Project specification
Project expertise
Description
- Design, implementation, and operation of Identity & Access Management solutions with LDAP, Kerberos, OIDC, OAuth2, SAML, and SCIM.
- Implementation of RBAC/ABAC models as well as multi-realm and multi-tenant architectures.
- Configuration of SSO flows, MFA, and identity federation.
- Deployment and operation of Keycloak on VMs, Docker, and Kubernetes (on-prem & GCP/GKE).
- Integration of Keycloak with LDAP, IPA, Active Directory, ADFS, and Entra ID for identity sync and federation.
- Securing Keycloak with TLS and handling ingress, SSL termination, and high availability.
- Integration of Keycloak with Google Identity as an identity provider or broker.
- Mapping Keycloak roles to GCP IAM roles for workload access control.
- Integration of HashiCorp Vault for securing secrets, certificates, and service credentials.
- Using Vault PKI to issue and rotate TLS certificates.
- Implementing dynamic database secrets via Vault.
- Automated secret injection into Kubernetes using Vault Agent, ESO, or sidecar.
- Introducing secret and certificate rotation policies to minimize security risks.
- Automating Keycloak and Vault with Terraform, Helm, ArgoCD, and Ansible.
- Automated configuration of realms, clients, and policies via APIs or the Terraform provider.
- Integration of IAM and Vault workflows into CI/CD pipelines for standardized application onboarding.
- Analysis and resolution of token, federation, and certificate errors.
- Monitoring IAM and Vault platforms with Prometheus and Grafana.
- Incident handling for certificate expirations, Vault unseal errors, and migration issues
Requirements
- Solid knowledge of authentication protocols (OIDC, OAuth2, SAML, Kerberos, LDAP).
- Extensive experience deploying Keycloak (VMs, Kubernetes, optional GCP).
- Experience integrating HashiCorp Vault for secret management.
- Experience with automation using Terraform, Helm, and ArgoCD.
- Strong troubleshooting skills for hybrid IAM workflows.
Not applying this time?
Get notified about similar projects matching your experience.