Skip to main content
Keycloak authentication combines OAuth2 / OIDC login with a dedicated Keycloak identity provider plugin, giving you single sign-on plus full synchronization of Keycloak users and groups into the ASEE Flow engine.

Dependencies

These are provided in the starter, so include them explicitly. camunda-platform-7-keycloak (the Keycloak identity provider plugin) is 7.24.0. The org.camunda.bpm.* coordinate is correct — it is an external Camunda extension that ASEE Flow uses as-is.

Configuration

Enable the mode and configure the Spring Security OAuth2 client (as for OAuth2):
Then configure the identity provider plugin so the engine can resolve users and groups from Keycloak:
These values are for local testing — a Keycloak at localhost:9000, the demo aseeflow realm and client, and disabled SSL validation. For production, point at your own Keycloak realm and URLs, supply the client secret via an environment variable, remove disableSSLCertificateValidation, and harden per Security.

How it works

Users are redirected to Keycloak for OAuth2 / OIDC login; Spring Security manages the session. The identity provider plugin synchronizes Keycloak users, groups, and roles into the engine’s Identity Service in real time, including nested group hierarchies and an administrator-group mapping. On logout, an OIDC-compliant flow returns the user to /webadmin/. When deploying behind a reverse proxy or load balancer, a ForwardedHeaderFilter ensures OAuth2 redirect URIs are assembled correctly, and a customized firewall permits the URL-encoded slashes used in nested Keycloak group paths.

When to use it

Keycloak authentication is ideal when your organization already uses Keycloak for SSO and you want full Keycloak role and group integration with ASEE Flow, beyond what token claims alone provide.

Properties

WebAdmin properties: Keycloak identity provider plugin properties (under plugin.identity.keycloak):
Use proper SSL certificates in production; disableSSLCertificateValidation is for development only. The demo enables it because Keycloak runs locally over HTTP.