Levelrail
Skip to content

Self-host Keycloak with Docker ​

An open-source identity and access management server with SSO, OAuth2, and SAML support.

This page describes the Levelrail template for Keycloak (Security). It deploys the services below as one Docker Compose app on your own server.

Project site: https://www.keycloak.org/documentation.

Recommended memory: about 1024 MiB.

Services, ports and volumes ​

ServiceImageContainer portsVolumes
keycloakquay.io/keycloak/keycloak:26.18080
keycloak_data -> /opt/keycloak/data

Environment variables ​

ServiceVariableValue
keycloakKC_BOOTSTRAP_ADMIN_PASSWORDGenerated at deploy
keycloakKC_BOOTSTRAP_ADMIN_USERNAMEGenerated at deploy
keycloakKC_HEALTH_ENABLEDPreset in the template
keycloakKC_HOSTNAMEPreset in the template
keycloakKC_HTTP_ENABLEDPreset in the template
keycloakKC_LEGACY_OBSERVABILITY_INTERFACEPreset in the template
keycloakKC_PROXY_HEADERSPreset in the template

Passwords and keys marked as generated are created for you when the app is deployed and stored as secrets. Values are not shown here.

Deploy Keycloak with Levelrail ​

In the dashboard, open Apps, choose New app, then Browse templates, and select Keycloak. Review the Compose body and deploy.

With the CLI:

levelrail-cli templates deploy keycloak --name my-keycloak

See Service template catalog for how templates work, and Getting started if you have not installed Levelrail yet.

More Security templates ​

All templates are listed in the self-host gallery.

Released under the Apache 2.0 License.