Skip to content

Latest commit

Β 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Red Hat Build of Keycloak (RHBK) on OpenShift 4.20+ GitOps Architecture

Enterprise Multi-Cluster Identity & Access Management with Microsoft Entra ID, Active Directory & OAuth 2.1

Keycloak Official Project

RHBK Keycloak OpenShift Kubernetes AWS License

OAuth 2.1 OIDC PKCE RFC 7523 RFC 8693 mTLS

Microsoft Entra ID Active Directory ESO Vault AWS Secrets Manager

ArgoCD Kustomize Jenkins CI Status Backstage Angular Quarkus

PostgreSQL Infinispan Prometheus Grafana AI Generated


Note

Generative AI Accelerator Disclaimer This repository and all associated architectures, manifests, configurations, and scripts were generated with Gemini 3.7 Flash High (Antigravity Agent). This content is intended as an illustrative, architectural reference and accelerator baseline. It has not been executed or validated in a live customer production environment. Platform engineering teams should review, profile, harden, and adapt these artifacts to their specific security policies, network topologies, and compliance mandates.


πŸ—ΊοΈ Quick Navigation Map

This enterprise repository provides an end-to-end, production-ready Red Hat Build of Keycloak (RHBK) GitOps architecture for Red Hat OpenShift 4.20+ on AWS. It integrates hybrid identity with Microsoft Entra ID (Azure AD) and Active Directory, strict OAuth 2.1 compliance (PKCE, Private Key JWT, Token Exchange), and multi-cluster ArgoCD deployment across DEV, STAGE, and PROD. Use this map to navigate the repository architecture and multimedia guides:

🧭 Repository Architecture Blueprint

keycloak-openshift-2026/                  # πŸš€ Enterprise RHBK OpenShift GitOps Platform
β”œβ”€β”€ πŸ“ apps/                             # Enterprise Client Workloads & Integrations
β”‚   β”œβ”€β”€ πŸ“ angular-spa/                  # Angular 18+ SPA (PKCE & BFF Gateway Pattern)
β”‚   β”œβ”€β”€ πŸ“ argocd/                       # OpenShift GitOps ArgoCD OIDC configuration
β”‚   β”œβ”€β”€ πŸ“ backstage-idp/                # Backstage Developer Portal IDP auth provider
β”‚   └── πŸ“ microservices/                # Quarkus & Node.js Resource Servers (JWT & Token Exchange)
β”œβ”€β”€ πŸ“ ci-cd/                            # Continuous Integration & Delivery
β”‚   └── πŸ“ jenkins/                      # Jenkins Helm deployment, OIDC auth & ArgoCD sync jobs
β”œβ”€β”€ πŸ“ gitops/                           # Declarative Kustomize Overlays & ArgoCD ApplicationSets
β”‚   β”œβ”€β”€ πŸ“„ root-application.yaml         # ArgoCD Root App-of-Apps master manifest
β”‚   β”œβ”€β”€ πŸ“ base/                         # Base Keycloak Operator and Keycloak CR templates
β”‚   └── πŸ“ clusters/                     # Multi-cluster overlays (Dev, Stage, Prod HA, Hub)
β”œβ”€β”€ πŸ“ local-dev/                        # Offline Developer Testing Sandbox Stack
β”‚   β”œβ”€β”€ πŸ“„ docker-compose.yml            # Local Keycloak (Quarkus), Postgres 16 & Mock OpenLDAP
β”‚   └── πŸ“ mock-ad-ldap/                 # Pre-seeded enterprise LDAPS directory container
β”œβ”€β”€ πŸ“ monitoring/                       # Observability & Alerting Suite
β”‚   β”œβ”€β”€ πŸ“ alerts/                       # PrometheusRule alerting definitions (SLAs, error spikes)
β”‚   └── πŸ“ dashboards/                   # Production Grafana dashboards (JVM, logins, cache hits)
β”œβ”€β”€ πŸ“ scripts/                          # Automated Day 0, Day 1, and Day 2 Lifecycle Runbooks
β”‚   β”œβ”€β”€ πŸ“„ day0-prereqs.sh               # TLS certificates, secrets & network prerequisites
β”‚   β”œβ”€β”€ πŸ“„ day1-deploy-operator-and-keycloak.sh # Automated Operator provisioning
β”‚   β”œβ”€β”€ πŸ“„ day1-configure-entra-federation.sh   # Microsoft Entra ID OIDC brokering setup
β”‚   β”œβ”€β”€ πŸ“„ day2-operations-suite.sh      # Health probing, realm backups & scaling operations
β”‚   └── πŸ“„ local-sandbox-up.sh           # 1-click local Docker Compose launch script
└── πŸ“ docs/                             # Exhaustive Engineering Architecture & Runbooks
    β”œβ”€β”€ πŸ“„ ARCHITECTURE.md               # End-to-end multi-cluster topology breakdown
    β”œβ”€β”€ πŸ“„ ENTRA_AD_FEDERATION_GUIDE.md   # Hybrid identity & LDAPS configuration guide
    β”œβ”€β”€ πŸ“„ OAUTH2_OIDC_SECURITY_FLOWS.md # OAuth 2.1, PKCE, mTLS & RFC 8693 specifications
    └── πŸ“„ DISASTER_RECOVERY_CROSS_SITE.md # Multi-region DR & Infinispan WAN replication

