Ferrum Community – high-performance Keycloak-compatible authorization server

Ferrum Community Authorization Server
Introduction:
The Ferrum Community Authorization Server is an open-source authorization server created by the Russian company Vizans LLC. Written in Go (Golang) and API-compatible with Keycloak, it distinguishes itself from Keycloak and other authorization servers through significantly simpler setup and installation, superior performance and reliability, and the ability to handle a larger number of concurrent clients. While it is common practice for Russian companies seeking quick profits to simply fork an open-source project and swap out the copyright notices to create “domestic software,” Ferrum represents a commitment to a different approach: building a solution from scratch to avoid inheriting existing errors and issues. Furthermore, our solution is fully open; anyone can inspect the code to verify that it is a genuinely proprietary product, developed in alignment with our philosophy.
Features:
The Ferrum Community Authorization Server was originally developed as a supporting tool for integration testing of multi-component information security solutions, but it soon became clear that it was a valuable product in its own right. Key technical features of Ferrum include:
- Support for simple file-based data storage, ideal for small-scale systems (e.g., deployments where setting up a dedicated database is unnecessary).
Compatibility with various data storage backends (Redis is currently used for production); extending support to other storage systems is straightforward. - Flexible user data structures (the user object lacks a rigid schema, allowing developers to define custom datasets for users that can be validated via the UserInfo endpoint).
- Zero runtime dependencies; the build output is a single ~40 MB file—nothing else is required besides this executable and a configuration file.
- Minimal resource consumption: a running instance of Ferrum consumes ~25 MB of RAM, whereas Keycloak requires 100–200 MB and OpenAM will not start with less than 1 GB; this demonstrates that Ferrum is well-suited for handling large numbers of users.
- Ability to embed the authorization server directly into the code of any Go application and run the authorization server concurrently with that application.
License cost:
The Ferrum Community Authorization Server is released under the Apache 2.0 license, allowing it to be used in commercial products completely free of charge and without restrictions.
Source code repository:
The source code for the Ferrum Community Authorization Server is hosted on multiple services:
- In the repository within our organization’s GitHub account.
- On the organization’s external GitLab server (note: there is no public access to the code or documentation there).
Documentation
A brief overview of features is provided below; however, full documentation is available in the project Wiki on our internal GitLab instance (see link)
Functional capabilities of the Ferrum Community Authorization Server
- Authentication using JWT tokens
- Token refresh capability
- Retrieving user information based on the token
- User authorization in applications based on user data and role assignments
- Support for federated user integration (LDAP)