# KubeCon + CloudNativeCon Japan — Schedule

Machine-readable mirror of the schedule page. Generated 2026-10-11.

- Source: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/
- Sessions: 15 across 1 days
- Times are the event's local times, exactly as published. Timing and rooms are subject to change.
- Each session links back to the schedule page, which opens that session's details.

## Tracks

- Keynote Sessions (4)
- Breakout Sessions (4)
- Lightning Talks (3)
- Registration (2)
- Breaks (1)
- Experiences (1)

## Tuesday, July 28, 2026

### 08:00–18:00 · Badge Pick-Up

- Room: 2F l Foyer
- Track: Registration
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226657

### 08:00–18:30 · Cloakroom

- Room: 1F l Foyer
- Track: Registration
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226658

### 09:00–09:10 · Welcome + Opening Remarks

- Room: 3F l 313+314
- Speakers: Alexander Schwartz
- Track: Keynote Sessions
- Labels: Any
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226612
- Slides: https://sessionize.com/download/kzacfek~N1Vvq7NaM7gYKhEVcVaLnZ.pdf~keycloakcon-japan-2026-opening-remarks.pptx.pdf

### 09:15–09:40 · Keycloak + Sigstore: Binding Human Identity to Artifact Signatures

- Room: 3F l 313+314
- Speakers: Oshi Gupta, Sagar Utekar
- Track: Breakout Sessions
- Labels: Any, Securing Applications and Cloud Native Infrastructure with Keycloak
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1191305
- Slides: https://sessionize.com/download/ivladyey~4rZWWKACWip1yUBZWWHSTD.pdf~keycloackcon-japan-2026.pdf

Most teams treat signing and identity as two separate problems. Sigstore handles your artifact signatures. Keycloak handles your users. Nobody asks whether the person who triggered that signed build is actually who the signature claims they are.

That gap matters more than people realize.

In this talk we will walk through how we wired Keycloak directly into Sigstore's keyless signing flow as the OIDC provider — so every artifact signature is cryptographically bound to a verified human or service identity that lives in your own identity infrastructure, not GitHub's, not Google's. Your keys, your trust root, your audit trail.

We'll cover the exact Fulcio configuration that makes this work, how Keycloak realm and client setup maps to Sigstore's identity claims, and the operational realities nobody documents — token expiry during long builds, claim mapping mismatches that silently break verification, and how to handle service identities for automated pipelines alongside human developer identities in the same trust domain.

If you care about knowing not just what was signed but who actually signed it and whether that person had the right to — this talk is for you.

### 09:45–10:10 · Simple Control: Managing Multi-Domain MCP Access via Keycloak IdP with ID-JAG

- Room: 3F l 313+314
- Speakers: Yutaka Obuchi
- Track: Breakout Sessions
- Labels: Intermediate, Keycloak and AI
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1206038

As enterprises adopt the Model Context Protocol (MCP) for autonomous AI agents, a critical gap emerges: the fragmentation of Granular Authorization Governance.
In complex environments, AI clients must act for users across Cross-Trust Domains. However, the current landscape delegates authorization logic entirely to individual MCP servers, making centralized oversight impossible. Relying on these server-specific security silos is inherently unscalable.

This session introduces a robust architecture using Keycloak as the central IdP to issue Identity Assertion JWT Authorization Grants (ID-JAG). By externalizing authorization from MCP servers to Keycloak, we enable secure Identity Chaining. Keycloak cryptographically attests that a user authorized an agent for specific actions, ensuring fine-grained, context-aware permissions are consistently propagated downstream.

Beyond the blueprint, we deep dive into the technical implementation using Keycloak's Token Exchange Provider. Through a live demo, we showcase how to extend Keycloak to generate signed ID-JAG assertions, bridging identity across trust boundaries.

### 10:15–10:20 · Sponsored Keynote | Midships Global: You Don't Need a New Identity Platform for the AI Era

- Room: 3F l 313+314
- Speakers: Yuxiang Lin
- Track: Keynote Sessions
- Labels: Any
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226622

Enterprises are deploying AI agents at speed — systems that act autonomously, call APIs, access sensitive data, and make consequential decisions on behalf of users and organizations. With that shift comes an identity problem that
is not yet being discussed with the clarity it deserves: who authorized the agent, on whose behalf is it acting, what is it permitted to access, and how is that access revoked when something goes wrong?
The dominant response in the market is to reach for a new tool. A purpose-built AI identity vendor. Another platform, another dependency, another contract.
This keynote makes the case that the response is wrong — and expensive. The core primitives of agentic identity already exist in Keycloak: OAuth 2.0 token delegation and exchange, fine-grained scope enforcement, service account management, short-lived credentials, policy-based access control, and audit trails that trace machine actions back to human authorization. These are not features on a roadmap. They are in production today.
Drawing on real implementation experience building agentic identity architectures on Keycloak, this session argues that the enterprises that get the AI era right will be those that build on identity foundations they already own and control — not those that accumulated a new vendor dependency for every new architectural shift.

