Authentication Skills
SkillSecurityAuthentication and authorization patterns for Rossoctl services
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Authentication Skills skill
What this skill tells your AI
The instructions your AI receives, as published by rossoctl/rossoctl in .claude/skills/auth/SKILL.md and read by ahel’s review.
Skills for configuring OAuth2, Keycloak, and service-to-service authentication.
Available Skills
| Skill | Description |
|---|---|
auth:keycloak-confidential-client | Create OAuth2 clients for service-to-service auth |
auth:mlflow-oidc-auth | Configure MLflow with Keycloak OIDC + OTEL trace ingestion |
auth:otel-oauth2-exporter | Configure OTEL collector with OAuth2 |
Common Patterns
Internal vs External URLs
For service-to-service communication, prefer internal URLs:
http://keycloak-service.keycloak.svc.cluster.local:8080
This avoids TLS certificate complexity.
Client Credentials Flow
For backend services, use client credentials flow:
- Create confidential client in Keycloak
- Get token from token endpoint
- Attach bearer token to requests
Related Skills
openshift:trusted-ca-bundleistio:ambient-waypoint
Signals
- GitHub stars
- 300
- Forks
- 107
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
auth-rossoctl- Source
- github.com/rossoctl/rossoctl