🎬 AI-Generated Multimedia Series (YouTube)

This repository is accompanied by an educational video masterclass and technical shorts synthesized with Gemini NotebookLM based directly on the architecture blueprints, hybrid identity federation guides, and OAuth 2.1 specifications from this project. All videos are freely accessible on YouTube on the @nubenetes channel.

Note

Multilingual Learning Experience:
Content features native spoken audio in English πŸ‡ΊπŸ‡Έ, with automated YouTube closed captions (CC) translated into Spanish πŸ‡ͺπŸ‡Έ and 20+ languages for global engineering teams.

πŸ“½οΈ Full-Length Technical Deep Dives (Architecture Masterclasses)

# Video Guide Title Engineering Domain & Core Architecture Duration Direct Link
01 Keycloak GitOps Blueprint Declarative Operator Lifecycle & ArgoCD Overlays
Quarkus engine, Kustomize multi-cluster promotion & ESO Vault sync
9:05 ▢️ Watch
02 Modern OAuth 2.1 & OIDC OAuth 2.1 Compliance & Token Security
Authorization Code Flow with PKCE, BFF Gateway pattern & RFC 8693 Token Exchange
9:10 ▢️ Watch
03 Keycloak Hybrid Identity Hybrid Identity Federation & Egress Isolation
Microsoft Entra ID OIDC brokering, on-prem LDAPS federation & EgressFirewall
8:49 ▢️ Watch
04 RHBK Multi-Region DR High Availability & Multi-Region DR
Aurora Multi-AZ, embedded Infinispan JGroups WAN mirroring & Route 53 ARC
9:33 ▢️ Watch

⚑ Video Shorts Matrix

# Short Title Architectural Domain & Focus Duration Action
01 The Ultimate Keycloak GitOps Blueprint Declarative IAM Operations
Replacing error-prone click-ops with version-controlled GitOps & ArgoCD
1:23 ▢️ Watch
02 How OpenShift EgressFirewalls Isolate Pods Zero-Trust Network Security
Restricting IAM pod egress to Entra ID and LDAPS while blocking lateral threats
1:11 ▢️ Watch
03 How to Run the Keycloak Offline Sandbox Developer Experience & Local Testing
1-command local Docker Compose sandbox with Quarkus Keycloak & Mock OpenLDAP
1:19 ▢️ Watch

For complete technical summaries, topic breakdowns, and direct studio links, see Section 16: Video Walkthroughs & Architecture References.


Table of Contents


1. Executive Summary & Architecture Overview

Modern enterprise identity architectures require a balance between centralized governance and distributed high availability. This repository provides a complete, declarative GitOps foundation for deploying Red Hat Build of Keycloak (RHBK) on OpenShift Container Platform (OCP) 4.20+ hosted on Amazon Web Services (AWS).

