Enterprise Multi-Cluster Identity & Access Management with Microsoft Entra ID, Active Directory & OAuth 2.1
Note
Generative AI Accelerator Disclaimer This repository and all associated architectures, manifests, configurations, and scripts were generated with Gemini 3.7 Flash High (Antigravity Agent). This content is intended as an illustrative, architectural reference and accelerator baseline. It has not been executed or validated in a live customer production environment. Platform engineering teams should review, profile, harden, and adapt these artifacts to their specific security policies, network topologies, and compliance mandates.
This enterprise repository provides an end-to-end, production-ready Red Hat Build of Keycloak (RHBK) GitOps architecture for Red Hat OpenShift 4.20+ on AWS. It integrates hybrid identity with Microsoft Entra ID (Azure AD) and Active Directory, strict OAuth 2.1 compliance (PKCE, Private Key JWT, Token Exchange), and multi-cluster ArgoCD deployment across DEV, STAGE, and PROD. Use this map to navigate the repository architecture and multimedia guides:
keycloak-openshift-2026/ # π Enterprise RHBK OpenShift GitOps Platform
βββ π apps/ # Enterprise Client Workloads & Integrations
β βββ π angular-spa/ # Angular 18+ SPA (PKCE & BFF Gateway Pattern)
β βββ π argocd/ # OpenShift GitOps ArgoCD OIDC configuration
β βββ π backstage-idp/ # Backstage Developer Portal IDP auth provider
β βββ π microservices/ # Quarkus & Node.js Resource Servers (JWT & Token Exchange)
βββ π ci-cd/ # Continuous Integration & Delivery
β βββ π jenkins/ # Jenkins Helm deployment, OIDC auth & ArgoCD sync jobs
βββ π gitops/ # Declarative Kustomize Overlays & ArgoCD ApplicationSets
β βββ π root-application.yaml # ArgoCD Root App-of-Apps master manifest
β βββ π base/ # Base Keycloak Operator and Keycloak CR templates
β βββ π clusters/ # Multi-cluster overlays (Dev, Stage, Prod HA, Hub)
βββ π local-dev/ # Offline Developer Testing Sandbox Stack
β βββ π docker-compose.yml # Local Keycloak (Quarkus), Postgres 16 & Mock OpenLDAP
β βββ π mock-ad-ldap/ # Pre-seeded enterprise LDAPS directory container
βββ π monitoring/ # Observability & Alerting Suite
β βββ π alerts/ # PrometheusRule alerting definitions (SLAs, error spikes)
β βββ π dashboards/ # Production Grafana dashboards (JVM, logins, cache hits)
βββ π scripts/ # Automated Day 0, Day 1, and Day 2 Lifecycle Runbooks
β βββ π day0-prereqs.sh # TLS certificates, secrets & network prerequisites
β βββ π day1-deploy-operator-and-keycloak.sh # Automated Operator provisioning
β βββ π day1-configure-entra-federation.sh # Microsoft Entra ID OIDC brokering setup
β βββ π day2-operations-suite.sh # Health probing, realm backups & scaling operations
β βββ π local-sandbox-up.sh # 1-click local Docker Compose launch script
βββ π docs/ # Exhaustive Engineering Architecture & Runbooks
βββ π ARCHITECTURE.md # End-to-end multi-cluster topology breakdown
βββ π ENTRA_AD_FEDERATION_GUIDE.md # Hybrid identity & LDAPS configuration guide
βββ π OAUTH2_OIDC_SECURITY_FLOWS.md # OAuth 2.1, PKCE, mTLS & RFC 8693 specifications
βββ π DISASTER_RECOVERY_CROSS_SITE.md # Multi-region DR & Infinispan WAN replication
This repository is accompanied by an educational video masterclass and technical shorts synthesized with Gemini NotebookLM based directly on the architecture blueprints, hybrid identity federation guides, and OAuth 2.1 specifications from this project. All videos are freely accessible on YouTube on the @nubenetes channel.
