Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Docs / DCA Hardened Identity Provider — for Keycloak™

DCA Hardened Identity Provider — for Keycloak™ — documentation & support card

Keycloak 26.8 in production mode, console on loopback, and an administrator plus realm keys created on each VM's first boot — none ship in the image.

Install Configure Troubleshoot Security

At a glance

TypeHardened VM image
Upstream / licenseKeycloak (Apache-2.0) — see licenses
VersionKeycloak 26.8.0 (upstream server distribution, sha256- and signature-verified) on Ubuntu's OpenJDK 21, Ubuntu 24.04 LTS; Google Cloud image built 2026-10-07. Exact image version: see the listing. Current builds: release notes.
Architecturex86-64
SizingAny current-generation instance with ≥ 4 vCPU (pay-as-you-go floor); 8 vCPU recommended for production.

Marketplaces

Network ports

PortPurposeState
22SSH — key-only, OS Login (IAM); the deployment package adds no SSH ruleyour VPC's firewall rules
8080Keycloak HTTP (admin console, realms, API) — bound to 127.0.0.1; reach it through an IAP SSH tunnelloopback only
9000Management interface (/health/ready) — inherits http-host, so 127.0.0.1loopback only
8443HTTPS — not listening until you configure a certificatecustomer-must-open (config + firewall toggle)

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Access & credentials

No shared or default credentials are included in this image. Access uses the SSH key you supply at launch; any application credential is generated uniquely on your instance at first boot and stored only there — we never know it.

Log in: SSH in with OS Login and forward port 8080 (gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap -- -L 8080:127.0.0.1:8080), then open http://localhost:8080/admin/.

A bootstrap administrator, admin, with a 32-character password generated on THIS VM's first boot by keycloak-firstboot.service; Keycloak creates the master realm, its signing keys and that administrator on its first start. Your copy: /root/keycloak-admin-credentials.txt (root-only, 0600). No administrator, realm or key exists in the image.

sudo cat /root/keycloak-admin-credentials.txt

Rotation: Keycloak treats this account as a temporary admin: sign in, create a permanent administrator in the master realm, then delete admin or give it a new password (Configuration page).

Step-by-step: first login / credentials.

Data & dependencies

Operate

Known limitations

Single node with Keycloak's embedded H2 file database (db=dev-file) and a local cache; Keycloak's guidance for production is an external database. No HTTPS listener until you add a certificate.

Support

Email support@dcassociatesgroup.com — first response within 1 business day (US Eastern), most tickets same-day. To escalate an open ticket, reply "ESCALATE"; it is reviewed by the founder within 1 business day. Security reports: vulnerability disclosure.

Privacy: policy · Terms: terms · Security practices: security & trust · Vulnerability reports: disclosure policy

Keycloak™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Keycloak project.