We've had a number of folks migrate from Keycloak due to some of this clunkiness, but I do know they've done some major overhauls recently (moving to Quarkus amongst other things).
It also used to be super resource intensive if you have a large number of realms (which is what Keycloak calls tenants and Cognito calls user pools). From this 2022 link, more than 100-200 can cause issues: https://github.com/keycloak/keycloak/discussions/11074
If you actually want to transport configuration across environments (DEV, QA, PROD), then you want to export realms and have it load by KC on startup or import it using the UI.
To the second sentence: I don’t know what the benefit is either but in some environments you are not able to use any cloud provider or other external service to realize the auth layer so you are stuck with things like keycloak. Hope this thread discusses some other solutions which you can self host.
Setting up basic forward auth or OIDC was super easy though.
I mentioned Ory above but you get both options - either as a managed service or run on your own infra
I have clients that definitely prefer combination of open source + owner-controlled + lower costs ;)
Keycloak looks like a big complicated monster, so I would prefer to stay away except that it looks like I will be required to have all that complexity to support all the use-cases we are looking at.
https://zitadel.com/docs/apis/saml/endpoints
https://zitadel.com/docs/guides/integrate/identity-providers...
https://zitadel.com/docs/concepts/features/selfservice#mfa--...
https://zitadel.com/docs/guides/migrate/introduction#multi-t...
https://zitadel.com/blog/zitadel-as-sso-provider-for-selfhos...
we really tried quite hard, since it was backed by CNCF, but it could just be a case of being a tad too immature for prime time.
it seems keycloak is now CNCF though
The only thing nicer in Kratos from Keycloak is the standalone self-service UI with JSON identity declaration. If someone from the Keycloak team is reading this, please, let’s have a talk about bringing that feature to Keycloak, then Keycloak will be perfect. The template approach is a bit of a hassle.
Source: deployed both stacks in production systems.
Also my experience with Keycloak in the past was that you can't do zero downtime deployment, or true configuration as code.
Very impressive ecosystem nevertheless.
Show HN: Ory Kratos https://news.ycombinator.com/item?id=31679811
Most HN comments are still relevant
I do recall the gossip protocol presenting problems back then, but now I believe the helm chart just works.
IIRC, if you're using an external identity provider, and you want clustering, you can just deploy Keycloak containers and load balance between them. You can then load a shared cache if you want (or need).
My memory is fuzzy right now, but although it isn't the leanest solution, I don't remember it as terrible. Ours wasn't a very custom solution anyway, we just hit an LDAP in the back and that was all.
Configuration sucked, but that's because Keycloak can do an awful lot.