Skip to main content

Keycloak OIDC

:::info Coming soon This section will be written when this component is deployed. :::

Keycloak is the enclave's identity provider. It handles OIDC authentication for Rancher Manager, Harbor, and DGX Spark workloads — all using a single enclave realm.

What it provides

  • OIDC provider at keycloak.carbide-enclave.kubernerdes.com (VIP .98)
  • Single sign-on across: Rancher, Harbor, AI serving workloads
  • Group/role mapping to Rancher RBAC and Harbor project permissions
  • Self-hosted — no external identity dependency

OIDC clients (planned)

ClientServiceNotes
rancherRancher ManagerGroup-based cluster role assignment
harborHarbor RegistryProject-based access control
spark-workloadsvLLM / OllamaAI serving authentication

Prerequisites

Next step

Rancher Manager