How do I secure static files exposed via httpd using Keycloak?

Viewed 548

Here is my setup:

Dockerfile

FROM httpd:2.4-alpine
COPY ./static-files/ /usr/local/apache2/htdocs/

I ran the image and can access the files at localhost:3000/static-files/

I also have a Keycloak(12.0.1) running at localhost:8080/auth (I have already created all its properties like Realm, client and users etc.)

My requirement is something like that:

Whenever I access localhost:3000/static-files/ I should be redirected to Keycloak localhost:8080/auth for authentication and after successful login, I should be able to view static files available at localhost:3000/static-files/

Basically, how do I tell httpd server that my Keycloak is running at localhost:8080/auth?

1 Answers

There is a module mod_auth_openidc that enables an Apache 2.x webserver to operate as an OpenID Connect Relying Party (RP) to an OpenID Connect Provider (OP). Using this we can secure any static website using any OpenID Connect Providers like Keycloak, etc.

Related