This is a repackaged software product wherein additional charges apply for seller maintenance.
Deploy a ready-to-run Keycloak 26.7.0 identity and access management server on Ubuntu 24.04 LTS minimal. Pre-installed as a systemd service with key-only SSH, auto-generated admin credentials, and an HTTPS admin console for SAML/OIDC authentication, MFA, user federation, and single sign-on.
Welcome to Keycloak on Ubuntu LTS Minimal, a production-ready Amazon Machine Image (AMI) that delivers the industry-standard open-source identity and access management (IAM) solution on AWS. Built on Keycloak 26.7.0 and hardened on Ubuntu 24.04 LTS minimal, this AMI combines enterprise-grade security with a ready-to-run systemd service, so you can deploy single sign-on (SSO), SAML and OIDC authentication, multifactor authentication (MFA), and user federation in minutes.
Why Keycloak for Identity & Access Management?
Keycloak is the leading open-source identity and access management (IAM) solution, providing single sign-on (SSO), SAML and OIDC authentication, multifactor authentication (MFA), and user federation for modern applications. Instead of building authentication from scratch, you get a battle-tested identity provider that centralizes access control across your application portfolio.
Enterprise Security Hardening
This AMI ships with security best practices out of the box:
Hardened Service User: Keycloak runs as a hardened systemd service under a dedicated non-login keycloak user
Automatic Credential Generation: Random admin credentials generated on first boot and stored in /etc/keycloak/.admin-credentials (root-readable only)
TLS by Default: Self-signed TLS certificate auto-generated on first boot; admin console served over HTTPS on port 8443
Automatic Security Updates: OpenJDK 25 (default-jre-headless) and OS packages updated via apt
Cloud-Optimized Configuration
Designed for AWS EC2 environments:
Default User: Pre-configured ubuntu account with sudo privileges, ready for immediate use
Systemd-Managed: keycloak.service runs Keycloak as a managed service, with keycloak-firstboot.service handling initialization
Configurable via Environment: Set database and runtime options in /etc/keycloak/env.conf
Health Check Endpoint: Verify availability with curl -k https://127.0.0.1:9000/health
Flexible Storage: Embedded H2 database for development and test; PostgreSQL (e.g., Amazon RDS) for production
Key Features & Benefits
Single Sign-On: One login for all your applications with SSO and centralized session management
Standard Protocols: Full SAML and OIDC support for seamless integration with your existing stack
Multifactor Authentication: Strengthen security with MFA across all federated applications
User Federation: Connect LDAP/Active Directory or custom user stores without migration
HTTPS Admin Console: Manage realms, clients, and users from a secure web console
Production-Ready Path: Start with embedded H2 for development, scale to PostgreSQL for production
Use Cases
Centralized Authentication: Secure all internal tools and dashboards behind one identity provider
Customer-Facing Applications: Add SSO, SAML, or OIDC login to your web and mobile applications
DevOps & CI/CD: Test authentication and authorization flows in isolated, reproducible environments
Security & Compliance: Enforce MFA and centralized access control for compliance requirements
Getting Started
Launch an EC2 instance using this AMI
Connect via SSH using your key pair with the default ubuntu account
Retrieve the auto-generated admin credentials with sudo cat /etc/keycloak/.admin-credentials
Access the admin console at https://<instance-ip>:8443
Verify the service is healthy with curl -k https://127.0.0.1:9000/health
(Optional) Point Keycloak at your own PostgreSQL via /etc/keycloak/env.conf
Technical Specifications
Keycloak: 26.7.0 (latest stable release)
OS: Ubuntu 24.04 LTS minimal
Runtime: OpenJDK 25 (default-jre-headless)
Architecture: x86_64
Default User: ubuntu (with sudo privileges)
Authentication: SSH key-based
Admin Console: HTTPS on port 8443
Management API: HTTPS on port 9000
Database: Embedded H2 (dev/test) or external PostgreSQL (production)
Why Choose This AMI?
