Skip to content
Carolina Code Conference
Served by F* (OCaml Unix) in 30ms

2026 speaker

Benjamin Overcash

Benjamin Overcash

System Architect

I am a System Architect and Full Stack Developer. I’ve been with CoLinx, LLC since 2008. My professional focus has been on e-commerce and web application development and I’ve always had a passion for security and authentication.

In my free time I am a maker. I love tinkering with old computers and electronics and my most recent obsession is the Z80 CPU.

2026 · lightning

Integrating Keycloak

The CoLinx Journey: Modernizing Identity in a Complex Ecosystem Since 2020, CoLinx, LLC—a joint venture providing IT solutions for competing manufacturing groups—has been on a journey to modernize authentication. This talk outlines how we integrated Keycloak into a long-established e-commerce platform with tens of thousands of users and complex legacy permissions, moving from static security to a robust, OIDC-compliant “Trust Service.”

Key Topics & Architectural Strategies:

Why Keycloak? A look at why we chose Keycloak over SaaS giants like Auth0 and Okta, focusing on extensibility through Java SPIs to meet complex business logic and on-premise requirements.

The “Pass-Through” Migration: How to avoid high-risk “lift-and-shift” migrations using Federated User Providers. We draw a box around login/password steps while leaving existing user storage intact, allowing for a phased transition.

Decoupling AuthN from AuthZ: A deep dive into our core philosophy: treating Keycloak strictly as an Identity Authentication Platform while reframing legacy systems as Authorization Platforms. This split simplifies OIDC adoption by clearly limiting scopes.

Identity Brokering & Multi-Tenancy: Leveraging Realms to silo users by tenancy and using Keycloak as an Identity Broker to bridge external SSOs, corporate ADs, and owner platforms safely.

Zero-Secret Transmission: How we replaced static API keys with Service Accounts using the JWT Authorization Grant flow (RFC 7523). We’ll discuss the security benefits of asymmetric trust, where credentials are never transmitted, only proven via signed, short-lived tokens.

Hard-Won Lessons from the Field: We wrap up with a “Practitioner’s Checklist” of effective security and deployment practices:

Container Security: Managing custom base images to maximize deployment velocity and CVE response.

Deep Extensions: Moving beyond themes by extending Form Providers and REST APIs to integrate with existing localization and CMS platforms.

The Ecosystem Pivot: A critical warning on the abandoned Keycloak Java Servlet Filter and the move toward modern alternatives like Spring Security and Nimbus.

Who this talk is for: Developers and architects looking to modernize identity in “brownfield” environments where data sovereignty, complex tenancy, and high-stakes security are non-negotiable.

From the talk