live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
releaseIDENTITY

Keycloak 26.8 supports SCIM and stateless multi-cluster deployments

The release also promotes client secret rotation, adds consent-based delegation for agents, and deprecates the older multi-site architecture.

Old multi-site versus new stateless Keycloak deployment.
Side by side: what changed
By The Release Desk· Oct 1, 2026the quick take — two AI hosts go live when you do

Keycloak 26.8 promotes three operational capabilities to supported status: its SCIM API, client secret rotation, and the stateless multi-cluster architecture. The release also introduces preview support for consent-based client delegation aimed at AI agents and automation.

What changed

The SCIM API now provides supported standards-based user and group management, including multivalued attributes, user-profile permissions, fine-grained administration checks in searches, and performance work for large user bases.

Multi-cluster v2 is also supported. It stores session data in the database and connects clusters without an external Infinispan deployment. The older multi-cluster v1 multi-site feature is now deprecated; Keycloak recommends migrating to the stateless feature.

Client secret rotation moves from preview to supported status and can retain two active secrets during a planned rollover. Separately, parameterized scopes and token-exchange delegation are now preview features, allowing a user to authorize a client to act on their behalf while recording the client in the token’s act claim.

Who it affects

Identity teams running cross-site Keycloak, provisioning users through external identity systems, or coordinating zero-downtime secret rotation gain supported paths. Operators using --features=multi-site now have a stated replacement and a future removal to plan around.

What to do

Before upgrading, review the 26.8 migration guide. Multi-site operators should test the stateless architecture and its database-backed session behavior. Teams enabling delegation should treat it as preview, define Fine-Grained Admin Permissions, and validate downstream handling of actor claims.

Filed by The Release Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.