# Does anyone tried to intergate gitlab and keycloak?

**URL:** <https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905>\
**Category:** Getting advice\
**Created:** [January 10, 2020, 9:03am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905 "2020-01-10T09:03:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![lixiran](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lixiran/32/266_2.png) [@lixiran](https://forum.keycloak.org/u/lixiran)\
**Post date:** [January 10, 2020, 9:03am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/1 "2020-01-10T09:03:52Z")

</div>

I want to let gitlab use keycloak oidc login.  
gitlab version: GitLab Enterprise Edition 12.6.3-ee  
keycloak version 8.0.1  
both are using http. https is not enabled.  
I am following this guide:  
[https://docs.gitlab.com/ee/administration/auth/oidc.html](https://docs.gitlab.com/ee/administration/auth/oidc.html)

click the keycloak button on the gitlab UI, the url return 500 error [http://gitlab.test.com/users/auth/openid\_connect](http://gitlab.test.com/users/auth/openid_connect) in /var/log/gitlab/gitlab-rails/production.log. I see below error:

OpenIDConnect::Discovery::DiscoveryFailed (SSL\_connect returned=1 errno=0 state=error: wrong version number):

lib/gitlab/middleware/rails\_queue\_duration.rb:27:in `call' lib/gitlab/metrics/rack_middleware.rb:17:in ` block in call’ lib/gitlab/metrics/transaction.rb:62:in `run' lib/gitlab/metrics/rack_middleware.rb:17:in ` call’ lib/gitlab/request\_profiler/middleware.rb:17:in `call' ee/lib/gitlab/jira/middleware.rb:19:in ` call’ lib/gitlab/middleware/go.rb:20:in `call' lib/gitlab/etag_caching/middleware.rb:13:in ` call’ lib/gitlab/middleware/correlation\_id.rb:16:in `block in call' lib/gitlab/middleware/correlation_id.rb:15:in ` call’ lib/gitlab/middleware/multipart.rb:117:in `call' lib/gitlab/middleware/read_only/controller.rb:48:in ` call’ lib/gitlab/middleware/read\_only.rb:18:in `call' lib/gitlab/middleware/basic_health_check.rb:25:in ` call’ lib/gitlab/request\_context.rb:32:in `call' config/initializers/fix_local_cache_middleware.rb:9:in ` call’ lib/gitlab/metrics/requests\_rack\_middleware.rb:49:in `call' lib/gitlab/middleware/release_env.rb:12:in ` call’

---

<div class="post-metadata">

**Author:** ![micedre](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/micedre/32/31_2.png) [@micedre](https://forum.keycloak.org/u/micedre)\
**Post date:** [January 10, 2020, 9:19am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/2 "2020-01-10T09:19:03Z")

</div>

What is your gitlab configuration ?  
It seems gitlab tries to parse the discovery endpoint with https (which doesn’t seem enabled on your keycloak instance).  
Our conf is like this:

```auto
gitlab_rails['omniauth_providers'] = [
  { 'name' => 'openid_connect',
     'label' => 'keycloak',
    'args' => {
      'name' => 'openid_connect',
      'scope' => ['openid','profile'],
      'response_type' => 'code',
      # realm url      
      'issuer' => 'https://<keycloak-url>/auth/realms/<realm>',
      #Gitlab fetch all the endpoints from 
      #https://<keycloak-url>/auth/realms/<realm>/.well-known/openid-configuration
      'discovery' => true,
      'client_auth_method' => 'basic',
     #Client Configuration
      'client_options' => {
        'identifier' => 'gitlab',
        'secret' => '<client secret',
        'redirect_uri' => '<gitlab-url>/users/auth/openid_connect/callback'
      }
    }
  }
]

```

---

<div class="post-metadata">

**Author:** ![Robinyo](https://avatars.discourse-cdn.com/v4/letter/r/dec6dc/32.png) [@Robinyo](https://forum.keycloak.org/u/Robinyo)\
**Post date:** [January 10, 2020, 9:24am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/3 "2020-01-10T09:24:53Z")

</div>

> Some detail documentation on how I have setup almost single sign-on to Gitea, [Taiga.io](http://Taiga.io), Grafana, Portainer and Bookstack using Openldap and Keycloak.

