# configuration-management

A management process for establishing and maintaining the integrity of information technology products and systems by controlling configuration changes throughout the system development life cycle.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Fedora Forge Usage Policy

DevFeed: [Fedora Forge Usage Policy](<https://devfeed.tech/articles/fedora-forge-usage-policy-31154.md>)

Original publisher: [Read original article](<https://communityblog.fedoraproject.org/fedora-forge-usage-policy/>)

Author: amoloney

Published: 2026-07-30T12:11:59Z

Content type: article

Language: en

Sources: [Fedora Community Blog](<https://devfeed.tech/sources/fedora-community-blog.md>)

Topics: [Fedora](<https://devfeed.tech/topics/fedora.md>), [forgejo](<https://devfeed.tech/topics/forgejo.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [release engineering](<https://devfeed.tech/topics/release-engineering.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [fedora-project-community](<https://devfeed.tech/tags/fedora-project-community.md>), [forge](<https://devfeed.tech/tags/forge.md>), [forgejo](<https://devfeed.tech/tags/forgejo.md>), [governance](<https://devfeed.tech/tags/governance.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [policy](<https://devfeed.tech/tags/policy.md>), [release-engineering](<https://devfeed.tech/tags/release-engineering.md>)

### AI overview

The Fedora Council is opening a minimum two-week public feedback period for a proposed Fedora Forge Usage Policy. The policy defines the Fedora Forge, a Forgejo instance operated by Fedora Infrastructure, as project infrastructure for hosting Fedora code, documentation, and tooling rather than a general-purpose public Git host.

### Source excerpt

After extensive review and discussion on the ticket request and in recent council meetings (see meetbot for 29 July and 15 July 2026), the Fedora Council would like to initiate the policy change policy process for ratifying the Fedora Forge Usage policy. This document is open to public feedback (if any) for a minimum of [...] The post Fedora Forge Usage Policy appeared first on Fedora Community Blog.

## Training Orchestrator: Unifying Model Training at Yelp

DevFeed: [Training Orchestrator: Unifying Model Training at Yelp](<https://devfeed.tech/articles/training-orchestrator-unifying-model-training-at-yelp-27429.md>)

Original publisher: [Read original article](<https://engineeringblog.yelp.com/2026/07/training-orchestrator-unifying-model-training-at-yelp.html>)

Author: Ying Wang and Nathan Sponberg, Software Engineer

Published: 2026-07-14T00:00:00Z

Content type: article

Language: en

Sources: [Yelp](<https://devfeed.tech/sources/yelp.md>)

Topics: [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Apache Spark](<https://devfeed.tech/topics/spark.md>), [Training AI Models](<https://devfeed.tech/topics/training-ai-models.md>), [Model Development](<https://devfeed.tech/topics/model-development.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [mlflow](<https://devfeed.tech/tags/mlflow.md>), [model-training](<https://devfeed.tech/tags/model-training.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [spark](<https://devfeed.tech/tags/spark.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

Yelp's Core Machine Learning Team developed Training Orchestrator to standardize how machine learning teams define and run Spark-based model training. The configuration-driven system addresses duplicated code, inconsistent configurations, limited local testing, scattered validation and monitoring, and poor reproducibility across environments.

### Source excerpt

At Yelp, we train many machine learning models on different schedules. Applied machine learning teams all have their own set of Spark-based training batches, scripts, and configurations. Over time, these diverged, leading to duplicated code, subtle inconsistencies, and a growing maintenance burden. Yelp's Core Machine Learning Team has developed excellent tooling across our ML ecosystem over the years: feature stores for reproducible data, a unified training library for neural networks and gradient-boosted trees, seamless Spark integration, and MLflow services for model tracking and deployment. But there was still one key piece missing right in the middle: a standardized way to...

## How to Apply NIST 800-53 to AI Systems

DevFeed: [How to Apply NIST 800-53 to AI Systems](<https://devfeed.tech/articles/how-to-apply-nist-800-53-to-ai-systems-29772.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/nist-800-53-ai-systems/>)

Author: info@goteleport.com (Matthew Smith)

Published: 2026-03-13T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [audit](<https://devfeed.tech/topics/audit.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Security](<https://devfeed.tech/topics/security.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [audit](<https://devfeed.tech/tags/audit.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [nist](<https://devfeed.tech/tags/nist.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains how NIST SP 800-53 applies to AI and agentic systems. It focuses on how autonomous systems complicate existing security controls and introduces Access Control, Audit and Accountability, and Configuration Management as starting points for further risk assessment.

### Source excerpt

Learn to apply NIST 800-53 to agentic systems and AI infrastructure with control guidance on identity, auditing, configuration management, and monitoring.

## How Klarna Built Cloud Inventory for AWS Configuration Management

DevFeed: [How Klarna Built Cloud Inventory for AWS Configuration Management](<https://devfeed.tech/articles/how-i-stopped-worrying-and-learned-to-love-cloud-inventory-35649.md>)

Original publisher: [Read original article](<https://engineering.klarna.com/how-i-stopped-worrying-and-learned-to-love-cloud-inventory-723cd3c49d46?source=rss----86090d14ab52---4>)

Author: Maxim Savin

Published: 2025-06-06T06:38:06Z

Content type: article

Language: en

Sources: [Klarna Engineering](<https://devfeed.tech/sources/klarna-engineering.md>)

Topics: [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [digital](<https://devfeed.tech/topics/digital.md>)

Tags: [automated](<https://devfeed.tech/tags/automated.md>), [aws](<https://devfeed.tech/tags/aws.md>), [change-management](<https://devfeed.tech/tags/change-management.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [cloud-inventory-software](<https://devfeed.tech/tags/cloud-inventory-software.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [engineering-management](<https://devfeed.tech/tags/engineering-management.md>), [lead-time](<https://devfeed.tech/tags/lead-time.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [logs](<https://devfeed.tech/tags/logs.md>), [rds](<https://devfeed.tech/tags/rds.md>), [security](<https://devfeed.tech/tags/security.md>), [snapshots](<https://devfeed.tech/tags/snapshots.md>), [technical-change](<https://devfeed.tech/tags/technical-change.md>)

### AI overview

Klarna describes Cloud Inventory, an ecosystem of services for collecting, normalizing, mapping, and serving information about ICT assets across its cloud infrastructure. The article explains how it supports configuration management through automated controls and reports faster control rollout and large-scale infrastructure optimization work.

### Source excerpt

A long time ago, as a punishment for his crimes, Hades, the king of the underworld, made Sisyphus roll a huge enchanted boulder endlessly up a steep hill. Since then, many tech companies have learned to do that at scale by the hardships of cloud configuration management. Consider an Engineer who wants to ensure that the data that moves through their system is encrypted along the way. This is a noble goal, and to achieve it they must identify every classic load balancer in their AWS environment to replace it with an application load balancer that enforces encryption in transit. Now imagine doing that at the scale of a company like Klarna, where teams collectively own more than a thousand AWS accounts? Add to this a multitude of other configuration challenges -- databases that have not been deployed in a multi-availability zone set-up, missing Cloudwatch logs, expired digital certificates, systems running on unsupported framework versions -- the list is endless. Identifying and rectifying violating cloud assets often feels like an endless game of whack-a-mole played blindfolded. This is the steep price tech companies pay to operate their systems securely and confidently, day by day. Klarna Engineering Platform (KEP) has been on a mission to facilitate configuration management for Klarna Engineers. After a few iterations we have built an ecosystem of Klarna services designed to collect, normalize, map, and serve data on ICT assets within Klarna's cloud infrastructure. We call this system Cloud Inventory. Over the last few months Klarna has: Rolled out over 100 automated controls enhancing every aspect of our configuration management (security, governance, and operational excellence), each control aimed to help system owners to identify and fix violations quickly. Reduced the lead time of rolling out a control from several weeks to a matter of minutes And as a result, successfully completed several large-scale cloud infrastructure optimization projects, such as a company-

## Unlocking Flexibility in Configuration: The Power of Hydra

DevFeed: [Unlocking Flexibility in Configuration: The Power of Hydra](<https://devfeed.tech/articles/unlocking-flexibility-in-configuration-the-power-of-hydra-20392.md>)

Original publisher: [Read original article](<https://tech.olx.com/unlocking-flexibility-in-configuration-the-power-of-hydra-3f9e69263bb4?source=rss----761b019b483f---4>)

Author: Catarina Goncalves

Published: 2025-06-02T17:02:34Z

Content type: tutorial

Language: en

Sources: [OLX](<https://devfeed.tech/sources/olx.md>)

Topics: [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Sorting](<https://devfeed.tech/topics/sorting.md>), [recommendation systems](<https://devfeed.tech/topics/recommendation-systems.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Python](<https://devfeed.tech/topics/python.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [hydra](<https://devfeed.tech/tags/hydra.md>), [integration](<https://devfeed.tech/tags/integration.md>), [project-organization](<https://devfeed.tech/tags/project-organization.md>), [python](<https://devfeed.tech/tags/python.md>), [ranking](<https://devfeed.tech/tags/ranking.md>), [search](<https://devfeed.tech/tags/search.md>), [sorting](<https://devfeed.tech/tags/sorting.md>)

### AI overview

OLX describes centralizing Learning to Rank projects and adopting Hydra to manage configuration across teams and repositories. The article introduces Hydra's hierarchical organization, runtime command-line overrides, optimization-tool integration, and Python usage.

### Source excerpt

As software systems continue to grow in complexity, the demand for effective configuration management tools becomes not just important but essential. Our work on Learning to Rank (LTR) projects exemplifies this challenge. At OLX we use LTR to improve the search results based on their relevance. This involves training models to rank ads based on various features, ensuring that the most relevant ones appear at the top of the list. The resulting sorting can be found under the 'Recommended Ads' option, the default option currently live on our OLX websites in several countries. Given the potential to enhance user experience and increase engagement -- while balancing the visibility of paid (boosted) ads-- this approach is also being tested in other business units, such as Motors and Real Estate. More projects meant increased complexity, with multiple repositories holding various configuration files. These projects were spread across different teams and repositories, leading to duplicated efforts and repeated issues for similar tasks. This growing redundancy pushed the team to centralize all LTR projects within a single repository. We quickly recognized the need to enhance the experience for Data Scientists and Machine Learning Engineers who would work directly with this new centralized framework. Enter Hydra. Hydra -- The configuration tool Developed and maintained by Facebook AI Research, Hydra stands out when it comes to configuration management. It empowers developers with a sophisticated yet easy-to-use solution that simplifies even the most complex configuration setups. With features such as hierarchical organization, runtime command-line overrides, and seamless integration with optimization tools like Optuna, Hydra offers flexibility and efficiency. These qualities made Hydra the ideal choice for our project, and we have successfully integrated it to enhance our configuration management workflow. And don't worry too much about a learning curve -- Hydra has extensive doc

## What is Koreo?

DevFeed: [What is Koreo?](<https://devfeed.tech/articles/what-is-koreo-23009.md>)

Original publisher: [Read original article](<https://bravenewgeek.com/what-is-koreo/>)

Published: 2025-05-08T15:12:33Z

Content type: article

Language: en

Sources: [Brave New Geek](<https://devfeed.tech/sources/brave-new-geek.md>)

Topics: [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>), [Helm charts](<https://devfeed.tech/topics/helm-charts.md>), [VPC](<https://devfeed.tech/topics/vpc.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [controllers](<https://devfeed.tech/tags/controllers.md>), [devops](<https://devfeed.tech/tags/devops.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [helm](<https://devfeed.tech/tags/helm.md>), [helm-charts](<https://devfeed.tech/tags/helm-charts.md>), [iac](<https://devfeed.tech/tags/iac.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [koreo](<https://devfeed.tech/tags/koreo.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [orchestration](<https://devfeed.tech/tags/orchestration.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [resource-orchestration](<https://devfeed.tech/tags/resource-orchestration.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

This article explains Koreo, an open-source platform engineering toolkit for Kubernetes. It describes Koreo's approach to Kubernetes configuration management and resource orchestration, and compares it with Helm and Kustomize, including their limitations for complex or dependent deployments.

### Source excerpt

The platform engineering toolkit for Kubernetes Last month we open sourced Koreo, our "platform engineering toolkit for Kubernetes." Since then, we've seen a lot of interest from folks in the platform engineering and DevOps space. We've also gotten a lot of questions from people trying to better understand how Koreo fits into an already crowded landscape of Kubernetes tools. Koreo is a fairly complex tool, so it can be difficult to quickly grasp just what exactly it is_,_ what problems it's designed to solve, and how it compares to other, similar tools. In this post, I want to dive into these topics and also discuss the original motivation behind Koreo.

## Keycloak Adopts Terraform Provider

DevFeed: [Keycloak Adopts Terraform Provider](<https://devfeed.tech/articles/keycloak-adopts-terraform-provider-31678.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/12/terraform-provider-adoption>)

Author: Thomas Darimont

Published: 2024-12-09T00:00:00Z

Content type: release

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [terraform provider](<https://devfeed.tech/topics/terraform-provider.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [migration](<https://devfeed.tech/topics/migration.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>)

Tags: [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [cve](<https://devfeed.tech/tags/cve.md>), [go](<https://devfeed.tech/tags/go.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [migration](<https://devfeed.tech/tags/migration.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>)

### AI overview

Keycloak announces that the Keycloak Terraform Provider has moved under the Keycloak organization. The article identifies new maintainers, describes required configuration migration, announces an Apache 2.0 license change, and previews maintenance and 5.0 releases.

### Source excerpt

New Repository Location We're excited to announce that the Keycloak Terraform Provider has officially moved under the Keycloak organization! You can find the new repository location here. The Journey So Far Thanks to our community survey, we confirmed that the Keycloak Terraform Provider by mrparkers is the most widely used tool for realm configuration management. The move to the Keycloak organization is a natural next step in making this essential tool a core part of the Keycloak ecosystem. Gratitude and Transition A huge thank-you to mrparkers for creating and maintaining the provider. Your contributions have been invaluable to the community. The new maintainers, Sebastian Schuster and Thomas Darimont, will ensure the project continues to thrive. Migration Notes You'll need to update your configurations to migrate to the Keycloak-hosted Terraform Provider. Check out our migration guide, especially the replace-provider instructions, to make the process smooth. Updates and Changes License Change: The Keycloak Terraform Provider now uses the Apache 2.0 license, ensuring broader adoption and clarity for contributors. Next releases: 4.5 Maintenance Release: Includes CVE fixes, Go upgrade, and license change. 5.0 Release (Upcoming): Adds support for Keycloak 24/26, new features, and improvements. Join the Community We're grateful for all contributors who've helped make the Terraform Provider what it is today. We welcome new contributions, issue reports, feature suggestions, and fixes. Let's work together to make it even better! Explore the new repository location, join the discussions, and help shape the future of the Keycloak Terraform Provider.

## What is Ansible? A brief history

DevFeed: [What is Ansible? A brief history](<https://devfeed.tech/articles/what-is-ansible-a-brief-history-30711.md>)

Original publisher: [Read original article](<https://www.windmill.dev/blog/ansible-history>)

Author: Henri Courdent

Published: 2024-11-29T00:00:00Z

Content type: article

Language: en

Sources: [Windmill Blog](<https://devfeed.tech/sources/windmill-blog.md>)

Topics: [Ansible](<https://devfeed.tech/topics/ansible.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Deployment](<https://devfeed.tech/topics/deployment.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [automation](<https://devfeed.tech/tags/automation.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [devops](<https://devfeed.tech/tags/devops.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This article traces Ansible's history and explains how its agentless, SSH-based, YAML-driven approach simplified configuration management, application deployment, and IT task automation.

### Source excerpt

A brief history of Ansible, the tool that makes it easy to automate infrastructure.

## Keycloak Realm Configuration Management Tools Survey Results

DevFeed: [Keycloak Realm Configuration Management Tools Survey Results](<https://devfeed.tech/articles/keycloak-realm-configuration-management-tools-survey-results-31658.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/09/realm-config-management-tools-survey-results>)

Author: Thomas Darimont

Published: 2024-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [terraform provider](<https://devfeed.tech/topics/terraform-provider.md>), [API](<https://devfeed.tech/topics/api.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>)

Tags: [code-completion](<https://devfeed.tech/tags/code-completion.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [management](<https://devfeed.tech/tags/management.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [realm](<https://devfeed.tech/tags/realm.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [validation](<https://devfeed.tech/tags/validation.md>)

### AI overview

The Keycloak project reports results from a community survey on realm configuration management tools, based on 433 responses. The Terraform Keycloak Provider received about 51% of votes, and the five most-used tools accounted for 84% of responses. Respondents also identified challenges involving Admin API usability, configuration change detection, release compatibility, automatically created components, linting, validation, and code completion.

### Source excerpt

Three months ago, the Keycloak project conducted a survey to gather insights on realm configuration tooling within our community. The number of responses overwhelmed us! With a total of 433 (!) submissions, it highlighted the diverse range of options our community uses for configuring realms. Thank You for your valuable feedback! Popular Tools in Use The survey revealed a variety of tools employed by the community for realm configuration, including: Terraform Provider for Keycloak Keycloak-Config-CLI Self-developed Realm Configuration Management Keycloak JSON Import/Export Keycloak Admin CLI kcadm.sh EPAM Keycloak Operator Keycloak Ansible Keycloak Pulumi Custom Operator for Realm Import/Update and Client Provisioning Keycloak Operator Realm Import via Custom Resources Crossplane Provider for Keycloak KeycloakMigration keycloak-configurator Keycloak Groovy Helpers Tool Usage Distribution From the submissions, we observed the following distribution of tool usage among respondents: Terraform Keycloak Provider ~51% of the votes Keycloak-Config-CLI ~16% of the votes Self-developed Realm Configuration Management ~7% of the votes Keycloak JSON Realm Import/Export ~6% of the votes Keycloak Admin CLI ~4% of the votes These top five tools accounted for 84% of all responses. Areas for Improvement While each tool has its strengths and weaknesses, the survey highlighted several common challenges: Using the Admin API can be awkward and inconsistent, for example, with references using IDs versus aliases. Recognizing changes in the configuration, such as when new roles are added to service accounts via the Admin UI, can be challenging or impossible. Many tools depend heavily on the Keycloak version used and are often not compatible with new releases. Managing components that are automatically created by Keycloak, like service accounts, is challenging with existing configuration tools. Lack of support for configuration linting, validation and code completion What's Next? Based on t

## Survey on Keycloak Realm Configuration Management Tools

DevFeed: [Survey on Keycloak Realm Configuration Management Tools](<https://devfeed.tech/articles/survey-on-keycloak-realm-configuration-management-tools-31649.md>)

Original publisher: [Read original article](<https://www.keycloak.org/2024/06/realm-config-manamagemtn-tools-survey>)

Author: Thomas Darimont

Published: 2024-06-25T00:00:00Z

Content type: article

Language: en

Sources: [Keycloak Blog](<https://devfeed.tech/sources/keycloak-blog.md>)

Topics: [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Keycloak](<https://devfeed.tech/topics/keycloak.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [DevOps](<https://devfeed.tech/topics/devops.md>), [Tool](<https://devfeed.tech/topics/tool.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [devops](<https://devfeed.tech/tags/devops.md>), [github](<https://devfeed.tech/tags/github.md>), [idm](<https://devfeed.tech/tags/idm.md>), [kerberos](<https://devfeed.tech/tags/kerberos.md>), [keycloak](<https://devfeed.tech/tags/keycloak.md>), [ldap](<https://devfeed.tech/tags/ldap.md>), [management](<https://devfeed.tech/tags/management.md>), [openid-connect](<https://devfeed.tech/tags/openid-connect.md>), [saml](<https://devfeed.tech/tags/saml.md>), [sso](<https://devfeed.tech/tags/sso.md>), [survey](<https://devfeed.tech/tags/survey.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

Keycloak asks its community to complete a survey about tools for managing Realm configurations. The survey covers configuration-as-code options including Keycloak Admin CLI, Keycloak-Config-CLI, Terraform Provider for Keycloak, Ansible, Pulumi, Crossplane, JSON import/export, the Keycloak Operator, custom resources, and manually managed configurations.

### Source excerpt

Numerous options exist for managing Keycloak Realm configurations within the Keycloak ecosystem. We know that configuration as code is an essential topic for DevOps and that the Keycloak ecosystem needs an excellent solution to make this possible. As the Keycloak team, we want to understand better what works best for the community and how we can improve the support for Realm configuration Management tools. So that we in the Keycloak community have a representative picture of the configuration options used, we would also like you to participate in the following brief, anonymous survey. The options that exist on our radar are as follows: Keycloak Admin CLI kcadm.sh Keycloak-Config-CLI Terraform Provider for Keycloak Keycloak Ansible Pulumi Keycloak Provider Crossplane Keycloak Provider Keycloak JSON Import / Export Keycloak Operator Realm Import via Custom Resources Hand-made Realm Configuration Management Join the related discussion on GitHub to discuss this in more details with the Keycloak community. And don't forget to fill out the survey! Thank you very much for your support!

## Issuing and using SSH Certificates

DevFeed: [Issuing and using SSH Certificates](<https://devfeed.tech/articles/issuing-and-using-ssh-certificates-37850.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/ssh-certificates/>)

Author: Carlos Alexandro Becker

Published: 2022-11-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [certificates](<https://devfeed.tech/topics/certificates.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [docker](<https://devfeed.tech/tags/docker.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This tutorial explains how SSH certificates let administrators control access to servers without managing authorized keys. It covers creating a Certificate Authority key pair, issuing short-lived user certificates, using certificates with private keys, and testing the setup with OpenSSH in Docker.

### Source excerpt

SSH certificates allow system administrators to SSH into machines without having to manage authorized keys in the servers.

## A Configuration-Management Approach to Building DUM-E-Inspired Robots

DevFeed: [A Configuration-Management Approach to Building DUM-E-Inspired Robots](<https://devfeed.tech/articles/dum-e-and-u-35163.md>)

Original publisher: [Read original article](<https://blog.jessfraz.com/post/dum-e-and-u/>)

Published: 2021-01-22T19:17:58Z

Content type: tutorial

Language: en

Sources: [Jessie Frazelle](<https://devfeed.tech/sources/jessie-frazelle.md>)

Topics: [Robotics](<https://devfeed.tech/topics/robotics.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Redis](<https://devfeed.tech/topics/redis.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>)

Tags: [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [docker](<https://devfeed.tech/tags/docker.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [redis](<https://devfeed.tech/tags/redis.md>), [robotic-arm](<https://devfeed.tech/tags/robotic-arm.md>), [robotics](<https://devfeed.tech/tags/robotics.md>)

### AI overview

This article explores how to build DUM-E-inspired workshop robots using a manufacturing configuration-management approach. It introduces ROS, Elementary Robotics' atom OS, Redis messaging, Docker-based component packaging, cameras, sensors, and machine learning, then begins outlining a fire-extinguisher robot.

### Source excerpt

DUM-E ("dummy") and U ("you") are the names of the robot arms in the Iron Man movies. After watching this movie for the n-teenth time, I have a strong urge to also have robotic arms in a workshop like Tony Stark. You can see the value of the robots clearly throughout the movie. The robots allow Tony to produce suits more quickly, help test the suits, and provide periodic comedic relief. At one point, DUM-E even saves Tony's life. As a bit of a thought experiment, I considered what it would take to get the same functionality in reality. What this ends up leading to is a configuration management system for manufacturing, much like a build system. This post is going to outline that a bit! The most popular open-source framework for building robots is ROS (Robotics Operating System). You can add different components like cameras or sensors and program all the functionality you need for your specific use case. The underlying infrastructure works by passing messages, through a pub/subsystem. Elementary Robotics created their own OS called atom. It's pretty cool, it uses Redis for the messaging layer and docker for packaging and defining the individual components. Need a camera on your robot? Include the camera container in your atom OS config file. You can then pipe the messages from the camera into machine learning in another container. It's important to know the basics of these frameworks to continue into how we would build DUM-E and U. Let's dive in. The end goal here is to be as productive as Tony Stark at building things. Fire extinguisher robot One of my favorite scenes with DUM-E is when Tony is testing the suits and it's DUM-E's job to blast him with a fire extinguisher when he is on fire. For comic relief in the movie, DUM-E messes this up a bunch and blasts Tony when he's not on fire. Let's break this down, starting with a robot that will shoot a fire extinguisher on any fire. First, what you would need is the robotic arm base, maybe you build your own, maybe it'

## The architecture of declarative configuration management

DevFeed: [The architecture of declarative configuration management](<https://devfeed.tech/articles/the-architecture-of-declarative-configuration-management-21948.md>)

Original publisher: [Read original article](<https://blog.nelhage.com/post/declarative-configuration-management/>)

Author: Nelson Elhage

Published: 2019-11-12T22:00:00Z

Content type: article

Language: en

Sources: [Nelson Elhage](<https://devfeed.tech/sources/nelson-elhage.md>)

Topics: [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Puppet](<https://devfeed.tech/topics/puppet.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Amazon EC2](<https://devfeed.tech/topics/amazon-ec2.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [code](<https://devfeed.tech/tags/code.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [data](<https://devfeed.tech/tags/data.md>), [declarative](<https://devfeed.tech/tags/declarative.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [interface](<https://devfeed.tech/tags/interface.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [plugins](<https://devfeed.tech/tags/plugins.md>), [puppet](<https://devfeed.tech/tags/puppet.md>), [state](<https://devfeed.tech/tags/state.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

This article presents a conceptual model of declarative configuration management tools. It explains how these tools represent a desired system state, compare it with the current state, and update the system to match. The article also describes resource schemas as a core architectural layer and discusses examples including Puppet, Chef, Terraform, and Kubernetes.

### Source excerpt

With the ongoing move towards "infrastructure-as-code" and similar notions, there's been an ongoing increase in the number and popularity of declarative configuration management tools. This post attempts to lay out my mental model of the conceptual architecture and internal layering of such tools, and some wishes I have for how they might work differently, based on this model. Background: declarative configuration management Declarative configuration management refers to the class of tools that allow operators to declare a desired state of some system (be it a physical machine, an EC2 VPC, an entire Google Cloud account, or anything else), and then allow the system to automatically compare that desired state to the present state, and then automatically update the managed system to match the declared state.

## Object Storage Use Cases Part 1: NFS Server Backups to cPouta S3

DevFeed: [Object Storage Use Cases Part 1: NFS Server Backups to cPouta S3](<https://devfeed.tech/articles/object-storage-use-cases-part-1-nfs-server-backups-to-cpouta-s3-19762.md>)

Original publisher: [Read original article](<https://cloud.blog.csc.fi/2018/04/object-storage-use-cases-part-1-nfs.html>)

Author: Jukka Nousiainen (noreply@blogger.com)

Published: 2018-04-24T11:20:00Z

Content type: tutorial

Language: en

Sources: [CSC - IT Center For Science - Cloud Team](<https://devfeed.tech/sources/csc-it-center-for-science-cloud-team.md>)

Topics: [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [Server](<https://devfeed.tech/topics/server.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [ceph](<https://devfeed.tech/topics/ceph.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [API](<https://devfeed.tech/topics/api.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [backups](<https://devfeed.tech/tags/backups.md>), [ceph](<https://devfeed.tech/tags/ceph.md>), [object-storage](<https://devfeed.tech/tags/object-storage.md>), [storage](<https://devfeed.tech/tags/storage.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

This tutorial presents a backup design for NFS shares hosted on a cPouta virtual machine, with backups scheduled to cPouta object storage. It discusses encrypting data before it reaches shared storage, using ZFS, Ansible, S3, and Ubuntu 16.04, and considers failure domains and storage redundancy.

### Source excerpt

After releasing object storage in cPouta, we've been asked quite a lot about various use cases. Thus we're starting a blog series to showcase some of them. Premise A popular design pattern for Pouta users is to host a data storage NFS server in the default project network and back it up to a host on their campus or home organization network. In similar fashion, in this blog post we will be enabling NFS shares from a cPouta Virtual Machine and scheduling backups to cPouta object storage. Since the demand to process biomedical and other types of sensitive data in cloud computing platforms is increasing, we also try to cater for these kind of scenarios by choosing a model where data is encrypted before it lands on any kind of shared storage. The reader is expected to be somewhat familiar with the following concepts: NFS which is used for file sharing within project network ZFS which is used as encrypting file storage Ansible which is used for configuration management S3 as the chosen API for uploading objects. The operating system used in the examples is Ubuntu 16.04. Failure domains One of the most important things to take into account when designing any kind of backup scheme are the failure domains of the underlying systems and services. In cPouta, users can store data in several locations, which map to several failure domains: standard persistent volumes on highly redundant Ceph block storage standard VM root disks on highly redundant Ceph block storage Highly redundant Ceph object storage RAID1 root disks of gpu VM flavors RAID0 root disks of hpc-gen1, hpc-gen2 and io flavors RAID0 ephemeral disks of io flavors Furthermore, all of these resources are currently in the single availability zone called nova. In our scheme, active NFS server data will reside on a dedicated persistent volume. Backups will go to object storage. As for redundancy, currently all backing Ceph pools are configured to replicate three copies of each block or object. Targeted data locations are

## Configuration management - How to start testing your salt formulas

DevFeed: [Configuration management - How to start testing your salt formulas](<https://devfeed.tech/articles/configuration-management-how-to-start-testing-your-salt-formulas-27949.md>)

Original publisher: [Read original article](<https://tech.trivago.com/post/2016-10-12-configuration-management-start-testing-saltstack/>)

Author: Marc Siebeneicher Follow

Published: 2016-10-12T00:00:00Z

Content type: tutorial

Language: en

Sources: [Trivago](<https://devfeed.tech/sources/trivago.md>)

Topics: [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [saltstack](<https://devfeed.tech/topics/saltstack.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [test](<https://devfeed.tech/topics/test.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>)

Tags: [also](<https://devfeed.tech/tags/also.md>), [backend](<https://devfeed.tech/tags/backend.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [devops](<https://devfeed.tech/tags/devops.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [salt](<https://devfeed.tech/tags/salt.md>), [testing](<https://devfeed.tech/tags/testing.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This tutorial explains why trivago began testing SaltStack formulas as its configuration repository grew in complexity. It describes common problems, including YAML syntax errors, incorrect conditions, template issues, networking problems, state-order issues, and logical changes, and motivates automated testing for pull requests.

### Source excerpt

Configuration management tools have recently gained a lot of popularity. At trivago we use SaltStack to automate our infrastructure. As the complexity of configuration files and formulas is increasing, we need a fast, reliable way to test our changes.

## Writing custom modules for Ansible

DevFeed: [Writing custom modules for Ansible](<https://devfeed.tech/articles/writing-custom-modules-for-ansible-22362.md>)

Original publisher: [Read original article](<http://www.afronski.pl/2016/03/28/writing-custom-modules-for-ansible.html>)

Author: Wojtek Gawroński (afronski)

Published: 2016-03-28T19:00:00Z

Content type: tutorial

Language: en

Sources: [Wojtek Gawroński](<https://devfeed.tech/sources/wojtek-gawronski.md>)

Topics: [Ansible](<https://devfeed.tech/topics/ansible.md>), [modules](<https://devfeed.tech/topics/modules.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>), [Erlang](<https://devfeed.tech/topics/erlang.md>), [JSON](<https://devfeed.tech/topics/json.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [Scripting](<https://devfeed.tech/topics/scripting.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [automation](<https://devfeed.tech/tags/automation.md>), [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [canvas](<https://devfeed.tech/tags/canvas.md>), [clojure](<https://devfeed.tech/tags/clojure.md>), [code](<https://devfeed.tech/tags/code.md>), [commands](<https://devfeed.tech/tags/commands.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [css](<https://devfeed.tech/tags/css.md>), [css3](<https://devfeed.tech/tags/css3.md>), [erlang](<https://devfeed.tech/tags/erlang.md>), [html](<https://devfeed.tech/tags/html.md>), [html5](<https://devfeed.tech/tags/html5.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [json](<https://devfeed.tech/tags/json.md>), [modules](<https://devfeed.tech/tags/modules.md>), [mono](<https://devfeed.tech/tags/mono.md>), [net](<https://devfeed.tech/tags/net.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [programming](<https://devfeed.tech/tags/programming.md>), [scripting](<https://devfeed.tech/tags/scripting.md>), [sicp](<https://devfeed.tech/tags/sicp.md>), [vagrant](<https://devfeed.tech/tags/vagrant.md>), [webgl](<https://devfeed.tech/tags/webgl.md>)

### AI overview

This tutorial explains Ansible modules, including their role in remote infrastructure management, YAML-based declarative configuration, dependencies on the provisioned machine, and JSON input/output requirements. It then introduces a case study for implementing a custom module in Erlang to process XML status pages.

### Source excerpt

Writing custom modules for Ansible Introduction What is Ansible and what is a module? If you are a big fan of automation, if you are focused on spreading and building software in line with DevOps culture, tools related with automation / configuration management like Chef or Ansible are probably well known to you. From the other hand that what differentiates those tools is a topic for a next blog post. Without diving into those differences, let's briefly zoom into details for those people which do not know what Ansible and modules are. Ansible is a free-software platform for configuring and managing machines. It combines deployment, ad-hoc tasks execution and configuration management. This tool uses YAML and declarative way of defining steps, which are modifying state of your fleet. Module is a single piece of those steps, a well defined way of executing certain tasks on the remote infrastructure. It executes commands, and communicates by outputting JSON to standard output - it means that it can be written in any programming or scripting language. Development Before we'll start actual implementation we need to know how it works underneath. Requirements If you want to write a custom module, we stated above that you have to be aware of two things. Your module code will be executed on the provisioned machine, so all dependencies which your module requires, have to be there. Second, your module communicates over specific input and output protocols. It uses certain syntax for sending input parameters (either sent as a stdin or a file) and JSON protocol which will be consumed as an output of the module. And nothing more - any other, non-JSON compliant output will be treated as an error, and would not be consumed by Ansible properly. Case Study We would like to consume XMLified status pages and do certain actions based on checked and exposed facts, scraped from aforementioned place. Because I like Erlang, I will use that language to implement that module. We will do it usin