Files
document-haness/docs/keycloak/final/assets/idp-broker-upstream-downstream-boundary/idp-broker-upstream-downstream-boundary.svg
T

92 lines
7.3 KiB
XML

<?xml version="1.0" encoding="UTF-8"?>
<svg xmlns="http://www.w3.org/2000/svg" width="1080" height="395" viewBox="0 0 1080 395" role="img" aria-labelledby="diagram-title diagram-description">
<title id="diagram-title">외부 IdP 인증은 Keycloak broker에서 application credential로 다시 경계가 나뉜다</title>
<desc id="diagram-description">왼쪽 upstream IdP zone의 Google이 identity assertion을 Keycloak broker에 넘긴다. Keycloak은 assertion을 검증하고 provider alias와 upstream sub로 local identity를 연결한 뒤 자기 authorization code를 발급한다. 이 code가 기존 AP1·AP2·AP3·AP4 application 경계 중 하나로 이어지므로 application이 신뢰하는 issuer는 계속 Keycloak이다.</desc>
<metadata>{&quot;techviz&quot;:{&quot;spec_version&quot;:&quot;1.1&quot;,&quot;id&quot;:&quot;idp-broker-upstream-downstream-boundary&quot;,&quot;profile&quot;:&quot;two-zone-pipeline&quot;},&quot;source_context&quot;:{&quot;document&quot;:&quot;docs/keycloak/final/document.md&quot;,&quot;document_sha256&quot;:&quot;ea10df24b892e2c57123a37a4b4f0d821e4f394353e6746f50df6a48342353e9&quot;,&quot;anchor&quot;:{&quot;kind&quot;:&quot;heading&quot;,&quot;value&quot;:&quot;Google login이 들어와도 네 애플리케이션 경계는 바뀌지 않는다&quot;,&quot;line&quot;:1150}},&quot;evidence_policy&quot;:&quot;Each factual element cites source lines or is marked assumption.&quot;,&quot;diagram_only&quot;:true}</metadata>
<defs>
<marker id="arrow" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse">
<path d="M 0 0 L 10 5 L 0 10 z" />
</marker>
<style>
:root { color-scheme: light; }
text { font-family: Inter, Pretendard, ui-sans-serif, system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", sans-serif; fill: #111827; }
.canvas { fill: #ffffff; }
.group-box { fill: #ffffff; stroke: #9ca3af; stroke-width: 1.4; stroke-dasharray: 7 5; }
.group-label-bg { fill: #ffffff; }
.group-label { font-size: 13px; font-weight: 650; fill: #374151; }
.edge { fill: none; stroke: #374151; stroke-width: 1.8; stroke-linejoin: round; stroke-linecap: round; marker-end: url(#arrow); }
.edge.style-dashed, .edge.semantic-dashed, .edge.assumption { stroke-dasharray: 7 5; }
.edge.style-dotted { stroke-dasharray: 2 5; }
.edge.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
.edge.emphasis-muted { stroke: #9ca3af; }
.edge.emphasis-warning, .edge.kind-failure, .edge.kind-error { stroke: #dc2626; stroke-width: 2.2; }
.edge-label-bg { fill: #ffffff; }
.edge-label { font-size: 12px; font-weight: 560; text-anchor: middle; }
.node-shape { fill: #ffffff; stroke: #4b5563; stroke-width: 1.7; }
.node-shape.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
.node-shape.emphasis-muted { stroke: #9ca3af; fill: #f9fafb; }
.node-shape.emphasis-warning { stroke: #d97706; stroke-width: 2; fill: #fffdf5; }
.node-shape.kind-database, .node-shape.kind-datastore, .node-shape.kind-storage { fill: #f8fafc; }
.node-shape.kind-queue, .node-shape.kind-event, .node-shape.kind-topic { fill: #fafafa; }
.node-shape.assumption { stroke-dasharray: 4 4; }
.storage-bottom, .controller-divider { fill: none; stroke: #4b5563; stroke-width: 1.4; }
.controller-led { fill: #4b5563; }
.actor-symbol { fill: none; stroke: #4b5563; stroke-width: 1.8; stroke-linecap: round; }
.actor-symbol.emphasis-primary { stroke: #2563eb; stroke-width: 2.2; }
.node-label { font-size: 14px; font-weight: 650; text-anchor: middle; }
.node-role { font-size: 10px; letter-spacing: 0.04em; text-anchor: middle; fill: #6b7280; }
.node-detail-divider { stroke: #d1d5db; stroke-width: 1; }
.node-detail { font-size: 11px; fill: #374151; }
