Get a Quote

Keycloak architecture, deployment and migration

A technical solution must match your needs. We start from your use cases to design a robust, scalable authentication architecture, then deploy it with you.

Let's talk about your project

It all starts with a workshop

With your team and a whiteboard, we analyze your authentication needs: applications to connect, user populations, existing directories, security and availability requirements. Together we identify OAuth2 flows, OpenID Connect integration, LDAP / Active Directory connections and your infrastructure constraints.

You get a complete report describing every interaction between your applications and your future SSO, with architecture diagrams, technical recommendations and a deployment plan.

What we design and deploy

SSO architecture

Realms, clients and scopes layout, the right OAuth2 / OpenID Connect or SAML flow for each application, roles and authorization management.

High availability

Keycloak clustering, distributed Infinispan cache, database, fail-over and disaster recovery strategies, monitoring.

On your infrastructure

Bare metal servers, cloud providers (AWS, Azure, GCP, OVH), Kubernetes clusters, PaaS… or managed Keycloak on Clever Cloud.

Directories and identity providers

LDAP / Active Directory federation, login through external identity providers (OpenID Connect, SAML, social) and retrieval of their tokens.

Application integration

Web and mobile apps, APIs, command line tools and IoT devices, legacy applications through an authentication proxy, VPN, databases, SaaS.

Migrations

Major version upgrades, moving to the Quarkus-based Keycloak distribution, moving your Keycloak to a new infrastructure, for instance to managed Keycloak on Clever Cloud.

Our process

1

Discovery

Understand your needs and current infrastructure.

2

Design

Architecture proposal with detailed documentation.

3

Implementation

Development, testing and deployment.

4

Support

Long-term support and maintenance.

Average project: 2-4 weeks | Everything is documented

Frequently asked questions

Self-hosted or managed Keycloak: which one?

Self-hosted, you control everything but you also run it: upgrades, security patches, backups, clustering. Managed, like Keycloak on Clever Cloud, the infrastructure is operated for you and you keep your custom extensions and themes. We help you choose based on your constraints and support both options.

Can Keycloak replace our LDAP or Active Directory?

Keycloak is not a directory, but it can rely on your LDAP / Active Directory through user federation, or store accounts itself. For applications that only speak LDAP, our LDAP bind proxy lets them authenticate through Keycloak.

How long does a project take?

An average project takes 2 to 4 weeks, from discovery to deployment, and every step is documented.

Let's talk about your Keycloak

Tell us about your context in a few lines: we will get back to you quickly to discuss it and suggest the right approach.

contact@please-open.it

Or follow us: LinkedIn · GitHub · Blog