Project reference ↗

The historical Keycloak Proxy protected web applications that could not integrate directly with Keycloak's login system. Placed in front of a service, it checked browser sessions or bearer tokens and could restrict access to selected paths by role. It was useful for adding access control at the proxy boundary. This is the retired proxy later known as Louketo, not the Keycloak identity server, so its replacement must preserve both login and authorization behavior.

Current guidance

This record concerns the former gambol99/keycloak-proxy, not the Keycloak identity server. Its verified repository relocation leads to louketo/louketo-proxy, whose README states that support and updates ended on November 21, 2020. The historical chart and role-filter examples therefore describe an ended proxy implementation.

Inventory the proxy’s responsibilities before replacing it: browser login, bearer-token validation, role or claim constraints, protected path patterns, upstream headers and WebSocket handling. Another OpenID Connect proxy may support login while applying different authorization or session semantics. Do not infer compatibility solely because both connect to the same Keycloak realm.

Build a request matrix with authenticated, expired, missing-token and insufficient-role cases, then compare responses against a separate candidate endpoint. Verify that clients cannot inject trusted identity headers and that redirects, issuer URLs and logout behavior match the public hostname. Rotate or remove obsolete client credentials after a controlled cutover. This page preserves the original project identity and EOL fact; it does not assert that a similarly named proxy is an official successor or a drop-in replacement.

Historical upstream link check · 2026-10-09

The recorded upstream address redirects to https://github.com/louketo/louketo-proxy and returned HTTP 200 on 2026-10-09. GitHub marks louketo/louketo-proxy as archived. This confirms the repository's read-only archive state; any successor or supported distribution needs separate evidence. GitHub resolves the old repository identity to louketo/louketo-proxy. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2018-09-08T09:56:28+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Keycloak has an HTTP(S) proxy that you can put in front of web applications and services where it is not possible to install the Keycloak adapter. You can set up URL filters so that certain URLs are secured either by browser login and/or bearer token authentication. You can also define role constraints for URL patterns within your applications.

This chart bootstraps a Keycloak Proxy Deployment on a Kubernetes cluster using the Helm package manager. It provisions a fully featured Keycloak Proxy installation.

 

Features:

 

  • Supports role-based URI controls
  • Web Socket connection upgrading
  • Token claim matching for additional ACL controls
  • Custom claim injections into authenticated requests
  • Stateless offline refresh tokens with optional predefined session limits
  • TLS and mutual TLS support
  • JSON field bases access logs
  • Custom Sign-in and access forbidden pages
  • Forward Signed Proxy
  • URL Role Tokenization
  • Listen on unix sockets, proxy upstream to unix sockets
  • Let’s Encrypt support

 

Keep in mind browser cookie limits, if you use to access or refresh tokens in the browser cookie. Keycloak-proxy divides cookie automatically if your cookie is longer than 4093 bytes. The real size of the cookie depends on the content of the issued access token. Also, encryption might add additional bytes to the cookie size. If you have large cookies (>200 KB), you might reach browser cookie limits.

All cookies are part of the header request, so you might find a problem with the max headers size limits in your infrastructure (some load balancers have very low this value, such as 8 KB). Be sure that all network devices have sufficient header size limits. Otherwise, your users won’t be able to obtain the access token.

The post Keycloak Proxy appeared first on kubedex.com.

Sources & further reading

  1. Louketo Proxy explicit EOL notice
  2. Recovered historical source

Spotted something that needs another look?

Help improve this page →