Note
Multilingual Learning Experience:
Content features native spoken audio in English πΊπΈ, with automated YouTube closed captions (CC) translated into Spanish πͺπΈ and 20+ languages for global engineering teams.
| # | Video Guide Title | Engineering Domain & Core Architecture | Duration | Direct Link |
|---|---|---|---|---|
| 01 | Keycloak GitOps Blueprint | Declarative Operator Lifecycle & ArgoCD Overlays Quarkus engine, Kustomize multi-cluster promotion & ESO Vault sync |
9:05 |
|
| 02 | Modern OAuth 2.1 & OIDC | OAuth 2.1 Compliance & Token Security Authorization Code Flow with PKCE, BFF Gateway pattern & RFC 8693 Token Exchange |
9:10 |
|
| 03 | Keycloak Hybrid Identity | Hybrid Identity Federation & Egress Isolation Microsoft Entra ID OIDC brokering, on-prem LDAPS federation & EgressFirewall |
8:49 |
|
| 04 | RHBK Multi-Region DR | High Availability & Multi-Region DR Aurora Multi-AZ, embedded Infinispan JGroups WAN mirroring & Route 53 ARC |
9:33 |
| # | Short Title | Architectural Domain & Focus | Duration | Action |
|---|---|---|---|---|
| 01 | The Ultimate Keycloak GitOps Blueprint | Declarative IAM Operations Replacing error-prone click-ops with version-controlled GitOps & ArgoCD |
1:23 |
|
| 02 | How OpenShift EgressFirewalls Isolate Pods | Zero-Trust Network Security Restricting IAM pod egress to Entra ID and LDAPS while blocking lateral threats |
1:11 |
|
| 03 | How to Run the Keycloak Offline Sandbox | Developer Experience & Local Testing 1-command local Docker Compose sandbox with Quarkus Keycloak & Mock OpenLDAP |
1:19 |
For complete technical summaries, topic breakdowns, and direct studio links, see Section 16: Video Walkthroughs & Architecture References.
- Quick Navigation Map
- AI-Generated Multimedia Series (YouTube)
- 1. Executive Summary & Architecture Overview
- 2. Multi-Cluster Topology (3 AWS OCP Clusters + Central Hub)
- 3. Hybrid Identity Architecture: Microsoft Entra ID & Active Directory
- 4. Modern OAuth 2.1 & OpenID Connect Security Paradigm
- 5. Comparative Matrices & Architectural Decision Records
- 6. Step-by-Step Operations Guide
- 7. Sample Applications & Enterprise Workload Integrations
- 7.1 ArgoCD GitOps UI (OIDC Auth Code + PKCE & Group RBAC)
- 7.2 Backstage Developer Portal (IDP Provider & Catalog Sync)
- 7.3 Enterprise Angular 18+ SPA (PKCE & BFF Gateway Pattern)
- 7.4 Quarkus Microservice (JWT Resource Server & Token Exchange RFC 8693)
- 7.5 Node.js API Gateway (Private Key JWT RFC 7523 & JWKS Validation)
- 8. Jenkins CI/CD on OpenShift DEV (Helm Chart + OIDC + ArgoCD)
- 9. Secrets Management Architecture (AWS Secrets Manager + HashiCorp Vault + ESO)
- 10. Zero-Trust Security: OpenShift EgressFirewall
- 11. Local Sandbox Environment (Offline Testing Stack)
- 12. Developer Makefile Reference
- 13. Observability, Prometheus Metrics & Grafana Dashboards
- 14. Disaster Recovery & Multi-Region Cross-Site Replication
- 15. Verification & End-to-End Validation
- 16. Video Walkthroughs & Architecture References (YouTube)
- 17. Up-to-Date References & Standards (2026)
Modern enterprise identity architectures require a balance between centralized governance and distributed high availability. This repository provides a complete, declarative GitOps foundation for deploying Red Hat Build of Keycloak (RHBK) on OpenShift Container Platform (OCP) 4.20+ hosted on Amazon Web Services (AWS).
