We use Keycloak (hooked up to FreeIPA) which will try to authenticate against Kerberos and then fall back to a regular login screen or a cookie for more limited SSO. The actual web apps are configured with OpenID Connect or SAML and don't know anything about Kerberos.