7.5 KiB
title, source_type, url, archive_url, status, confidence, tags, related_branches, related_projects, created, last_reviewed
| title | source_type | url | archive_url | status | confidence | tags | related_branches | related_projects | created | last_reviewed | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Keycloak with Google Login — Codemancers 기술블로그 | company-tech-blog | https://www.codemancers.com/blog/keycloak-with-google-login | raw | medium |
|
|
|
2026-05-25 | 2026-05-27 |
Keycloak with Google Login — Codemancers
Layer:
raw/company-tech-blogs/— Codemancers (system analyst Mohammad Hussain, 2025-06-12). Keycloak Admin Console 에서 Google IdP 등록하는 step-by-step 튜토리얼 사례. 공식 best practice 아님 — Keycloak 공식 docs 와 교차 확인 필수.
Parent / 활용 branch (필수)
| Branch | 이 자료가 정당화하는 결정 |
|---|---|
| raw/branch-notes/feature-keycloak-patterns | keycloak-patterns root — Google IdP federation 설정 실무 화면 흐름의 사례 자료 |
| raw/branch-notes/feature-keycloak-edge-forwardauth-google-federation | P1B Edge + Google federation 구현 시 Google Cloud Console / Keycloak Admin Console 등록 trap 예방 사례 |
컨텍스트 / 왜 저장했는지
공식 문서는 추상적 절차만 제공. 실무 환경에서 Google Cloud Console / Keycloak Admin Console 을 오가며 등록할 때 발생하는 구체적 화면 흐름, redirect URI 매칭 실수 등의 사례적 근거 확보. P1B 구현 시 trap 예방용 메모.
출처 / Source
- 원본 URL: https://www.codemancers.com/blog/keycloak-with-google-login
- 아카이브 URL: (미수집)
- 저자 / 조직: Mohammad Hussain (System Analyst, Codemancers)
- 발행일: 2025-06-12
- 마지막 확인일: 2026-05-27
핵심 인용 / Key quotes (verbatim)
[§Keycloak Admin Console] "Go to the Identity Providers section from the left-hand menu."
[§Add Provider] "Click Add Provider and select Google from the list of available providers."
[§Google Cloud Console] "Head over to the Google Cloud Console."
[§Google credentials] "Navigate to API & Services > Credentials."
[§Create credentials] "Click Create Credentials and choose OAuth Client ID."
[§Application type] "Select Web Application as the application type and click Create."
[§Client ID / Secret 확보] "You'll be presented with a Client ID and Client Secret. Copy both."
[§Redirect URI 매칭] "copy the Redirect URI displayed here and add it to the Authorized redirect URIs in your Google Cloud configuration."
Claims Extracted / 추출된 주장
| Claim ID | Claim (이 자료가 직접 말하는 것) | Evidence quote | Strength | Applies to | Does not prove |
|---|---|---|---|---|---|
| CM-KC-GG-C1 | Keycloak Admin Console 의 Identity Providers 메뉴 → Add Provider → Google 선택으로 Google IdP 추가 가능 | [§Keycloak Admin Console / Add Provider] "Go to the Identity Providers section from the left-hand menu." + "Click Add Provider and select Google from the list of available providers." | company-case-study |
Keycloak Admin UI 의 Identity Provider 등록 흐름 | Keycloak 버전 별 메뉴 위치/이름이 동일한지 본 인용 범위 밖. 공식 docs 별도 확인 |
