Introduce Keycloak Identity Integration
Overview
Establish Keycloak SSO without registration or local credentials
User
The AeroSim delivery team
What the user can do
Establish Keycloak SSO without registration or local credentials
Why the user benefits
The capability becomes an explicit, testable project boundary.
User need
The delivery team needs the AeroSim solution to establish Keycloak SSO without registration or local credentials.
In scope
Establish Keycloak SSO without registration or local credentials
- StatusProposed
- OwnerAeroSim Scope (proposed; not accepted)
- Parent EpicAEROSIM-EP-1
- Depends onAEROSIM-FT-41, AEROSIM-FT-42
Tasks
AEROSIM-TS-39Planning status: DoneImplement the Nebula Keycloak PKCE session client
A protected Nebula route redirects an unauthenticated user to Keycloak and restores the originally intended route after successful Authorization Code with PKCE sign-in.
- ComponentWeb Application — Keycloak session client
- Depends onAEROSIM-TS-13, AEROSIM-TS-16
- RequirementsFR-0057, NFR-0007
AEROSIM-TS-40Planning status: DoneImplement the Singularity Keycloak identity guard
Protected API routes validate Keycloak JWT signatures and claims and expose a trusted authenticated-subject context.
- ComponentAPI Service — Keycloak identity guard
- Depends onAEROSIM-TS-39
- RequirementsFR-0057, NFR-0007
AEROSIM-TS-41Planning status: DoneRemove and prohibit local credential surfaces
AeroSim contains no registration, password-entry, password-reset, or local-credential persistence path.
- ComponentWeb Application and API Service — identity boundary
- Depends onAEROSIM-TS-40
- RequirementsFR-0057, NFR-0007
AEROSIM-TS-42Planning status: DoneVerify Keycloak redirect, return, and rejection flows
Automated integration tests prove intended-route restoration, authenticated API access, and rejection of missing, invalid, expired, or incorrectly scoped tokens.
- ComponentWeb Application and API Service — Keycloak integration tests
- Depends onAEROSIM-TS-41
- RequirementsFR-0057, NFR-0007
AEROSIM-TS-128Planning status: DoneBind AeroSim Keycloak configuration to project-scoped Bitwarden keys
AeroSim deployment reads its Keycloak issuer, client identity, API audience, JWKS endpoint, and cache policy from project-scoped Bitwarden keys and uses an AeroSim system client identity rather than a Nebula technology name.
- ComponentWeb Application, API Service, and deployment identity configuration
- Depends onAEROSIM-TS-42, AEROSIM-TS-127
- RequirementsFR-0057, NFR-0007
Acceptance outcomes
- 01
Protected AeroSim access redirects to Keycloak and returns to the intended route after success.
- 02
No registration, password, or local credential form exists in AeroSim.
Functional requirements and measurable criteria
Introduce Keycloak Identity Integration
The system shall establish Keycloak SSO without registration or local credentials.
Acceptance 01
GivenAEROSIM-FT-50 is exercised within its governed scope under supported conditions
Whenthe primary capability path is completed
ThenProtected AeroSim access redirects to Keycloak and returns to the intended route after success
EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.
Acceptance 02
GivenAEROSIM-FT-50 is exercised within its governed scope under supported conditions
Whenthe continuation or repeat path is completed
ThenNo registration, password, or local credential form exists in AeroSim
EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.
Non-functional requirements
- NFR-0007 — Engineering reproducibility and supply-chain integrity
Repeated validation from the same immutable inputs produces equivalent artifacts and rejects unlicensed, untraceable, invalid, or over-budget inputs.
Risks
- Risk
Partial introduction could leave an ungoverned or duplicated technical boundary.
Original source and prototype evidence
- discord: Engineering Features grounded in the selected AeroSim technology stack.
- discord: Engineering Feature decomposition continuation.
- discord: RootAtSkic directed publication of the agreed Scope update.
Prototype and discovery boundary
Existing implementation is discovery evidence only; it establishes no current approval, acceptance, or release state.