Skip to content

Template · Auth

Keycloak

Identity and access management (OIDC/SAML) with PostgreSQL.

Deploy on Skiffly

Opens the dashboard with this template pre-selected. Sign in with GitHub if you are new; the free tier needs no card.

  • Postgrespostgres:17
  • Keycloakquay.io/keycloak/keycloak:26.3
Upstream documentation

What gets deployed

2 services in the environment you pick, on the private network of the project.

About this template

quay.io/keycloak/keycloak:26.3 started with kc.sh start behind the platform's TLS proxy, PostgreSQL 17. Bootstrap admin credentials are generated.

Postgres

Image: postgres:17

  • Port 5432/tcp
  • 10 GB volume at /var/lib/postgresql/data
  • 1 vCPU · 1 GB

Keycloak

Image: quay.io/keycloak/keycloak:26.3

  • Port 8080/http
  • Public domain with TLS
  • 1 vCPU · 1.5 GB

/opt/keycloak/bin/kc.sh start

Variables

Generated secrets never leave the platform; references are resolved on the private network. Anything marked required is asked for at deploy time.

Postgres

NameValue
POSTGRES_USERpostgresSuperuser name
POSTGRES_PASSWORDgenerated (password)Generated at deploy
POSTGRES_DBkeycloakDatabase created on first start
PGDATA/var/lib/postgresql/data/pgdata
DATABASE_URLpostgresql://${{self.POSTGRES_USER}}:${{self.POSTGRES_PASSWORD}}@${{self.SKIFFLY_PRIVATE_DOMAIN}}:5432/${{self.POSTGRES_DB}}Connection string on the private network

Keycloak

NameValue
KC_DBpostgres
KC_DB_URLjdbc:postgresql://${{Postgres.SKIFFLY_PRIVATE_DOMAIN}}:5432/${{Postgres.POSTGRES_DB}}
KC_DB_USERNAME${{Postgres.POSTGRES_USER}}
KC_DB_PASSWORD${{Postgres.POSTGRES_PASSWORD}}
KC_HOSTNAMEhttps://${{self.SKIFFLY_PUBLIC_DOMAIN}}
KC_HTTP_ENABLEDtrue
KC_PROXY_HEADERSxforwarded
KC_HEALTH_ENABLEDtrue
KC_BOOTSTRAP_ADMIN_USERNAMEadmin
KC_BOOTSTRAP_ADMIN_PASSWORDgenerated (password)

Deploy button for your README

Add a one-click deploy link to your repository or docs. Two variants: for light and dark backgrounds.

Deploy on SkifflyDeploy on Skiffly
Markdown · Light background
[![Deploy on Skiffly](https://skiffly.dev/button.svg)](https://skiffly.dev/templates/keycloak)
Markdown · Dark background
[![Deploy on Skiffly](https://skiffly.dev/button-dark.svg)](https://skiffly.dev/templates/keycloak)
HTML
<a href="https://skiffly.dev/templates/keycloak"><img src="https://skiffly.dev/button.svg" alt="Deploy on Skiffly" height="32"></a>

Deploy Keycloak in one click

Volumes, secrets and domain pre-wired. Runs on EU nodes, paid per minute from a prepaid balance.