OCI IAM Federation, Dynamic Groups & Network Sources | Keycloak SAML 2.0 | Project 3n4/10
SecureTechWithJKA
0:00 / 0:00
OCI IAM Federation, Dynamic Groups & Network Sources | Keycloak SAML 2.0 | Project 3n4/10
23 просмотра · 2 нед. назад
SecureTechWithJKA
37 подписчиков
23 просмотра · 2 нед. назад
In this 30-minute OCI project demonstration, I build Project 3 — IAM Federation & Dynamic Groups in Oracle Cloud Infrastructure (OCI), focusing on identity federation, credential-free workload access, and network-based security controls.
🔐 What I Build
1. SAML 2.0 Federation with Keycloak
Configure Keycloak as the corporate Identity Provider
Add a SAML 2.0 Identity Provider in OCI
Configure OCI group mappings
Map Keycloak groups to OCI groups
Test federated authentication
2. Dynamic Groups & Resource Principals
Create a dynamic group for workload compute instances
Create a dynamic group for OCI Functions
Use matching rules based on compartment and resource type
Grant compute instances access to OCI Vault without storing API keys
Configure policies for Vault and key management access
3. Network Source Security
Configure an OCI Network Source for corporate/VPN-style access control
Restrict sensitive administrative API operations based on source network
Demonstrate how network-based restrictions can add another layer of protection to OCI IAM
🛡️ Key Security Concepts
This project demonstrates how to move beyond traditional IAM credentials by combining:
SAML federation → centralized authentication through Keycloak
Group mappings → federated users receive appropriate OCI permissions
Dynamic groups → workloads authenticate using their OCI resource identity
Resource principals → no stored API keys or credentials on compute instances
Network Sources → restrict sensitive API operations by network location
IAM policies → enforce least-privilege access
The goal is to demonstrate a practical enterprise-style OCI security architecture where users authenticate through the corporate IdP and workloads authenticate through their OCI resource identity, rather than relying on manually managed credentials.
📌 Project 3 Complete
By the end of the demonstration:
✅ Keycloak SAML federation configured
✅ OCI group mappings configured
✅ Dynamic group for compute workloads
✅ Dynamic group for OCI Functions
✅ Credential-free Vault access from compute
✅ IAM policies for dynamic groups
✅ Network Source security demonstrated
✅ Enterprise IAM security model demonstrated
This is part of my OCI network and security project series focused on building and demonstrating practical cloud security controls in Oracle Cloud Infrastructure.
#OCI #OracleCloud #IAM #Keycloak #SAML #CloudSecurity #DevSecOps #DynamicGroups #OracleCloudInfrastructure #CyberSecurity