Uploaded July 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Yokohama, Japan (29-30 July, 2026), and Shanghai, China (8-9 September, 2026) Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
No More Secrets With Keycloak's Federated Client Authentication - Rishabh Singh, Red Hat
Keycloak has from day one supported identity brokering, allowing users to authenticate via an external OpenID Connect or SAML 2.0 identity provider. With its latest version, you can use Kubernetes Service Account tokens and other federated client authentication to authenticate OpenID Connect clients.
Depending on the environment the clients is running in this can eliminate the need for managing secrets for clients altogether.
A number of cloud vendors for example support injecting tokens automatically for workloads, Kubernetes have support for service accounts, and last but not least there is SPIFFE that can be leveraged in most environments.
Join this talk to learn about the concepts, see a live demo, and hear what's next on our road map.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Yokohama, Japan (29-30 July, 2026), and Shanghai, China (8-9 September, 2026) Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
No More Secrets With Keycloak's Federated Client Authentication - Rishabh Singh, Red Hat
Keycloak has from day one supported identity brokering, allowing users to authenticate via an external OpenID Connect or SAML 2.0 identity provider. With its latest version, you can use Kubernetes Service Account tokens and other federated client authentication to authenticate OpenID Connect clients.
Depending on the environment the clients is running in this can eliminate the need for managing secrets for clients altogether.
A number of cloud vendors for example support injecting tokens automatically for workloads, Kubernetes have support for service accounts, and last but not least there is SPIFFE that can be leveraged in most environments.
Join this talk to learn about the concepts, see a live demo, and hear what's next on our road map.










