Skip to content

Fix Keycloak issuer at id.fzymgc.house from day one

Fix Keycloak issuer at id.fzymgc.house from day one

Section titled “Fix Keycloak issuer at id.fzymgc.house from day one”

Date: 2026-06-28 Status: Accepted Decision: hl-mx5n Deciders: Sean Brandt

A Keycloak realm’s issuer URL is embedded in every issued JWT and in every OIDC client’s discovery configuration; changing it after tokens are issued forces a token-rotation and client-reconfiguration cascade. The migration runs Keycloak alongside Authentik (auth.fzymgc.house) through Phases 0–4.

Publish Keycloak at id.fzymgc.house with realm issuer https://id.fzymgc.house/realms/fzymgc from Phase 0, and retire auth.fzymgc.house (do not repoint it) at Phase 5 decommission.

  • The issuer URL is baked into JWTs and client configs — fixing it once, up front, avoids a token-rotation cascade at decommission.
  • Repointing auth.fzymgc.house to Keycloak at decommission would not change already-issued Keycloak token issuers and provides no value.
  • New hostname id.fzymgc.house from Phase 0 (chosen): issuer never changes; OIDC clients are configured once; cost is a new DNS record and TLS cert alongside auth.fzymgc.house during the parallel run.
  • Reuse auth.fzymgc.house, repoint at decommission (rejected): impossible during a parallel run where both IdPs coexist, and the repoint would not update already-issued token issuers.
  • Positive: OIDC client configurations are stable across all migration phases; auth.fzymgc.house retirement is clean with no lingering aliases.
  • Negative: a new DNS record and TLS cert are required for id.fzymgc.house from Phase 0.
  • Neutral: both hostnames coexist through Phases 0–4.