Federated data access testbed: one credential per user, valid at every member service, with the federation's centre never in the data path. Keycloak + Apache APISIX, control plane and data plane on separate hosts.
jwt oauth2 keycloak docker-compose api-gateway rate-limiting openid-connect reference-implementation wmo single-sign-on pkce federated-identity jwks rfc8628 apache-apisix meteogate identity-broker device-authorization-grant
-
Updated
Aug 25, 2026 - Shell