Historically we deployed Traefik Forward Auth for auth on all our sites and later added Keycloak. Consquently, we have a mix of sites using TFA or Keycloak and clusters that are running the Keycloak operator but still relying solely on TFA.
We should do away with TFA in favor of Keycloak for all sites. Internal sites for Posit employees can have their Keycloak instance configured with Posit Okta as the identity provider.
This will give us a consistent auth story for both internal and external facing sites.