| CM-KC-GG-C2 | Google credentials 발급은 Google Cloud Console > API & Services > Credentials > Create Credentials > OAuth Client ID 경로 | [§Google credentials / Create credentials] "Navigate to API & Services > Credentials." + "Click Create Credentials and choose OAuth Client ID." | company-case-study |
Google Cloud Console UI 흐름 (2025-06 시점) | Google Cloud Console UI 가 변경되지 않는다는 보장 아님 — 본 인용은 2025-06 스냅샷 |
| CM-KC-GG-C3 | OAuth Client 타입 으로 Web Application 선택 필요 | [§Application type] "Select Web Application as the application type and click Create." | company-case-study |
Keycloak ↔ Google OIDC 통합 시 OAuth client type 선택 | "Web Application" 외 다른 타입 (예: Desktop / iOS) 으로는 통합 불가하다는 직접 증명 아님 — 단지 본 사례의 선택 |
| CM-KC-GG-C4 | 생성된 Client ID / Client Secret 을 Keycloak Google IdP 설정에 입력하고, Keycloak 이 표시한 Redirect URI 를 Google 의 Authorized redirect URIs 에 추가해야 함 (양방향 등록) | [§Client ID / Secret 확보] "You'll be presented with a Client ID and Client Secret. Copy both." + [§Redirect URI 매칭] "copy the Redirect URI displayed here and add it to the Authorized redirect URIs in your Google Cloud configuration." | company-case-study |
Keycloak ↔ Google OIDC handshake 의 redirect URI 정합성 | Redirect URI 경로 형식 (/realms/<realm>/broker/google/endpoint) 의 정확한 spec 은 본 인용에 없음 — Keycloak 공식 docs 확인 |
Usage Boundaries / 적용 경계
- 이 자료가 직접 증명하는 것:
CM-KC-GG-C1~C4: Keycloak Admin Console 과 Google Cloud Console 의 화면 흐름 / 등록 순서 (2025-06 시점 Codemancers 튜토리얼)
- 이 자료가 증명하지 않는 것:
- "Web Application" 외 OAuth client type 선택 시 redirect URI 입력 칸이 사라진다는 trap (raw 메모에 적혀 있으나 본 fetch 인용에 직접 없음)
- Keycloak realm 이름 변경 시 redirect URI 가 함께 변경되어 Google 콘솔 재등록 필요 (raw 메모에 적혀 있으나 본 fetch 인용에 직접 없음)
- prod 환경에서의 Google API rate limit / Google account suspended 시 Keycloak 측 처리 (원래 raw 메모에서
needs-confirmation으로 표기됨, 본 글 범위 밖) subclaim 기반 매칭 vs email 기반 매칭의 선택 (별도 raw: keycloak-first-login-flow)
- 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
- Keycloak 버전 (예: 22 / 23 / 24) 별 Admin Console UI 메뉴 위치 일치 여부
- Redirect URI 경로
/realms/<realm>/broker/google/endpoint의 spec — Keycloak 공식 docs (Identity Brokering chapter) - Google
email_verifiedclaim 의 신뢰 정책 —feature-keycloak-account-linking-sub-vs-email결정과 결합
메모 / Notes (내 프로젝트 해석)
본 섹션은 자료 직접 인용 아님. P1B 결정 컨텍스트 해석.
- 공식 vs 블로그 구분: 절차 자체는 raw/official-docs/keycloak-google-idp-setup 와 일치 (추정). 본 블로그는 화면 캡처·트러블슈팅 측면에서 보조 자료. 공식 best practice 로 인용 금지.
- 사례에서 자주 나오는 trap (본 raw 직접 증명 아님, 일반 운영 경험):
- Google Cloud Console 에서 OAuth client type 을 "Web Application" 이 아닌 다른 것으로 선택 → redirect URI 입력 칸 자체가 안 뜸.
- Keycloak realm 이름 변경 시 redirect URI 경로 (
/realms/<realm>/broker/google/endpoint) 도 같이 변경 → Google 콘솔 재등록 필요.
- 확인 안 됨 (P1B 학습 범위 밖, 원래 raw 메모 보존): prod 환경에서의 Google API rate limit, Google account suspended 시 Keycloak 측 처리. →
needs-confirmation.
Related / 관련
- 같은 주제 다른 raw:
- raw/official-docs/keycloak-google-idp-setup (공식 절차)
- raw/official-docs/keycloak-first-login-flow (외부 IdP 최초 로그인 정책)
- 인용하는 branch:
- 인용한 wiki 요약: (미작성)