You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

jBPM独立版通过IdentityServer4认证及KeyCloak作为客户端对接可行性的技术咨询

jBPM 对接 IdentityServer4:两种可行方案(含KeyCloak中转选项)

Great question! Let’s break this down clearly—you don’t actually need to use Keycloak as a middleman client to connect jBPM to your IdentityServer4 (though that’s an option if you have existing Keycloak integrations you want to align with). Here are two actionable solutions:


方案一:直接让jBPM对接IdentityServer4(推荐)

jBPM standalone has built-in support for OpenID Connect, so you can hook it directly to your IdentityServer4 instance without extra tools. Here’s how to set it up:

  1. 更新jBPM的安全域配置
    找到jBPM安装目录下的standalone/configuration/standalone.xml(或standalone-full.xml,取决于你使用的配置文件),定位到安全域部分,把默认基于users.properties的认证替换为OpenID Connect配置:

    <security-domain name="kie-oidc" cache-type="default">
        <authentication>
            <login-module code="org.keycloak.adapters.jboss.KeycloakOIDCLoginModule" flag="required">
                <module-option name="keycloak.config.file" value="${jboss.server.config.dir}/keycloak.json"/>
            </login-module>
        </authentication>
    </security-domain>
    

    别担心配置里的"Keycloak"字样——这个适配器是通用的OpenID Connect实现,完全兼容IdentityServer4。

  2. 创建OpenID配置文件
    在standalone/configuration目录下新建keycloak.json,填入你的IdentityServer4客户端信息:

    {
        "realm": "YourIdentityServerTenantName",
        "auth-server-url": "https://your-identityserver4-domain.com",
        "ssl-required": "external",
        "resource": "JBPM_CLIENT",
        "credentials": {
            "secret": "YourClientSecretFromIdentityServer4"
        },
        "confidential-port": 0,
        "principal-attribute": "preferred_username",
        "use-resource-role-mappings": false,
        "enable-cors": true
    }
    

    替换占位符为你的实际配置:

    • auth-server-url: IdentityServer4的基础地址
    • resource: 你注册的客户端ID(JBPM_CLIENT)
    • secret: JBPM_CLIENT对应的客户端密钥
    • realm: IdentityServer4的租户/领域名称(如果没自定义,用master即可)
  3. 配置jBPM web应用使用该安全域
    在standalone.xml中找到undertow子系统,将默认安全域设置为kie-oidc,并添加应用安全域映射:

    <subsystem xmlns="urn:jboss:domain:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="kie-oidc">
        <!-- 保留原有配置,缺失则添加以下部分 -->
        <application-security-domains>
            <application-security-domain name="kie-oidc" security-domain="kie-oidc"/>
        </application-security-domains>
    </subsystem>
    
  4. 在IdentityServer4中配置回调地址
    登录IdentityServer4后台,找到JBPM_CLIENT客户端,添加重定向URI:
    https://your-jbpm-domain.com/*
    (测试阶段用*即可,生产环境可以缩小到具体端点)

  5. 重启jBPM服务
    启动jBPM后,访问控制台会自动跳转到IdentityServer4的登录页面,完成认证后即可返回jBPM正常使用。


方案二:用KeyCloak作为中转对接IdentityServer4

如果你已有基于KeyCloak的集成体系,希望统一认证入口,可以将KeyCloak配置为IdentityServer4的客户端,再让jBPM对接KeyCloak。步骤如下:

  1. 在IdentityServer4中注册KeyCloak作为客户端

    • 创建新客户端,ID设为keycloak-client
    • 客户端类型选择Confidential
    • 添加重定向URI:https://your-keycloak-domain.com/auth/realms/master/broker/oidc/endpoint
    • 允许的Scope:openid、profile、email(按需调整)
    • 生成安全的客户端密钥并保存
  2. 在KeyCloak中添加IdentityServer4作为身份提供商

    • 登录KeyCloak后台,进入你的领域(比如master)
    • 左侧菜单选择Identity Providers,点击OpenID Connect v1.0
    • 填写以下信息:
      • Alias: identityserver4(给身份提供商起个友好名称)
      • Authorization URL: https://your-identityserver4-domain.com/connect/authorize
      • Token URL: https://your-identityserver4-domain.com/connect/token
      • Client ID: keycloak-client(步骤1中创建的客户端ID)
      • Client Secret: 步骤1中生成的客户端密钥
      • Default Scopes: openid、profile
    • 保存配置并测试连接是否正常
  3. 在KeyCloak中创建jBPM专用客户端

    • 新建客户端,ID设为jbpm-client
    • 开启Standard Flow Enabled(jBPM使用的授权码模式)
    • 添加重定向URI:https://your-jbpm-domain.com/*
    • 生成该客户端的密钥并保存
  4. 让jBPM对接KeyCloak
    参考方案一的步骤,但修改keycloak.json指向KeyCloak实例:

    {
        "realm": "master",
        "auth-server-url": "https://your-keycloak-domain.com/auth",
        "ssl-required": "external",
        "resource": "jbpm-client",
        "credentials": {
            "secret": "YourKeycloakClientSecret"
        },
        "confidential-port": 0
    }
    
  5. 测试认证流程
    访问jBPM控制台会跳转到KeyCloak登录页,KeyCloak会进一步重定向到IdentityServer4完成认证,成功后依次返回KeyCloak、jBPM,建立有效会话。


注意事项

  • 生产环境必须使用HTTPS:开发阶段可以临时关闭SSL校验,但绝不能用于生产。
  • 角色映射:jBPM需要用户角色来控制权限,你可以在IdentityServer4中把角色作为Claim传递,或在KeyCloak中转时处理角色映射。
  • 适配器兼容性:方案一中使用的Keycloak适配器,只要和你的JBoss/Wildfly版本兼容,就能正常对接IdentityServer4。

内容的提问来源于stack exchange,提问作者techrhl

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 10:57:39