Skip to main content

Introduce Keycloak Identity Integration

Overview​

User capability

Establish Keycloak SSO without registration or local credentials

User

The AeroSim delivery team

What the user can do

Establish Keycloak SSO without registration or local credentials

Why the user benefits

The capability becomes an explicit, testable project boundary.

User need

The delivery team needs the AeroSim solution to establish Keycloak SSO without registration or local credentials.

In scope

Establish Keycloak SSO without registration or local credentials

Tasks​

AEROSIM-TS-39Planning status: Done

Implement the Nebula Keycloak PKCE session client

A protected Nebula route redirects an unauthenticated user to Keycloak and restores the originally intended route after successful Authorization Code with PKCE sign-in.

AEROSIM-TS-40Planning status: Done

Implement the Singularity Keycloak identity guard

Protected API routes validate Keycloak JWT signatures and claims and expose a trusted authenticated-subject context.

  • ComponentAPI Service — Keycloak identity guard
  • Depends onAEROSIM-TS-39
  • RequirementsFR-0057, NFR-0007
AEROSIM-TS-41Planning status: Done

Remove and prohibit local credential surfaces

AeroSim contains no registration, password-entry, password-reset, or local-credential persistence path.

  • ComponentWeb Application and API Service — identity boundary
  • Depends onAEROSIM-TS-40
  • RequirementsFR-0057, NFR-0007
AEROSIM-TS-42Planning status: Done

Verify Keycloak redirect, return, and rejection flows

Automated integration tests prove intended-route restoration, authenticated API access, and rejection of missing, invalid, expired, or incorrectly scoped tokens.

  • ComponentWeb Application and API Service — Keycloak integration tests
  • Depends onAEROSIM-TS-41
  • RequirementsFR-0057, NFR-0007
AEROSIM-TS-128Planning status: Done

Bind AeroSim Keycloak configuration to project-scoped Bitwarden keys

AeroSim deployment reads its Keycloak issuer, client identity, API audience, JWKS endpoint, and cache policy from project-scoped Bitwarden keys and uses an AeroSim system client identity rather than a Nebula technology name.

  • ComponentWeb Application, API Service, and deployment identity configuration
  • Depends onAEROSIM-TS-42, AEROSIM-TS-127
  • RequirementsFR-0057, NFR-0007

Acceptance outcomes​

  1. 01

    Protected AeroSim access redirects to Keycloak and returns to the intended route after success.

  2. 02

    No registration, password, or local credential form exists in AeroSim.

Functional requirements and measurable criteria​

FR-0057

Introduce Keycloak Identity Integration

The system shall establish Keycloak SSO without registration or local credentials.

Acceptance 01

GivenAEROSIM-FT-50 is exercised within its governed scope under supported conditions

Whenthe primary capability path is completed

ThenProtected AeroSim access redirects to Keycloak and returns to the intended route after success

EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.

Acceptance 02

GivenAEROSIM-FT-50 is exercised within its governed scope under supported conditions

Whenthe continuation or repeat path is completed

ThenNo registration, password, or local credential form exists in AeroSim

EvidenceFuture reviewed automated and browser evidence must verify this exact outcome against the current requirement.

Non-functional requirements

Risks​

  • Risk

    Partial introduction could leave an ungoverned or duplicated technical boundary.

Original source and prototype evidence​

Prototype and discovery boundary

Existing implementation is discovery evidence only; it establishes no current approval, acceptance, or release state.