docs: Add note about OIDC discovery redirect for Keycloak

Using an external OIDC IDP means that, that IDP also needs to serve
the OIDC discovery information.

Fixes: https://github.com/owncloud/ocis/issues/2676
This commit is contained in:
Ralf Haferkamp
2021-11-01 12:50:48 +01:00
parent c5fae63c20
commit b8d737a914

View File

@@ -17,7 +17,8 @@ geekdocFilePath: ocis_keycloak.md
[Find this example on GitHub](https://github.com/owncloud/ocis/tree/master/deployments/examples/ocis_keycloak)
The docker stack consists 4 containers. One of them is Traefik, a proxy which is terminating ssl and forwards the requests to oCIS in the internal docker network.
The docker stack consists 4 containers. One of them is Traefik, a proxy which is terminating ssl and forwards the requests to oCIS in the internal docker network. It
is also responsible for redirecting requests on the OIDC discovery endpoints (e.g. `.well-known/openid-configuration`) to the correct destination in Keycloak.
Keycloak add two containers: Keycloak itself and a PostgreSQL as database. Keycloak will be configured as oCIS' IDP instead of the internal IDP [LibreGraph Connect]({{< ref "../../extensions/idp" >}})