[keycloak-user] Internet facing Keycloak, security best practices ?

Mathieu Poussin me at mpouss.in
Thu Nov 29 06:03:52 EST 2018


Hello.

Is there any king of best practices on how to deploy and secure an internet facing Keycloak instance ?

So far I've been doing some filtering on my reverse proxy :

- Limit /auth/admin to trusted IP
- Block = /auth (The default auth page)

But I suppose there are maby other things that can be done ?
I could not find any official documentation.

Thanks.




More information about the keycloak-user mailing list