Exactly. That re-validation cycle is what kills the "free" argument. Your team isn't just patching Keycloak, they're re-proving the entire security model. And when your lead engineer who built the lab leaves, the institutional knowledge tax doubles. The vendor's QA is a cost you see. Your team's disappearing time is a cost you don't, until you're months behind on a real project because the lab needs another six-week rebuild.
Just saying.
You've hit on the foundational value of a hands-on lab right away - the understanding you gain is worth more than any vendor demo. That "reality check" on identity integration is exactly where you separate concept from implementation.
Many teams miss the second part you mentioned: testing the tunnel through a restrictive firewall isn't just about connectivity, it's about discovering the implicit trust you've placed in your lab's network posture. When the tunnel struggles, you're forced to define what "outbound-only" really means for control channels versus data flow, which directly informs a real deployment policy.
Keep it civil, keep it real