- Red Hat Build of Keycloak Operator (Quarkus Engine): Replaces legacy WildFly-based RHSSO 7.x with modern Quarkus-powered Keycloak (v24/v26 stream) for fast startup, low memory footprint (~1.5GB/instance), and full declarative reconciliation.
- Hybrid Corporate Identity: Bridges cloud-native Microsoft Entra ID (Azure AD) and on-premises Active Directory via OIDC Identity Brokering and LDAPS User Federation with bidirectional group mappings.
- Strict OAuth 2.1 Compliance: Deprecates insecure legacy flows (Implicit Grant and Resource Owner Password Credentials) and enforces Authorization Code Flow with PKCE (RFC 7636), Backend-For-Frontend (BFF) proxying, Private Key JWT (RFC 7523), and Token Exchange (RFC 8693).
- GitOps-First Automation: Powered by ArgoCD ApplicationSets and Kustomize overlays for automated multi-cluster rollout across Development (
cluster-alpha-dev), Staging (cluster-bravo-stage), Production HA (cluster-charlie-prod), and an optional Central Management Hub (cluster-hub-central). - Continuous Integration & Secrets Management: Jenkins deployed via official Helm chart on OpenShift DEV, federated with Keycloak OIDC, triggering ArgoCD GitOps syncs, with secrets synchronized via External Secrets Operator (ESO) from AWS Secrets Manager and HashiCorp Vault.
graph TD
subgraph CorpID["Corporate Identity Layer (Hybrid)"]
Entra["<b>Microsoft Entra ID</b><br/>Cloud Users & Groups<br/>Conditional Access & MFA<br/>App Registrations"]
AD["<b>Active Directory</b><br/>On-Premises LDAPS<br/>Domain User Accounts"]
EntraSync["<b>Entra Cloud Sync</b><br/>Hybrid DirSync Engine"]
AD <-->|Password Hash Sync| EntraSync
EntraSync <-->|OIDC Provisioning| Entra
end
subgraph HubCluster["(Optional) Central Identity Hub (OCP)"]
HubKC["<b>Parent Keycloak (RHBK)</b><br/>Central Broker & Policy Engine"]
HubDB[("<b>AWS Aurora DB</b><br/>Global PostgreSQL")]
HubKC <--> HubDB
end
subgraph SpokeDev["Cluster 1: Alpha (Dev)"]
KC1["<b>Keycloak Dev</b><br/>1 Replica"]
Apps1["<b>Dev Workloads</b><br/>ArgoCD & Backstage"]
KC1 <--> Apps1
end
subgraph SpokeStage["Cluster 2: Bravo (Stage)"]
KC2["<b>Keycloak Stage</b><br/>2 Replicas (HA)"]
Apps2["<b>Stage Workloads</b><br/>Microservices & APIs"]
KC2 <--> Apps2
end
subgraph SpokeProd["Cluster 3: Charlie (Prod HA)"]
KC3["<b>Keycloak Prod HA</b><br/>3+ Replicas (Multi-AZ)"]
Apps3["<b>Production Apps</b><br/>Angular SPA & APIs"]
KC3 <--> Apps3
end
Entra -->|OIDC Federation| HubKC
AD -->|LDAPS Sync| HubKC
Entra -.->|Direct OIDC| KC1
Entra -.->|Direct OIDC| KC2
Entra -.->|Direct OIDC| KC3
HubKC -->|Hub Delegation| KC1
HubKC -->|Hub Delegation| KC2
HubKC -->|Hub Delegation| KC3
classDef corp fill:#e0f2fe,stroke:#0284c7,stroke-width:2px,color:#0f172a;
classDef hub fill:#fef3c7,stroke:#d97706,stroke-width:2px,color:#0f172a;
classDef spoke fill:#f0fdf4,stroke:#16a34a,stroke-width:2px,color:#0f172a;
class Entra,AD,EntraSync corp;
class HubKC,HubDB hub;
class KC1,Apps1,KC2,Apps2,KC3,Apps3 spoke;
Enterprise organizations typically host core user identities in Microsoft Entra ID (Azure AD) and on-premises Active Directory Domain Services (AD DS). Keycloak acts as the OpenShift-native Identity Provider (IdP) Broker and Token Authority.
