WilliamLam.com

  • About
    • About
    • Privacy
  • VMware Cloud Foundation
    • VMware Cloud Foundation 9.1
    • VMware Cloud Foundation 9.0
  • VKS
  • Homelab
    • Hardware Options
    • Hardware Reviews
    • Lab Deployment Scripts
    • Nested Virtualization
    • Homelab Podcasts
  • VMware Nostalgia
  • Apple

Configuring OIDC with PKCE in Keycloak for VCF Private AI Services

08.26.2026 by William Lam // Leave a Comment

I have taken a short hiatus from playing with my NVIDIA RTX 4000, which fits perfectly inside a Minisforum MS-A2 and is what I use to run VMware Cloud Foundation (VCF) 9.1. While redeploying my environment to test an upcoming release of VCF Private AI Services (PAIS), I was reminded that the deployment requires an OIDC provider that supports the Authorization Code grant flow with PKCE (Proof Key for Code Exchange).

When I originally deployed PAIS with VCF 9.0, I used Authentik as my identity provider (IdP). With my VCF Infrastructure Services (VIS) Appliance which provides a number of services including Keycloak as an OIDC provider, I wanted to figure out the required Keycloak configuration to satisfy the PAIS OIDC requirements, especially as this can help accelerate Lab/PoC deployments.

After some trial and error, and with the help of OpenAI Codex to debug my live environment, I now have Keycloak successfully configured with PAIS, along with a script to generate the access token required to interact with a PAIS Model Endpoint! 🥳

[Read more...]

Categories // Private AI Services, VMware Cloud Foundation Tags // PAIS, VCF 9.1

Quick Tip - When using self-signed TLS Certificates with VCF Private AI Services (PAIS)

09.10.2025 by William Lam // Leave a Comment

Like many of our users, I was excited to hear that VMware Private AI Services (PAIS) will now be included as part of VMware Cloud Foundation (VCF), I already had some ideas brewing in my head and I definitely needed to get some hands on!

While setting up some of the requirements for PAIS, I ran into a couple of issues that revolved around the use of self-signed TLS certificates, which is probably common for many of  you, especially in a lab/proof of concept environment.

I spent good chunk of the day debugging the issues, which was not even the worse part, but it was the error messages that we saw. The error messages was not from the product code, but rather the underlying libraries that it relies upon and if you try to interpret the message as-is, you could go down a rabbit hole.

PAIS Engineering is already aware of the issues I ran into, so these will be enhanced in future updates but I did want to share the scenarios in case you run into them while deploying PAIS in your environment.

[Read more...]

Categories // Private AI Services, VMware Cloud Foundation Tags // PAIS

Search

Thank Author

Author

William is Distinguished Platform Engineering Architect in the VMware Cloud Foundation (VCF) Division at Broadcom. His primary focus is helping customers and partners build, run and operate a modern Private Cloud using the VMware Cloud Foundation (VCF) platform.

Connect

  • Bluesky
  • Email
  • GitHub
  • LinkedIn
  • Reddit
  • RSS
  • Twitter
  • Vimeo

Recent

  • 10 Exciting Enhancements in VMware Cloud Foundation 9.1.1 09/03/2026
  • VCF 9.1.1: Adopting the Reduced VCF Management Services (VCFMS) Footprint After an Upgrade 09/03/2026
  • Configuring OIDC with PKCE in Keycloak for VCF Private AI Services 08/26/2026
  • VCF 9.1 - Understanding VCF Converge & Import Scenarios for vCenter Server Without NSX 08/24/2026
  • VCF 9.1 - Configuring Harbor to use VCF Identity Broker (IDB) for External Identity Federation 08/19/2026
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.

To find out more, including how to control cookies, see here: Cookie Policy

Copyright WilliamLam.com © 2026