This product has charges associated with it for image hardening, maintenance, and support. Keycloak identity and access management on Amazon Linux 2023 with Amazon Corretto 21, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, no default admin password (per-instance bootstrap credential), and continuously patched images.
Keycloak (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Keycloak identity and access management server (OpenID Connect, OAuth 2.0, SAML 2.0), maintained and supported by Derek Coleman & Associates Incorporated.
This is repackaged open-source software. Keycloak is a Cloud Native Computing Foundation project distributed under the Apache License 2.0. Keycloak is a trademark of Red Hat, Inc.; this listing is not endorsed by or affiliated with Red Hat or the CNCF. This product bundles unmodified upstream Keycloak on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no default admin credentials - the temporary bootstrap admin password is generated per instance on first boot (set to the EC2 instance ID); Keycloak requires you to create a permanent admin account on first login. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Ships with the embedded dev-file database for evaluation and small deployments; point it at PostgreSQL for production clusters (documented in the usage instructions).
Highlights
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, no default admin password - bootstrap credential is per-instance (the EC2 instance ID).
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
Production-ready: Keycloak 26.7 on Amazon Corretto 21, systemd-managed, health endpoints enabled; swap the embedded database for PostgreSQL when you scale.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for a hardened Keycloak image running on Amazon Linux 2023. Pricing is organized by compute instance size, not by feature tiers. The three options—c7i.xlarge, c7i.2xlarge, and c7i.4xlarge—reflect increasing vCPU and memory capacity. You select the instance that matches your workload. Software fees accrue only while an instance runs and are metered by AWS on your existing invoice. The underlying compute, storage, and network are billed separately by AWS. All three options deliver the same software; they differ only in the machine size you run it on.
Top-of-mind questions for buyers
What compute specification do I get with each c7i instance size?
Each option maps to a compute-optimized instance size. c7i.xlarge offers 4 vCPUs, c7i.2xlarge offers 8 vCPUs, and c7i.4xlarge offers 16 vCPUs, with memory scaling accordingly. You pick the size that fits your Keycloak workload. The software runs identically on all three sizes.
Am I charged when the instance is stopped or powered off?
Software fees accrue only while an instance runs. Fully stopped instances do not generate software charges. The vendor meters running time only and does not access your instances. Underlying AWS storage may still incur separate AWS fees while the instance is stopped.
Are the compute and storage costs included in the hourly software price?
No. The hourly rate covers the software license only. AWS bills the underlying compute, storage, and network separately under your own account agreement. Both the software fee and the AWS infrastructure charges appear on your existing AWS invoice, metered by AWS.
www.dcassociatesgroup.com+1
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console). Browse to http://<public-ip>:8080 and sign in with username admin and the temporary password equal to the EC2 instance ID (e.g. i-0abc123...); Keycloak then requires you to create a permanent admin account. For production, terminate TLS on 8443 or a load balancer, set a hostname, and configure an external PostgreSQL database in /opt/keycloak/conf/keycloak.conf, then: sudo systemctl restart keycloak. SSH: ssh -i <key> ec2-user@<public-ip>; root login is disabled; use sudo.
Support
Vendor support
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This product has charges associated with it for seller support. Keycloak is an open-source identity and access management (IAM) solution designed to secure applications and services. Developed by Red Hat, Keycloak simplifies user authentication, authorization, and user management, offering a centralized platform for handling identity-related tasks. It supports various authentication methods, including social logins, single sign-on (SSO), and multi-factor authentication, making it a versatile solution for securing web applications, mobile apps, and APIs.
This is a repackaged open source software product wherein additional charges apply for patching the operating system and the maintenance provided by Kurian. This AMI has Keycloak installed as a service with PostgreSQL as the backend database.
Choose AMI for the target OS and version.
Launch a private Keycloak identity and access management server on AWS with automated first boot, generated administrator credentials, HTTPS access, PostgreSQL, and built in backup and restore helpers. This product has a fee associated with the provision and deployment of the application and AMI support.
KeyCloak is an Identity and Access Management Solution. Add authentication to applications and secure services with minimum effort. No need to deal with storing users or authenticating users.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.