Logo Atlas
  • Home
  • About Me
  • Skills
  • Education
  • Recent Posts
  • Certifications
  • Posts
  • English
    Español English
  • Dark Theme
    Light Theme Dark Theme System Theme
Logo Inverted Logo
  • Tags
  • ACLs
  • Administration
  • ANDROID
  • APACHE
  • API Gateway
  • API Key
  • Architecture
  • ARP
  • ASIR
  • ASO
  • Authentication
  • AW
  • Basic Auth
  • BIND9
  • Bridge
  • CENTOS
  • CI/CD
  • Cinder
  • Cisco
  • Cloning
  • CMS
  • Commands
  • Containers
  • Contenedores
  • Controladores NVIDIA
  • Cookies
  • DEBIAN
  • Debian 12
  • Debian13
  • DHCP
  • Directory Services
  • DNAT
  • DNS
  • DNSMASQ
  • Docker
  • Docker Compose
  • Enrutamiento
  • FIREWALL
  • FORENSE
  • FORTINET
  • FORWARDING
  • FTP
  • Gateway API
  • Glance
  • GNS3
  • HMAC
  • Horizon
  • HTTPS
  • Hypervisor
  • Identity
  • Installation
  • Introduction
  • IPTABLES
  • IPv4
  • IPv6
  • ISO
  • IWEB
  • Jenkins
  • JSON Web Token
  • JWT
  • Key Auth
  • Keycloak
  • Keystone
  • KIC
  • Kong
  • Kubernetes
  • KVM
  • LAMP
  • LDAP
  • LEMP
  • Libvirt
  • Linux
  • MariaDB
  • Metrics
  • Mysql
  • NAT
  • Network
  • Networking
  • Networks
  • Neutron
  • NFTABLES
  • Nova
  • NVIDIA Drivers
  • OAuth 2.0
  • Observability
  • OpenID Connect
  • Openstack
  • OPENVPN
  • Oracle
  • Placement
  • Planning
  • Pools
  • PostgreSQL
  • Prometheus
  • Redes
  • REDHAT
  • Resize
  • Resources
  • ROCKY
  • Routing
  • SAML
  • Services
  • Servicios
  • Sessions
  • Signatures
  • Sistemas
  • SMR
  • Snapshots
  • SNAT
  • SSH
  • Storage
  • STRONGSWAN
  • Switches
  • Templates
  • Testing
  • Token Introspection
  • Topologies
  • Ubuntu
  • Vagrant
  • Validation
  • Verification
  • Virtualization
  • VM
  • Volumes
  • VPN
  • WINDOWS
  • WIREGUARD
  • Wireshark
  • WordPress
Hero Image
OAuth 2.0 Token Introspection in Kong

Kong Enterprise includes an official OAuth 2.0 Introspection plugin, but it requires a license. In this lab, we will overcome that limitation by installing an open community or free-software plugin on Kong Gateway 3.10. In addition to the plugin, we will deploy Keycloak in Kubernetes. Keycloak will issue access tokens through client_credentials and expose the introspection endpoint defined by RFC 7662. Every response shown in this article comes from this real scenario.

  • Kong
  • OAuth 2.0
  • Token Introspection
  • Keycloak
  • KIC
Sunday, July 26, 2026 | 9 minutes Read
Hero Image
OpenID Connect in Kong

Kong’s official OpenID Connect plugin requires an Enterprise license. In this lab, we use the open community or free-software cuongntr/kong-openid-connect-plugin adapter on top of lua-resty-openidc to complete an Authorization Code flow without a license. We will deploy a separate Keycloak instance in Kubernetes, log in with a real user, and verify both the callback and cookie reuse. Every response in this article comes from the lab VM. This lab continues from Installing KIC. It reuses the kong Gateway, the echo Service, KIC 3.5, and 192.168.121.200 as the kong-gateway-proxy address.

  • Kong
  • OpenID Connect
  • OAuth 2.0
  • Keycloak
  • KIC
Sunday, July 26, 2026 | 5 minutes Read
Hero Image
SAML in Kong through Keycloak

Kong’s official saml plugin requires an Enterprise license. After reviewing the open community and free-software alternatives, I could not find a direct, maintained SAML plugin compatible with Kong 3.x that would be responsible to recommend. This lab therefore uses a different, fully open architecture: Keycloak acts as the SAML Service Provider and identity broker, while Kong uses the open community or free-software kong-openid-connect plugin installed in the previous article. User authentication still performs a real SAML request and response. Keycloak validates the signed XML and returns an OpenID Connect Authorization Code to Kong.

  • Kong
  • SAML
  • OpenID Connect
  • Keycloak
  • KIC
Sunday, July 26, 2026 | 5 minutes Read
Navigation
  • About Me
  • Skills
  • Education
  • Recent Posts
  • Certifications
Contact me:
  • contacto@javiercd.es
  • javierasping
  • Francisco Javier Cruces Doval

Liability Notice: This theme is under MIT license. So, you can use it for non-commercial, commercial, or private uses. You can modify or distribute the theme without requiring any permission from the theme author. However, the theme author does not provide any warranty or takes any liability for any issue with the theme.


Toha Theme Logo Toha
© 2023 Copyright.
Powered by Hugo Logo