frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Open-source "God mode killer" IGA in Keycloak

https://github.com/tide-foundation/keycloak-IGA
2•SaltNHash•5h ago

Comments

SaltNHash•5h ago
Hi HN,

Keycloak is a popular open‑source Identity & Access Management (IAM) server, but like most IAMs it lets any admin make instant, irreversible changes. In regulated or high-security setups that "god mode" is a nightmare.

We built Keycloak-IGA, a fork that bakes a light weight approval workflow into the server, which must be cleared before high stakes changes can go live:

Features include: - Draft → Pending → Approved states for user, role, client & realm changes - Quorum engine (default "70%" of admins) - four-eyes control enforced by code - Zero overhead unless you switch it on - Emits audit events aligned with PCI-DSS, SOX, ISO 27001, HIPAA, NIST 800‑53

Try it in a few mins git clone https://github.com/tide-foundation/keycloak-IGA cd keycloak-IGA docker compose up # spins a demo realm with IGA extensions pre-wired

Walkthrough video(4min): https://www.youtube.com/watch?v=BrTBgFM7Lq0

Looking for feedback on: - Does the built‑in model beat the usual "proxy + ticket + webhook" approach? - Is 70% quorum sane? Would you prefer fixed reviewers, AD groups, etc.? - What's missing before you'd trust this in prod?

Background & design notes: https://github.com/keycloak/keycloak/discussions/41350

MIT licensed, so fork away, and tell us what you think.

Thanks!

josephcsible•4h ago
Does this make it impossible to have a "break glass" account?
SaltNHash•4h ago
Yes it does. It replaces it with a break glass quorum approved process.

Show HN: I made a tool that tells you what to do on Reddit for the next 4 weeks

https://www.MediaFa.st
1•countofarthur•19s ago•0 comments

Mastercard and Visa Under Fire as Petition 'Not Police' Legal Content Blows Up

https://www.ibtimes.co.uk/mastercard-visa-under-fire-petition-payment-giants-not-police-legal-content-blows-1739406
1•nabla9•1m ago•0 comments

Attempt to outlaw AI that jacks up prices based on what it knows about you

https://www.theregister.com/2025/07/26/ai_surveillance_pricing/
1•luckys•2m ago•0 comments

NAD+ the New Collagen? The Anti-Ageing Molecule Everyone's Talking About

https://www.marieclaire.co.uk/beauty/nad-benefits
1•Bluestein•9m ago•0 comments

I Saved a PNG Image to a Bird [video]

https://www.youtube.com/watch?v=hCQCP-5g5bo
2•houzi•12m ago•0 comments

Why Are Quiet Spaces Disappearing?

https://www.honest-broker.com/p/why-are-quiet-spaces-disappearing
1•Khaine•16m ago•1 comments

Show HN: DogNamesWorld – A fast dog name directory built with Astro

https://dognamesworld.com
1•laimingj•18m ago•0 comments

Thorpe is a SWE at a startup – he's also serving his 11th year in prison

https://techcrunch.com/2025/07/24/preston-thorpe-is-a-software-engineer-at-a-san-francisco-startup-hes-also-serving-his-11th-year-in-prison/
1•Gunnerhead•20m ago•0 comments

Myo Gesture Armband Teardown

https://learn.adafruit.com/myo-armband-teardown/inside-myo
1•downboots•20m ago•0 comments

Show HN: ExtractQ cuts auto-insurance claim time 75% with zero-training AI

https://www.scalong.com/case-studies/revolutionizing-auto-insurance-claims-with-processq
1•berwinsingh•24m ago•0 comments

Study Suggests Covid Shots Saved Fewer Lives Compared with Prior Estimates

https://www.medpagetoday.com/infectiousdisease/covid19vaccine/116674
2•Ozarkian•26m ago•0 comments

Multi vs. Single Page Apps – two implementations comparison

https://binaryigor.com/multi-vs-single-page-apps.html
1•BinaryIgor•26m ago•0 comments

Barbie's new pink (insulin) pumps – help children with type 1 diabetes

https://www.science.org/content/article/meet-diabetes-researcher-behind-barbie-s-new-pink-insulin-pumps
1•MukundMohanK•26m ago•0 comments

Climate groups call for wealth tax to make super-rich fund sustainable economy

https://www.theguardian.com/environment/2025/jul/15/climate-groups-call-uk-wealth-tax-make-super-rich-fund-sustainable-economy
3•PaulHoule•30m ago•0 comments

Channel-level EEG analysis systematically misattributes cortical source

https://neuromechanist.github.io/papers/uecog-2025/
2•lentoutcry•32m ago•0 comments

San Francisco's AI boom is intensifying battles for workers, housing

https://www.washingtonpost.com/business/2025/07/26/ai-boom-san-francisco-tech-workers-housing/
1•edward•34m ago•0 comments

Does visualization help AI understand data?

https://arxiv.org/abs/2507.18022
1•babushkaboi•37m ago•0 comments

Worlds Largest "Vibe Coding" Hackathon Winner

https://twitter.com/boltdotnew/status/1949171389224624301
1•babushkaboi•38m ago•0 comments

Sapients paper on the concept of Hierarchical Reasoning Model

https://arxiv.org/abs/2506.21734
6•hansmayer•55m ago•0 comments

Beyond Food and People

https://aeon.co/essays/nietzsches-startling-provocation-youre-edible-and-delicious
3•Petiver•59m ago•0 comments

Fragmentary Latin inscriptions can be completed with AI

https://www.economist.com/science-and-technology/2025/07/23/fragmentary-latin-inscriptions-can-be-completed-with-ai
1•helsinkiandrew•1h ago•1 comments

First release candidate of systemd 258 is here

https://www.theregister.com/2025/07/25/systemd_258_first_rc_here/
2•ossusermivami•1h ago•0 comments

When We Get Komooted

https://bikepacking.com/plog/when-we-get-komooted/
3•atakan_gurkan•1h ago•0 comments

AWR6843AOP – Single-chip 60GHz radar sensor with antenna on package, DSP and MCU

https://www.ti.com/product/AWR6843AOP
2•nynyny7•1h ago•0 comments

Linux on Snapdragon X Elite: Linaro and Tuxedo Pave the Way for ARM64 Laptops

https://www.linaro.org/blog/linux-on-snapdragon-x-elite/
12•MarcusE1W•1h ago•1 comments

Development shells with Nix: four quick examples

https://michael.stapelberg.ch/posts/2025-07-27-dev-shells-with-nix-4-quick-examples/
2•todsacerdoti•1h ago•0 comments

Releasing a Python Library for Deploying Agents with Microsoft Azure

1•manuelfdng•1h ago•0 comments

Christopher Lasch, Plain Writing, and Democracy

https://providencemag.com/2025/07/christopher-lasch-plain-writing-and-democracy/
1•Caiero•1h ago•0 comments

Specials (2021)

https://www.brendangregg.com/specials.html
2•todsacerdoti•1h ago•0 comments

TimescaleDB-Art

https://blog.cloudflare.com/timescaledb-art/
1•Vedant817•1h ago•0 comments