Home / Docs / DCA Hardened Identity Provider — for Keycloak™ / Security
| Port | Purpose | State |
|---|---|---|
| 22 | SSH — key-only, OS Login (IAM); the deployment package adds no SSH rule | your VPC's firewall rules |
| 8080 | Keycloak HTTP (admin console, realms, API) — bound to 127.0.0.1; reach it through an IAP SSH tunnel | loopback only |
| 9000 | Management interface (/health/ready) — inherits http-host, so 127.0.0.1 | loopback only |
| 8443 | HTTPS — not listening until you configure a certificate | customer-must-open (config + firewall toggle) |
"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.
| We maintain | The hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs. |
|---|---|
| You control | The running instance: OS patching between image versions, network exposure, IAM, data, and backups. |
| Your cloud provides | Physical/hypervisor security, marketplace billing, and the firewall primitives this design relies on. |
Keycloak™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Keycloak project.