Перейти к содержимому

OCI IAM Federation, Dynamic Groups & Network Sources | Keycloak SAML 2.0 | Project 3n4/10

SecureTechWithJKA

0:00 / 0:00

OCI IAM Federation, Dynamic Groups & Network Sources | Keycloak SAML 2.0 | Project 3n4/10

23 просмотра · 2 нед. назад
SecureTechWithJKA
37 подписчиков
23 просмотра · 2 нед. назад
In this 30-minute OCI project demonstration, I build Project 3 — IAM Federation & Dynamic Groups in Oracle Cloud Infrastructure (OCI), focusing on identity federation, credential-free workload access, and network-based security controls. 🔐 What I Build 1. SAML 2.0 Federation with Keycloak Configure Keycloak as the corporate Identity Provider Add a SAML 2.0 Identity Provider in OCI Configure OCI group mappings Map Keycloak groups to OCI groups Test federated authentication 2. Dynamic Groups & Resource Principals Create a dynamic group for workload compute instances Create a dynamic group for OCI Functions Use matching rules based on compartment and resource type Grant compute instances access to OCI Vault without storing API keys Configure policies for Vault and key management access 3. Network Source Security Configure an OCI Network Source for corporate/VPN-style access control Restrict sensitive administrative API operations based on source network Demonstrate how network-based restrictions can add another layer of protection to OCI IAM 🛡️ Key Security Concepts This project demonstrates how to move beyond traditional IAM credentials by combining: SAML federation → centralized authentication through Keycloak Group mappings → federated users receive appropriate OCI permissions Dynamic groups → workloads authenticate using their OCI resource identity Resource principals → no stored API keys or credentials on compute instances Network Sources → restrict sensitive API operations by network location IAM policies → enforce least-privilege access The goal is to demonstrate a practical enterprise-style OCI security architecture where users authenticate through the corporate IdP and workloads authenticate through their OCI resource identity, rather than relying on manually managed credentials. 📌 Project 3 Complete By the end of the demonstration: ✅ Keycloak SAML federation configured ✅ OCI group mappings configured ✅ Dynamic group for compute workloads ✅ Dynamic group for OCI Functions ✅ Credential-free Vault access from compute ✅ IAM policies for dynamic groups ✅ Network Source security demonstrated ✅ Enterprise IAM security model demonstrated This is part of my OCI network and security project series focused on building and demonstrating practical cloud security controls in Oracle Cloud Infrastructure. #OCI #OracleCloud #IAM #Keycloak #SAML #CloudSecurity #DevSecOps #DynamicGroups #OracleCloudInfrastructure #CyberSecurity