Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.
At a glance
| Status | Submitted for Oracle certification review |
|---|
| Version | 26.8.0 |
|---|
| Platform | Oracle Linux 9 |
|---|
| Ports open in the host firewall | SSH (22/tcp), 8443/tcp, 8080/tcp |
|---|
| Category | Security |
|---|
| Upstream licence | Apache-2.0 |
|---|
| Pricing | Pay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab |
|---|
Quick start
This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.
After launch:
- Connect over SSH as the opc user with the key you supplied at launch:
ssh opc@<public-ip>
- On first boot the image creates the PostgreSQL role and database, the temporary admin and a self-signed certificate, then Keycloak creates its schema on its first start; allow one to two minutes. Check all three units:
sudo systemctl status postgresql keycloak-firstboot keycloak
- The temporary bootstrap admin password and the database password were generated uniquely for this instance at first boot. Read them (root only):
sudo cat /root/.keycloak_default_credentials
- Smoke-test from the instance (all listeners are loopback-bound: HTTPS 8443, HTTP 8080, health 9000, cluster transport 7800):
curl -s http://127.0.0.1:9000/health/ready
curl -sk https://127.0.0.1:8443/realms/master/.well-known/openid-configuration
To open the admin console without exposing anything, tunnel from your workstation:
ssh -L 8443:127.0.0.1:8443 opc@<public-ip>
then browse https://localhost:8443/admin/ (accept the self-signed certificate) and sign in as admin.
- Replace the temporary admin before you expose the server. Keycloak treats the bootstrap account as temporary: in the master realm create a new user, set a password, grant it the admin realm role, sign in as that user, delete the temporary admin user, then remove its bootstrap file:
sudo rm /etc/keycloak/bootstrap-admin.env
User and client credentials are managed inside Keycloak (admin console or kcadm.sh in /opt/keycloak/bin).
- To reach Keycloak from your application tier, expose it deliberately. Install your CA-issued certificate chain and key at /etc/keycloak/tls/server.crt.pem and /etc/keycloak/tls/server.key.pem (owner root:keycloak, key mode 0640; Keycloak reloads them hourly). Then bind to all interfaces, turn off plain HTTP, and set your public URL (replace sso.example.com with your hostname):
sudo sed -i -e 's/^http-host=127.0.0.1$/http-host=0.0.0.0/' -e 's/^http-enabled=true$/http-enabled=false/' -e 's/^hostname-strict=false$/hostname-strict=true/' /etc/keycloak/keycloak.conf
echo 'hostname=https://sso.example.com' | sudo tee -a /etc/keycloak/keycloak.conf
sudo systemctl restart keycloak
The issuer in https://<your-host>:8443/realms/master/.well-known/openid-configuration is then https://sso.example.com/realms/master.
- Ports 8443 and 8080 are already permitted in the host firewall. Restrict them in your VCN security list to the application tier or load balancer CIDR; never expose plain HTTP 8080 to the internet. Keep http-enabled=true only when a TLS-terminating reverse proxy or OCI load balancer fronts 8080 — then also set proxy-headers=xforwarded and point hostname at the proxy's public URL. The health port 9000, the Infinispan cluster transport 7800 (bound to loopback for this single node by cache-embedded-network-bind-address in keycloak.conf; to add cluster peers, remove that line and permit 7800 between peers only) and PostgreSQL 5432 remain blocked by the host firewall.
- Data lives in PostgreSQL at /var/lib/pgsql/data; the Keycloak server tree is /opt/keycloak (a symlink to the versioned install), with custom providers in /opt/keycloak/providers and themes in /opt/keycloak/themes. After adding a provider or changing a build-time option, rebuild and restart:
sudo -u keycloak /opt/keycloak/bin/kc.sh build --db=postgres --health-enabled=true && sudo systemctl restart keycloak
For anything beyond evaluation, place /var/lib/pgsql/data on a block volume and back the database up before upgrades. Rotate the database password at any time with sudo -u postgres psql -c '\password keycloak' (prompts; the password never reaches a log), then update db-password in /etc/keycloak/keycloak.conf and restart keycloak.
The image is CVE-patched at build time. Apply ongoing operating system, OpenJDK and PostgreSQL updates with:
sudo dnf -y update
Keycloak itself is installed from the upstream release and is not updated by dnf: launch the newest image version, or upgrade in place by unpacking a newer release beside /opt/keycloak-<version>, running kc.sh build as above, repointing the /opt/keycloak symlink and restarting (Keycloak migrates the schema automatically; back up the database first).
What the image provides
- Keycloak 26.8.0, installed from the project's official release on GitHub with its GPG signature and SHA-256 digest verified at build time, pre-built for PostgreSQL in production mode so the first start does not wait for augmentation, running as the dedicated unprivileged keycloak service on OpenJDK 21 from the Oracle Linux 9 AppStream repository.
- PostgreSQL 16 co-located from the Oracle Linux 9 AppStream repository, bound to loopback, with the Keycloak role and database created on first boot behind an instance-unique password — no embedded development database.
- Safe-by-default network posture: HTTPS (8443) and HTTP (8080) listen on loopback until you expose them deliberately with one documented configuration file. Both are declared in the host firewall; the management/health port (9000), the Infinispan cluster transport (7800, bound to loopback for this single node) and PostgreSQL (5432) stay behind the firewall's default-deny.
- Instance-unique secrets generated on first boot and surfaced to the operator over SSH: the temporary bootstrap admin password, the database password, and a self-signed TLS keypair that Keycloak reloads without a restart once you replace it with your CA-issued certificate — never a shared secret baked into the image.
- A locked-down systemd service and security hardening aligned to the Oracle Cloud Marketplace image standards: SELinux enforcing, host firewall default-deny with only SSH, 8443 and 8080 permitted, no account with a usable password, no stray keys, and the image fully patched at build time. The operating system, OpenJDK and PostgreSQL keep receiving Oracle's security errata through dnf update; Keycloak itself is refreshed by a new image version on each upstream release.
Still stuck?
Email support@dcassociatesgroup.com (response within 1 business day) or use the
contact form. Include the listing name, your OCI region, the instance OCID and the
output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.
Keycloak™ is a trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Keycloak project, the Cloud Native Computing Foundation, or The Linux Foundation.