frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Open-source "God mode killer" IGA in Keycloak

https://github.com/tide-foundation/keycloak-IGA
2•SaltNHash•9h ago

Comments

SaltNHash•9h ago
Hi HN,

Keycloak is a popular open‑source Identity & Access Management (IAM) server, but like most IAMs it lets any admin make instant, irreversible changes. In regulated or high-security setups that "god mode" is a nightmare.

We built Keycloak-IGA, a fork that bakes a light weight approval workflow into the server, which must be cleared before high stakes changes can go live:

Features include: - Draft → Pending → Approved states for user, role, client & realm changes - Quorum engine (default "70%" of admins) - four-eyes control enforced by code - Zero overhead unless you switch it on - Emits audit events aligned with PCI-DSS, SOX, ISO 27001, HIPAA, NIST 800‑53

Try it in a few mins git clone https://github.com/tide-foundation/keycloak-IGA cd keycloak-IGA docker compose up # spins a demo realm with IGA extensions pre-wired

Walkthrough video(4min): https://www.youtube.com/watch?v=BrTBgFM7Lq0

Looking for feedback on: - Does the built‑in model beat the usual "proxy + ticket + webhook" approach? - Is 70% quorum sane? Would you prefer fixed reviewers, AD groups, etc.? - What's missing before you'd trust this in prod?

Background & design notes: https://github.com/keycloak/keycloak/discussions/41350

MIT licensed, so fork away, and tell us what you think.

Thanks!

josephcsible•9h ago
Does this make it impossible to have a "break glass" account?
SaltNHash•8h ago
Yes it does. It replaces it with a break glass quorum approved process.

Show HN: Competitor Finder – Paste your domain, get your top competitors

https://champsignal.com/tools/competitor-finder
2•maximedupre•37m ago•0 comments

Show HN: QuickTunes: Apple Music player for Mac with iPod vibes

https://furnacecreek.org/quicktunes/
80•albertru90•12h ago•25 comments

Show HN: A Modular Phoenix SaaS Starter Kit

https://www.phoenixsaaskit.com/
2•bustylasercanon•2h ago•0 comments

Show HN: Mapping supply chain of products (updated)

https://www.beneluxmanufacturing.com/supply-chain-explorer/
3•nodezero•2h ago•0 comments

Show HN: Historical GPX Wind Visualizer

https://github.com/ppp-one/windgpx
2•pppone•6h ago•0 comments

Show HN: Price Per Token – LLM API Pricing Data

https://pricepertoken.com/
324•alexellman•1d ago•126 comments

Show HN: Cant, rust nn lib for learning

https://github.com/TuckerBMorgan/can-t
2•TuckerBMorgan•7h ago•0 comments

Show HN: Explore GitHub via What Stargazers Also Starred

https://github.com/fengkan/GitHub-Stargazer-Constellation
2•fengkan•8h ago•0 comments

Show HN: I built a biological network visualization tool

https://nodes.bio
37•jmg421•2d ago•25 comments

Show HN: Open-source "God mode killer" IGA in Keycloak

https://github.com/tide-foundation/keycloak-IGA
2•SaltNHash•9h ago•3 comments

Show HN: The Aria Programming Language

https://github.com/egranata/aria
2•egranata_aria•9h ago•2 comments

Show HN: The Montana MiniComputer

https://mtmc.cs.montana.edu/
109•recursivedoubts•1d ago•22 comments

Show HN: Apple Health MCP Server

https://github.com/neiltron/apple-health-mcp
196•_neil•3d ago•41 comments

Show HN: Nia – MCP server that gives more docs and repos to coding agents

https://www.trynia.ai/
78•jellyotsiro•2d ago•67 comments

Show HN: Convert from MIDI file to ASCII tablature (and more)

https://github.com/scottvr/gtrsnipe/blob/main/README.md
2•ycombiredd•11h ago•0 comments

Show HN: I made a web app for structured podcast summaries

https://wisdomsnap.com/
8•bardonadam•1d ago•0 comments

Show HN: Suhya – Omegle Alternative

https://suhya.com/
3•Codegres•12h ago•2 comments

Show HN: Tsbro – TypeScript for the browser, no build step

https://github.com/stagas/tsbro
38•stagas•6d ago•26 comments

Show HN: A macOS clock that stays visible when coding or binging in fullscreen

https://cornertime.app/en
53•muvich3n•1d ago•38 comments

Show HN: Mcp-chromautomation – Chrome MCP that is not a puppeteer

https://github.com/gleicon/mcp-chromautomation
3•tunabr•18h ago•0 comments

Show HN: Open IT Maintenance Planner

https://maintenance-planner.vangemert.dev/
12•spmvg•4d ago•7 comments

Show HN: Compass CNC – Open-source handheld CNC router

https://www.compassrouter.com
174•camchaney•1w ago•46 comments

Show HN: The missing link of a bookstore's tech stack

https://bookhead.net/
94•greenie_beans•3d ago•26 comments

Show HN: A word of the day that doesn't suck

82•jsomers•5d ago•33 comments

Show HN: Phind.design – Image editor & design tool powered by 4o / custom models

https://phind.design
88•rushingcreek•4d ago•22 comments

Show HN: TheProtector – Linux Bash script for the paranoid admin on a budget

https://github.com/IHATEGIVINGAUSERNAME/theProtector
165•lotussmellsbad•3d ago•35 comments

Show HN: The Magic of Code – book about the wonders and weirdness of computation

https://themagicofcode.com/sample/
110•arbesman•5d ago•29 comments

Show HN: Tinder but it's only pictures of my wife and I can only swipe right

https://trytender.app/
1008•risquer•3d ago•261 comments

Show HN: A code editor that integrates into the browser

https://tachicode.dev/
44•quintu5•2d ago•10 comments

Show HN: Lotas – Cursor for RStudio

https://www.lotas.ai/
81•jorgeoguerra•5d ago•28 comments