Skip to content

Feature/integrate keycloak sso#51

Merged
USHER-PB merged 14 commits intomainfrom
feature/integrate-keycloak-sso
Feb 25, 2026
Merged

Feature/integrate keycloak sso#51
USHER-PB merged 14 commits intomainfrom
feature/integrate-keycloak-sso

Conversation

@USHER-PB
Copy link
Collaborator

  • Replace Grafana's local basic authentication with a robust, automated Single Sign-On (SSO) integration using Keycloak. This transition establishes Keycloak as the single source of truth for identity and access management across the LGTM stack.

…trol

- Auto-configure Keycloak 'grafana-oauth' client, groups, and roles via Terraform
- Map Keycloak groups (admins, editors, viewers) to Grafana organization roles
- Implement strict access control: only users in Grafana groups can access the stack
- Create a dedicated Grafana admin user in Keycloak separate from other services
- Fix Helm chart 'assertNoLeakedSecrets' validation by using environment variable for client secret
- Update GKE deployment workflow to support new Keycloak secrets and branch triggers
@USHER-PB USHER-PB self-assigned this Feb 23, 2026
@USHER-PB USHER-PB merged commit f3656eb into main Feb 25, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants