Work

Two engagements, anonymised. Specifics on request, where contracts allow.

One sign-on for several hundred websites

Web platform operator · Keycloak · remote, part-time

The problem

The operator ran several hundred web properties and needed single sign-on across all of them. There was no shared identity layer to extend. It had to be built from scratch, as one platform for the whole estate.

Constraints

  • One engineer. I was the only identity engineer on the account: architecture, build and incident response.
  • Part-time. The work fitted a fixed weekly budget, alongside a full-time job.
  • Keycloak out of the box was not enough. The standard configuration did not cover everything the platform needed.

What I built

A Keycloak SSO platform serving the whole estate, up to 10,000 end users.

Three custom extensions, written in Java, where configuration stopped: an authentication flow, themes, and an event listener that passes Keycloak events on to another internal system.

Then the upkeep. I took the platform through three major Keycloak version upgrades. Each ran blue/green: a parallel cluster on the new version, then a switch of traffic, so the running platform was never upgraded in place.

Result

  • Users sign in once and are signed in across several hundred properties.
  • Three major upgrades, each with under 5 minutes of user-facing downtime.
  • One person ran all of it, part-time.

Moving identity out of a monolith without users noticing

SaaS company · Keycloak, OpenFGA · remote, part-time

The problem

Authentication, roles and permissions lived inside the company’s monolith. Any change to who could sign in, or what they could do, meant a change to the monolith. That made every access rule expensive, and it blocked splitting the monolith up.

Constraints

  • No planned downtime.
  • The legacy system had to keep working, with as little change to it as possible.
  • Users, roles, permissions and objects had to move without anyone noticing.
  • Access differs per customer organisation. A user can hold different rights in different tenants, which plain role checks do not express.
  • Remote and part-time.

What I built

A new IAM on Keycloak, replacing the in-house authentication code, for 10,000+ users.

A central authorization model on OpenFGA. Roles, permissions and objects were extracted from the monolith into Keycloak and OpenFGA. The model expresses per-organisation access: what a user may do depends on the organisation they are acting in. It replaced role checks scattered through the code with one place that answers “who can do what”.

The start of the monolith split. Three services were extracted over 6–12 months, again with no planned downtime.

Cloud cost. Rightsizing, and optimising applications and data processing, took cloud spend down by around 10–15%.

Result

  • 10,000+ users moved to Keycloak with no planned downtime.
  • One authorization model in place of scattered role checks.
  • Three services out of the monolith.
  • Cloud spend down by around 10–15%.

Have a similar problem?

ante.rados@delmisoft.hr