Fix Keycloak issuer at id.fzymgc.house from day one
Fix Keycloak issuer at id.fzymgc.house from day one
Section titled “Fix Keycloak issuer at id.fzymgc.house from day one”Date: 2026-06-28 Status: Accepted Decision: hl-mx5n Deciders: Sean Brandt
Context
Section titled “Context”A Keycloak realm’s issuer URL is embedded in every issued JWT and in every OIDC client’s discovery configuration; changing it after tokens are issued forces a token-rotation and client-reconfiguration cascade. The migration runs Keycloak alongside Authentik (auth.fzymgc.house) through Phases 0–4.
Decision
Section titled “Decision”Publish Keycloak at id.fzymgc.house with realm issuer https://id.fzymgc.house/realms/fzymgc from Phase 0, and retire auth.fzymgc.house (do not repoint it) at Phase 5 decommission.
Rationale
Section titled “Rationale”- The issuer URL is baked into JWTs and client configs — fixing it once, up front, avoids a token-rotation cascade at decommission.
- Repointing
auth.fzymgc.houseto Keycloak at decommission would not change already-issued Keycloak token issuers and provides no value.
Alternatives Considered
Section titled “Alternatives Considered”- New hostname
id.fzymgc.housefrom Phase 0 (chosen): issuer never changes; OIDC clients are configured once; cost is a new DNS record and TLS cert alongsideauth.fzymgc.houseduring the parallel run. - Reuse
auth.fzymgc.house, repoint at decommission (rejected): impossible during a parallel run where both IdPs coexist, and the repoint would not update already-issued token issuers.
Consequences
Section titled “Consequences”- Positive: OIDC client configurations are stable across all migration phases;
auth.fzymgc.houseretirement is clean with no lingering aliases. - Negative: a new DNS record and TLS cert are required for
id.fzymgc.housefrom Phase 0. - Neutral: both hostnames coexist through Phases 0–4.