[email protected]

Keycloak: Managed Hosting, Installation and Operations

WZ-IT plans, installs and operates Keycloak as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.

Reviews
At a glance
  • OperationManaged Hosting
  • Monitoring24/7
  • Service Levelselectable as needed
Cloud Wolke HerausforderungServer NachhaltigkeitIT Beratung Service Consulting SoforthilfeTimo Wevelsiep Robin ZinsExperten für Innovation Migration AWSHetzner Hosting zuverlässig

Companies worldwide trust WZ-IT

  • Stadtwerke Brühl
  • DGHO e.V.
  • ABCO Water Systems
  • Golem.de
  • EVADXB
  • nextGYM
  • AInergy
  • ml&s
  • Odiseo Solutions
  • Annota
  • ARGE
  • SweetConnect GmbH
  • Aphy AG
  • CORGOS
  • Rekorder
  • SolidProof
  • Yonju
  • Keymate
  • Paritel
  • Mr. Clipart
  • Millenium
  • Negosh
  • Führerscheinmacher
  • Boese VA
Read client reviews

About the technology

What is Keycloak?

Keycloak is an open-source identity and access management (IAM) solution. The platform centralises authentication, single sign-on and authorisation functions for connected applications and APIs.

Keycloak supports OpenID Connect, OAuth 2.0 and SAML as well as connections to directory services and external identity providers. Roles, login flows and the operating architecture are designed for the relevant environment.

Keycloak Features

  • Single Sign-On (SSO)

    Users authenticate once with Keycloak and automatically have access to all connected applications.
  • Standard Protocols

    Support for OpenID Connect, OAuth 2.0 and SAML 2.0 to connect compatible applications and services.
  • User Federation

    Native integration with LDAP and Active Directory plus support for custom user stores.
  • Identity Brokering

    External identity providers and social login services can be connected through configured broker flows.
  • Admin Console

    Centralized web-based management of all aspects of Keycloak, applications, users, and policies.
  • Fine-Grained Authorization

    Advanced authorization services with role-based and policy-based access control mechanisms.
  • Account Management

    Self-service portal for users to manage their profiles, passwords, and two-factor authentication.
  • Scalable Deployment

    Depending on login load, availability and dependencies, Keycloak can be deployed as a single instance or as part of a cluster architecture.
  • Customizable & Extensible

    Themes for custom designs, extensive APIs and SPI for tailored extensions.

Operations beyond installation

Operate Keycloak as critical identity infrastructure

When Keycloak fails or is misconfigured, multiple applications are affected. We therefore treat runtime, database, protocols, directories, keys and emergency access as one system.

  • Identity platform

    Keycloak, database, realms and configuration are deployed reproducibly and kept upgradeable.
  • Protocols and federation

    OIDC, OAuth 2.0, SAML, LDAP and external identity providers are integrated in a controlled way.
  • Policies and applications

    Clients, roles, flows, MFA and token content are coordinated with application teams.
  • Operations and emergency access

    Monitoring, backups, updates, key rotation and break-glass access protect operations.

Area

Responsibilities in the identity architecture

We operate the platform and integrate systems; business roles and permissions remain with the customer.

AreaResponsibilityScope and boundaries
Architecture and Keycloak platformWZ-ITSizing and operation of Keycloak, database, proxy and agreed cluster components.
Updates and monitoringWZ-ITControlled version changes, technical monitoring and incident handling according to service level.
Backups and recoveryWZ-ITBackup of database, configuration and relevant keys plus scheduled restore checks.
Clients and protocol integrationSharedWZ-IT configures flows and mappings; application teams test login, logout and failure cases.
LDAP, AD and identity providersSharedDirectory access, attributes, groups and synchronisation rules are agreed together.
Role and permission modelCustomerThe customer owns business roles, approvals and the permissibility of access.
Themes, SPIs and custom flowsOptional WZ-IT serviceCustom themes, providers and authentication flows can be developed and tested separately.

Infrastructure, integration and operations

Keycloak as part of your infrastructure

We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.

Architecture and migration

Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.

  • On-Premise

    In your data center: Installation on bare-metal, VM or Docker · Integration with existing Active Directory/LDAP

  • Cloud Installation

    AWS, Azure, Hetzner & more: Installation on AWS, Azure, GCP, Hetzner · Terraform/IaC setup (optional) · Kubernetes or Docker Compose · Capacity and scaling design

  • Enterprise Setup

    Advanced architecture after technical and licence assessment: HA and recovery design where supported by the application and edition · Logging according to feature set and edition · Custom security policies

Network and identity

SSO, secure access, internal systems and existing security components are integrated appropriately.

