Publicação
Design and Implementation of a Highly Available, Containerized, Federated Authentication Architecture Using Open-Source Technologies
| datacite.subject.fos | Engenharia e Tecnologia::Engenharia Eletrotécnica, Eletrónica e Informática | |
| datacite.subject.sdg | 09:Indústria, Inovação e Infraestruturas | |
| dc.contributor.advisor | Rodrigues, Nuno G. | |
| dc.contributor.advisor | Lopes, Rui Pedro | |
| dc.contributor.author | Hossain, Shahadat | |
| dc.date.accessioned | 2026-07-23T15:03:22Z | |
| dc.date.available | 2026-07-23T15:03:22Z | |
| dc.date.issued | 2026 | |
| dc.description.abstract | Modern enterprises demand highly available, scalable, and observable identity systems. Managed IAM services introduce vendor lock-in and recurring costs, while self-hosted alternatives often lack validated automated failover and reproducible performance evidence. This thesis presents a containerized, open-source Keycloak High-Availability (HA) IAM architecture. It combines HA Proxy for load balancing, Patroni-managed PostgreSQL for database replication, and an observability stack (Prometheus, Grafana, Loki). Provisioned via Ansible and Docker Compose, the solution ensures reproducible deployment on commodity hardware. To guarantee cluster stability within Docker networks, JDBC_PING is used for peer discovery, mitigating split-brain anomalies. Empirical evaluation via the official Keycloak Gatling benchmark demonstrates 185.7 req/s sustained throughput with sub-100 ms latency, scaling to 722.2 req/s (0% error rate) upon edge-layer vertical expansion. Failover testing under load confirms automated leader election and VIP migration, achieving recovery under 30 seconds with zero data loss. Validated within an institutional network using HARICA-issued certificates, the architecture achieves a 61% cost reduction versus managed cloud alternatives, proving to be a practical, cloud-agnostic IAM Deployment model for mid-scale enterprises. | eng |
| dc.description.abstract | As empresas modernas exigem sistemas de identidade altamente disponíveis, escaláveis e observáveis. Os serviços de IAM geridos introduzem dependência do fornecedor e custos recorrentes, enquanto soluções auto-hospedadas frequentemente carecem de failover automatizado validado e provas de desempenho reproduzíveis. Esta tese apresenta uma arquitetura IAM de Alta Disponibilidade (HA) em Keycloak, contentorizada e em código aberto. A solução integra HÁ Proxy para balanceamento, Post-greSQL gerido por Patroni para replicação e uma stack de observabilidade (Prometheus, Grafana, Loki). Provisionada via Ansible e Docker Compose, garante implementações repetíveis em hardware comercial. Para assegurar a estabilidade do cluster nas redes Docker, utiliza-se JDBC_PING na descoberta de pares, mitigando anomalias split-brain. A avaliação empírica com o benchmark Gatling oficial demonstra 185,7 req/s de taxa sustentada com latência inferior a 100 ms, escalando para 722,2 req/s (0% taxa de erro) após expansão vertical na borda. Testes de failover sob carga confirmam a eleição automática de líder e migração de VIP, recuperando em menos de 30 segundos sem perda de dados. Validada numa rede institucional com certificados emitidos pela HARICA, a arquitetura alcança 61% de redução de custos face a alternativas geridas na cloud, provando ser um modelo prático e independente da cloud para empresas de média dimensão. | por |
| dc.description.sponsorship | This work was conducted in the framework of the projects Bee3Pomics: Omics insights into molecular effects of plant protection products in honey bees (Apis mellifera) funded by the RESTART-FCT and MEDIBEES - Monitoring the Mediterranean Honey Bee Subspecies and their Resilience to Climate Change for the Improvement of Sustainable Agro-Ecosystems. MEDIBEES is part of the PRIMA program supported by the European Union. This research was also supported by national funds through FCT/MCTES (PIDDAC): CIMO UID/00690/2025 (https://doi.org/10.54499/UID/00690/2025) and UID/PRR/00690/2025 (https://doi.org/10.54499/UID/PRR/00690/2025); SusTEC, LA/P/0007/2020 (https://doi.org/10.54499/LA/P/0007/2020) | |
| dc.identifier.tid | 204330092 | |
| dc.identifier.uri | http://hdl.handle.net/10198/37031 | |
| dc.language.iso | eng | |
| dc.relation | Mountain Research Center - UID/00690/2025 | |
| dc.relation | CIMO - Mountain Research Center - UID/PRR/00690/2025 | |
| dc.relation | Associate Laboratory for Sustainability and Tecnology in Mountain Regions - LA/P/0007/2020 | |
| dc.rights.uri | http://creativecommons.org/licenses/by/4.0/ | |
| dc.subject | Keycloak | |
| dc.subject | Identity and access management | |
| dc.subject | High availability | |
| dc.subject | OpenID con- nect | |
| dc.subject | OAuth 2.0 | |
| dc.subject | HAProxy | |
| dc.subject | Patroni | |
| dc.subject | PostgreSQL | |
| dc.subject | Docker compose | |
| dc.subject | Ansible | |
| dc.subject | Infrastructure as code | |
| dc.title | Design and Implementation of a Highly Available, Containerized, Federated Authentication Architecture Using Open-Source Technologies | |
| dc.type | master thesis | |
| dspace.entity.type | Publication | |
| oaire.awardNumber | UID/00690/2025 | |
| oaire.awardNumber | UID/PRR/00690/2025 | |
| oaire.awardNumber | LA/P/0007/2020 | |
| oaire.awardTitle | Mountain Research Center - UID/00690/2025 | |
| oaire.awardTitle | CIMO - Mountain Research Center - UID/PRR/00690/2025 | |
| oaire.awardTitle | Associate Laboratory for Sustainability and Tecnology in Mountain Regions - LA/P/0007/2020 | |
| oaire.awardURI | http://hdl.handle.net/10198/35759 | |
| oaire.awardURI | http://hdl.handle.net/10198/36356 | |
| oaire.awardURI | info:eu-repo/grantAgreement/FCT/6817 - DCRRNI ID/LA%2FP%2F0007%2F2020/PT | |
| oaire.fundingStream | CIMO | |
| oaire.fundingStream | 6817 - DCRRNI ID | |
| project.funder.identifier | http://doi.org/10.13039/501100001871 | |
| project.funder.identifier | http://doi.org/10.13039/501100001871 | |
| project.funder.identifier | http://doi.org/10.13039/501100001871 | |
| project.funder.name | Fundação para a Ciência e a Tecnologia | |
| project.funder.name | Fundação para a Ciência e a Tecnologia | |
| project.funder.name | Fundação para a Ciência e a Tecnologia | |
| relation.isProjectOfPublication | b264f2c4-92d0-4975-b1d9-0d5385dd6cbb | |
| relation.isProjectOfPublication | f84eb641-171d-41b5-8664-4e3a31224386 | |
| relation.isProjectOfPublication | 6255046e-bc79-4b82-8884-8b52074b4384 | |
| relation.isProjectOfPublication.latestForDiscovery | b264f2c4-92d0-4975-b1d9-0d5385dd6cbb | |
| thesis.degree.name | Mestrado em Informática |