Key Architectural Pillars

  1. Red Hat Build of Keycloak Operator (Quarkus Engine): Replaces legacy WildFly-based RHSSO 7.x with modern Quarkus-powered Keycloak (v24/v26 stream) for fast startup, low memory footprint (~1.5GB/instance), and full declarative reconciliation.
  2. Hybrid Corporate Identity: Bridges cloud-native Microsoft Entra ID (Azure AD) and on-premises Active Directory via OIDC Identity Brokering and LDAPS User Federation with bidirectional group mappings.
  3. Strict OAuth 2.1 Compliance: Deprecates insecure legacy flows (Implicit Grant and Resource Owner Password Credentials) and enforces Authorization Code Flow with PKCE (RFC 7636), Backend-For-Frontend (BFF) proxying, Private Key JWT (RFC 7523), and Token Exchange (RFC 8693).
  4. GitOps-First Automation: Powered by ArgoCD ApplicationSets and Kustomize overlays for automated multi-cluster rollout across Development (cluster-alpha-dev), Staging (cluster-bravo-stage), Production HA (cluster-charlie-prod), and an optional Central Management Hub (cluster-hub-central).
  5. Continuous Integration & Secrets Management: Jenkins deployed via official Helm chart on OpenShift DEV, federated with Keycloak OIDC, triggering ArgoCD GitOps syncs, with secrets synchronized via External Secrets Operator (ESO) from AWS Secrets Manager and HashiCorp Vault.

2. Multi-Cluster Topology (3 AWS OCP Clusters + Central Hub)

graph TD
    subgraph CorpID["Corporate Identity Layer (Hybrid)"]
        Entra["<b>Microsoft Entra ID</b><br/>Cloud Users & Groups<br/>Conditional Access & MFA<br/>App Registrations"]
        AD["<b>Active Directory</b><br/>On-Premises LDAPS<br/>Domain User Accounts"]
        EntraSync["<b>Entra Cloud Sync</b><br/>Hybrid DirSync Engine"]
        AD <-->|Password Hash Sync| EntraSync
        EntraSync <-->|OIDC Provisioning| Entra
    end

    subgraph HubCluster["(Optional) Central Identity Hub (OCP)"]
        HubKC["<b>Parent Keycloak (RHBK)</b><br/>Central Broker & Policy Engine"]
        HubDB[("<b>AWS Aurora DB</b><br/>Global PostgreSQL")]
        HubKC <--> HubDB
    end

    subgraph SpokeDev["Cluster 1: Alpha (Dev)"]
        KC1["<b>Keycloak Dev</b><br/>1 Replica"]
        Apps1["<b>Dev Workloads</b><br/>ArgoCD & Backstage"]
        KC1 <--> Apps1
    end

    subgraph SpokeStage["Cluster 2: Bravo (Stage)"]
        KC2["<b>Keycloak Stage</b><br/>2 Replicas (HA)"]
        Apps2["<b>Stage Workloads</b><br/>Microservices & APIs"]
        KC2 <--> Apps2
    end

    subgraph SpokeProd["Cluster 3: Charlie (Prod HA)"]
        KC3["<b>Keycloak Prod HA</b><br/>3+ Replicas (Multi-AZ)"]
        Apps3["<b>Production Apps</b><br/>Angular SPA & APIs"]
        KC3 <--> Apps3
    end

    Entra -->|OIDC Federation| HubKC
    AD -->|LDAPS Sync| HubKC
    Entra -.->|Direct OIDC| KC1
    Entra -.->|Direct OIDC| KC2
    Entra -.->|Direct OIDC| KC3
    HubKC -->|Hub Delegation| KC1
    HubKC -->|Hub Delegation| KC2
    HubKC -->|Hub Delegation| KC3

    classDef corp fill:#e0f2fe,stroke:#0284c7,stroke-width:2px,color:#0f172a;
    classDef hub fill:#fef3c7,stroke:#d97706,stroke-width:2px,color:#0f172a;
    classDef spoke fill:#f0fdf4,stroke:#16a34a,stroke-width:2px,color:#0f172a;

    class Entra,AD,EntraSync corp;
    class HubKC,HubDB hub;
    class KC1,Apps1,KC2,Apps2,KC3,Apps3 spoke;
Loading

