Designing Secure Microservices with Keycloak (LFWS305)
This one-day course introduces you to securing microservices with Keycloak, using OAuth2, OIDC and single sign-on (SSO) to build identity and access management (IAM) skills for cloud native applications.
Suggested prerequisites: Familiarity with Linux terminal commands, Docker or Podman, Kubernetes basics and Helm, and comfort with a programming language such as Python or JavaScript.
Audience: Developers, DevOps engineers and security professionals who design or manage cloud native applications
IAM has become a core capability for anyone building modern cloud native systems. This course is made for developers, DevOps engineers and security professionals who want to add that expertise to their toolbox, advance their careers and strengthen the security of their organizations.
The day is built around hands-on labs. You will take a walkthrough of the Keycloak admin console, set up Keycloak locally with Docker and configure API security, and connect Google and GitHub as social identity providers. You will protect several microservices behind a gateway, use Keycloak authorization services to restrict API access by user role, and deploy and scale your setup on Kubernetes. You will also simulate a high-availability production setup and finish by auditing and hardening a configuration, looking at token expiration, session timeouts and secret rotation.
By the end you will be ready to design, deploy and manage secure IAM systems with Keycloak, skills that are valued across DevOps, platform engineering and security roles, and that fit zero-trust, enterprise-ready environments. The course includes a certificate of completion and a digital badge.