sequenceDiagram
autonumber
actor Dev as Enterprise Developer
participant ClientApp as OpenShift App<br/>(ArgoCD / Backstage / SPA)
participant Keycloak as Red Hat Build<br/>of Keycloak (RHBK)
participant Entra as Microsoft Entra ID<br/>(Azure AD)
participant AD as On-Premises AD<br/>(LDAPS)
Dev->>ClientApp: Access Application
ClientApp->>Keycloak: Initiate OAuth 2.1 Flow<br/>(PKCE S256 Challenge)
Keycloak->>Entra: Federate via OpenID Connect<br/>(Corporate Azure SSO)
Entra->>Entra: Enforce Corporate MFA &<br/>Conditional Access Policies
Entra-->>Keycloak: Return ID Token<br/>(UPN, email, Entra groups)
opt Active Directory LDAP Query
Keycloak->>AD: Query LDAPS for on-prem<br/>attributes & legacy groups
AD-->>Keycloak: Return Directory Attributes
end
Keycloak->>Keycloak: Apply Protocol Mappers<br/>(Map Entra/AD groups to Roles)
Keycloak-->>ClientApp: Issue Signed JWTs<br/>(Access Token & ID Token)
ClientApp->>ClientApp: Validate Claims & Roles
ClientApp-->>Dev: Grant Authorized Access
OAuth 2.1 consolidates security best practices developed over a decade of OAuth 2.0 deployments.
graph TD
subgraph Prohibited["β Prohibited Legacy Flows"]
Imp["<b>Implicit Grant</b><br/>Tokens exposed in URL / history"]
ROPC["<b>Password Grant (ROPC)</b><br/>Direct credentials harvesting risk"]
end
subgraph Modern["β
Enforced Modern OAuth 2.1 & OIDC Flows"]
PKCE["<b>Auth Code + PKCE</b><br/>RFC 7636 (S256)<br/>Mandatory for UI apps"]
BFF["<b>BFF Proxy Pattern</b><br/>HttpOnly secure cookies<br/>Zero browser token exposure"]
PrivKey["<b>Private Key JWT</b><br/>RFC 7523 Asymmetric Auth<br/>For confidential services"]
TokEx["<b>Token Exchange</b><br/>RFC 8693 Delegation<br/>Scoped audience tokens"]
end
style Prohibited fill:#fee2e2,stroke:#b91c1c,stroke-width:2px,color:#7f1d1d;
style Modern fill:#dcfce7,stroke:#15803d,stroke-width:2px,color:#14532d;
| Pattern | Mechanism | Use Case | Latency | Resilience | Complexity |
|---|---|---|---|---|---|
| OIDC Identity Brokering | Keycloak -> Microsoft Entra ID OIDC | Cloud-first users, Microsoft 365, Azure Conditional Access | Low (<150ms) | Dependent on Entra ID availability | Low (standard OIDC) |
| LDAPS User Federation | Keycloak -> On-Prem AD (LDAPS:636) | Legacy on-prem AD users, Kerberos ticket exchange | Medium (<300ms) | Local caching reduces WAN reliance | Medium (LDAP schema mappers) |
| Hybrid Hub-Spoke | Spoke Keycloak -> Parent Hub Keycloak -> Entra ID | Multi-cluster enterprise governance with regional failover | Low-Medium | High (regional offline caches) | High (multi-tier federation) |
| Client Application | Client Type | Authentication Method | Grant Type | PKCE Method | Token Lifespan |
|---|---|---|---|---|---|
| ArgoCD GitOps | Confidential | client_secret / private_key_jwt |
Authorization Code | S256 |
15 mins (Refreshable) |
| Backstage IDP | Confidential | client_secret + Service Account |
Authorization Code | S256 |
30 mins |
| Angular 18+ SPA | Public / BFF | none (with PKCE) or BFF Cookie |
Authorization Code | S256 |
5 mins (Short-lived) |
| API Gateway | Confidential | private_key_jwt (RFC 7523) |
Client Credentials | N/A (Server-to-Server) | 10 mins |
| Quarkus Microservice | Bearer-only / Service | client_secret / mTLS |
Token Exchange (RFC 8693) | N/A | 5 mins (Scoped audience) |
