Spring boot with keycloak separate resource for backend services and users

Viewed 80

I have simple architecture like:

enter image description here

backend microservice needs long duration token, like 2 days, and its service account so is authing with keycloak by grant_type: client_credentials

enter image description here

frontend of course serves users, so they use grant_type: password

enter image description here

and spring boot app has special API prefix for internal microservices calls so /internal/ should be authed by this internal-client and other apis by fronted-client

in spring boot application.properties under .resource we can define just 1 keycloak.resource ( client ).

how can I deal with such scenario ?

1 Answers

ok I managed to make it working. It very simple, in spring boot as a resource I need to keep this main one ( client for internal services ), but for frontend I need need to configure it. Important is that in frontend client I have connected proper roles and thats it.

Related