How My VPA Unified Access on AWS Keycloak
Our partnership with My VPA GmbH began over five years ago when the company came to Perfsys with a specific challenge: to update and centralize its identity management system across various SaaS components. My VPA, a prominent provider of virtual personal assistance services, was using a custom authentication system developed in PHP and supported by a MySQL database. As their platform grew, new products—including the primary web application, ownCloud for file sharing, and internal management tools—required a cohesive and secure single sign-on (SSO) solution. To address this need, Perfsys created and implemented a Keycloak-based identity and access management (IAM) system hosted on Amazon Web Services (AWS). This architecture was set up on EKS (Kubernetes), utilizing RDS MySQL, EC2 instances, and Application Load Balancers to ensure scalability, performance, and high availability. A significant milestone in this project was the creation of a custom user federation provider—a specialized Keycloak extension that directly integrated Keycloak with My VPA’s existing MySQL user database. This innovation enabled My VPA to keep all existing accounts and passwords without needing to migrate or interrupt services, facilitating a seamless transition to centralized authentication. Since the initial rollout, Perfsys has consistently supported, upgraded, and optimized My VPA’s Keycloak infrastructure. The system has been enhanced through various Keycloak updates (from version 3.1 to 23), accompanied by regular maintenance cycles for Kubernetes and EC2, proactive monitoring, and security upgrades. It has been operational for over five years, scaling from hundreds to thousands of users, maintaining robust performance, and cutting IAM-related costs by almost 90% compared to SaaS options. Currently, Perfsys continues to be a vital technology partner for My VPA, ensuring their system remains secure, up-to-date, and cost-efficient as their digital services expand.