keycloak plugin for Tutor
Local Keycloak IdP for developing Open edX SAML SSO without a real IdP.
Development only: adds a keycloak service to tutor dev, never to tutor local.
- Keycloak container, auto-imported realm (default
openedx) with a SAML client for the LMS. - SAML attributes released:
firstName,lastName,email,username,attr_user_permanent_id(attr_user_permanent_idis the Keycloak user ID, so self-registered users work too). - Test user (default
testuser/tutor config printvalue KEYCLOAK_TEST_PASSWORD). keycloak-setupdo-command (dev only) creating the SAML SP config +keycloakIdP provider (attribute mapping included) and pulling IdP metadata.
pip install tutor-contrib-keycloaktutor plugins enable keycloak
tutor config save
tutor dev launch
tutor dev do keycloak-setup # SAML provider in the LMS; needs Keycloak upThen:
- Keycloak admin: http://auth.local.openedx.io:8080 (
admin/tutor config printvalue KEYCLOAK_ADMIN_PASSWORD) - LMS login: http://local.openedx.io:8000/auth/login/tpa-saml/?auth_entry=login&idp=keycloak
- SP metadata: http://local.openedx.io:8000/auth/saml/metadata.xml
*.local.openedx.io resolves to 127.0.0.1; the compose network alias makes the same
hostname work from inside the LMS container (needed to fetch IdP metadata).
KEYCLOAK_DOCKER_IMAGE |
quay.io/keycloak/keycloak:26.4 |
KEYCLOAK_HOST / KEYCLOAK_PORT |
auth.{{ LMS_HOST }} / 8080 |
KEYCLOAK_REALM |
openedx |
KEYCLOAK_SP_ENTITY_ID |
openedx |
KEYCLOAK_REGISTRATION_ALLOWED |
true |
KEYCLOAK_ADMIN_USER / _PASSWORD |
admin / generated |
KEYCLOAK_TEST_USER / _PASSWORD |
testuser / tutor config printvalue KEYCLOAK_TEST_PASSWORD |
KEYCLOAK_USERNAME_ATTR |
username |
KEYCLOAK_PERMANENT_ID_ATTR |
attr_user_permanent_id |
KEYCLOAK_REGISTRATION_ALLOWEDshows a "Register" link on the Keycloak login page.- Permanent ID: the LMS links an IdP identity to an account by this value. If the IdP sends no such attribute the login
fails (
Invalid value for parameter attr_user_permanent_id). SetKEYCLOAK_PERMANENT_ID_ATTRto an empty string to let the LMS fall back to theuidOID attribute, then the SAML NameID (this client uses NameID formatusername, so a renamed user would look like a new person;persistentis safer). Re-runtutor dev do keycloak-setupafter changing it.
This software is licensed under the terms of the AGPLv3.