Primary language: German

          C 1 Reply Last reply
          2
          • luckowL luckow

            @Sam_uk besides Keycloak - have you tried the new OpenID Connect Provider feature in Cloudron v. 7.4?

            C Offline
            C Offline
            cuzy-app
            wrote on last edited by cuzy-app
            #53

            @luckow Thanks, this is a great news!

            However, this solution is not possible for us because we use modules in some apps that synchronizes groups and roles with Keycloak.
            And it would be too much work to migrate all or ecosystem to another SSO.
            Moreover, users would need to recreate their password.

            1 Reply Last reply
            4
            • girishG girish

              @BrutalBirdie thanks for testing, will prioritize getting this published.

              Sam_ukS Offline
              Sam_ukS Offline
              Sam_uk
              wrote on last edited by
              #54

              @girish When do you think you might be able to have a look at this one please?

              nebulonN 1 Reply Last reply
              1
              • Sam_ukS Sam_uk

                @girish When do you think you might be able to have a look at this one please?

                nebulonN Away
                nebulonN Away
                nebulon
                Staff
                wrote on last edited by
                #55

                @Sam_uk while this is not exactly keycloak, have you seen https://docs.cloudron.io/user-management/#openid-connect ? Does this help in your case? So far in our testing with various apps, we are quite positive that this is a very feature.

                C 1 Reply Last reply
                2
                • nebulonN nebulon

                  @Sam_uk while this is not exactly keycloak, have you seen https://docs.cloudron.io/user-management/#openid-connect ? Does this help in your case? So far in our testing with various apps, we are quite positive that this is a very feature.

                  C Offline
                  C Offline
                  cuzy-app
                  wrote on last edited by
                  #56

                  @nebulon Yes, thanks.

                  However, this solution is not possible for us because we use modules in some apps that synchronizes groups and roles with Keycloak.
                  And it would be too much work to migrate all or ecosystem to another SSO.
                  Moreover, users would need to recreate their password.

                  Sam_ukS 1 Reply Last reply
                  2
                  • C cuzy-app

                    @nebulon Yes, thanks.

                    However, this solution is not possible for us because we use modules in some apps that synchronizes groups and roles with Keycloak.
                    And it would be too much work to migrate all or ecosystem to another SSO.
                    Moreover, users would need to recreate their password.

                    Sam_ukS Offline
                    Sam_ukS Offline
                    Sam_uk
                    wrote on last edited by Sam_uk
                    #57

                    Does anyone have insight into this build problem? https://github.com/njsubedi/cloudron-keycloak/issues/7#issuecomment-1384001649

                    I can make a modest budget available to resolve this issue, if you're interested in doing this as paid work then please DM me.

                    cc @cuzy-app

                    Sam_ukS 1 Reply Last reply
                    1
                    • Sam_ukS Sam_uk

                      Does anyone have insight into this build problem? https://github.com/njsubedi/cloudron-keycloak/issues/7#issuecomment-1384001649

                      I can make a modest budget available to resolve this issue, if you're interested in doing this as paid work then please DM me.

                      cc @cuzy-app

                      Sam_ukS Offline
                      Sam_ukS Offline
                      Sam_uk
                      wrote on last edited by
                      #58

                      @girish thanks for your comment on this. Despite spending a couple of hours more on it we cannot work it out. Could you (or anyone else who understands Cloudron) see if they are able to replicate our issue please?

                      girishG 1 Reply Last reply
                      1
                      • Sam_ukS Sam_uk

                        @girish thanks for your comment on this. Despite spending a couple of hours more on it we cannot work it out. Could you (or anyone else who understands Cloudron) see if they are able to replicate our issue please?

                        girishG Offline
                        girishG Offline
                        girish
                        Staff
                        wrote on last edited by
                        #59

                        @Sam_uk unfortunately, this seems quite app specific. So, I have to spend some time with the app to understand what has changed between releases etc.

                        Sam_ukS 1 Reply Last reply
                        1
                        • girishG girish

                          @Sam_uk unfortunately, this seems quite app specific. So, I have to spend some time with the app to understand what has changed between releases etc.

                          Sam_ukS Offline
                          Sam_ukS Offline
                          Sam_uk
                          wrote on last edited by
                          #60

                          @girish Thanks. What are your intentions around the Keycloak app? Are you still planning to implement it on Cloudron?

                          I'm considering cutting my losses and just putting it on a normal Vserver.

                          If you do plan to make it an official app then it might be worth continuing to debug the Cloudron version.

                          girishG 1 Reply Last reply
                          1
                          • Sam_ukS Sam_uk

                            @girish Thanks. What are your intentions around the Keycloak app? Are you still planning to implement it on Cloudron?

                            I'm considering cutting my losses and just putting it on a normal Vserver.

                            If you do plan to make it an official app then it might be worth continuing to debug the Cloudron version.

                            girishG Offline
                            girishG Offline
                            girish
                            Staff
                            wrote on last edited by girish
                            #61

                            @Sam_uk we have nothing against it, if that's what you are asking 🙂 It just takes time to package/test/publish new apps. We have @vladimir-d helping us out with packaging/publishing, but he has quite a bit on his plate still.

                            I would say, you can always set it up separately for the moment. When we have the Cloudron app, I guess you can migrate. Not sure if keycloak has import/export.

                            Sam_ukS 1 Reply Last reply
                            1
                            • girishG girish

                              @Sam_uk we have nothing against it, if that's what you are asking 🙂 It just takes time to package/test/publish new apps. We have @vladimir-d helping us out with packaging/publishing, but he has quite a bit on his plate still.