| Parameter | Dev Cluster (cluster-alpha-dev) |
Stage Cluster (cluster-bravo-stage) |
Prod HA Cluster (cluster-charlie-prod) |
Hub Cluster (cluster-hub-central) |
|---|---|---|---|---|
| Replicas | 1 | 2 | 3 to 10 (HPA enabled) | 3 (Multi-AZ) |
| CPU / Memory Req | 500m / 1024Mi | 1000m / 1536Mi | 2000m / 2048Mi | 2000m / 2048Mi |
| CPU / Memory Limit | 1000m / 2048Mi | 2000m / 3072Mi | 4000m / 4096Mi | 4000m / 4096Mi |
| Database Tier | PostgreSQL Single-Pod | Crunchy PGO HA (2 instances) | AWS Aurora PostgreSQL Multi-AZ | AWS Aurora Multi-Region |
| Hostname | keycloak-dev.apps.cluster-alpha... |
keycloak-stage.apps.cluster-bravo... |
sso.enterprise.example.com |
sso-hub.enterprise.example.com |
| Phase | Scope | Primary Automation Tool | Key Deliverables |
|---|---|---|---|
| Day 0 | Prerequisites & Infra | scripts/day0-prereqs.sh |
Namespace, TLS certs, DB secrets, NetworkPolicies |
| Day 1 | Provisioning & IdP Config | scripts/day1-*.sh + GitOps |
Operator CSV, Keycloak CR, Declarative Realm Imports |
| Day 2 | Maintenance & Ops | scripts/day2-operations-suite.sh |
DB backups, Realm exports, Prometheus metrics, HPA, Upgrades |
| Decom | Teardown & Archival | scripts/decommission-cluster.sh |
Final DB/Realm snapshot, route removal, resource shredding |
| Feature | AWS Secrets Manager + ESO (Recommended) | HashiCorp Vault Hub-Spoke (PR) | In-Cluster Vault + ESO |
|---|---|---|---|
| Multi-Cluster Sync | Native AWS IAM / STS across clusters | Requires Vault Enterprise license | ESO pulls from central AWS Secrets |
| Operational Effort | Zero state (Managed AWS service) | High (Consensus, unsealing, WAN links) | Medium (Standalone instance) |
| Auth Mechanism | AWS IRSA (IAM Roles for Service Accounts) | Token / AppRole / Kubernetes Auth | Kubernetes ServiceAccount Auth |
| Best For | AWS OpenShift Clusters (ROSA / IPI) | Heterogeneous multi-cloud enterprises | Local Transit encryption & dynamic DB |
Execute Day 0 preparation on the target OpenShift cluster:
./scripts/day0-prereqs.shDeploy the Red Hat Build of Keycloak Operator and provision the instance:
# For Dev Cluster
./scripts/day1-deploy-operator-and-keycloak.sh cluster-alpha-dev
# For Production Cluster
./scripts/day1-deploy-operator-and-keycloak.sh cluster-charlie-prodNext, configure Microsoft Entra ID and Active Directory federation:
ENTRA_TENANT_ID="<your-tenant-uuid>" \
ENTRA_CLIENT_ID="<your-app-client-uuid>" \
ENTRA_CLIENT_SECRET="<your-client-secret>" \
./scripts/day1-configure-entra-federation.shFinally, register sample applications (ArgoCD, Backstage, Angular SPA, Microservices):
./scripts/day1-register-sample-apps.shLaunch the interactive Day 2 operations suite:
./scripts/day2-operations-suite.shWhen decommissioning a cluster or tearing down a testing environment:
./scripts/decommission-cluster.sh- ArgoCD GitOps:
apps/argocd/(OIDC configuration + group RBAC). - Backstage Developer Portal:
apps/backstage-idp/(App config + backend auth plugin). - Angular 18+ Single Page App:
apps/angular-spa/(AuthCode PKCE service, standalone UI, BFF OAuth2-Proxy / Nginx config). - Quarkus Microservice:
apps/microservices/quarkus-api-service/(SmallRye JWT, RFC 8693 Token Exchange). - Node.js API Gateway:
apps/microservices/nodejs-api-gateway/(Express,joseJWT validation, Private Key JWT RFC 7523).
