This image, sourcemation/keycloak, is built on a minimal Debian base to provide a robust Keycloak environment. It's designed for adding authentication to applications and securing services with minimal effort, providing a comprehensive Identity and Access Management (IAM) solution. The image integrates the complete Keycloak server and can be configured for production workloads.
Maintained by the Sourcemation automation team, this Keycloak distribution is regularly updated to ensure it's current, secure, and compact. It's built on a minimal Debian Slim base, and cryptographic signatures are used during the build process to guarantee the integrity of all source code and packages.
This image is intended for production environments where centralized authentication and authorization are critical. To start the server for the first time, you must provide an initial admin username and password.
Example for a local, non-production test:
docker run \
-e KC_BOOTSTRAP_ADMIN_USERNAME=admin \
-e KC_BOOTSTRAP_ADMIN_PASSWORD=password \
-p 8080:8080 \
-it sourcemation/keycloak
This command runs the Keycloak container in development mode, mapping port 8080 on your local machine to the container's default port 8080.
This container uses the following environment variables for configuration. For any variable ending in _PASSWORD, _USER, etc., you can also use a _FILE suffix (e.g., KC_BOOTSTRAP_ADMIN_PASSWORD_FILE) to provide the value from a file, which is recommended for sensitive data.
KC_BOOTSTRAP_ADMIN_USERNAME: The username for the initial admin user created on the first run.
adminKC_BOOTSTRAP_ADMIN_PASSWORD: The password for the initial admin user.
KEYCLOAK_JDBC_DRIVER: The JDBC driver for the database connection. For PostgreSQL, the value is postgresql.KEYCLOAK_DATABASE_HOST: The hostname or IP address of the PostgreSQL database server.KEYCLOAK_DATABASE_PORT: The port number of the PostgreSQL database server.KEYCLOAK_DATABASE_NAME: The name of the database Keycloak will connect to.KC_DB_USERNAME: The username for the database connection.KC_DB_PASSWORD: The password for the database user.KEYCLOAK_PRODUCTION: Set to true to run Keycloak with the production start command. If false or unset, it will use the start-dev command.
falseKEYCLOAK_EXTRA_ARGS: A space-separated list of additional command-line arguments that will be appended to the server's startup command (e.g., kc.sh start-dev).
"--log-level=DEBUG --features=token-exchange"The standard Keycloak port, 8080 and 8443, are exposed by default.
We'd love for you to contribute! You can request new features, report bugs, or submit a pull request with your contribution to this image on the Sourcemation GitHub repository.
Disclaimer: The sourcemation/keycloak image is not affiliated with the CNCF or Red Hat. The respective companies and
organisations own the trademarks mentioned in the offering. The sourcemation/keycloak image is a separate project and is maintained by Sourcemation.
A comprehensive risk analysis report detailing the image and its components can be accessed on the Sourcemation platform.
For more information, check out the overview of Keycloak page.
The base license for Keycloak is the Apache License 2.0
Content type
Image
Digest
sha256:65a51f74f…
Size
416 MB
Last updated
2 days ago
docker pull sourcemation/keycloak