{"repo":"alexanderwolz/keycloak-registry-mapper","free":true,"listed":false,"github":"https://github.com/alexanderwolz/keycloak-registry-mapper","clone":"git clone https://github.com/alexanderwolz/keycloak-registry-mapper.git","description":"Authorization Mapping Provider Plugin for Keycloak's Docker Registry (token protocol) - based on client roles and realm groups with configuration options.","language":"Kotlin","stars":15,"topics":["docker","registry","groups","keycloak","roles","authorization","docker-registry","mapping","kotlin","authentication"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Docker v2 - Groups and Role Mapper for Keycloak 26.x 🧑‍💻 About This repository provides a MappingProvider for Keycloak's Docker-v2 protocol. It manages registry access for users with client role or and who are assigned to realm groups named like . Clients without any roles are treated as and will be granted read-only access to the namespace by default. This behavior can be overwritten by environment variables (see configuration) 🛠️ Build 1. Create jar resource using 2. Copy into Keycloak´s folder 3. Build keycloak instance using See also Keycloak Dockerfile for reference in examples section. 🐳 Docker Image Alternatively use a pre-built Keycloak Docker image, which bundles this mapper plugin. 🔬 Basic Concept - Users can be grouped to the same repository namespace by assigning them to one or several groups starting with . - Without any client roles assigned, users will be granted read-only access to their namespaces. - Default namespaces (repositories without prefix/) can only be accessed by admins. - Assigning the client role will allow users to also push and delete images in their namespaces. - Assigning the client role will allow access to any resource in the whole registry and give full access. - Users could be grouped to domain-namespaces according to their email-addresses (can be configured via environment variables, default off) - Without having any roles and groups assigned, users will have full access to the namespace if it matches their username (can be configure","default_branch":null,"files":null,"tree":[],"storefront":"/r/alexanderwolz","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alexanderwolz/keycloak-registry-mapper/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}