Bug 56302 - Fix wrong information about failover in keycloak abb documentation
Fix wrong information about failover in keycloak abb documentation
Status: NEW
Product: UCS
Classification: Unclassified
Component: Keycloak
UCS 5.0
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2023-07-11 06:50 CEST by Daniel Duchon
Modified: 2023-12-05 18:57 CET (History)
2 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 3: Simply Wrong: The implementation doesn't match the docu
Who will be affected by this bug?: 1: Will affect a very few installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.034
Enterprise Customer affected?: Yes
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Duchon univentionstaff 2023-07-11 06:50:50 CEST
The keycloak app documentation says, you can install keycloak multiple times in the domain to "to increase availability and provide failover using the default DNS name ucs-sso-ng.$(hostname -d)" [1].

This falsely suggests that the keycloak app is fail-safe. However, this is only the case if the central keycloak server with the keycloak postgresql database does not go offline.

If this happens, all keycloak installations are no longer usable.

The documentation should further address this circumstance and educate the customer about it. It should also go into more detail about why this decision was made and what the customer can do to make the app actually failsafe.

[1]: https://docs.software-univention.de/keycloak-app/latest/configuration.html#multiple-installations-in-the-domain