3. Hybrid Identity Architecture: Microsoft Entra ID & Active Directory

Enterprise organizations typically host core user identities in Microsoft Entra ID (Azure AD) and on-premises Active Directory Domain Services (AD DS). Keycloak acts as the OpenShift-native Identity Provider (IdP) Broker and Token Authority.

sequenceDiagram
    autonumber
    actor Dev as Enterprise Developer
    participant ClientApp as OpenShift App<br/>(ArgoCD / Backstage / SPA)
    participant Keycloak as Red Hat Build<br/>of Keycloak (RHBK)
    participant Entra as Microsoft Entra ID<br/>(Azure AD)
    participant AD as On-Premises AD<br/>(LDAPS)

    Dev->>ClientApp: Access Application
    ClientApp->>Keycloak: Initiate OAuth 2.1 Flow<br/>(PKCE S256 Challenge)
    Keycloak->>Entra: Federate via OpenID Connect<br/>(Corporate Azure SSO)
    Entra->>Entra: Enforce Corporate MFA &<br/>Conditional Access Policies
    Entra-->>Keycloak: Return ID Token<br/>(UPN, email, Entra groups)
    opt Active Directory LDAP Query
        Keycloak->>AD: Query LDAPS for on-prem<br/>attributes & legacy groups
        AD-->>Keycloak: Return Directory Attributes
    end
    Keycloak->>Keycloak: Apply Protocol Mappers<br/>(Map Entra/AD groups to Roles)
    Keycloak-->>ClientApp: Issue Signed JWTs<br/>(Access Token & ID Token)
    ClientApp->>ClientApp: Validate Claims & Roles
    ClientApp-->>Dev: Grant Authorized Access
Loading

4. Modern OAuth 2.1 & OpenID Connect Security Paradigm

OAuth 2.1 consolidates security best practices developed over a decade of OAuth 2.0 deployments.

graph TD
    subgraph Prohibited["❌ Prohibited Legacy Flows"]
        Imp["<b>Implicit Grant</b><br/>Tokens exposed in URL / history"]
        ROPC["<b>Password Grant (ROPC)</b><br/>Direct credentials harvesting risk"]
    end

    subgraph Modern["βœ… Enforced Modern OAuth 2.1 & OIDC Flows"]
        PKCE["<b>Auth Code + PKCE</b><br/>RFC 7636 (S256)<br/>Mandatory for UI apps"]
        BFF["<b>BFF Proxy Pattern</b><br/>HttpOnly secure cookies<br/>Zero browser token exposure"]
        PrivKey["<b>Private Key JWT</b><br/>RFC 7523 Asymmetric Auth<br/>For confidential services"]
        TokEx["<b>Token Exchange</b><br/>RFC 8693 Delegation<br/>Scoped audience tokens"]
    end

    style Prohibited fill:#fee2e2,stroke:#b91c1c,stroke-width:2px,color:#7f1d1d;
    style Modern fill:#dcfce7,stroke:#15803d,stroke-width:2px,color:#14532d;
Loading

5. Comparative Matrices & Architectural Decision Records

5.1 Identity Integration Patterns Matrix

Pattern Mechanism Use Case Latency Resilience Complexity
OIDC Identity Brokering Keycloak -> Microsoft Entra ID OIDC Cloud-first users, Microsoft 365, Azure Conditional Access Low (<150ms) Dependent on Entra ID availability Low (standard OIDC)
LDAPS User Federation Keycloak -> On-Prem AD (LDAPS:636) Legacy on-prem AD users, Kerberos ticket exchange Medium (<300ms) Local caching reduces WAN reliance Medium (LDAP schema mappers)
Hybrid Hub-Spoke Spoke Keycloak -> Parent Hub Keycloak -> Entra ID Multi-cluster enterprise governance with regional failover Low-Medium High (regional offline caches) High (multi-tier federation)