The ci-cd/jenkins/ module configures Jenkins on OpenShift DEV using the official Helm chart:
- Helm Values:
ci-cd/jenkins/values-openshift.yamlconfigured with OpenShift SCC compatibility, persistent storage, and dynamic Kubernetes agent clouds. - Keycloak OIDC JCasC:
ci-cd/jenkins/jenkins-keycloak-oidc-jcasc.yamlmapping Keycloak/Adminsand/Developersgroups to matrix permissions. - Jenkins Pipeline:
ci-cd/jenkins/Jenkinsfileexecuting automated Kustomize checks and triggering ArgoCD application synchronization.
sequenceDiagram
autonumber
actor Dev as Platform Engineer
participant Jenkins as Jenkins (OCP DEV)
participant KC as Keycloak (RHBK)
participant Argo as ArgoCD (openshift-gitops)
Dev->>KC: Log in via Entra ID SSO
KC-->>Jenkins: Authorize OIDC session (/Admins group)
Dev->>Jenkins: Trigger CI Pipeline (Jenkinsfile)
Note over Jenkins: Lint scripts & validate Kustomize
Jenkins->>Argo: Dispatch Application Sync (/api/v1/applications/sync)
Argo-->>Dev: Declarative GitOps deployment reconciled
Detailed architecture guide available in docs/SECRETS_MANAGEMENT_VAULT_AWS.md.
graph TD
subgraph AWS_Cloud["AWS Cloud Infrastructure"]
AWS_SM["<b>AWS Secrets Manager</b><br/>Enterprise Cloud Authority"]
end
subgraph OCP_Fleet["OpenShift 4.20+ Multi-Cluster"]
ESO1["<b>External Secrets Operator</b><br/>Cluster Dev (IRSA)"]
ESO2["<b>External Secrets Operator</b><br/>Cluster Stage (IRSA)"]
ESO3["<b>External Secrets Operator</b><br/>Cluster Prod (IRSA)"]
KC["<b>Keycloak Instances</b>"]
end
AWS_SM ===>|AWS IRSA Auth| ESO1
AWS_SM ===>|AWS IRSA Auth| ESO2
AWS_SM ===>|AWS IRSA Auth| ESO3
ESO1 & ESO2 & ESO3 -->|Reconcile Secrets| KC
style AWS_Cloud fill:#fef3c7,stroke:#d97706,stroke-width:2px,color:#0f172a;
style OCP_Fleet fill:#f0fdf4,stroke:#16a34a,stroke-width:2px,color:#0f172a;
style AWS_SM fill:#fed7aa,stroke:#ea580c,stroke-width:2px,color:#0f172a;
Configured in gitops/base/networking/egress-firewall.yaml to restrict outbound traffic from Keycloak pods:
- Allowed:
login.microsoftonline.com,graph.microsoft.com, AWS STS, AWS Secrets Manager, and on-premises LDAPS CIDR. - Blocked: All other outbound internet ranges (
0.0.0.0/0) are denied at the kernel level.