                              I would say, you can always set it up separately for the moment. When we have the Cloudron app, I guess you can migrate. Not sure if keycloak has import/export.

                              Sam_ukS Offline
                              Sam_ukS Offline
                              Sam_uk
                              wrote on last edited by
                              #62

                              @girish I'm already running Keycloak in Cloudron! I just can't update it.

                              Can I pay you to bump it up @vladimir-d to do list?

                              girishG 1 Reply Last reply
                              1
                              • Sam_ukS Sam_uk

                                @girish I'm already running Keycloak in Cloudron! I just can't update it.

                                Can I pay you to bump it up @vladimir-d to do list?

                                girishG Offline
                                girishG Offline
                                girish
                                Staff
                                wrote on last edited by
                                #63

                                @Sam_uk while keycloak is in our roadmap, it's not in our immediate roadmap. But, if you are in the market for paying a developers salary for a week or so, please contact us at support@ . Just want to set expectations here, this is going to be many times over the cloudron cost itself by nature of developer salary.

                                1 Reply Last reply
                                0
                                • nebulonN Away
                                  nebulonN Away
                                  nebulon
                                  Staff
                                  wrote on last edited by
                                  #64

                                  Just took a closer look at that package https://github.com/njsubedi/cloudron-keycloak/blob/main/CloudronManifest.json#L22

                                  It does Cloudron LDAP integration, so @Sam_uk maybe it would be good to understand the setup and use-case for keycloak in such a context, especially with the addition of OpenId Connect in Cloudron recently.

                                  1 Reply Last reply
                                  0
                                  • marcusquinnM Offline
                                    marcusquinnM Offline
                                    marcusquinn
                                    wrote on last edited by marcusquinn
                                    #65

                                    If you work with any organisation, you quickly find the majority still reuse passwords, don't use password managers correctly, and just want one login for all apps.

                                    They don't know or care what is SaaS or internal.

                                    They just want one login, password, maybe 2FA and that to get them into everything they will ever need.

                                    The company also wants one off-switch for their access to everything.

                                    Right now, you're options are using Google, Microsoft or one of the SSO providers, like Auth0, Okta. They are all lock-in by design services.

                                    Keycloak is the only open-source solution, that I know of, to this, without tying you to never-ending per-user costs.

                                    Unless you think you can make Cloudron LDAP and OpenID work as Single Sign-On (SSO) as a service for all the other non-Cloudron apps that support SSO?

                                    Web Design https://www.evergreen.je
                                    Development https://brandlight.org
                                    Life https://marcusquinn.com

                                    girishG 1 Reply Last reply
                                    2
                                    • marcusquinnM marcusquinn

                                      If you work with any organisation, you quickly find the majority still reuse passwords, don't use password managers correctly, and just want one login for all apps.

                                      They don't know or care what is SaaS or internal.

                                      They just want one login, password, maybe 2FA and that to get them into everything they will ever need.

                                      The company also wants one off-switch for their access to everything.

                                      Right now, you're options are using Google, Microsoft or one of the SSO providers, like Auth0, Okta. They are all lock-in by design services.

                                      Keycloak is the only open-source solution, that I know of, to this, without tying you to never-ending per-user costs.

                                      Unless you think you can make Cloudron LDAP and OpenID work as Single Sign-On (SSO) as a service for all the other non-Cloudron apps that support SSO?

                                      girishG Offline
                                      girishG Offline
                                      girish
                                      Staff
                                      wrote on last edited by
                                      #66

                                      @marcusquinn said in Keycloak & Cloudron:

                                      Unless you think you can make Cloudron LDAP and OpenID work as Single Sign-On (SSO) as a service for all the other non-Cloudron apps that support SSO?

                                      That's what has been added to 7.4. Internal apps will slowly get migrated from ldap. For external app, you can create oidc client tokens.

                                      1 Reply Last reply
                                      2
                                      • J Offline
                                        J Offline
                                        JLX89
                                        wrote on last edited by
                                        #67

                                        I apologize if this was already mentioned, but another use case is to use Keycloak outside of Cloudron. Basically hosting the app inside Cloudron but used for other apps. For example, say we have an externally hosted app and we want to integrate Keycloak.

                                        I do this with some other apps, where we host the services inside Cloudron but they're used outside on other customer sites and such (EX: Stats, Directus, Cloudsurfer).

                                        While OpenID integration is great, I personally would want to use Keycloak outside of Cloudron users, if possible.

                                        girishG 1 Reply Last reply
                                        1
                                        • J JLX89

                                          I apologize if this was already mentioned, but another use case is to use Keycloak outside of Cloudron. Basically hosting the app inside Cloudron but used for other apps. For example, say we have an externally hosted app and we want to integrate Keycloak.

                                          I do this with some other apps, where we host the services inside Cloudron but they're used outside on other customer sites and such (EX: Stats, Directus, Cloudsurfer).

                                          While OpenID integration is great, I personally would want to use Keycloak outside of Cloudron users, if possible.

                                          girishG Offline
                                          girishG Offline
                                          girish
                                          Staff
                                          wrote on last edited by
                                          #68

                                          @JLX89 said in Keycloak & Cloudron:

                                          While OpenID integration is great, I personally would want to use Keycloak outside of Cloudron users, if possible.

                                          Can you elaborate a bit more on this? Is this because it feels more trusted/better features or something else? Or maybe you have extensively used keycloak in the past and like that tool. That's fine too, just trying to get some information here.

                                          J 1 Reply Last reply
                                          1
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search