  • VPN Access

    WireGuard, NetBird, Tailscale, Headscale, OpenVPN, Cloudflare Tunnel · Easy client setup for all devices

  • SSO Integration

    Directly or through an upstream identity layer

  • Multi-Factor Auth

    Depends on application, edition and identity provider

  • Firewall & Hardening

    Fail2Ban, Rate Limiting, IP Whitelisting

Monitoring and service level

Updates, backups, technical monitoring and response paths follow a transparent operational scope.

  • 24/7 proactive monitoring

  • Updates and patches

    CVE and security-advisory monitoring for the operating system and managed application, regular updates, and priority deployment of available patches for critical vulnerabilities

  • Daily backup with 7-day retention

  • Personal technical contact

Integration and development

APIs, automation and custom extensions can be delivered beyond basic deployment.

  • User Storage SPI

    The most important point: We don't necessarily migrate your users. We develop User Storage Providers allowing Keycloak to read users directly from your existing SQL DB, mainframe, or API - without duplication.

  • Event Listener SPI

    Audit compliance requires gapless logs. We write Event Listeners that stream every login, error, and admin action to your SIEM (Splunk, ELK, Graylog) in real-time.

  • Custom Themes (Freemarker)

    The standard login window is off-putting. We develop responsive, accessible themes (based on your CI/CD) that seamlessly integrate the login experience into your application.

Full-service installation with no hidden costs

What the Keycloak setup includes

  • Complete installation & configuration
  • SSL certificate & reverse proxy setup
  • Backup strategy & disaster recovery
  • Performance optimization & tuning
  • Security hardening following OWASP
  • Monitoring & logging setup
  • Documentation & best practices
  • Administrator training (remote)
  • 30 days email support included
  • Dedicated contact person
  • Optional integration: LDAP/AD, SSO, MFA
  • Update strategy & patch management setup

The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.

Use Cases

Using Keycloak in your organisation

  • Enterprise Single Sign-On

    Centralised authentication for connected enterprise applications using SAML, OAuth 2.0 and OpenID Connect
  • Identity & Access Management

    IAM with user and role management, authorisation functions and configurable access controls
  • Social Login Integration

    Connection of compatible external identity providers and social-login services through configured broker flows
  • Multi-Factor Authentication

    Multi-factor authentication using OTP or WebAuthn with agreed recovery and emergency procedures
  • API Security

    OAuth 2.0 and OpenID Connect as the identity and token foundation for APIs and service-to-service communication
  • LDAP/AD Integration

    Planned integration with existing Active Directory and LDAP directory services

Concrete Use Cases

Keycloak Development & Integration

Keycloak is modular to the core. Almost every functionality is a replaceable provider. We use Java to implement these SPIs and adapt Keycloak exactly to your infrastructure.

Federation with Legacy Systems

Problem

You have thousands of users in an old MySQL database of an EOL software that cannot be migrated.

Solution

A 'read-only' User Storage SPI connects the old DB. Keycloak authenticates against old hashes but issues modern OAuth2/OIDC tokens for new apps.

Passwordless Auth & Magic Links

Problem

B2C customers constantly forget passwords. The login process must be frictionless.

Solution

Implementation of a custom authentication flow that only asks for emails and sends magic links. Fully integrated into Keycloak core, secure, and audited.

Token Enrichment (Mappers)

Problem

Your application needs specific data in the JWT (e.g., tenant ID, cost center) not found in LDAP.

Solution

A Script Mapper (JavaScript) or Protocol Mapper (Java) loads this data from an external API during login and signs it into the access token.

Managed Hosting & Operations

How much does hosting for Keycloak cost?

Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.

Starter workload from€129.90/ month · Modular pricing based on your requirements - service level, apps and compute selectable individually.

Keycloak hosting in Germany: GDPR-compliant operations

  • One managed standard application included
  • Dedicated compute workload in S, M, L or XL
  • Subdomain on wz-it.cloud included
  • German provider, German data centres, no US clouds
  • ISO 27001-certified and BSI C5-attested data centres
  • 99.9 % standard availability per month
  • CVE and security-advisory monitoring for the operating system and managed application, regular updates, and priority deployment of available patches for critical vulnerabilities
  • Central collection of agreed system and operations logs with immutable retention
  • Daily backup with 7-day retention
  • 5 TB outbound traffic per workload and month
  • 24/7 proactive monitoring
  • Five clearly separated service levels
  • 24/7 P1 response with Production or Critical
  • Personal technical contact

All prices are net and exclude statutory VAT. The offers are addressed to businesses. All on-premises options

Sizing and deployment

Size Keycloak by login load and dependencies

User count alone says little. Login peaks, token refreshes, client count, federation, sessions and availability targets determine the architecture.

