{"repo":"lifs-tools/keycloak-docker-role-mapper","free":true,"listed":false,"github":"https://github.com/lifs-tools/keycloak-docker-role-mapper","clone":"git clone https://github.com/lifs-tools/keycloak-docker-role-mapper.git","description":"Keycloak mapper implementation to support role-based authentication via Keycloak, mapping to docker registries push and pull scopes.","language":"Java","stars":13,"topics":["keycloak","docker-registry-v2"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Keycloak Role to Docker Registry Pull and Push Scope Mapper This keycloak mapper adds role mapping capability for the docker-v2 authentication flow in Keycloak. It currently requires two roles ('docker-pull' and 'docker-push') to be present in the list of a user's roles. These roles are checked and depending on their presence or absence, access to the registry or any repository is permitted or denied. If none of the roles are present, access is denied (e.g. docker login will fail, but so will pull and push). For docker login to succeed, at least one of the groups must be present for a user. Through Keycloak's composite roles concept, the 'docker-push' role could be defined to automatically include 'docker-pull', too. This is up to the administrator to configure, though. Please note the the role names are currently hard-coded in the mapper. However, pull requests are always welcome to change this to a more Keycloak-like dynamic mapping. Also, defining different access scopes for individual repositories is currently not possible. Namespace The module / mapper has the namespace org.lifstools.keycloak.keycloak-docker-role-mapper (see below for instructions on registration). Installation in Keycloak 1. Make sure to start Keycloak with the -Dkeycloak.profile.feature.docker=enabled profile enabled. 2. Documentation specifically for Keycloak authentication for a Docker registry is here: https://www.keycloak.org/docs/latest/server admin/index.html# docker 3. Create a new module 4. Act","default_branch":null,"files":null,"tree":[],"storefront":"/r/lifs-tools","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/lifs-tools/keycloak-docker-role-mapper/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}