Keycloak

skycloak_update_cluster_security

Update a cluster's edge-security configuration. Only the sections you provide are changed; CAPTCHA settings are preserved. Supports IP allow-listing, rate limiting, WAF, geo-blocking, and bot management.

Remote skycloak/keycloak-mcp

Remote (network-hosted)

Other tools also called skycloak_update_cluster_security? See providers with this name

Input Schema


            {
  "type": "object",
  "properties": {
    "waf": {
      "type": [
        "null",
        "object"
      ],
      "required": [
        "enabled",
        "mode",
        "preset",
        "paranoia_level"
      ],
      "properties": {
        "mode": {
          "type": "string",
          "description": "enforcement: detect or block (case-insensitive)"
        },
        "preset": {
          "type": "string",
          "description": "rule set: full_crs, owasp_top_10, or custom (case-insensitive)"
        },
        "enabled": {
          "type": "boolean"
        },
        "categories": {
          "type": [
            "null",
            "object"
          ],
          "required": [
            "cross_site_scripting",
            "data_leakage",
            "java_attacks",
            "local_file_inclusion",
            "php_injection",
            "protocol_attacks",
            "protocol_enforcement",
            "remote_code_execution",
            "remote_file_inclusion",
            "session_fixation",
            "sql_injection",
            "webshell_detection"
          ],
          "properties": {
            "data_leakage": {
              "type": "boolean"
            },
            "java_attacks": {
              "type": "boolean"
            },
            "php_injection": {
              "type": "boolean"
            },
            "sql_injection": {
              "type": "boolean"
            },
            "protocol_attacks": {
              "type": "boolean"
            },
            "session_fixation": {
              "type": "boolean"
            },
            "webshell_detection": {
              "type": "boolean"
            },
            "cross_site_scripting": {
              "type": "boolean"
            },
            "local_file_inclusion": {
              "type": "boolean"
            },
            "protocol_enforcement": {
              "type": "boolean"
            },
            "remote_code_execution": {
              "type": "boolean"
            },
            "remote_file_inclusion": {
              "type": "boolean"
            }
          },
          "additionalProperties": false
        },
        "paranoia_level": {
          "type": "integer"
        }
      },
      "description": "web application firewall settings",
      "additionalProperties": false
    },
    "cluster_id": {
      "type": "string",
      "description": "the cluster ID"
    },
    "geo_blocking": {
      "type": [
        "null",
        "object"
      ],
      "required": [
        "enabled",
        "mode",
        "countries"
      ],
      "properties": {
        "mode": {
          "type": "string",
          "description": "how the countries list is applied: allowlist or blocklist (case-insensitive)"
        },
        "enabled": {
          "type": "boolean"
        },
        "countries": {
          "type": [
            "null",
            "array"
          ],
          "items": {
            "type": "string"
          }
        }
      },
      "description": "country-based access control",
      "additionalProperties": false
    },
    "rate_limiting": {
      "type": [
        "null",
        "object"
      ],
      "required": [
        "enabled"
      ],
      "properties": {
        "enabled": {
          "type": "boolean"
        },
        "global_rpm": {
          "type": "integer"
        },
        "per_ip_rpm": {
          "type": "integer"
        },
        "endpoint_limits": {
          "type": [
            "null",
            "array"
          ],
          "items": {
            "type": "object",
            "required": [
              "path",
              "rpm"
            ],
            "properties": {
              "rpm": {
                "type": "integer"
              },
              "path": {
                "type": "string"
              }
            },
            "additionalProperties": false
          }
        }
      },
      "description": "request-rate ceilings",
      "additionalProperties": false
    },
    "bot_management": {
      "type": [
        "null",
        "object"
      ],
      "required": [
        "enabled",
        "mode",
        "challenge_mode"
      ],
      "properties": {
        "mode": {
          "type": "string",
          "description": "enforcement: detect or block (case-insensitive)"
        },
        "enabled": {
          "type": "boolean"
        },
        "challenge_mode": {
          "type": "string",
          "description": "challenge to serve: none, javascript, or captcha (case-insensitive)"
        }
      },
      "description": "bot detection and challenge settings",
      "additionalProperties": false
    },
    "ip_access_control": {
      "type": [
        "null",
        "object"
      ],
      "required": [
        "path_rules"
      ],
      "properties": {
        "path_rules": {
          "type": [
            "null",
            "array"
          ],
          "items": {
            "type": "object",
            "required": [
              "path"
            ],
            "properties": {
              "path": {
                "type": "string"
              },
              "allowed_ips": {
                "type": [
                  "null",
                  "array"
                ],
                "items": {
                  "type": "string"
                }
              },
              "description": {
                "type": "string"
              },
              "allowed_cidrs": {
                "type": [
                  "null",
                  "array"
                ],
                "items": {
                  "type": "string"
                }
              }
            },
            "additionalProperties": false
          }
        }
      },
      "description": "per-path IP allow rules",
      "additionalProperties": false
    }
  }
}