Start the complete offline development and testing stack locally via Docker Compose:
# 1-Click Startup Script
./scripts/local-sandbox-up.shStack includes:
- Keycloak 24/26 on
http://localhost:8080(admin/admin). - OpenLDAP on
ldap://localhost:389with pre-seeded AD users (john.doe,jane.admin). - PostgreSQL 16 on port
5432. - Node.js API Gateway on
http://localhost:8085. - Angular 18+ SPA on
http://localhost:4200.
| Command | Description |
|---|---|
make lint |
Runs bash -n syntax validation on all shell scripts |
make validate |
Validates all Kustomize overlays across all cluster environments |
make test-oauth2 |
Executes end-to-end OAuth 2.1 / OIDC protocol test suite |
make day0 |
Provisions Day 0 prerequisites, TLS certs, and NetworkPolicies |
make day1-dev |
Deploys Operator and Keycloak to Dev cluster |
make day1-prod |
Deploys Operator and Keycloak HA to Prod cluster |
make day2 |
Opens Day 2 interactive maintenance and operations CLI |
make local-up |
Starts local Docker Compose offline development stack |
make local-down |
Stops local Docker Compose offline stack |
- ServiceMonitor:
gitops/base/monitoring/servicemonitor.yaml - Grafana Dashboard:
monitoring/dashboards/keycloak-quarkus-dashboard.json - Prometheus SLO Rules:
monitoring/alerts/keycloak-prometheus-alerts.yaml
Detailed guide available in docs/DISASTER_RECOVERY_CROSS_SITE.md:
- Active-Active vs Active-Passive topologies.
- JGroups RELAY2 Infinispan session mirroring.
- AWS Route 53 Application Recovery Controller (ARC) automated DNS routing.
./scripts/validate-oauth2-flows.shArchitectural deep dives, video walkthroughs, and technical shorts for keycloak-openshift-2026, Red Hat Build of Keycloak (RHBK), and hybrid enterprise identity federation on OpenShift 4.20+ are hosted on the Nubenetes YouTube Channel (@nubenetes).
π Full-Length Technical Deep Dives (Architecture Masterclasses)
- π Direct Link: https://www.youtube.com/watch?v=vyxP8hPBdjA
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 9:05
- π·οΈ Engineering Domain: Declarative Operator Lifecycle, Kustomize Multi-Cluster Overlays & ArgoCD GitOps
- π Technical Overview: Architectural blueprint for deploying Red Hat Build of Keycloak (RHBK) on Red Hat OpenShift 4.20+ using declarative GitOps and enterprise identity standards. Explains the Quarkus-based Keycloak Operator evolution, Kustomize multi-cluster promotion across DEV, STAGE, and PROD, declarative KeycloakRealmImport custom resources, zero-trust secrets injection via External Secrets Operator (ESO) syncing HashiCorp Vault and AWS Secrets Manager, and automated Jenkins CI/CD integration.
- π οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
- π Direct Link: https://www.youtube.com/watch?v=FPEfUxEKIz8
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 9:10
- π·οΈ Engineering Domain: OAuth 2.1 Compliance, PKCE (RFC 7636), BFF Gateway Pattern & Token Exchange
- π Technical Overview: Deconstructs modern OAuth 2.1 and OpenID Connect (OIDC) security standards for enterprise cloud architectures on OpenShift 4.20+. Explains why OAuth 2.1 deprecates legacy Implicit Grant and Resource Owner Password Credentials (ROPC) flows, and demonstrates production implementations of Authorization Code Flow with PKCE for Angular 18+ SPAs, the Backend-For-Frontend (BFF) proxy pattern, Private Key JWT (RFC 7523) for machine-to-machine integrations, and RFC 8693 Token Exchange for downstream microservices.
- π οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
- π Direct Link: https://www.youtube.com/watch?v=jWZYf-V1yRk
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 8:49
- π·οΈ Engineering Domain: Hybrid Identity Brokering, LDAPS User Federation & OpenShift Egress Isolation
- π Technical Overview: Details hybrid enterprise identity architecture with Red Hat Build of Keycloak on OpenShift 4.20+. Covers externalizing workforce authentication to Microsoft Entra ID (Azure AD) via OIDC Identity Brokering, syncing on-premises corporate directories via TLS-encrypted LDAPS User Federation (port 636), Just-In-Time (JIT) provisioning, and hardening pod network boundaries with OpenShift EgressFirewall rules to prevent unauthorized lateral network movement.
