You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻求支持多租户架构的免费本地化Headless CMS(需兼容Keycloak)

Top Free, Self-Hosted Headless CMS with Multitenancy & Keycloak Compatibility

Awesome question—let’s dive into the best open-source, self-hosted Headless CMS options that check all your boxes: multitenancy support, no cloud lock-in, and compatibility with Keycloak.

1. Directus

  • Multitenancy: Directus has native multitenancy via its core "Projects" feature in the open-source version. Each tenant gets a fully isolated workspace with separate data, roles, and permissions—no third-party plugins required to keep content siloed.
  • Self-Hosted & Free: Licensed under GPLv3, it’s 100% open-source and designed for self-hosting. Deploy it on your own servers, Docker, Kubernetes, or any infrastructure you control—no mandatory cloud subscriptions.
  • Keycloak Integration: Directus supports OpenID Connect (OIDC) natively. You can easily configure Keycloak as an external identity provider by adding your Keycloak server’s OIDC endpoints, client credentials, and mapping Keycloak roles to Directus’s permission system for seamless access control.

2. Payload CMS

  • Multitenancy: Payload is highly customizable, and multitenancy can be implemented natively using its flexible collection system and access control hooks. Create a "Tenants" collection, attach content entries to specific tenants, and use access controls to ensure users only interact with their tenant’s data.
  • Self-Hosted & Free: Released under the MIT license, Payload is built for self-hosting on Node.js servers. You have full control over deployment and infrastructure with no cloud dependencies.
  • Keycloak Integration: Extend Payload’s auth system with OIDC support using community plugins or a custom auth strategy. Connect to Keycloak to handle user login, token validation, and role syncing—keeping your authentication consistent across your stack.

3. Strapi (Community-Driven Multitenancy)

  • Multitenancy: While native multitenancy is in Strapi’s Enterprise tier, the open-source community has created robust free plugins (like strapi-plugin-multitenancy) that add full multitenancy capabilities. These plugins let you isolate content, roles, and API endpoints per tenant effectively.
  • Self-Hosted & Free: Core Strapi is open-source under the MIT license, with full support for self-hosting on any Node.js-compatible infrastructure.
  • Keycloak Integration: Use community plugins (such as strapi-plugin-auth-oidc) or build custom middleware to connect Strapi to Keycloak via OIDC. This lets you sync user accounts and roles between Keycloak and Strapi, maintaining a unified auth system.

Quick Implementation Tips

  • Always test data isolation rigorously after setting up multitenancy to ensure tenants can’t access each other’s content.
  • For Keycloak integration, validate token scopes and role mappings to keep access control secure and consistent across tenants.
  • All these CMS options have active communities and detailed documentation to help you troubleshoot setup hurdles.

内容的提问来源于stack exchange,提问作者Multitenant testers

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 19:22:28