### 10:25–10:30 · Sponsored Keynote | Hitachi: OSS Contribution Empowers AI in Social Infrastructure and Services

- Room: 3F l 313+314
- Speakers: Takashi Norimatsu
- Track: Keynote Sessions
- Labels: Any
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226624

Modern AI is no longer limited to chatbots for general users or coding agents for software developers; it is also beginning to be applied in the field of social infrastructure, such as transportation systems and energy.

At the same time, today’s AI relies heavily on open source software (OSS). Therefore, contributing to, promoting, and maintaining OSS is essential for the widespread adoption and sustainability of AI in social infrastructure.

In this context, Hitachi, which is deeply involved in the AI field, is actively working to contribute to and promote OSS, thereby supporting the expansion and sustainability of AI.

Furthermore, these efforts contribute to enhancing the presence of Japanese companies in the AI domain.

Why not work together to build and promote reliable, safe, and enterprise-grade AI through contributions to the AI field?

### 10:30–10:40 · Coffee Break

- Room: 3F l 311+312
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226638

### 10:40–10:50 · Lightning Talk: What Is New and Coming for Managing Cloud-Native Identities in Keycloak

- Room: 3F l 313+314
- Speakers: Alexander Schwartz
- Track: Lightning Talks
- Labels: Beginner, New and noteworthy features in Keycloak
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1205464
- Slides: https://sessionize.com/download/ipcawmeu~K78pvQPGzduBygvW1N37At.pdf~what-is-new-and-coming-for-managing-cloud-native-identities-in-keycloak.pdf

Identities are the key to accessing applications and their data, and Keycloak is a leading tool to meet the needs of the cloud-native ecosystem.

This talk highlights how to use the features Keycloak already supports, what’s new, and what we are working on.

This ranges from machine identities and how to leverage SPIFFE/SPIRE or Kubernetes service account tokens, authenticating humans with strong authentication like Passkeys, or synchronizing user and groups across domains and applications via SCIM.

Join this session to see Keycloak's features in a demo and how they can help you building a capable cloud-native platform for your organization!

### 11:00–11:25 · MCPIdentity: Keyless MCP Agent Authentication Patterns on Kubernetes with Keycloak 26.6

- Room: 3F l 313+314
- Speakers: Mustafa Dayıoğlu
- Track: Breakout Sessions
- Labels: Intermediate, Keycloak and AI
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1206194
- Slides: https://sessionize.com/download/ibcapsen~f6T6DuQDyKUJbrnMeyy9C9.pdf~mcp-agents-identity-kubecon-japan-keycloakcon-2026.pdf

MCP agents on Kubernetes authenticate with static credentials — client secrets as files, API keys in environment variables, ServiceAccount tokens on disk. Every pod carries extractable key material that survives restarts and requires manual rotation.

MCPIdentity eliminates static keys in two layers. Layer 1 (runtime identity): SPIRE attests each pod and issues short-lived JWT-SVIDs in memory — ServiceAccount token mount disabled, no key touches disk. DPoP binds every token to the pod's in-memory keypair, blocking replay. Layer 2 (agent registration): agents publish CIMD documents so Keycloak registers them by URL — no admin creates a client, no secret is provisioned. OPA enforces a trust matrix per tool call. Standard Keycloak and SPIRE extension points — no core modifications.

Two agents, two servers, four namespaces — zero credential files, zero human-created Keycloak clients. Two CIMD gaps filed upstream with reproducer scripts and a three-tier threat model.

This is not a generic agent security talk — it is an upstream-compatible Keycloak 26.6 pattern for MCP workload identity, validated on Kubernetes, with two concrete CIMD feedback items for the Keycloak community.

