Configuring Talend Administration Center in
IdP-initiated mode with Keycloak
This section describes the configuration steps in Talend Administration Center for SSO
with Keycloak as Identity Provider.
Procedure
On Keycloak web platform, download the Keycloak IDP
metadata file from Realm Settings
page:
From Talend Administration Center, go to Configuration > SSO and set parameters as follows:
Click Launch upload to upload the metadata
file
Service Provider Entity ID (Keycloak "Client
ID"): enter tac
IDP Authentication Plugin: select
Keycloak. A message displays to enable the
Personal Access Token: please follow step 5
of the procedure described in this link.
Use Role Mapping: select
either true: login to TAC from the identity
provider will create/update users with Talend Administration Center roles, attributes name: firstName, lastName, email, tac.projectType,
tac.role (for more details, refer to section Configuring Role Mapping)
or false: no attributes are obtained from
the identity provider, but with the default Security
Administrator user that was created earlier, you can assign
Talend Administration Center roles to other users created by the identity provider.
Go to Applications page and click Talend Administration Center.