Skip to content

2.keycloak gatekeeper

zhoumingjun edited this page Jul 29, 2019 · 1 revision

keycloak-gatekeeper
--discovery-url=http://iam.apigw.sensetime.com:8080/auth/realms/test
--client-id=client1
--client-secret=8b4eba6e-8830-4e97-a9c2-e6dcb0bb7473
--listen=127.0.0.1:3000 \
--redirection-url=http://127.0.0.1:3000
--enable-refresh-tokens=true
--encryption-key=AgXa7xRcoClDEU0ZDSH4X0XhL5Qy2Z2j
--upstream-url=http://127.0.0.1:8000
--enable-default-deny=true
--resources="uri=/admin*|roles=test1,test2"
--resources="uri=/backend*|roles=test1"
--resources="uri=/css/|white-listed=true"
--resources="uri=/img/
|white-listed=true"
--resources="uri=/public/*|white-listed=true"
--headers="myheader1=value1"
--headers="myheader2=value2"

important

https://stackoverflow.com/questions/53550321/keycloak-gatekeeper-aud-claim-and-client-id-do-not-match

<<AllPages()>>

Clone this wiki locally