5.2 Client Types & OAuth 2.1 Security Profiles Matrix

Client Application Client Type Authentication Method Grant Type PKCE Method Token Lifespan
ArgoCD GitOps Confidential client_secret / private_key_jwt Authorization Code S256 15 mins (Refreshable)
Backstage IDP Confidential client_secret + Service Account Authorization Code S256 30 mins
Angular 18+ SPA Public / BFF none (with PKCE) or BFF Cookie Authorization Code S256 5 mins (Short-lived)
API Gateway Confidential private_key_jwt (RFC 7523) Client Credentials N/A (Server-to-Server) 10 mins
Quarkus Microservice Bearer-only / Service client_secret / mTLS Token Exchange (RFC 8693) N/A 5 mins (Scoped audience)

5.3 Cluster Environment Matrix

Parameter Dev Cluster (cluster-alpha-dev) Stage Cluster (cluster-bravo-stage) Prod HA Cluster (cluster-charlie-prod) Hub Cluster (cluster-hub-central)
Replicas 1 2 3 to 10 (HPA enabled) 3 (Multi-AZ)
CPU / Memory Req 500m / 1024Mi 1000m / 1536Mi 2000m / 2048Mi 2000m / 2048Mi
CPU / Memory Limit 1000m / 2048Mi 2000m / 3072Mi 4000m / 4096Mi 4000m / 4096Mi
Database Tier PostgreSQL Single-Pod Crunchy PGO HA (2 instances) AWS Aurora PostgreSQL Multi-AZ AWS Aurora Multi-Region
Hostname keycloak-dev.apps.cluster-alpha... keycloak-stage.apps.cluster-bravo... sso.enterprise.example.com sso-hub.enterprise.example.com

5.4 Lifecycle Operations Matrix (Day 0 to Decommissioning)

Phase Scope Primary Automation Tool Key Deliverables
Day 0 Prerequisites & Infra scripts/day0-prereqs.sh Namespace, TLS certs, DB secrets, NetworkPolicies
Day 1 Provisioning & IdP Config scripts/day1-*.sh + GitOps Operator CSV, Keycloak CR, Declarative Realm Imports
Day 2 Maintenance & Ops scripts/day2-operations-suite.sh DB backups, Realm exports, Prometheus metrics, HPA, Upgrades
Decom Teardown & Archival scripts/decommission-cluster.sh Final DB/Realm snapshot, route removal, resource shredding

5.5 Secrets Management: AWS Secrets Manager vs. HashiCorp Vault Matrix

Feature AWS Secrets Manager + ESO (Recommended) HashiCorp Vault Hub-Spoke (PR) In-Cluster Vault + ESO
Multi-Cluster Sync Native AWS IAM / STS across clusters Requires Vault Enterprise license ESO pulls from central AWS Secrets
Operational Effort Zero state (Managed AWS service) High (Consensus, unsealing, WAN links) Medium (Standalone instance)
Auth Mechanism AWS IRSA (IAM Roles for Service Accounts) Token / AppRole / Kubernetes Auth Kubernetes ServiceAccount Auth
Best For AWS OpenShift Clusters (ROSA / IPI) Heterogeneous multi-cloud enterprises Local Transit encryption & dynamic DB

6. Step-by-Step Operations Guide

6.1 Day 0: Infrastructure Prerequisites, TLS & Network Policies

Execute Day 0 preparation on the target OpenShift cluster:

./scripts/day0-prereqs.sh

6.2 Day 1: GitOps Operator Provisioning & Declarative Realms

Deploy the Red Hat Build of Keycloak Operator and provision the instance:

# For Dev Cluster
./scripts/day1-deploy-operator-and-keycloak.sh cluster-alpha-dev

# For Production Cluster
./scripts/day1-deploy-operator-and-keycloak.sh cluster-charlie-prod

Next, configure Microsoft Entra ID and Active Directory federation:

ENTRA_TENANT_ID="<your-tenant-uuid>" \
ENTRA_CLIENT_ID="<your-app-client-uuid>" \
ENTRA_CLIENT_SECRET="<your-client-secret>" \
./scripts/day1-configure-entra-federation.sh

Finally, register sample applications (ArgoCD, Backstage, Angular SPA, Microservices):

./scripts/day1-register-sample-apps.sh

6.3 Day 2: Maintenance, Backups, Autoscaling & Observability

Launch the interactive Day 2 operations suite:

./scripts/day2-operations-suite.sh

6.4 Decommissioning: Graceful Teardown & Secret Shredding

When decommissioning a cluster or tearing down a testing environment:

./scripts/decommission-cluster.sh

7. Sample Applications & Enterprise Workload Integrations


8. Jenkins CI/CD on OpenShift DEV (Helm Chart + OIDC + ArgoCD)

The ci-cd/jenkins/ module configures Jenkins on OpenShift DEV using the official Helm chart:

sequenceDiagram
    autonumber
    actor Dev as Platform Engineer
    participant Jenkins as Jenkins (OCP DEV)
    participant KC as Keycloak (RHBK)
    participant Argo as ArgoCD (openshift-gitops)

    Dev->>KC: Log in via Entra ID SSO
    KC-->>Jenkins: Authorize OIDC session (/Admins group)
    Dev->>Jenkins: Trigger CI Pipeline (Jenkinsfile)
    Note over Jenkins: Lint scripts & validate Kustomize
    Jenkins->>Argo: Dispatch Application Sync (/api/v1/applications/sync)
    Argo-->>Dev: Declarative GitOps deployment reconciled
Loading

9. Secrets Management Architecture (AWS Secrets Manager + HashiCorp Vault + ESO)

Detailed architecture guide available in docs/SECRETS_MANAGEMENT_VAULT_AWS.md.

graph TD
    subgraph AWS_Cloud["AWS Cloud Infrastructure"]
        AWS_SM["<b>AWS Secrets Manager</b><br/>Enterprise Cloud Authority"]
    end

    subgraph OCP_Fleet["OpenShift 4.20+ Multi-Cluster"]
        ESO1["<b>External Secrets Operator</b><br/>Cluster Dev (IRSA)"]
        ESO2["<b>External Secrets Operator</b><br/>Cluster Stage (IRSA)"]
        ESO3["<b>External Secrets Operator</b><br/>Cluster Prod (IRSA)"]
        KC["<b>Keycloak Instances</b>"]
    end

    AWS_SM ===>|AWS IRSA Auth| ESO1
    AWS_SM ===>|AWS IRSA Auth| ESO2
    AWS_SM ===>|AWS IRSA Auth| ESO3
    ESO1 & ESO2 & ESO3 -->|Reconcile Secrets| KC

    style AWS_Cloud fill:#fef3c7,stroke:#d97706,stroke-width:2px,color:#0f172a;
    style OCP_Fleet fill:#f0fdf4,stroke:#16a34a,stroke-width:2px,color:#0f172a;
    style AWS_SM fill:#fed7aa,stroke:#ea580c,stroke-width:2px,color:#0f172a;
Loading

10. Zero-Trust Security: OpenShift EgressFirewall

Configured in gitops/base/networking/egress-firewall.yaml to restrict outbound traffic from Keycloak pods:

  • Allowed: login.microsoftonline.com, graph.microsoft.com, AWS STS, AWS Secrets Manager, and on-premises LDAPS CIDR.
  • Blocked: All other outbound internet ranges (0.0.0.0/0) are denied at the kernel level.

11. Local Sandbox Environment (Offline Testing Stack)

Start the complete offline development and testing stack locally via Docker Compose:

# 1-Click Startup Script
./scripts/local-sandbox-up.sh

Stack includes:

  • Keycloak 24/26 on http://localhost:8080 (admin/admin).
  • OpenLDAP on ldap://localhost:389 with pre-seeded AD users (john.doe, jane.admin).
  • PostgreSQL 16 on port 5432.
  • Node.js API Gateway on http://localhost:8085.
  • Angular 18+ SPA on http://localhost:4200.