### 11:30–11:40 · Lightning Talk: Using Keycloak Authorization Service for Kubernetes Service-to-Service Authorization

- Room: 3F l 313+314
- Speakers: Halil Özkan
- Track: Lightning Talks
- Labels: Advanced, Securing Applications and Cloud Native Infrastructure with Keycloak
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1206124
- Slides: https://sessionize.com/download/hmavsey~ngG7K4h4VBLkBV7uHKM5AH.pdf~keycloakcon-japan-2026-keycloak-authorization-services-for-kubernetes-slides-and-notes.pdf

Modern Kubernetes environments often centralize identity but still leave service-to-service authorization spread across
application code, gateway rules, and proxy-specific configuration. This session presents a practical pattern for using
Keycloak Authorization Services as a centralized authorization control plane while enforcing decisions at the platform
layer instead of inside each application.

The talk shows how Kubernetes workloads can remain unchanged while a mesh-level Policy Enforcement Point evaluates HTTP
requests using workload identity, request metadata, and centrally managed policy. The architecture uses Istio Ambient
mode, waypoint proxies, a WebAssembly-based enforcement extension, and a Keycloak-backed decision flow.

The session also covers allow and deny behavior, fail-closed handling, bypass-prevention requirements, observability
with OpenTelemetry, and the latency and reliability trade-offs that appear when Keycloak participates in the live
authorization path. A live demo shows both the enforcement path and the operational signals it produces.

### 11:45–11:55 · Lightning Talk: Surviving Certificate Expiry in Enterprise Keycloak: Per-Client Key Rotation

- Room: 3F l 313+314
- Speakers: Hiroyuki Wada
- Track: Lightning Talks
- Labels: Intermediate, Managing Keycloak upgrades and availability, and automating IT operations
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1206177
- Slides: https://sessionize.com/download/iqbakher~3vECMPgn2eZcGSaxyYwLvb.pdf~surviving-certificate-expiry-in-enterprise-keycloak.pdf

Keycloak's built-in key generation produces realm signing certificates with a hardcoded 10-year expiry. For organizations that adopted Keycloak in the late 2010s using these generated keys, that expiry is now on the horizon. In enterprise environments with many OIDC and SAML integrations, rotating the realm key all at once is extremely risky. OIDC standardizes key discovery via JWKS endpoints, enabling automatic rotation in most cases. For SAML, although metadata URLs exist, automatic key refresh is rarely adopted in practice, so certificate updates are almost always manual — and even some OIDC integrations rely on manual key configuration. One missed update means a production outage.

Keycloak manages signing keys only at the realm level, making gradual migration impossible. This talk explores why realm key rotation is so painful at scale and introduces a proposed upstream solution: per-client signing key selection for OIDC and SAML (PR #47277: https://github.com/keycloak/keycloak/pull/47277), enabling administrators to migrate clients one by one with minimal risk.

### 12:00–12:25 · Securing Non-Human Identities: A Defense-in-Depth Blueprint for AI Agents

- Room: 3F l 313+314
- Speakers: Tatsuya Yano
- Track: Breakout Sessions
- Labels: Intermediate, Keycloak and AI
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1205771
- Slides: https://sessionize.com/download/isjalney~MdRqvkTN3E5x6BkBFZFBSf.pdf~keycloakcon-japan-2026-securing-non-human-identities.pdf

The rise of AI agents and the MCP is revolutionizing autonomous system interactions. However, it introduces a severe security flaw: the "Confused Deputy" problem. When an AI agent executes tasks on behalf of a human, traditional service-to-service authentication often drops the original user's context, potentially granting the agent excessive permissions to access unauthorized data.

This session, will demystify "Identity Chaining" - a robust architectural pattern designed to solve this critical flaw, and will explore how to seamlessly propagate user intent across microservices and agents using the emerging "ID-JAG" (Identity Assertion JWT Authorization Grant) standard alongside "RFC 8693 Token Exchange."

Drawing from massive-scale web service implementations powering LINE and Yahoo! JAPAN, we showcase a Single Source of Truth (SSoT) design. While IdP-agnostic, we demonstrate unifying CNCF Keycloak (User) with CNCF Athenz (Workload) to build a zero-trust AI architecture.

### 12:25–12:30 · Keynote: Closing Remarks

- Room: 3F l 313+314
- Speakers: Yoshiyuki Tabata
- Track: Keynote Sessions
- Labels: Any
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1226626

### 17:00–18:15 · Reception | Sponsored by Octopus Deploy

- Room: 3F l 311+312
- Track: Experiences
- Labels: Any
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/?id=1264809

Join us for drinks and appetizers with your fellow speakers and attendees. All attendees of ArgoCon + KeycloakCon are welcome.