Starting-point guidance
Usage scenarioTechnical starting pointKey factors
Internal SSO for a few applicationsS or M, external databaseSuitable for moderate login load and a clearly limited set of clients.
Many applications, realms or directoriesM or L, separate databaseFederation, sessions, token lifetimes and peaks are measured or estimated.
Public login or high authentication loadCustom architectureLoad tests, cache behaviour, rate limits and abuse protection are included.
Business-critical or highly available IAMCustom architectureCluster, database, keys, upstream IdPs and break-glass procedures must work as one system.
  • The calculator is a starting point for a standard instance. HA, load testing, complex federation and multiple environments are designed individually.

Sizing and deployment

Deployment aligned with the trust boundary

Keycloak can run on WZ-IT infrastructure, in your cloud, on-premises or close to distributed applications and directory services in a hybrid design.

  • WZ-IT managed hosting

    Operations on European infrastructure with compute, backup, monitoring and a selectable service level.
  • Your cloud account

    Operations in your cloud with existing network, security and logging services.
  • On-premises

    Integration with your data centre, virtualisation and internal directory services.
  • Hybrid and multi-site

    Secure connection to distributed applications, clouds, LDAP/AD and external identity providers.

Target architecture

Design identity flows across applications and locations

Keycloak connects users, directories and applications. We document trust relationships, token flows, administrative access and failure paths.

Users and applications

Browsers, mobile apps, APIs, service accounts and administrative access.

Secure entry

TLS, reverse proxy, rate limits, network rules and separated administration paths.

Directories and identity providers

LDAP/AD, social or enterprise IdPs plus defined federation and broker flows.

Keycloak platform

Realms, clients, sessions, roles, MFA, flows and token issuance.

Database and cache

Persistent configuration, sessions and, where needed, cluster cache for the target availability.

Clients and APIs

OIDC, OAuth and SAML integrations with tested login, logout and failure paths.

Audit and monitoring

Metrics, events, logs, alerts and optional forwarding to SIEM or central observability.

Identity is a shared dependency. Changes are therefore planned with staging, defined rollback steps and emergency access.

Role in the overall system

Related services for Keycloak

This page covers installation and the agreed platform operations for Keycloak. Custom code, the access layer and special confidentiality requirements remain clearly separated responsibilities that can be added when needed.

Three relevant adjacent paths instead of a long list of further products. All prices are net and exclude statutory VAT. The offers are addressed to businesses.

View the overall system

Questions about Keycloak managed hosting

Answers about migration, SSO, high availability and operations.

Reviews & projects

Client feedback and projects worldwide

WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.
Steve KirchnerManaging Director, nextGYM GmbH
View project

International

Built in Germany's Ruhr Valley. Running worldwide.

WZ-IT designs, develops and operates infrastructure and software for clients in Germany and internationally. We deliver projects remotely and continue supporting them in ongoing operations after go-live.

Selected projects

Read client reviews

  • Secure your Proxmox & backup setup
  • Modernize your infrastructure - sovereign
  • Plan a sovereign open-source stack
  • Integrate a local AI solution
  • Modernize your legacy software
  • Cut cloud cost - up to −81%
  • Build a high-availability Proxmox cluster
  • Virtualize with Managed Proxmox
  • Design an open-source AI architecture
  • Get collaboration fully managed
  • Ship your prototype to production
  • Connect sites and clusters securely

Managed Hosting & Operations

Enquire about hosting and operations for Keycloak

Briefly describe the current state and objective for Keycloak. We assess infrastructure, integration, and ongoing operations.

  • Straight with Timo and Robin - no sales team, no pitch
  • An honest take, including when we are not the right fit
  • Concrete next steps for infrastructure, software or AI

No risk: worst case, you leave with a clearer understanding of your project than before.

Timo and Robin, founders of WZ-IT

Which Keycloak service do you need?

Choose the appropriate starting point or simply describe the situation.

We usually respond within one business day. Please do not submit credentials.

WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.
Jakob ÖschlbergerInno7 GmbH