Skip to main content
Version: 2.0.0

ADR 007: Select IAM Tool

Date: 2025-09-10 Status: Accepted

Decision Makers: @JulianSobott

Context​

We need a central IAM Tool, which is powerful to fulfill all requirements and is open-source. In civitas v1, KeycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs. was used for this. Although it is a bit more complex than other tools, it is very powerful and integrated well in the platform.

Checked Architecture Principles​

  • [full] Model-centric data flow – Configurable-as-code via keycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs.-config-cli (see ADR 005)
  • [full] Distributed architecture with unified user experience – Centralizes auth/SSO and can be themed to feel like one UI while remaining a decoupled service.
  • [partial] Modular design – Provides a single responsibility (IAM/SSO) and could be replaced by any OIDC/SAML provider. KeycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs. specific features, could make this change difficult.
  • [full] Integration capability through defined interfaces – Implements OpenID Connect/OAuth2, plus an Admin REST API.
  • [full] Open source as the default – Fully open source with active community.
  • [full] Cloud-native architecture – Official containers, Kubernetes-ready, supports HA and horizontal scaling.
  • [full] Prefer standard solutions over custom development
  • [full] Self-contained deployment
  • [full] Technological consistency to ensure maintainability
  • [full] Multi-tenancy – Realms enable strong tenantTenantAn isolated organizational partition that owns Data pools, Datasets, Users, Groups, and Roles. All access rules exist within their Tenant, and the Tenant is the widest Scope of a Role. Currently, one Tenant corresponds to the Platform. isolation
  • [full] Security by design – Centralized auth, OIDC, fine-grained policies, least-privilege patterns and modern security protocols.

Decision​

KeycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs. should be used as a central Identity and Access Management tool. It worked very well in v1, is well maintained, and still satisfies all our required features. Most of the tools have direct integrations with keycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs..

Consequences​

All tools must connect to KeycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs. via OIDC

Alternatives​

  • Authentik: Not so powerful and stable for larger projects

See also​