Data Flow: Authentication & Authorization
How users authenticate via Keycloak OIDC and receive Kubernetes RBAC permissions from group claims.
How users authenticate via Keycloak OIDC and receive Kubernetes RBAC permissions from group claims.
RBACDefinition CRDs and Keycloak group binding.
Self-service team onboarding — namespace creation, quota assignment, Git repository scaffolding, and RBAC binding through portal UI or API.
Onboard new application teams with RBAC, namespaces, and quotas.