Deploy Keycloak on Antyxsoft Cloud

Single sign-on, user federation and fine-grained authorisation for your applications — self-hosted, standards-based identity you own.

By
Keycloak / CNCF
Licence
Open source — no additional charge
Deploy this app

Create an instance, pick Marketplace App at the template step, and choose it from the list. You pay for the instance.

What Keycloak gives you

Keycloak is an identity and access management server: it holds your users, or federates them from an existing directory, and issues tokens to your applications over OpenID Connect and SAML. Login screens, multi-factor enrolment, password policies and social logins all come out of the box.

Self-hosting identity keeps the user store and the audit trail in your own region — often the deciding factor when the applications behind it handle regulated data.

Key features

  • Single sign-on. One login across web apps, APIs and internal tools via OIDC or SAML.
  • User federation. LDAP and Active Directory as the source of truth, without migration.
  • Multi-factor. OTP and WebAuthn enrolment enforced by policy per realm.
  • Fine-grained authorisation. Roles, groups and policies evaluated centrally, not per application.
  • Realms. Separate tenants — staff, customers, per-client — in one deployment.

What is in the image

ApplicationLatest stable Keycloak release
DatabasePreconfigured relational backing store
AccessAdmin console on the instance address; root over SSH
Suggested sizeFrom 2 vCPU / 4 GB RAM; scale with token volume

Good fit for

  • Internal tool sprawl One login for the dozen apps your team uses.
  • SaaS products Customer identity, MFA and social login without a per-user vendor bill.
  • Compliance Auth logs and user data kept inside your chosen region.

Getting started

Four steps from sign-in to a running application. The full walkthrough, with screenshots, is in the knowledge base.

  1. 01
    Log in to the Cloud Portal

    Sign in at portal.antyxsoft.io and start creating an instance, choosing the region closest to your users.

  2. 02
    At Select Template, open Marketplace App

    In the instance creation flow, switch from operating-system images to the Marketplace App tab.

  3. 03
    Pick the template and deploy

    Select the ready-to-go template, confirm the plan and region, then review and deploy. The instance boots with the application installed.

  4. 04
    Finish the application setup

    Open the admin console, create the administrator, then define a realm, add a client for your application and issue the first tokens.

Before it carries real traffic

  • Attach a Cloud Firewall that opens only the ports this application needs, with management access limited to your own addresses.
  • Schedule backups covering both the database and the application's data directory.
  • Add a Block Storage volume for data that will outgrow the instance disk.
  • Put it inside a VPC when it needs private access to other services.

Support

Antyxsoft supports the image and the infrastructure it runs on. Application-level questions are also covered by the upstream project's own documentation and community.

Supported byAntyxsoft
Support hours08:00 – 17:00 EEST

What is covered

Antyxsoft covers

The image itself, deployment problems, the instance, storage, network and platform availability.

You control

Configuration, add-ons, content, application updates and anything you change inside the guest.

Need it managed?

Ask about managed operations — updates, monitoring and backup handled for you.

Frequently asked questions

Can Keycloak use our existing Active Directory?
Yes. LDAP and Active Directory can be federated as the user store, so credentials stay where they are and Keycloak issues the tokens your applications consume.
Which protocols do applications use to connect?
OpenID Connect and OAuth 2.0 for modern applications, SAML 2.0 for older ones. Most frameworks have a library or adapter that needs only the realm URL and a client secret.
What resources does Keycloak need?
Two virtual CPUs and 4 GB of memory suit most internal deployments. Token volume rather than user count drives sizing, and the instance can be resized as traffic grows.

Own your login screen

Deploy Keycloak in your region and put every application behind one identity provider you control.