NAME
Airlock::Upstream::Keycloak - Use a Keycloak login as the subject of an Airlock approval
VERSION
version 0.001
SYNOPSIS
my $keycloak = Airlock::Upstream::Keycloak->new;
my $airlock = Airlock->new(
policy => { always => ['upstream'] },
factors => [ $keycloak->factor( max_age => 300 ) ],
...
);
# in the approval action, with the claims of the person's ID token
my $result = $airlock->approve( $code, subject => $keycloak->subject($claims) );
DESCRIPTION
When the host application logs people in through Keycloak, this class turns the token claims into the subject Airlock wants, and builds the Airlock::Factor::Upstream that recognises a Keycloak login with a second factor.
A Keycloak realm in its default configuration does not report a second factor in the token: with Keycloak 26.8.0 a password login and a login with TOTP both carry acr=1 and no amr. Two settings change that:
the client, or a client scope it uses, has the protocol mapper Authentication Method Reference (AMR) (
oidc-amr-mapper);the steps of the authentication flow carry a reference value (
default.reference.value, withdefault.reference.maxAge), for examplepwdon the password form andotpon the OTP form.
A login with TOTP then carries amr => [ 'pwd', 'otp' ], which the default "mfa_amr" recognises. t/keycloak/setup.pl in the distribution does the second part through the Admin REST API, and t/90-live-keycloak.t checks the whole chain against a running Keycloak.
mfa_amr
amr values that mean a second factor was used.
mfa_acr
acr values that mean a second factor was used.
subject
my $subject = $keycloak->subject($claims);
The Airlock subject for a set of token claims: id from sub, and amr, acr and auth_time as Keycloak sent them. Croaks without sub.
factor
my $factor = $keycloak->factor( max_age => 300 );
An Airlock::Factor::Upstream that holds for a Keycloak login with a second factor. Takes its options.
SUPPORT
Issues
Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-airlock/issues.
IRC
Join #kubernetes on irc.perl.org or message Getty directly.
CONTRIBUTING
Contributions are welcome! Please fork the repository and submit a pull request.
AUTHOR
Torsten Raudssus <getty@cpan.org>
COPYRIGHT AND LICENSE
This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.
This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.