I am trying to secure an API using Kong as API Gateway, Keycloak as IAM service and NGINX as reverse proxy all of which are up within containers. Kong and Keycloak are connected to each other via OIDC plugin. The desired scenario is the following;
When a client makes request NGINX will redirect the request to Kong and if the client is not logged in it will be redirected to Keycloak’s login page to be redirected to Kong again after a successful login. Most of the flow is working except when the client is redirected to Keycloak, Keycloak’s 8080 port is not hidden, same for the Kong’s 8000 port once the user makes a successful login and redirected back to Kong. We tried a couple of solutions but they did not work out. What is the correct way to set these up to hide their ports?
Thanks in advance.