49

Update your Keycloak

For community, version 26.7.2 has the fix:
https://www.keycloak.org/2026/08/keycloak-2672-released

top 10 comments
sorted by: hot top new old
[-] plateee@piefed.social 16 points 1 day ago

This one is bad - unauthenticated user account take over.

If you're like me and only using it internally on a homelab, the risks are lessened, but if you expose keycloak to by the Internet - boy howdy

[-] iamthetot@piefed.ca 7 points 1 day ago

Out of curiosity, what is the advantage of using something like this on LAN only?

[-] plateee@piefed.social 3 points 1 day ago

For me, I have multiple OIDC compatible systems (Proxmox, Netbox, Synology, Zabbix, Vault, etc).

So keycloak offers a SSO option to make my life easier with a single account to worry about instead of individual ones.

Plus MFA because it's cool?

[-] Dunstabzugshaubitze@feddit.org 11 points 1 day ago

for many people homelabbing is a way to gain knowledge they can use on the job.

other than that: proper single sign on across your services is nice even if you don't expose them to anybody else.

[-] B0rax@feddit.org 4 points 1 day ago

It will still sync to all devices. And if you have an always on vpn to your home network, there really is no need to expose it to the public

[-] possiblylinux127@lemmy.zip 3 points 1 day ago

Not being impacted by security issues like these for one

[-] NarrativeBear@lemmy.world 2 points 1 day ago* (last edited 1 day ago)

When you host something on LAN only you are not exposing the service to the wider internet directly.

This means someone would need access to your LAN or local area network first (such as your WiFi password) before being able to reach said service.

Now when you expose something directly to the internet, in a way that for example it displays a publicly accessible webpage, it makes it easier for anyone to reach that webpage, and potentially figure out your login and password information through brute force. Or some other type of exploit that allows full bypass of the login credentials.

Some self-hoster's choose to keep their "more sensitive" services on the LAN only, and then use a VPN (that's hosted privately) to access their LAN remotely from anywhere in the world.

With a VPN hosted on your LAN it provides a good layer of security as someone would first need to have access to your VPN to then potentially try and get access into your services.

[-] iamthetot@piefed.ca 3 points 1 day ago

I appreciate you taking the time to write this out, but I knew all of that and didn't really address the question. I was asking why the commenter above mine was using an auth service, like Keycloak, on LAN.

It has been answered a few times, thanks.

[-] NarrativeBear@lemmy.world 3 points 1 day ago* (last edited 1 day ago)

No worries, not sure how I misunderstood the question, but hopefully it helps someone else out who's getting into self-hosting.

[-] exu@feditown.com 6 points 1 day ago

Especially in an enterprise environment where plenty of people use first.lastname@company

this post was submitted on 25 Aug 2026
49 points (98.0% liked)

Selfhosted

61734 readers
399 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS