Dependencies
provided in the starter, so include them explicitly. camunda-platform-7-keycloak (the Keycloak identity provider plugin) is 7.24.0. The org.camunda.bpm.* coordinate is correct — it is an external Camunda extension that ASEE Flow uses as-is.
Configuration
Enable the mode and configure the Spring Security OAuth2 client (as for OAuth2):These values are for local testing — a Keycloak at
localhost:9000, the demo aseeflow realm and client, and disabled SSL validation. For production, point at your own Keycloak realm and URLs, supply the client secret via an environment variable, remove disableSSLCertificateValidation, and harden per Security.How it works
Users are redirected to Keycloak for OAuth2 / OIDC login; Spring Security manages the session. The identity provider plugin synchronizes Keycloak users, groups, and roles into the engine’s Identity Service in real time, including nested group hierarchies and an administrator-group mapping. On logout, an OIDC-compliant flow returns the user to/webadmin/.
When deploying behind a reverse proxy or load balancer, a ForwardedHeaderFilter ensures OAuth2 redirect URIs are assembled correctly, and a customized firewall permits the URL-encoded slashes used in nested Keycloak group paths.
When to use it
Keycloak authentication is ideal when your organization already uses Keycloak for SSO and you want full Keycloak role and group integration with ASEE Flow, beyond what token claims alone provide.Properties
WebAdmin properties:
Keycloak identity provider plugin properties (under
plugin.identity.keycloak):
Use proper SSL certificates in production;
disableSSLCertificateValidation is for development only. The demo enables it because Keycloak runs locally over HTTP.