You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Keycloak管理控制台为client_credentials流客户端配置IP限制?

How to Set IP Restrictions for a Keycloak Client Using Client_Credentials Flow

Got it, I’ve run into this exact scenario before—Keycloak doesn’t expose IP restrictions for clients directly in the admin console out of the box, but there are a couple of solid ways to implement this for your client_credentials flow setup. Here’s what you can do:

Method 1: Use Keycloak’s Built-in Fine-Grained Authorization

This is the simplest approach since it leverages Keycloak’s native authorization features without needing custom code:

  • Step 1: Enable authorization for your client
    Go to your client’s configuration in the admin console, switch to the Authorization tab, and toggle on Authorization Enabled. Save the changes.

  • Step 2: Create an IP policy
    On the same Authorization page, click Policies in the left sidebar, then select Create Policy → IP. Give the policy a descriptive name (like Allowed IPs for Service Client), then add your allowed IP addresses or CIDR ranges in the Allowed IPs field (e.g., 192.168.0.0/24 for a subnet, or 10.0.1.5 for a single IP). Save the policy.

  • Step 3: Bind the IP policy to a permission
    Next, go to Permissions in the left sidebar. Create a new Resource Permission (or Scope Permission if you want to restrict access to specific API scopes). In the policy section of the permission setup, select the IP policy you just created. Make sure the permission is applied to the relevant resources/scopes for your client, then save.

From now on, when your client uses the client_credentials flow to request a token, Keycloak will automatically check if the request’s source IP is in your allowed list. If not, it’ll reject the authorization request.

Method 2: Custom Authenticator SPI (For Advanced Scenarios)

If you need more flexible logic (like dynamic IP lists, or integrating with an external IP allowlist service), you can build a custom authenticator SPI:

  • Step 1: Add custom attributes to your client
    Go to your client’s Attributes tab and add a custom attribute (e.g., allowed_ips) with a comma-separated list of allowed IPs/ranges (e.g., 10.0.0.1,10.0.0.2/24).

  • Step 2: Build the custom authenticator
    Create a Java class that implements Keycloak’s Authenticator interface. In the authenticate method:

    1. Fetch the client’s custom allowed_ips attribute from the ClientModel.
    2. Get the source IP of the incoming request from the HttpRequest object.
    3. Validate if the request IP matches any entry in the allowed list.
    4. If validation fails, throw an AuthenticationFlowException to block the token issuance.
  • Step 3: Deploy and configure the SPI
    Package your class into a JAR file and drop it into Keycloak’s providers directory. Restart Keycloak, then go to your client’s Authentication Flow settings. Add your custom authenticator as an execution step in the client_credentials flow.

Important Note About Reverse Proxies

If you’re running Keycloak behind a reverse proxy (like Nginx or Apache), make sure to configure Keycloak to trust the proxy. This ensures Keycloak reads the real client IP from the X-Forwarded-For header instead of using the proxy’s IP address, which would break your IP restrictions.

内容的提问来源于stack exchange,提问作者Rasool Ghafari

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 14:52:54