Pretty happy with this setup, though it has less features than Keycloak, it's easier to administrate from code.
[1] https://github.com/lldap/lldap [2] https://www.authelia.com/
Pretty happy with this setup, though it has less features than Keycloak, it's easier to administrate from code.
[1] https://github.com/lldap/lldap [2] https://www.authelia.com/
edit: BTW authelia looks very promising. Thank you for the link! The bus factor seems a bit low for such a mission critical application, at least when evaluating it as an alternative for production. But I really like how open the core team is about that.
You can apparently build an "optimized" image[1] so it doesn't do it at runtime, but I didn't want to build a custom image, and I felt like the KeyCloak philosophy didn't align with my own.
In general I found myself avoiding Java applications because of their memory footprint.
[1] https://www.keycloak.org/server/containers#_creating_a_custo...
I can only assume it's a cultural thing since reflection and abstraction is used so much.
Rust apps are always nice since they are generally <20MB or something.
However, it's a different story when picking the solution for my day job, where RAM is abundant, but developer time is in short supply.
From their system info page: https://door.casdoor.com/sysinfo, it only consumes about 10MB memory and with no less features (more features actually) than Keycloak
I think I looked at:
- Keycloak
- Zitadel
- Authelia
- Authentik
And maybe a few more, but I never heard of Casdoor before today, and even now there are few Reddit references to it.
The lldap config I use is here if you want it for any examples or something: https://github.com/RedlineTriad/private_server/tree/master/s...
What was your original goal? Which services are linked to your lldap? How many users? Does it simplify things or make it more complex?
1. My original goal was not having 5 different passwords for my own server because although I have a password manager it's still a bit annoying. Also just for learning.
2. You can see the services here[1], since my entire setup is provisioned from GitHub with Terraform and Ansible.
3. I have about 5 users.
4. I would say simplify so far, but it depends on what kind of complexity you care about, and which services you want to integrate.
[1] https://github.com/RedlineTriad/private_server/tree/master/s...
I "solved" that problem by having configuration management deploy same password (hash) on all of my servers. Requires keeping the repo with password hashes relatively safe and of course changing them is a bit of a process but extremely easy and low tech if there is already CM in place.
But I wouldn't want to figure out how to write the password hash into the databases of each application like grafana, or grocy.
JVM programs have high initial memory usage, but they scale up very well.