12. Developer Makefile Reference

Command Description
make lint Runs bash -n syntax validation on all shell scripts
make validate Validates all Kustomize overlays across all cluster environments
make test-oauth2 Executes end-to-end OAuth 2.1 / OIDC protocol test suite
make day0 Provisions Day 0 prerequisites, TLS certs, and NetworkPolicies
make day1-dev Deploys Operator and Keycloak to Dev cluster
make day1-prod Deploys Operator and Keycloak HA to Prod cluster
make day2 Opens Day 2 interactive maintenance and operations CLI
make local-up Starts local Docker Compose offline development stack
make local-down Stops local Docker Compose offline stack

13. Observability, Prometheus Metrics & Grafana Dashboards


14. Disaster Recovery & Multi-Region Cross-Site Replication

Detailed guide available in docs/DISASTER_RECOVERY_CROSS_SITE.md:

  • Active-Active vs Active-Passive topologies.
  • JGroups RELAY2 Infinispan session mirroring.
  • AWS Route 53 Application Recovery Controller (ARC) automated DNS routing.

15. Verification & End-to-End Validation

./scripts/validate-oauth2-flows.sh

16. Video Walkthroughs & Architecture References (YouTube)

Architectural deep dives, video walkthroughs, and technical shorts for keycloak-openshift-2026, Red Hat Build of Keycloak (RHBK), and hybrid enterprise identity federation on OpenShift 4.20+ are hosted on the Nubenetes YouTube Channel (@nubenetes).

πŸ“‚ Full-Length Technical Deep Dives (Architecture Masterclasses)
1. Keycloak GitOps Blueprint: Enterprise RHBK on OpenShift 4.20
  • πŸ”— Direct Link: https://www.youtube.com/watch?v=vyxP8hPBdjA
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 9:05
  • 🏷️ Engineering Domain: Declarative Operator Lifecycle, Kustomize Multi-Cluster Overlays & ArgoCD GitOps
  • πŸ“ Technical Overview: Architectural blueprint for deploying Red Hat Build of Keycloak (RHBK) on Red Hat OpenShift 4.20+ using declarative GitOps and enterprise identity standards. Explains the Quarkus-based Keycloak Operator evolution, Kustomize multi-cluster promotion across DEV, STAGE, and PROD, declarative KeycloakRealmImport custom resources, zero-trust secrets injection via External Secrets Operator (ESO) syncing HashiCorp Vault and AWS Secrets Manager, and automated Jenkins CI/CD integration.
  • πŸ› οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
2. Modern OAuth 2.1 & OIDC Security Architecture for Enterprise OpenShift
  • πŸ”— Direct Link: https://www.youtube.com/watch?v=FPEfUxEKIz8
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 9:10
  • 🏷️ Engineering Domain: OAuth 2.1 Compliance, PKCE (RFC 7636), BFF Gateway Pattern & Token Exchange
  • πŸ“ Technical Overview: Deconstructs modern OAuth 2.1 and OpenID Connect (OIDC) security standards for enterprise cloud architectures on OpenShift 4.20+. Explains why OAuth 2.1 deprecates legacy Implicit Grant and Resource Owner Password Credentials (ROPC) flows, and demonstrates production implementations of Authorization Code Flow with PKCE for Angular 18+ SPAs, the Backend-For-Frontend (BFF) proxy pattern, Private Key JWT (RFC 7523) for machine-to-machine integrations, and RFC 8693 Token Exchange for downstream microservices.
  • πŸ› οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
3. Keycloak Hybrid Identity: Microsoft Entra ID & Active Directory on OCP
  • πŸ”— Direct Link: https://www.youtube.com/watch?v=jWZYf-V1yRk
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 8:49
  • 🏷️ Engineering Domain: Hybrid Identity Brokering, LDAPS User Federation & OpenShift Egress Isolation
  • πŸ“ Technical Overview: Details hybrid enterprise identity architecture with Red Hat Build of Keycloak on OpenShift 4.20+. Covers externalizing workforce authentication to Microsoft Entra ID (Azure AD) via OIDC Identity Brokering, syncing on-premises corporate directories via TLS-encrypted LDAPS User Federation (port 636), Just-In-Time (JIT) provisioning, and hardening pod network boundaries with OpenShift EgressFirewall rules to prevent unauthorized lateral network movement.
  • πŸ› οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
4. RHBK Multi-Region DR: High Availability & Cross-Site Replication on OCP
  • πŸ”— Direct Link: https://www.youtube.com/watch?v=z2O2ET0YCKA
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 9:33
  • 🏷️ Engineering Domain: Multi-Region Disaster Recovery, Infinispan WAN Mirroring & Aurora Multi-AZ
  • πŸ“ Technical Overview: High Availability and Disaster Recovery (HA/DR) architecture for Red Hat Build of Keycloak across multi-region OpenShift clusters on AWS. Explains Amazon Aurora PostgreSQL Multi-AZ global clusters, distributed session caching with embedded Infinispan and JGroups RELAY2 cross-site WAN replication, split-brain avoidance strategies, global traffic management using AWS Route 53 Application Recovery Controller (ARC), and automated backup lifecycle procedures.
  • πŸ› οΈ Direct Links: Watch on YouTube | Edit in YouTube Studio
πŸ“‚ Technical Shorts Matrix & Architecture Breakdowns

