Overview
Deploy a private and self hosted identity and access management platform inside your AWS account without spending hours installing, configuring, and securing the underlying software stack. Keycloak Identity and Access Management Server by Code Creator provides a ready to launch environment for developers, software companies, platform teams, IT administrators, and organizations that need centralized authentication and access control for applications and services.
The AMI includes Keycloak 26.7.0, PostgreSQL 18.4, Nginx, Docker, and Docker Compose on Ubuntu 26.04 LTS. Automated first boot provisioning generates unique administrator and database credentials, creates an HTTPS certificate for the instance public IP address, initializes the database, configures the permanent Keycloak administrator, and starts the complete application stack. Customers can retrieve their generated login information through SSH and access the Keycloak administration console within minutes.
Keycloak supports Single Sign On, OpenID Connect, OAuth 2, SAML, LDAP, Active Directory, external identity providers, multi factor authentication, OTP, WebAuthn, user federation, role based access control, and customizable login, registration, password recovery, and account pages. Administrators can manage users, groups, roles, clients, permissions, identity providers, and authentication flows from one centralized interface.
The product also includes operating tools that simplify common administration tasks. Customers can check system health, display generated credentials, review logs, restart the application stack, create validated backups, and restore compatible backups using included commands. PostgreSQL and Keycloak internal service ports remain private within the Docker network configuration, while customer data, administrator credentials, identity information, and backups remain inside the customer AWS account.
No domain name or IAM instance role is required for the validated quick start deployment. Customers can launch the AMI with a public IP address and begin configuring authentication services immediately. The initial HTTPS certificate is self signed and generated for the public IP address detected during first boot. Customers planning a long term production deployment should use a stable network address and a properly managed TLS configuration.
This is a repackaged open source software product. Software charges apply for Code Creator AMI engineering, automated deployment, first boot provisioning, AWS configuration, operating tools, customer documentation, maintenance, Marketplace compliance, and support. Keycloak remains open source software, and official documentation and community resources remain available from the Keycloak project.
Highlights
- Launch a ready to use Keycloak 26.7.0 server in minutes. Automated first boot generates unique administrator and database credentials, creates an HTTPS certificate for the instance public IP, initializes PostgreSQL, and starts the complete application stack automatically
- Centralize authentication and authorization with standards based Single Sign On using OpenID Connect, OAuth 2.0, and SAML 2.0. Create realms, users, groups, roles, clients, authentication flows, and self-service account experiences from the Keycloak administration console
- Connect existing identity sources with LDAP, Active Directory, and external identity providers. The AMI includes private PostgreSQL networking, Nginx HTTPS access, status and log helpers, safe restart commands, and validated backup and restore tools
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Cost/hour |
|---|---|
t3.medium Recommended | $0.03 |
t3.xlarge | $0.03 |
t3.2xlarge | $0.03 |
t3.large | $0.03 |
m7i.12xlarge | $0.03 |
m7i.2xlarge | $0.03 |
m7i.4xlarge | $0.03 |
m7i.8xlarge | $0.03 |
m7i.large | $0.03 |
Vendor refund policy
You may cancel the AWS Marketplace subscription at any time. No contracts. Software charges already incurred are not refundable.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
This enhanced release updates Keycloak to version 26.7.0 on Ubuntu 26.04 LTS with PostgreSQL 18.4 and Nginx 1.30.4. It adds faster automated first boot, unique administrator and database credentials, HTTPS setup, improved network isolation, customer helper commands, and validated backup and restore tools. Fresh launch, browser login, reboot recovery, administrator access, and runtime health were fully validated.
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.