realmlint

Keycloak fixes

Keycloak fix · medium

Who changed this Keycloak setting? Turning on admin events

Keycloak does not record configuration changes by default. Here is how to turn on admin events, read them, and keep them from filling your database.

realmlint check admin-events-disabledKeycloak 26Updated

A client's redirect URIs changed, or a user suddenly has realm-admin, and nobody remembers doing it. Keycloak can tell you who did, but only if admin events were already switched on when it happened. They are off by default in every new realm.

What realmlint reports

  MEDIUM    Admin events are not saved [admin-events-disabled]
            - admin events are not saved
  LOW       Login events are not saved [login-events-disabled]
            - user events are not saved

If admin events are on but Include representation is off, realmlint reports it as low: you can see who changed something, but not what they changed it to.

Turn on admin events

  1. Open the realm and go to Realm settings, then the Events tab.
  2. Open Admin events settings and turn on Save events.
  3. Turn on Include representation, so each event records the new configuration as well as the fact that it changed.
  4. Set an Expiration, for example 90 days, then click Save. Without one, events are kept forever in Keycloak's database.
  5. While you are there, open User events settings and turn on Save events for logins too, with its own expiration.
  6. Repeat for every realm, including master.

Read them

Go to Events in the left-hand menu and open the Admin events tab. Each event shows the time, the Resource path (for example clients/<id>), the Operation type (create, update or delete) and who made the change: the realm, client, user ID and IP address. With representation turned on, you can open the event to see the new configuration.

The event shows the user's ID rather than their username. Search for that ID under Users in the realm the admin logged in to, usually master.

Admin events only cover changes made through the admin console and admin REST API. Realms imported at startup, changes made directly in the database, and anything that happened before you switched them on are not recorded.

Fix it in a realm file

{
  "realm": "myrealm",
  "adminEventsEnabled": true,
  "adminEventsDetailsEnabled": true,
  "eventsEnabled": true,
  "eventsExpiration": 7776000
}

eventsExpiration is in seconds and applies to user events. Set the admin events expiration in the admin console.

Check it worked

kc.sh export --realm myrealm --file myrealm.json
realmlint check myrealm.json

To see what changed between two points in time, export again later and compare the two files:

realmlint diff myrealm-before.json myrealm-after.json

The diff tells you what changed. The admin events tell you who changed it.