See: [https://blog.exceptionerror.io/2018/08/29/openldap-keycloak-and-docker/](https://blog.exceptionerror.io/2018/08/29/openldap-keycloak-and-docker/)

---

<div class="post-metadata">

**Author:** ![lixiran](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lixiran/32/266_2.png) [@lixiran](https://forum.keycloak.org/u/lixiran)\
**Post date:** [January 10, 2020, 2:52pm UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/4 "2020-01-10T14:52:22Z")

</div>

@micedre  
thanks for reply  
actually I haven’t enable SSL for both gitlab and keycloak

is SSL mandatory ?

this is my gitlab config

gitlab\_rails[‘omniauth\_providers’] = [  
{  
‘name’ =\> ‘openid\_connect’,  
‘label’ =\> ‘keycloak’,  
‘args’ =\> {  
‘name’ =\> ‘openid\_connect’,  
‘scope’ =\> [‘openid’,‘profile’],  
‘response\_type’ =\> ‘code’,  
‘issuer’ =\> ‘[http://172](http://172)._._._:8080/auth/realm/\<_**\>’,  
‘discovery’ =\> true,  
‘client\_auth\_method’ =\> ‘query’,  
‘uid\_field’ =\> ‘preferred\_username’,  
‘client\_options’ =\> {  
‘identifier’ =\> ‘gitlab’,  
‘secret’ =\> '6de3c7ea-**\*\*\*’,  
‘redirect\_uri’ =\> ‘[http://gitlab.test.com/users/auth/openid\_connect/callback](http://gitlab.test.com/users/auth/openid_connect/callback)’

```
         }

 }

```

}  
]

---

<div class="post-metadata">

**Author:** ![lixiran](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lixiran/32/266_2.png) [@lixiran](https://forum.keycloak.org/u/lixiran)\
**Post date:** [January 12, 2020, 12:50am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/5 "2020-01-12T00:50:32Z")

</div>

@micedre  
what cert are you using for gitlab and keycloak ?  
self signed ?

---

<div class="post-metadata">

**Author:** ![lixiran](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lixiran/32/266_2.png) [@lixiran](https://forum.keycloak.org/u/lixiran)\
**Post date:** [January 12, 2020, 1:27am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/6 "2020-01-12T01:27:14Z")

</div>

@Robinyo  
thanks. are you using https or http？

---

<div class="post-metadata">

**Author:** ![micedre](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/micedre/32/31_2.png) [@micedre](https://forum.keycloak.org/u/micedre)\
**Post date:** [January 13, 2020, 6:05am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/7 "2020-01-13T06:05:59Z")

</div>

I don’t think https is mandatory, but maybe your keycloak instance force a redirection.

Your conf should be fine, is your keycloak accessible from gitlab.

For the cert, you can use self signed as long as you configure gitlab to trust it :  
[https://docs.gitlab.com/omnibus/settings/ssl.html#install-custom-public-certificates](https://docs.gitlab.com/omnibus/settings/ssl.html#install-custom-public-certificates)

---

<div class="post-metadata">

**Author:** ![lixiran](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lixiran/32/266_2.png) [@lixiran](https://forum.keycloak.org/u/lixiran)\
**Post date:** [January 13, 2020, 8:55am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/8 "2020-01-13T08:55:32Z")

</div>

thanks. dude.

I have figured that out.  
Now I am working Oauth2 part.  
I want to use keycloak to request a access\_token from gitlab. have you tried that ?

---

<div class="post-metadata">

**Author:** ![micedre](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/micedre/32/31_2.png) [@micedre](https://forum.keycloak.org/u/micedre)\
**Post date:** [January 13, 2020, 9:06am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/9 "2020-01-13T09:06:51Z")

</div>

I don’t understand, what do you want to do ?

All I am doing in addition to login from keycloak is getting the gitlabs groups from the users (and adding them as user attribute). I do it by a script mapper.

---

<div class="post-metadata">

**Author:** ![lixiran](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/lixiran/32/266_2.png) [@lixiran](https://forum.keycloak.org/u/lixiran)\
**Post date:** [January 13, 2020, 9:11am UTC](https://forum.keycloak.org/t/does-anyone-tried-to-intergate-gitlab-and-keycloak/905/10 "2020-01-13T09:11:31Z")

</div>

I have two applications.  
one is gitlab, the other is my app.  
I want to do:

1. login my app via keycloak.
2. getting all my issues from gitlab and display on the UI.

in the past, i used gitlab as oauth2 provider. my app open a oauth2 request to gitlab and gitlab will return me a access\_token. I can use access\_token to access gitlab API to get resource.

Keycloak support oauth2. so I wanna know how to do step2 via keycloak.
