Install Keycloak Using Docker Compose
This article is for those looking for a detailed and straightforward guide on installing Keycloak using Docker Compose.
Keycloak is an open-source software product to allow single sign-on with identity and access management aimed at modern applications and services.
💾 You can find the repository used in this guide on GitHub.
We will be using Traefik as a reverse proxy. It will be responsible for obtaining cryptographic certificates for your domain names from Let’s Encrypt and redirecting requests to specific domain names to the services corresponding to those domain names.
❗ It is important to note that you will need cryptographic certificates for your domain names. In my configuration, certificates are requested automatically using Traefik and Let’s Encrypt.
❗ To obtain cryptographic certificates, you will need A-type records in the external DNS zone, which point to the IP address of your server where Traefik is installed. If you have created these records recently, you should wait before starting the installation of the services. Full replication of these records between DNS servers can take from a few minutes to 48 hours or even longer in rare cases.
In this guide, we will consider the case where you already have a server with Ubuntu Server 22.04 LTS installed on it.
You can find detailed information on how to install Ubuntu Server 22.04 LTS in my guide “Install Ubuntu Server 22.04 LTS”.
Docker Engine and Docker Compose must also be installed on the server.
You can learn how to install Docker Engine on Ubuntu Server by reading Install Docker Engine and Docker Compose on Ubuntu Server”.
In addition, OpenSSH must be installed on the server, and port 22 must be open in order to be able to connect to the server using the SSH protocol.
To install OpenSSH on the server you can use the command:
sudo apt install openssh-server
If you plan to connect to the server using the Windows operating system, you can use PuTTY or MobaXterm.
This guide covers connecting to the server using the terminal emulator iTerm2, installed on the macOS operating system.
💡 Please note, you will need to open the following TCP ports for access to the services:
- TCP port 80 - to obtain a free cryptographic certificate through the Let’s Encrypt certification center.
- TCP port 443 - to access the Keycloak web interface.
We connect to the server on which Keycloak is planned to be installed.
Now it is necessary to create networks for your services.
We create a network for Traefik using the command:
docker network create traefik-network
We create a network for Keycloak using the command:
docker network create keycloak-network
Next, you need to clone the repository that contains the configuration files, which include all the necessary conditions for Keycloak to work.
You can clone the repository using the command:
git clone https://github.com/heyValdemar/keycloak-traefik-letsencrypt-docker-compose.git
Navigate to the directory with the repository using the command:
cd keycloak-traefik-letsencrypt-docker-compose
Next, you need to change the variables in the .env
file according to your requirements.
💡 Note that the .env
file should be in the same directory as keycloak-traefik-letsencrypt-docker-compose.yml
.
Now let’s start Keycloak with the command:
docker compose -f keycloak-traefik-letsencrypt-docker-compose.yml -p keycloak up -d
To access the Keycloak management panel, go to https://keycloak.heyvaldemar.net from your workstation, where keycloak.heyvaldemar.net is the domain name of my service. Accordingly, you need to specify your domain name that points to the IP address of your server with the installed Traefik service, which will redirect the request to Keycloak.
💡 Note that you need to specify the domain name of the service, previously defined in the .env
file.
Click on the “Administration Console” button.
Enter the username and password previously set in the .env
file, and click the “Sign In” button.
Welcome to the Keycloak control panel.
To access the Traefik control panel, go to https://traefik.keycloak.heyvaldemar.net from your workstation, where traefik.keycloak.heyvaldemar.net is the domain name of my service. Accordingly, you need to specify your domain name that points to the IP address of your server with the installed Traefik.
💡 Note that you need to specify the domain name of the service, previously defined in the .env
file.
Enter the username and password previously set in the .env
file, and click the “OK” button.
Welcome to the Traefik control panel.