.assumption-badge { font-size: 9px; font-weight: 700; fill: #92400e; }
.failure-mark { stroke: #dc2626; stroke-width: 4; stroke-linecap: round; }
.lifeline { stroke: #9ca3af; stroke-width: 1.2; stroke-dasharray: 5 5; }
.timeline-axis { stroke: #374151; stroke-width: 1.8; marker-end: url(#arrow); }
.timeline-stem { stroke: #6b7280; stroke-width: 1.3; }
.timeline-marker { fill: #ffffff; stroke: #374151; stroke-width: 1.7; }
.timeline-marker.primary { fill: #2563eb; stroke: #2563eb; }
.timeline-marker.warning { fill: #dc2626; stroke: #dc2626; }
.timeline-label { font-size: 13px; font-weight: 650; text-anchor: middle; }
.timeline-detail { font-size: 11px; fill: #4b5563; text-anchor: middle; }
</style>
</defs>
<rect class="canvas" width="1080" height="395" />
<rect class="group-box" x="45.0" y="49.0" width="250.0" height="143.0" rx="8" />
<rect class="group-label-bg" x="59.0" y="39.0" width="106.0" height="22" />
<text class="group-label" x="69.0" y="54.0">Upstream IdP</text>
<rect class="group-box" x="565.0" y="49.0" width="470.0" height="281.0" rx="8" />
<rect class="group-label-bg" x="579.0" y="39.0" width="176.0" height="22" />
<text class="group-label" x="589.0" y="54.0">Keycloak → Application</text>
<polyline class="edge kind-data style-solid emphasis-normal" points="265.0,130.5 430.0,130.5 430.0,147.5 595.0,147.5" data-evidence="1157-1158" />
<rect class="edge-label-bg" x="384.7" y="125.0" width="138.6" height="22" rx="3" />
<text class="edge-label" x="454.0" y="140.0">identity assertion</text>
<polyline class="edge kind-data style-solid emphasis-primary" points="785.0,147.5 815.0,147.5 815.0,59.0 785.0,59.0 785.0,123.0 815.0,123.0" data-evidence="1158-1161" />
<rect class="edge-label-bg" x="769.8" y="17.0" width="85.0" height="22" rx="3" />
<text class="edge-label" x="812.2" y="32.0">issue code</text>
<polyline class="edge kind-data style-solid emphasis-normal" points="910.0,169.0 910.0,350.0 690.0,350.0 690.0,304.0" data-evidence="1161-1165" />
<rect class="edge-label-bg" x="808.2" y="308.0" width="118.5" height="22" rx="3" />
<text class="edge-label" x="867.5" y="323.0">Keycloak issuer</text>
<g id="node-google">
<rect class="node-shape kind-service emphasis-normal role-source" data-evidence="1152-1157" x="75.0" y="95.0" width="190.0" height="71.0" rx="7" />
<text class="node-label" x="170.0" y="122.0">Google IdP</text>
<line class="node-detail-divider" x1="89.0" y1="143.0" x2="251.0" y2="143.0" />
<text class="node-detail" x="91.0" y="160.0">identity assertion</text>
</g>
<g id="node-broker">
<rect class="node-shape kind-service emphasis-primary role-service" data-evidence="1152-1160" x="595.0" y="95.0" width="190.0" height="105.0" rx="7" />
<text class="node-label" x="690.0" y="122.0">Keycloak broker</text>
<line class="node-detail-divider" x1="609.0" y1="143.0" x2="771.0" y2="143.0" />
<text class="node-detail" x="611.0" y="160.0">broker validation</text>
<text class="node-detail" x="611.0" y="176.0">provider alias + sub</text>
<text class="node-detail" x="611.0" y="192.0">local user · session</text>
</g>
<g id="node-keycloak-code">
<rect class="node-shape kind-data emphasis-normal role-service" data-evidence="1161-1165" x="815.0" y="95.0" width="190.0" height="74.0" rx="7" />
<text class="node-label" x="910.0" y="122.0">Keycloak authorization</text>
<text class="node-label" x="910.0" y="140.0">code</text>
</g>
<g id="node-downstream">
<rect class="node-shape kind-service emphasis-normal role-sink" data-evidence="1162-1165" x="595.0" y="240.0" width="190.0" height="64.0" rx="7" />
<text class="node-label" x="690.0" y="270.0">AP1 · AP2 · AP3 · AP4</text>
</g>
</svg>