CERN SSO

The corporate authentication service: Keycloak on Kubernetes, on-premise, serving ~9,000 applications and ~150,000 potential identities at ~100 logins per minute. It authenticates; it deliberately does not decide permissions — that belongs to gms and the authorization-service-api.


Topology

  • Part of: identity-architecture
  • Integrates: oidc-integration — exposes the realm’s standard endpoints.
  • Integrates: gms — consumes computed memberships to inject roles.
  • Authenticates: wlcg-iam — acts as identity provider for the grid IAM instances.
  • Complies with: oc5 — subject to the IAA subsidiary rules.
  • Supersedes: adfs-legacy — replaced the 2008-era federation service.
  • Cites: why-keycloak — scale figures and architecture.