jBPM独立版通过IdentityServer4认证及KeyCloak作为客户端对接可行性的技术咨询
Great question! Let’s break this down clearly—you don’t actually need to use Keycloak as a middleman client to connect jBPM to your IdentityServer4 (though that’s an option if you have existing Keycloak integrations you want to align with). Here are two actionable solutions:
方案一:直接让jBPM对接IdentityServer4(推荐)
jBPM standalone has built-in support for OpenID Connect, so you can hook it directly to your IdentityServer4 instance without extra tools. Here’s how to set it up:
更新jBPM的安全域配置
找到jBPM安装目录下的standalone/configuration/standalone.xml(或standalone-full.xml,取决于你使用的配置文件),定位到安全域部分,把默认基于users.properties的认证替换为OpenID Connect配置:<security-domain name="kie-oidc" cache-type="default"> <authentication> <login-module code="org.keycloak.adapters.jboss.KeycloakOIDCLoginModule" flag="required"> <module-option name="keycloak.config.file" value="${jboss.server.config.dir}/keycloak.json"/> </login-module> </authentication> </security-domain>别担心配置里的"Keycloak"字样——这个适配器是通用的OpenID Connect实现,完全兼容IdentityServer4。
创建OpenID配置文件
在standalone/configuration目录下新建keycloak.json,填入你的IdentityServer4客户端信息:{ "realm": "YourIdentityServerTenantName", "auth-server-url": "https://your-identityserver4-domain.com", "ssl-required": "external", "resource": "JBPM_CLIENT", "credentials": { "secret": "YourClientSecretFromIdentityServer4" }, "confidential-port": 0, "principal-attribute": "preferred_username", "use-resource-role-mappings": false, "enable-cors": true }替换占位符为你的实际配置:
auth-server-url: IdentityServer4的基础地址resource: 你注册的客户端ID(JBPM_CLIENT)secret: JBPM_CLIENT对应的客户端密钥realm: IdentityServer4的租户/领域名称(如果没自定义,用master即可)
配置jBPM web应用使用该安全域
在standalone.xml中找到undertow子系统,将默认安全域设置为kie-oidc,并添加应用安全域映射:<subsystem xmlns="urn:jboss:domain:undertow:12.0" default-server="default-server" default-virtual-host="default-host" default-servlet-container="default" default-security-domain="kie-oidc"> <!-- 保留原有配置,缺失则添加以下部分 --> <application-security-domains> <application-security-domain name="kie-oidc" security-domain="kie-oidc"/> </application-security-domains> </subsystem>在IdentityServer4中配置回调地址
登录IdentityServer4后台,找到JBPM_CLIENT客户端,添加重定向URI:https://your-jbpm-domain.com/*
(测试阶段用*即可,生产环境可以缩小到具体端点)重启jBPM服务
启动jBPM后,访问控制台会自动跳转到IdentityServer4的登录页面,完成认证后即可返回jBPM正常使用。
方案二:用KeyCloak作为中转对接IdentityServer4
如果你已有基于KeyCloak的集成体系,希望统一认证入口,可以将KeyCloak配置为IdentityServer4的客户端,再让jBPM对接KeyCloak。步骤如下:
在IdentityServer4中注册KeyCloak作为客户端
- 创建新客户端,ID设为
keycloak-client - 客户端类型选择
Confidential - 添加重定向URI:
https://your-keycloak-domain.com/auth/realms/master/broker/oidc/endpoint - 允许的Scope:
openid、profile、email(按需调整) - 生成安全的客户端密钥并保存
- 创建新客户端,ID设为
在KeyCloak中添加IdentityServer4作为身份提供商
- 登录KeyCloak后台,进入你的领域(比如
master) - 左侧菜单选择
Identity Providers,点击OpenID Connect v1.0 - 填写以下信息:
- Alias:
identityserver4(给身份提供商起个友好名称) - Authorization URL:
https://your-identityserver4-domain.com/connect/authorize - Token URL:
https://your-identityserver4-domain.com/connect/token - Client ID:
keycloak-client(步骤1中创建的客户端ID) - Client Secret: 步骤1中生成的客户端密钥
- Default Scopes:
openid、profile
- Alias:
- 保存配置并测试连接是否正常
- 登录KeyCloak后台,进入你的领域(比如
在KeyCloak中创建jBPM专用客户端
- 新建客户端,ID设为
jbpm-client - 开启
Standard Flow Enabled(jBPM使用的授权码模式) - 添加重定向URI:
https://your-jbpm-domain.com/* - 生成该客户端的密钥并保存
- 新建客户端,ID设为
让jBPM对接KeyCloak
参考方案一的步骤,但修改keycloak.json指向KeyCloak实例:{ "realm": "master", "auth-server-url": "https://your-keycloak-domain.com/auth", "ssl-required": "external", "resource": "jbpm-client", "credentials": { "secret": "YourKeycloakClientSecret" }, "confidential-port": 0 }测试认证流程
访问jBPM控制台会跳转到KeyCloak登录页,KeyCloak会进一步重定向到IdentityServer4完成认证,成功后依次返回KeyCloak、jBPM,建立有效会话。
注意事项
- 生产环境必须使用HTTPS:开发阶段可以临时关闭SSL校验,但绝不能用于生产。
- 角色映射:jBPM需要用户角色来控制权限,你可以在IdentityServer4中把角色作为Claim传递,或在KeyCloak中转时处理角色映射。
- 适配器兼容性:方案一中使用的Keycloak适配器,只要和你的JBoss/Wildfly版本兼容,就能正常对接IdentityServer4。
内容的提问来源于stack exchange,提问作者techrhl

