Keycloak: why choose a managed solution rather than doing it yourself?

2025 05 15 clever cloud banniere blog keycloak en
Keycloak is the benchmark for managing identity and access in applications. It offers a rich range of functions: single sign-on, federation, MFA, fine-grained role management.

However, its deployment in production remains an obstacle for many. Complex maintenance, limited supervision, risky parameters… the obstacles are numerous.

Simplifying the use of Keycloak without sacrificing control

We found this to be the case during our last webinar. Within minutes, the session was fully booked. Many of the participants had already tested Keycloak. Few had put it into production. This confirms what we’re seeing in the field: technical teams are looking for a simpler solution, but one that’s no less robust.

With this in mind, we designed Keycloak as a Service. A managed, pre-configured solution hosted on dedicated infrastructure and integrated into the Clever Cloud ecosystem. It automates what needs to be automated, while giving teams the freedom to customise, extend and fine-tune their instance.

The webinar demonstrated this live. In less than six clicks, a Keycloak is deployed. It’s ready to use, secure and accessible with temporary identifiers. There are also pre-configured realms, the ability to import your existing configurations, and a Bootstrap administration client to automate deployments.

A managed solution for demanding teams

We haven’t touched the heart of Keycloak. The version we are offering remains faithful to the open source project maintained by Red Hat. But we have encapsulated all the operational aspects: supervision, backup, scalability and customisation. And we’ve made it accessible via our usual tools.

During the webinar, several participants expressed their fears about going into production. This feedback is frequent. It reflects a reality: Keycloak is not easy to use independently. It requires specific skills, constant attention and an effort to ensure security right from the initial configuration.

Our managed solution meets these challenges. It automates the critical points, without locking teams in. The instance can be modified, extended and integrated. You can add your own themes, modules and rules.

Do you feel you need support to push customisation/migration further? Our partner Please Open IT can help.

Keycloak integrated into your Clever Cloud environment

One of the major advantages of our Keycloak as a Service is its natural integration into your existing architecture. Whether your applications are deployed on Clever Cloud or elsewhere, you can connect the services via our private networks, our Files System Buckets and our PostgreSQL databases.

To ensure that several instances communicate securely with each other, you can use our Network Groups. This mechanism allows you to establish private connections between your services, without public exposure. This is particularly useful for connecting several Keycloak nodes, or for connecting Keycloak to other components such as an LDAP database or an internal OpenID provider. All without complex network configuration.

You also get technical and business dashboards. These enable you to monitor the load, connections, performance and usage of your users. These metrics can be accessed from Grafana, without any additional configuration.

Finally, our solution is designed to be scalable. It can manage thousands of connections, with synchronised nodes and an auto-scaling system. All the instances are isolated, with their own application, database and storage. This isolation guarantees performance and security, with no shared resources.

Shared vision, concrete results

This project was born out of a call. Please Open It asked us to co-construct a managed, reliable and scalable solution to democratise the use of Keycloak. We accepted without hesitation. Because we share the same high technical standards. And because we too believe that Keycloak deserves to be used differently.

The webinar is an illustration of this: beyond the technical demonstration, it showed a real need. The need to delegate the operation of a powerful but complex tool. A need to focus on usage, not servers.

The solution is available now, from €37/month, with a dedicated infrastructure and isolated resources. You can test it, configure it and connect it to your ecosystem in just a few clicks.

The full replay of the webinar is now available. You’ll find the presentation, a demonstration of our Keycloak as a Service, and answers to all the questions asked by participants.

Blog

À lire également

UP Program: Clever Cloud announces its fifth startup selection

With this new batch, Clever Cloud welcomes four startups to the UP Program: Sentibee, Pictaderm, Legaia and Cockpit Agriculture.
Company

Sōzu 2.0 — turning a reverse proxy into a programmable edge

Sōzu is the reverse proxy that sits in front of every application running on Clever Cloud. After eighteen months of work — first the HTTP/2 multiplexer, built on our existing kawa pivot, then almost every other layer of the proxy, and finally a long run in production on the cleverapps.io load balancers — Sōzu 2.0 is out.
Engineering

K3s vs K8s: What Are the Differences and Which One Should You Choose in 2026?

Kubernetes has become the standard for container orchestration. But depending on your infrastructure constraints (limited resources, edge computing, IoT, or large-scale enterprise clusters), the distribution you choose can radically change the operational experience. K3s and K8s (upstream Kubernetes) address different needs, even though both share the same CNCF-certified foundation.
Engineering Features