Sign inSign up

readystack/keycloak

By readystack

•Updated about 4 hours ago

Keycloak IAM in one container; requires an external PostgreSQL database you provide

Image
0

2.3K

readystack/keycloak repository overview

⁠Keycloak

readystack/keycloak:26.5.4-CE-ubuntu24.04-r1

A hardened, cosign-signed, offline-rebuildable build of github.com/keycloak/keycloak 26.5.4 (Apache-2.0), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout — re-checked daily; today's grade and the reason for it are at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/keycloak:26.5.4-CE-ubuntu24.04-r1.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is 26.5.4-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/keycloak:26.5.4-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/keycloak:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/keycloak:26.5.4-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container — a Quarkus-based Identity & Access Management server (OpenID Connect / OAuth2 / SAML provider, admin console, account console). REQUIRES an EXTERNAL PostgreSQL database the customer provisions and points the container at via KC_DB=postgres + KC_DB_URL_HOST/KC_DB_URL_DATABASE (or a full KC_DB_URL JDBC string) + KC_DB_USERNAME/KC_DB_PASSWORD. The image is built 'optimized' (kc.sh build --db=postgres --health-enabled --metrics-enabled baked at image-build) and started with kc.sh start --optimized. Keycloak creates and Liquibase-migrates its own schema in that postgres on first start. NOT a docker-compose-only or Kubernetes-only product, but it is NOT self-contained: postgres is a hard external dependency for production (an embedded dev-file H2 fallback exists via start-dev but is non-production).

docker run -d --name keycloak -p 8080:8080 -p 9000:9000 -e KC_DB_URL_HOST=YOUR_PG_HOST -e KC_DB_URL_DATABASE=keycloak -e KC_DB_USERNAME=keycloak -e KC_DB_PASSWORD=YOUR_PW -e KC_BOOTSTRAP_ADMIN_USERNAME=admin -e KC_BOOTSTRAP_ADMIN_PASSWORD=YOUR_ADMIN_PW readystack/keycloak:26.5.4-CE-ubuntu24.04-r1 start --optimized --hostname=https://auth.example.com

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:4e8e9fb96…

Size

251 Bytes

Last updated

about 4 hours ago

docker pull readystack/keycloak:sha256-4021f66ebf4c9818177f65f56f7e416d9d4f67019ae3d35b6b9b90934838d132.sig