Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Keycloak

In Oracle review

DCA Hardened Identity and Access Management for Keycloak — Support & Quick Start

A hardened, CVE-patched virtual machine image running Keycloak™ — the open-source identity and access management server (OpenID Connect, OAuth 2.0 and SAML 2.0) and a Cloud Native Computing Foundation incubating project — on Oracle Linux 9.

Submitted for Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusSubmitted for Oracle certification review
Version26.8.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8443/tcp, 8080/tcp
CategorySecurity
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. On first boot the image creates the PostgreSQL role and database, the temporary admin and a self-signed certificate, then Keycloak creates its schema on its first start; allow one to two minutes. Check all three units:
    sudo systemctl status postgresql keycloak-firstboot keycloak
  3. The temporary bootstrap admin password and the database password were generated uniquely for this instance at first boot. Read them (root only):
    sudo cat /root/.keycloak_default_credentials
  4. Smoke-test from the instance (all listeners are loopback-bound: HTTPS 8443, HTTP 8080, health 9000, cluster transport 7800):
    curl -s http://127.0.0.1:9000/health/ready
    curl -sk https://127.0.0.1:8443/realms/master/.well-known/openid-configuration

    To open the admin console without exposing anything, tunnel from your workstation:

    ssh -L 8443:127.0.0.1:8443 opc@<public-ip>

    then browse https://localhost:8443/admin/ (accept the self-signed certificate) and sign in as admin.
  5. Replace the temporary admin before you expose the server. Keycloak treats the bootstrap account as temporary: in the master realm create a new user, set a password, grant it the admin realm role, sign in as that user, delete the temporary admin user, then remove its bootstrap file:
    sudo rm /etc/keycloak/bootstrap-admin.env

    User and client credentials are managed inside Keycloak (admin console or kcadm.sh in /opt/keycloak/bin).

  6. To reach Keycloak from your application tier, expose it deliberately. Install your CA-issued certificate chain and key at /etc/keycloak/tls/server.crt.pem and /etc/keycloak/tls/server.key.pem (owner root:keycloak, key mode 0640; Keycloak reloads them hourly). Then bind to all interfaces, turn off plain HTTP, and set your public URL (replace sso.example.com with your hostname):
    sudo sed -i -e 's/^http-host=127.0.0.1$/http-host=0.0.0.0/' -e 's/^http-enabled=true$/http-enabled=false/' -e 's/^hostname-strict=false$/hostname-strict=true/' /etc/keycloak/keycloak.conf
    echo 'hostname=https://sso.example.com' | sudo tee -a /etc/keycloak/keycloak.conf
    sudo systemctl restart keycloak

    The issuer in https://<your-host>:8443/realms/master/.well-known/openid-configuration is then https://sso.example.com/realms/master.

  7. Ports 8443 and 8080 are already permitted in the host firewall. Restrict them in your VCN security list to the application tier or load balancer CIDR; never expose plain HTTP 8080 to the internet. Keep http-enabled=true only when a TLS-terminating reverse proxy or OCI load balancer fronts 8080 — then also set proxy-headers=xforwarded and point hostname at the proxy's public URL. The health port 9000, the Infinispan cluster transport 7800 (bound to loopback for this single node by cache-embedded-network-bind-address in keycloak.conf; to add cluster peers, remove that line and permit 7800 between peers only) and PostgreSQL 5432 remain blocked by the host firewall.
  8. Data lives in PostgreSQL at /var/lib/pgsql/data; the Keycloak server tree is /opt/keycloak (a symlink to the versioned install), with custom providers in /opt/keycloak/providers and themes in /opt/keycloak/themes. After adding a provider or changing a build-time option, rebuild and restart:
    sudo -u keycloak /opt/keycloak/bin/kc.sh build --db=postgres --health-enabled=true && sudo systemctl restart keycloak

    For anything beyond evaluation, place /var/lib/pgsql/data on a block volume and back the database up before upgrades. Rotate the database password at any time with sudo -u postgres psql -c '\password keycloak' (prompts; the password never reaches a log), then update db-password in /etc/keycloak/keycloak.conf and restart keycloak.

The image is CVE-patched at build time. Apply ongoing operating system, OpenJDK and PostgreSQL updates with:

sudo dnf -y update

Keycloak itself is installed from the upstream release and is not updated by dnf: launch the newest image version, or upgrade in place by unpacking a newer release beside /opt/keycloak-<version>, running kc.sh build as above, repointing the /opt/keycloak symlink and restarting (Keycloak migrates the schema automatically; back up the database first).

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Keycloak™ is a trademark of The Linux Foundation. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Keycloak project, the Cloud Native Computing Foundation, or The Linux Foundation.