← All case studiesCase study 03 / Treetracker by Greenstand

Auditable identity without replacing the identity provider.

Bringing Keycloak authentication and Hyperledger Fabric identity operations together for Greenstand’s TreeTracker platform.

Role
DevSecOps Engineer
Organization
Greenstand · Remote
Scope / period
November 2023 – December 2025
Explore the live Treetracker map

The context

Treetracker is Greenstand’s open-source reforestation platform. Its live web map lets visitors explore registered tree captures from global clusters down to individual trees.

The identity integration aimed to support secure, auditable access across applications and organizations. Hyperledger Fabric provides a permissioned ledger for traceable records. Authentication microservices connect that capability to application access.

The integration connected conventional authentication with Fabric identity operations. Keycloak remained the identity provider while the blockchain services handled enrollment, wallets and ledger interactions.

Identity flow from Keycloak through a protected API to Fabric CA enrollment and the Fabric ledger.KeycloakJWT + RBACFabric CAFabric ledger
Simplified identity relationship. Protected APIs validate JWTs and enforce RBAC before invoking enrollment or ledger operations.

My contribution

Built and upstreamed the Keycloak–Fabric identity bridge. The work covered JWT authentication, RBAC on protected endpoints, Fabric CA enrollment, wallet management and container security configuration.

Designed and operated a multi-organization Fabric network with certificate authorities, peers, a RAFT ordering service, channel governance and CouchDB state databases.

Led delivery onto Kubernetes with Argo CD GitOps, GHCR image publishing and Kustomize overlays. Added security checks to CI/CD and documented recovery procedures.

Engineering decisions

01. Preserve a familiar identity layer

Bridging Keycloak and Fabric retained an established authentication workflow while adding the required blockchain identity operations.

02. Make deployment declarative

GitOps made desired state explicit. Kustomize overlays kept environment differences reviewable.

03. Treat operations as a deliverable

Recovery, credential and persistence runbooks helped make the platform understandable to a changing contributor base.

The outcome

The identity bridge was merged upstream. Platform delivery became declarative, traceable and reversible with Kubernetes and GitOps.

Tools & evidence

Hyperledger FabricKeycloakJWT / RBACTypeScriptNode.jsKubernetesArgo CDKustomizePostgreSQLCouchDB

Contribution and operating scope are drawn from my project record. The linked repositories provide the surrounding open-source context.

NEXT CASE STUDYKubernetes platform library
Let's start a conversation

What are you trying
to keep running?

Have a role or a project in mind?
Tell me what you’re working on.

North Carolina, USAOpen to remote opportunities

Send me a message

Minimum 10 characters.

Privacy Policy