Cloud Native Malaga

Cloud Native Talks: Kubernetes operator for infinite Keycloaks: AI-assisted, human-supervised

Capacity: 40
in-person
Event date
Oct 20, 26
06:00 PM - 08:30 PM CEST
Registration is open until Oct 19, 2026 at 10:00 AM CEST.
Location
Innovation Campus Malagueta, Málaga
About this event

Teddy is a DevSecOps engineer at IonikTech. He specializes in Kubernetes, cloud-native platforms and security. He has designed, built and run production Kubernetes platforms for global enterprises, both on-premises and in the cloud. His focus is on making these platforms secure, automated and easy to operate at scale.

He holds the Certified Kubernetes Administrator (CKA) and Certified Kubernetes Security Specialist (CKS) certifications. His work brings security into every stage of platform delivery: zero-trust design, identity and access management, policy-as-code and GitOps. He is passionate about using AI and LLMs to make engineering teams faster without lowering the quality bar.

Today he leads the design of the Keycloak Config Operator (KCO). It is a Kubernetes operator that lets teams manage Keycloak identity configuration as native Kubernetes resources, with high availability built in. He built KCO with a team of AI agents, guided by shared rules, skills and automated quality gates. In his talk, he shows why trust in AI-built code comes from the gates around it, not from who wrote it.

Agenda

  • 17:30 - Open and Registration
  • 18:00 - Welcome to CNCF Málaga https://ocgroups.dev/cncf/group/gt3tr94
  • 18:10 - Teddy Diamandescu, Ionik Tech (Málaga): Kubernetes operator for infinite Keycloaks: AI-assisted, human-supervised (English)
  • 19:15 - Networking (drinks and nibbles on the roof top!)
  • 20:30 - Leaving the space

Description The problem. We run many 10 Keycloak instances, and the number is growing. All their configuration is in Terraform: one module, one workspace per instance, and different environment variables for each. Each change means a platform engineer switches the workspace, loads the correct variables, and runs plan and apply by hand. The same steps are then repeated for the next instance. It is slow, an apply can fail halfway when Keycloak is busy, and application teams cannot create their own clients. They must wait for us.

 The operator. Keycloak Config Operator (KCO) lets us manage Keycloak through Kubernetes resources. Realms, clients, roles, groups, users, LDAP and authentication flows are YAML that lives next to the application. The operator applies it to the right Keycloak and keeps it in sync. A new Keycloak instance is one more small resource, not one more workspace. The operator runs on several replicas at the same time and recovers by itself when Keycloak is down or overloaded.

 Why we built it. Other tools in this area exist, for example the realm import of the official Keycloak operator, some community operators, and the Crossplane provider. We did not find one that covered what we need together: many Keycloak instances from one operator, several active replicas, clear handling of conflicting resources, recovery from outages and throttling, proxy protocol support, and coverage of LDAP federation and authentication flows.

Tags
keycloak operator cks crossplane
Organizers
Gallery