Self-host Keycloak with Docker
An open-source identity and access management server with SSO, OAuth2, and SAML support.
This page describes the Levelrail template for Keycloak (Security). It deploys the services below as one Docker Compose app on your own server.
Project site: https://www.keycloak.org/documentation.Recommended memory: about 1024 MiB.
Services, ports and volumes
| Service | Image | Container ports | Volumes |
|---|---|---|---|
keycloak | quay.io/keycloak/keycloak:26.1 | 8080 | keycloak_data -> /opt/keycloak/data |
Environment variables
| Service | Variable | Value |
|---|---|---|
keycloak | KC_BOOTSTRAP_ADMIN_PASSWORD | Generated at deploy |
keycloak | KC_BOOTSTRAP_ADMIN_USERNAME | Generated at deploy |
keycloak | KC_HEALTH_ENABLED | Preset in the template |
keycloak | KC_HOSTNAME | Preset in the template |
keycloak | KC_HTTP_ENABLED | Preset in the template |
keycloak | KC_LEGACY_OBSERVABILITY_INTERFACE | Preset in the template |
keycloak | KC_PROXY_HEADERS | Preset in the template |
Passwords and keys marked as generated are created for you when the app is deployed and stored as secrets. Values are not shown here.
Deploy Keycloak with Levelrail
In the dashboard, open Apps, choose New app, then Browse templates, and select Keycloak. Review the Compose body and deploy.
With the CLI:
levelrail-cli templates deploy keycloak --name my-keycloakSee Service template catalog for how templates work, and Getting started if you have not installed Levelrail yet.
More Security templates
All templates are listed in the self-host gallery.