- π οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
- π Direct Link: https://www.youtube.com/watch?v=z2O2ET0YCKA
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 9:33
- π·οΈ Engineering Domain: Multi-Region Disaster Recovery, Infinispan WAN Mirroring & Aurora Multi-AZ
- π Technical Overview: High Availability and Disaster Recovery (HA/DR) architecture for Red Hat Build of Keycloak across multi-region OpenShift clusters on AWS. Explains Amazon Aurora PostgreSQL Multi-AZ global clusters, distributed session caching with embedded Infinispan and JGroups RELAY2 cross-site WAN replication, split-brain avoidance strategies, global traffic management using AWS Route 53 Application Recovery Controller (ARC), and automated backup lifecycle procedures.
- π οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
π Technical Shorts Matrix & Architecture Breakdowns
| # | Short Title | Architectural Domain & Focus | Duration | Action |
|---|---|---|---|---|
| 01 | The Ultimate Keycloak GitOps Blueprint | Declarative IAM Operations Replacing error-prone click-ops with version-controlled GitOps & ArgoCD |
1:23 |
|
| 02 | How OpenShift EgressFirewalls Isolate Pods | Zero-Trust Network Security Restricting IAM pod egress to Entra ID and LDAPS while blocking lateral threats |
1:11 |
|
| 03 | How to Run the Keycloak Offline Sandbox | Developer Experience & Local Testing 1-command local Docker Compose sandbox with Quarkus Keycloak & Mock OpenLDAP |
1:19 |
- π Direct Link: https://www.youtube.com/shorts/lHxEGX4E0MM
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 1:23
- π·οΈ Engineering Domain: Declarative Operator IAM, Kustomize Multi-Cluster Overlays & ArgoCD
- π Technical Overview: Explains why managing enterprise IAM through manual UI click-ops is dangerous at scale. Details how declarative GitOps with the Keycloak Operator, Kustomize overlays, and ArgoCD automates configuration across DEV, STAGE, and PROD with pull-request review and instant rollback capabilities.
- π οΈ Direct Links: Watch Short | Edit in YouTube Studio
- π Direct Link: https://www.youtube.com/shorts/rNbtLUKBcuc
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 1:11
- π·οΈ Engineering Domain: Zero-Trust Egress Filtering, Network Security & Lateral Movement Prevention
- π Technical Overview: Demonstrates how OpenShift EgressFirewalls lock down identity pods. Shows how outbound traffic is strictly restricted to verified Microsoft Entra ID endpoints and LDAPS domain controllers (port 636), while all other unauthorized lateral and egress requests are dropped at the SDN kernel layer.
- π οΈ Direct Links: Watch Short | Edit in YouTube Studio
- π Direct Link: https://www.youtube.com/shorts/t2AJe5Mrs5c
- π Origin Language: English (Subtitles in 20+ languages)
- β±οΈ Duration: 1:19
- π·οΈ Engineering Domain: Local Developer Sandbox, Docker Compose, Quarkus Engine & Mock OpenLDAP
- π Technical Overview: Shows how developers can spin up a complete local offline Keycloak testing stack in under 30 seconds using make sandbox-up. Covers pre-seeded corporate users, roles, and OAuth 2.1 client configurations for offline frontend and microservice authentication development.
- π οΈ Direct Links: Watch Short | Edit in YouTube Studio
- Red Hat Build of Keycloak Documentation
- Red Hat OpenShift 4.20 Release Notes & Security Guides
- OpenShift GitOps (ArgoCD) Documentation
- Keycloak Official Documentation (Quarkus Server)
- Keycloak High Availability & Cross-Site Guide
- Keycloak Securing Applications and Services Guide
- IETF RFC 7636: Proof Key for Code Exchange (PKCE) by OAuth Public Clients
- IETF RFC 7523: JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication
- IETF RFC 8693: OAuth 2.0 Token Exchange
- IETF RFC 8705: OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens
- IETF RFC 9449: OAuth 2.0 Demonstrating Proof-of-Possession (DPoP)
- OAuth 2.1 Draft Specification (IETF OAuth WG)
- OAuth 2.0 Security Best Current Practice (BCP)