Locke is a drop-in Keycloak distribution that runs Keycloak's caching on Redis instead of an embedded JGroups cluster. Same admin console, same datenbank, one switch (KC_CACHE=redis).
What is Locke
Locke is the upstream Keycloak codebase plus one thing: a Redis cache backend behind a single switch. Same SPIs, same admin console, same datenbank schema. Flip it back and you have ordinary Keycloak.
Wechseln Sie KC_CACHE=infinispan|redis beim Boot. Keine Code-Änderungen, keine Migration.
Voll Open Source: Standard-Keycloak plus Redis Cache Backend, nichts weggesperrt.
Funktioniert mit jedem Managed Redis. Colocated oder extern leistet dasselbe.
Keine Cluster Discovery, Split-Brain-Handling oder State Transfer. Redis koordiniert.
The benchmark
Ein 3-Instanzen-Produktionscluster, Kopf an Kopf. Durchsatz ist ausgeglichen. Der Unterschied zeigt sich in dem Moment, wenn eine Node ausfällt.
| Load (logins/sec) | Stock / Infinispan | Locke / Redis | Parity |
|---|---|---|---|
| 80 | 274 req/s | 274 req/s | 100% |
| 160 | 548 req/s | 548 req/s | 100% |
| 250 | 856 req/s | 856 req/s | 100% |
Balken verwenden eine komprimierte Skala, um Locke sichtbar zu halten; die Lücke beträgt ~15-34x. Wenn eine Infinispan-Node stirbt, stockt der Cluster bei einem JGroups-Rebalance und State Transfer. Locke serviert weiter von Redis.
3-Instanzen-Cluster, Keycloak 26.6.1, start --optimized, keycloak-benchmark Gatling AuthorizationCode Flow. Vollständige Methodik im Report.
Why it matters
A lost node is a sub-second blip, not a 31-second JGroups rebalance stall that hangs authentifizierung mid-incident.
Across an Infinispan-version boundary the recommended Keycloak path is a brief planned restart; Locke can do that same Upgrade as a rolling update because there is no JGroups version handshake. Keycloak doesn't guarantee no-downtime minor Upgrades in general, so this is one fewer constraint, not a blanket promise.
Richten Sie Keycloak auf das Managed Redis aus, das Sie bereits betreiben und überwachen. Keine JGroups Discovery, kein State Transfer, ein verteiltes System weniger zu betreiben.
Quick start
Führen Sie das Locke-Image im Produktionsmodus aus und richten Sie es auf Ihr Redis.
The honest part
An honest trade. Moving local caches to Redis adds a few milliseconds of read latency at moderate load (both stay under 170ms p99 to 250 logins/sec). And Redis does not raise Keycloak's realm-count ceiling. That limit is datenbank-bound, not cache-bound. We benchmark these things and say so.
Open Source, Apache 2.0, im Produktionsmodus gebenchmarkt.