This AMI saves you hours of setup while delivering a secure, production-ready identity and access management foundation for your AWS workloads. Whether you need single sign-on, SAML or OIDC authentication, multifactor authentication, or user federation, this hardened, dependable identity provider deploys with confidence and scales with ease.
Experience the power of open-source identity and access management on AWS. Deploy with confidence, secure with simplicity.
Highlights
Ready-to-run Keycloak 26.7.0 as a hardened systemd service under a dedicated non-login 'keycloak' user on Ubuntu 24.04 LTS minimal
HTTPS admin console on port 8443 with auto-generated self-signed certificate and random admin credentials on first boot
Production-ready path: embedded H2 for dev/test, PostgreSQL via environment variables, OpenJDK 25 with automatic security updates, key-only SSH
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 7 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier for more details.
You pay by the hour for the software running on an Amazon EC2 instance. Pricing is not tiered by features. Instead, each dimension maps to a specific EC2 instance type, and the hourly rate follows the size and family of that instance. Smaller instances like t3.nano or t3.micro carry lower hourly rates. Larger compute, memory, GPU, and high-memory instances (such as m7i, r7i, p5.48xlarge, or u-24tb1.112xlarge) carry higher rates. You pick the instance type that fits your capacity needs and pay only for the hours it runs.
Top-of-mind questions for buyers
What exactly am I paying for with the hourly software rate on each EC2 instance type?
You pay a software fee for the pre-configured Keycloak on Ubuntu image running on that instance. This is charged on top of the underlying AWS compute cost. The rate maps to the instance type you launch, so larger or specialized instances carry higher software rates.
Am I charged the software fee when my instance is stopped or paused?
The hourly software fee applies only while the instance runs. Stopped or paused instances stop accruing the software charge. Note that AWS may still bill separately for attached storage or other resources tied to a stopped instance, but that is not the software fee itself.
If I move to a larger instance type, how does my cost change?
You pay the hourly rate tied to whichever instance type is currently running. Switching to a larger family or size means the new rate applies from that point forward. There is no upfront commitment, so you can change instance types as capacity needs shift and pay only for hours used.
epoksystems.com
Helpful?
Vendor refund policy
We do not currently support refunds, but you can cancel at any time.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
Launch an EC2 instance using this AMI (t3.medium or larger, with a key pair and a security group allowing SSH on port 22 and HTTPS on port 8443)
Connect via SSH with your key pair using the default ubuntu account
Retrieve the auto-generated admin credentials with sudo cat /etc/keycloak/.admin-credentials
Access the admin console at https://<instance-ip>:8443 (self-signed certificate)
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Secure your cloud infrastructure with our CIS-hardened Ubuntu AMI, meticulously crafted to meet industry best practices. Built on a minimal Ubuntu standard image, our AMI applies a subset of CIS hardening rules, enhancing your AWS environment's resilience against cyber threats.
This product has charges associated with it for seller maintenance.
This is a repackaged open source software product wherein additional charges apply for support provided by Galaxys
Minimal Ubuntu 22.04 LTS - Jammy (Arm) is a preconfigured, user-friendly product tailored for Arm-based systems, ensuring a seamless and efficient experience.
This is a repackaged software product wherein additional charges apply for Bansir's support 24 hours for 365 days of the years. Minimal Ubuntu 22.04 LTS Jammy for ARM is a preconfigured solution, complemented by Bansir's expert support, offering a streamlined ARM experience for efficient operations.
This product has charges associated includes additional support provided by Fifty Clouds. By choosing this product, you gain not only the robustness of the original software but also access to specialized technical assistance and updates, ensuring optimal performance and seamless integration in your AWS environment.
This is a repackaged open source software product wherein additional charges apply for support. Linux Mint is an operating system for desktop and laptop computers. It is designed to work 'out of the box' and comes fully equipped with the apps most people need.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.