Keycloak OIDC
:::info Coming soon This section will be written when this component is deployed. :::
Keycloak is the enclave's identity provider. It handles OIDC authentication for
Rancher Manager, Harbor, and DGX Spark workloads — all using a single enclave realm.
What it provides
- OIDC provider at
keycloak.carbide-enclave.kubernerdes.com(VIP.98) - Single sign-on across: Rancher, Harbor, AI serving workloads
- Group/role mapping to Rancher RBAC and Harbor project permissions
- Self-hosted — no external identity dependency
OIDC clients (planned)
| Client | Service | Notes |
|---|---|---|
rancher | Rancher Manager | Group-based cluster role assignment |
harbor | Harbor Registry | Project-based access control |
spark-workloads | vLLM / Ollama | AI serving authentication |
Prerequisites
- Harbor running — Harbor Registry