# Set up the identity subsystem

> Set up the identity subsystem, based on Keycloak

Unity Virtual Private Cloud includes an identity provider and broker component based on Keycloak. Keycloak includes these major capabilities:

* Authentication and authorization
* Storage of information about users and service accounts keys

Keycloak is included in the above deployment, but you must perform customer-specific postdeployment and administration tasks.

## 1. Access Keycloak

To access the Keycloak admin console from a browser, enter a URL in this format:

```text
https://<domain_name>/auth/admin/master/console/
```

The default user is **admin**. To retrieve the password, run this command:

```sh
kubectl get -n asset-solutions secret keycloak -o jsonpath="{.data.admin-password}" | base64 --decode
```

### Change the default admin credentials

The keycloak admin credentials are static and aren't tied to any identity provider.

When you sign in for the first time, change the default admin credentials:

1. In the Keycloak admin console, switch to the default realm, that is, the **master** realm.
2. Go to **Users**, and then select the `admin` user.
3. On the **Credentials** tab, select **Reset password**.
4. Enter a new password.
5. Turn off **Temporary**.
6. Record the credentials somewhere secure.

## 2. Complete the setup of the identity subsystem

To complete the setup of the identity subsystem, ensure that you are signed in to Keycloak, and then go to the **unity** realm.

### 2.1 Regenerate the secret for the `mini-usf` client

To regenerate the secret, complete these steps:

1. In the Keycloak admin console, switch to the **unity** realm.

2. Go to **Manage** > **Clients**, and then select the **mini-usf** client.

3. On the **Credentials** tab, select **Regenerate** next to the client secret.

4. Copy the secret to the clipboard.

5. Save the secret:

   1. Use the copied secret to redefine the **keycloak\_mini\_usf\_clientsecret** variable in the directory `aws/terraform/tfvars/{region}.tfvars`.
   2. From the directory `aws/terraform`, run this command:

   ```sh
   make apply-us-east-1
   ```

6. To restart the mini-usf pods in Kubernetes and apply the new secret, run this command:

   ```sh
   kubectl rollout restart deployment -n asset-solutions mini-usf
   ```

### 2.2 Set up the URI properties for the dashboard client

To redirect the browser back to the frontend after a successful sign-in, add a valid redirect URI.

1. Go to **Manage** > **Clients**, and then select the **dashboard** client.
2. On the **Settings** tab, modify these values:

   * Set **Root URI** to `https://<solution-domain-name>`.
   * Set **Valid redirect URIs** to `https://<solution-domain-name>/*`.
3. Select **Save**.

## 3. Perform administration tasks

1. Complete the [initial solution onboarding](/cloud/virtual-private-cloud/admin/solution-onboarding.md.md).

2. If required, [set up single sign-on (SSO)](/cloud/virtual-private-cloud/admin/single-sign-on.md.md) for the identity subsystem.

3. If you don't use SSO, then [create users](/cloud/virtual-private-cloud/admin/users-service-accounts/create-user.md.md) in Keycloak.

4. [Grant user access](/cloud/virtual-private-cloud/admin/users-service-accounts/manage-access-for-user.md.md) to the organization.

5. Optionally, configure monitoring integration in parallel or later.

After you have completed these steps, users can access the application.