⚑ Video Shorts Matrix

# Short Title Architectural Domain & Focus Duration Action
01 The Ultimate Keycloak GitOps Blueprint Declarative IAM Operations
Replacing error-prone click-ops with version-controlled GitOps & ArgoCD
1:23 ▢️ Watch
02 How OpenShift EgressFirewalls Isolate Pods Zero-Trust Network Security
Restricting IAM pod egress to Entra ID and LDAPS while blocking lateral threats
1:11 ▢️ Watch
03 How to Run the Keycloak Offline Sandbox Developer Experience & Local Testing
1-command local Docker Compose sandbox with Quarkus Keycloak & Mock OpenLDAP
1:19 ▢️ Watch

1. The Ultimate Keycloak GitOps Blueprint
  • πŸ”— Direct Link: https://www.youtube.com/shorts/lHxEGX4E0MM
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 1:23
  • 🏷️ Engineering Domain: Declarative Operator IAM, Kustomize Multi-Cluster Overlays & ArgoCD
  • πŸ“ Technical Overview: Explains why managing enterprise IAM through manual UI click-ops is dangerous at scale. Details how declarative GitOps with the Keycloak Operator, Kustomize overlays, and ArgoCD automates configuration across DEV, STAGE, and PROD with pull-request review and instant rollback capabilities.
  • πŸ› οΈ Direct Links: Watch Short | Edit in YouTube Studio
2. How OpenShift EgressFirewalls Isolate Pods
  • πŸ”— Direct Link: https://www.youtube.com/shorts/rNbtLUKBcuc
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 1:11
  • 🏷️ Engineering Domain: Zero-Trust Egress Filtering, Network Security & Lateral Movement Prevention
  • πŸ“ Technical Overview: Demonstrates how OpenShift EgressFirewalls lock down identity pods. Shows how outbound traffic is strictly restricted to verified Microsoft Entra ID endpoints and LDAPS domain controllers (port 636), while all other unauthorized lateral and egress requests are dropped at the SDN kernel layer.
  • πŸ› οΈ Direct Links: Watch Short | Edit in YouTube Studio
3. How to Run the Keycloak Offline Sandbox
  • πŸ”— Direct Link: https://www.youtube.com/shorts/t2AJe5Mrs5c
  • 🌐 Origin Language: English (Subtitles in 20+ languages)
  • ⏱️ Duration: 1:19
  • 🏷️ Engineering Domain: Local Developer Sandbox, Docker Compose, Quarkus Engine & Mock OpenLDAP
  • πŸ“ Technical Overview: Shows how developers can spin up a complete local offline Keycloak testing stack in under 30 seconds using make sandbox-up. Covers pre-seeded corporate users, roles, and OAuth 2.1 client configurations for offline frontend and microservice authentication development.
  • πŸ› οΈ Direct Links: Watch Short | Edit in YouTube Studio

17. Up-to-Date References & Standards (2026)

Official Red Hat & OpenShift Documentation

Keycloak & Quarkus Core

OAuth 2.1 & IETF Security RFCs

Microsoft Entra ID & Active Directory

About

Enterprise GitOps architecture for Red Hat Build of Keycloak on OpenShift 4.20+ on AWS with Microsoft Entra ID & Active Directory federation, OAuth 2.1 PKCE/BFF flows, Jenkins CI/CD, External Secrets Operator, and Day 0/1/2 automation.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages