The platform maps Keycloak groups to managed Kubernetes namespaces and uses each namespace as the shared home for a group’s services and workloads. The platform team builds and maintains the access rules, workload identities, network controls, resource limits, approved configurations, monitoring, and cleanup attached to each namespace. New packs and services can use this common platform design instead of creating a separate security and operations model each time. Based on the same group-to-tenant mapping, the platform gives each service a dedicated Kubernetes identity and project-scoped AWS IAM role. EKS Pod Identity, STS, S3 policies, and KMS then enforce what that service can access.
Identity + authorization plane
PeopleUsersBrowser clients
Identity providerKeycloakOIDC login · full group paths
Data authorizationGeneric data catalogMetadata · grants · durable references