This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Keycloak identity and access management on Amazon Linux 2023 with Amazon Corretto 21, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, no default admin password (per-instance bootstrap credential), and continuously patched images.
Keycloak (Hardened) on Amazon Linux 2023 is a production-ready, security-hardened image of the Keycloak identity and access management server (OpenID Connect, OAuth 2.0, SAML 2.0), maintained and supported by Derek Coleman & Associates Inc.
This is repackaged open-source software. Keycloak is a Cloud Native Computing Foundation project distributed under the Apache License 2.0. Keycloak is a trademark of Red Hat, Inc.; this listing is not endorsed by or affiliated with Red Hat or the CNCF. This product bundles unmodified upstream Keycloak on a hardened Amazon Linux 2023 base; the charges associated with this listing are for image hardening, continuous patching, vulnerability scanning, and business-day support - not for the underlying open-source software, which remains free.
Hardening baseline: minimal package footprint, SSH key-only access (password authentication disabled), IMDSv2 enforced, and no default admin credentials - the temporary bootstrap admin password is generated per instance on first boot (set to the EC2 instance ID); Keycloak requires you to create a permanent admin account on first login. Images are rebuilt, scanned for HIGH and CRITICAL vulnerabilities, and republished on a regular cadence so that new launches start current. Ships with the embedded dev-file database for evaluation and small deployments; point it at PostgreSQL for production clusters (documented in the usage instructions).
Highlights
Production-ready: Keycloak 26.7 on Amazon Corretto 21, systemd-managed, health endpoints enabled; swap the embedded database for PostgreSQL when you scale.
Security-hardened at build time: minimal packages, key-only SSH, IMDSv2-only, no default admin password - bootstrap credential is per-instance (the EC2 instance ID).
Continuously patched: rebuilt, vulnerability-scanned, and republished on a regular cadence.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay by the hour for the instance size you launch. All three options run the same hardened image; they differ only by compute capacity. The c7i.xlarge gives you 4 vCPU and 8 GiB memory. The c7i.2xlarge gives you 8 vCPU and 16 GiB. The c7i.4xlarge gives you 16 vCPU and 32 GiB. Software charges scale with the size you pick. There is no subscription and no minimum. AWS infrastructure charges are billed separately by AWS. Charges stop when you terminate the instance.
Top-of-mind questions for buyers
What am I actually paying the software charge for, given Keycloak is open-source?
The software charge covers image hardening, continuous patching, vulnerability scanning, and business-day support. It does not cover the underlying Keycloak software, which stays free under its open-source license. You pay for the maintained, security-hardened image and the support around it.
Am I charged the software fee when the instance is stopped or terminated?
Software charges stop when you terminate the instance. There is no subscription and no minimum, so metering follows running time. A stopped instance may still incur AWS storage fees for its EBS volume, billed separately by AWS.
Does the hourly software price change if I move to a larger instance for production scaling?
Yes. The software charge is tied to the instance size you launch. Moving from c7i.xlarge to c7i.2xlarge or c7i.4xlarge changes the hourly rate. You pick the size at launch; scaling up means launching a larger type, not an automatic upgrade.
products.dcassociatesgroup.com
Helpful?
Vendor refund policy
Usage-based hourly billing; charges stop when instances are terminated. Contact support@dcassociatesgroup.com for billing questions.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
[Security] Refreshed image: rebuilt on the latest hardened Amazon Linux 2023 baseline; all OS packages current at build.
Additional details
Usage instructions
Launch from AWS Marketplace (1-Click or EC2 console).
Use a web browser to access the application at http://<public-ip>:8080. Sign in with username admin and the temporary password equal to the EC2 instance ID (e.g. i-0abc123...); Keycloak then requires you to create a permanent admin account.
For production, terminate TLS on 8443 or a load balancer, set a hostname, and configure an external PostgreSQL database in /opt/keycloak/conf/keycloak.conf, then: sudo systemctl restart keycloak.
SSH access: ssh -i <key> ec2-user@<public-ip>. Root login is disabled; use sudo.
Verify: sudo systemctl status keycloak (health endpoints are enabled).
Sensitive data: the only credential is the temporary admin password (the EC2 instance ID), which you replace at first login. Logs under /var/log may contain client IPs - treat as personal data.
Backup: snapshot the EBS volume (it contains all configuration and data).
Resources: a single instance uses 1 EC2 instance and 1 gp3 EBS volume; no other AWS resources are created.
Support by Derek Coleman & Associates Incorporated. Email: support@dcassociatesgroup.com. Business-day response. Covers image operation, hardening baseline, and launch issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
This is a repackaged open source software product wherein additional charges apply for image hardening, maintenance, and support. Traefik reverse proxy on Amazon Linux 2023, security-hardened for production: minimal package set, SSH key-only access, IMDSv2-only, dashboard and API disabled, runs as a non-root user, and continuously patched images.
This product has charges associated with the pre-built hardening to the CIS Benchmarks™ and recurring maintenance. The CIS Hardened Images® are hardened in accordance with the associated CIS Benchmarks, an industry best practice for secure configuration. Reduce cost, time, and risk by building your AWS solution with CIS AMIs.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.