User access and administration using Keycloak
HCL DevOps Loop uses Keycloak for user authentication and access management.
DevOps Loop uses Keycloak to manage users, groups, authentication, and access to the platform. When you install DevOps Loop, a Keycloak realm named devops-automation is created. DevOps Loop users belong to this realm and authenticate through it when they log in to DevOps Loop.
As an administrator, you can use the Keycloak Admin Console to manage users, assign administrator privileges, configure authentication settings, and manage user credentials.
Assign administrator privileges
By default, no DevOps Loop user has administrator privileges. A DevOps Loop administrator is required to perform administrative tasks, such as claiming ownership of projects and unarchiving projects.
You can assign administrator privileges to a user by adding the user to the Admins group in Keycloak.
- Log in to the Keycloak Admin Console at:
https://<fully-qualified-dns-name>/auth/Note:Do not use the Keycloak administrator account to perform regular DevOps Loop tasks. Instead, create or use a separate user account.The default username for the Keycloak administrator iskeycloak. The password is randomly generated during installation. You can retrieve the password by running the following command:kubectl get secret -n <namespace> <helm name>-keycloak -o jsonpath="{.data.password}" | base64 --decode; echo - In the Keycloak Admin Console, go to the Users page.
- Search for and select the user that you want to make a DevOps Loop administrator.
- On the Groups tab, add the user to the
Admins group.
The user can now perform the administrative functions available to a DevOps Loop administrator.
Add users
All users must belong to the Users group to access DevOps Loop.
To add a user to the Users group:
- In the Keycloak Admin Console, go to the Users page.
- Search for and select the user.
- On the Groups tab, add the user to the Users group.
For more information about managing groups in Keycloak, see Groups in the Keycloak documentation.
Default authentication settings
The devops-automation realm has the following authentication settings by default:
- The minimum password length is 8 characters.
- Email verification for new users is disabled.
- The Forgot Password feature is enabled.
- Keycloak is not configured to send password-reset instructions by default.
You can modify these settings in the Keycloak Admin Console to meet the security requirements of your environment.
Configure email settings
To allow Keycloak to send password-reset and email-verification messages, you must configure an SMTP server.
- Log in to the Keycloak Admin Console.
- Configure the SMTP server settings for the devops-automation realm.
For more information, see Email Settings in the Keycloak documentation.
Enable password-reset emails
The Forgot Password feature is enabled by default. However, Keycloak must be configured with an SMTP server before users can receive password-reset instructions by email.
For more information, see Login settings in the Keycloak documentation.
Configure the password policy
The devops-automation realm has a default password policy that requires passwords to be at least 8 characters long. You can modify the password policy in Keycloak to meet the security requirements of your environment.
After you log in to the Keycloak Admin Console, see Password Policies in the Keycloak documentation.
Manage user passwords
When you create a user, you can set the user's password from the Credentials tab.
- In the Keycloak Admin Console, go to the Users page.
- Search for and select the user.
- Open the Credentials tab.
- Select Set password and enter the password.
- If you want the user to change the password at their first login, enable the Temporary option.
If Keycloak is not configured to send password-reset instructions by email, you must use the Keycloak Admin Console to change or reset a user's password.
For more information, see User Credentials in the Keycloak documentation.
Delete users
When a user no longer needs access to DevOps Loop, you can delete the user from Keycloak.
- In the Keycloak Admin Console, go to the Users page.
- Search for and select the user.
- Delete the user.
For more information, see Deleting Users in the Keycloak documentation.