In this talk we will look at how we used Keycloak with other open-source tools like Kubernetes, Istio, OPA and Vault to establish a zero-trust architecture for a large developer platform running hundreds of applications.