Prerequisites
- An account on the target cloud with permission to launch VM instances (no special IAM roles are required by this product unless stated below — IAM required: none).
- An SSH key pair registered in the target cloud (all access is key-only; password SSH is disabled).
- Instance size ≥ 4 vCPU (pricing floor; 8 vCPU recommended).
- No internet access or external dependency is required at deploy time — the image is self-contained.
Google Cloud
- Deploy from the Google Cloud Marketplace listing (or its deployment package): at least 4 vCPU and 16 GB RAM (default n2-standard-8, 50 GB balanced boot disk). Leave the tcp:8443 firewall toggle off until HTTPS is configured.
Expected result The VM DEPLOYMENT-vm is RUNNING; on it, curl -fsS http://127.0.0.1:9000/health/ready reports UP. - Tunnel port 8080 and sign in to http://localhost:8080/admin/ with the credential in /root/keycloak-admin-credentials.txt.
Expected result The admin console opens in the master realm. - To serve users and applications: configure HTTPS on 8443 with your certificate and hostname (Configuration page), then allow tcp:8443 from your users' ranges.
Expected result https://<your hostname>:8443/ serves Keycloak with your certificate.
Validate
curl -fsS http://127.0.0.1:9000/health/ready → status UP
First boot: keycloak-firstboot.service mints the bootstrap administrator before keycloak.service first starts; Keycloak creates the master realm with it; keycloak-verify-firstboot.service proves the administrator obtains a token, a wrong password is refused, the version is 26.8.0 and every listener is loopback-only, then removes /etc/keycloak/bootstrap-admin.env and writes /var/lib/dca-firstboot/keycloak.verified. The first start takes a while; health/ready answers UP when it is done.
First login / credentials
- Connect with OS Login and forward the console: gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap -- -L 8080:127.0.0.1:8080 (reading the credential file needs sudo, i.e. roles/compute.osAdminLogin).
- Read this VM's administrator: sudo cat /root/keycloak-admin-credentials.txt (root-only, 0600) — KEYCLOAK_ADMIN_USER=admin and KEYCLOAK_ADMIN_PASSWORD.
- Open http://localhost:8080/admin/ on your workstation and sign in to the master realm as admin. Then create a permanent administrator and delete or re-password admin (Configuration page).
Secure it
- Restrict SSH (22) to your own IP range in the cloud firewall/security group.
- Open application ports only per the ports table — closed-by-default is deliberate.
- Volume encryption: use your cloud's native volume encryption (enabled by default on most accounts); the image adds no proprietary encryption layer.
Costs & quotas
Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed
by your cloud at its standard rates. The recommended size fits default service quotas in most accounts —
if you scale out, review your cloud's quota console before launch.
Next: configuration · troubleshooting · security notes
Keycloak™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Keycloak project.