Listing Thumbnail

    Keycloak on Ubuntu LTS Minimal (by Epok Systems)

     Info
    Deployed on AWS
    Free Trial
    AWS Free Tier
    This is a repackaged software product wherein additional charges apply for seller maintenance. Deploy a ready-to-run Keycloak 26.7.0 identity and access management server on Ubuntu 24.04 LTS minimal. Pre-installed as a systemd service with key-only SSH, auto-generated admin credentials, and an HTTPS admin console for SAML/OIDC authentication, MFA, user federation, and single sign-on.

    Overview

    Welcome to Keycloak on Ubuntu LTS Minimal, a production-ready Amazon Machine Image (AMI) that delivers the industry-standard open-source identity and access management (IAM) solution on AWS. Built on Keycloak 26.7.0 and hardened on Ubuntu 24.04 LTS minimal, this AMI combines enterprise-grade security with a ready-to-run systemd service, so you can deploy single sign-on (SSO), SAML and OIDC authentication, multifactor authentication (MFA), and user federation in minutes.

    Why Keycloak for Identity & Access Management?

    Keycloak is the leading open-source identity and access management (IAM) solution, providing single sign-on (SSO), SAML and OIDC authentication, multifactor authentication (MFA), and user federation for modern applications. Instead of building authentication from scratch, you get a battle-tested identity provider that centralizes access control across your application portfolio.

    Enterprise Security Hardening

    This AMI ships with security best practices out of the box:

    • Key-Only SSH: Password authentication disabled, root login disabled, ensuring only key-based authentication
    • Hardened Service User: Keycloak runs as a hardened systemd service under a dedicated non-login keycloak user
    • Automatic Credential Generation: Random admin credentials generated on first boot and stored in /etc/keycloak/.admin-credentials (root-readable only)
    • TLS by Default: Self-signed TLS certificate auto-generated on first boot; admin console served over HTTPS on port 8443
    • Automatic Security Updates: OpenJDK 25 (default-jre-headless) and OS packages updated via apt

    Cloud-Optimized Configuration

    Designed for AWS EC2 environments:

    • Default User: Pre-configured ubuntu account with sudo privileges, ready for immediate use
    • Systemd-Managed: keycloak.service runs Keycloak as a managed service, with keycloak-firstboot.service handling initialization
    • Configurable via Environment: Set database and runtime options in /etc/keycloak/env.conf
    • Health Check Endpoint: Verify availability with curl -k https://127.0.0.1:9000/health
    • Flexible Storage: Embedded H2 database for development and test; PostgreSQL (e.g., Amazon RDS) for production

    Key Features & Benefits

    • Single Sign-On: One login for all your applications with SSO and centralized session management
    • Standard Protocols: Full SAML and OIDC support for seamless integration with your existing stack
    • Multifactor Authentication: Strengthen security with MFA across all federated applications
    • User Federation: Connect LDAP/Active Directory or custom user stores without migration
    • HTTPS Admin Console: Manage realms, clients, and users from a secure web console
    • Production-Ready Path: Start with embedded H2 for development, scale to PostgreSQL for production

    Use Cases

    • Centralized Authentication: Secure all internal tools and dashboards behind one identity provider
    • Customer-Facing Applications: Add SSO, SAML, or OIDC login to your web and mobile applications
    • DevOps & CI/CD: Test authentication and authorization flows in isolated, reproducible environments
    • Security & Compliance: Enforce MFA and centralized access control for compliance requirements

    Getting Started

    1. Launch an EC2 instance using this AMI
    2. Connect via SSH using your key pair with the default ubuntu account
    3. Retrieve the auto-generated admin credentials with sudo cat /etc/keycloak/.admin-credentials
    4. Access the admin console at https://<instance-ip>:8443
    5. Verify the service is healthy with curl -k https://127.0.0.1:9000/health
    6. (Optional) Point Keycloak at your own PostgreSQL via /etc/keycloak/env.conf

    Technical Specifications

    • Keycloak: 26.7.0 (latest stable release)
    • OS: Ubuntu 24.04 LTS minimal
    • Runtime: OpenJDK 25 (default-jre-headless)
    • Architecture: x86_64
    • Default User: ubuntu (with sudo privileges)
    • Authentication: SSH key-based
    • Admin Console: HTTPS on port 8443
    • Management API: HTTPS on port 9000
    • Database: Embedded H2 (dev/test) or external PostgreSQL (production)

    Why Choose This AMI?

    This AMI saves you hours of setup while delivering a secure, production-ready identity and access management foundation for your AWS workloads. Whether you need single sign-on, SAML or OIDC authentication, multifactor authentication, or user federation, this hardened, dependable identity provider deploys with confidence and scales with ease.

    Experience the power of open-source identity and access management on AWS. Deploy with confidence, secure with simplicity.

    Highlights

    • Ready-to-run Keycloak 26.7.0 as a hardened systemd service under a dedicated non-login 'keycloak' user on Ubuntu 24.04 LTS minimal
    • HTTPS admin console on port 8443 with auto-generated self-signed certificate and random admin credentials on first boot
    • Production-ready path: embedded H2 for dev/test, PostgreSQL via environment variables, OpenJDK 25 with automatic security updates, key-only SSH

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 7 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    Keycloak on Ubuntu LTS Minimal (by Epok Systems)

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.
    If you are an AWS Free Tier customer with a free plan, you are eligible to subscribe to this offer. You can use free credits to cover the cost of eligible AWS infrastructure. See AWS Free Tier  for more details. If you created an AWS account before July 15th, 2025, and qualify for the Legacy AWS Free Tier, Amazon EC2 charges for Micro instances are free for up to 750 hours per month. See Legacy AWS Free Tier  for more details.

    Usage costs (591)

     Info
    • ...
    Dimension
    Cost/hour
    t2.medium
    Recommended
    $0.02
    t3.micro
    $0.01
    t2.micro
    $0.01
    m7a.metal-48xl
    $0.13
    m7i.48xlarge
    $0.13
    m7i.metal-48xl
    $0.13
    p5.48xlarge
    $0.13
    r6a.48xlarge
    $0.13
    r6a.metal
    $0.07
    r7a.48xlarge
    $0.13

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for the software running on an Amazon EC2 instance. Pricing is not tiered by features. Instead, each dimension maps to a specific EC2 instance type, and the hourly rate follows the size and family of that instance. Smaller instances like t3.nano or t3.micro carry lower hourly rates. Larger compute, memory, GPU, and high-memory instances (such as m7i, r7i, p5.48xlarge, or u-24tb1.112xlarge) carry higher rates. You pick the instance type that fits your capacity needs and pay only for the hours it runs.

    Top-of-mind questions for buyers

    You pay a software fee for the pre-configured Keycloak on Ubuntu image running on that instance. This is charged on top of the underlying AWS compute cost. The rate maps to the instance type you launch, so larger or specialized instances carry higher software rates.
    The hourly software fee applies only while the instance runs. Stopped or paused instances stop accruing the software charge. Note that AWS may still bill separately for attached storage or other resources tied to a stopped instance, but that is not the software fee itself.
    You pay the hourly rate tied to whichever instance type is currently running. Switching to a larger family or size means the new rate applies from that point forward. There is no upfront commitment, so you can change instance types as capacity needs shift and pay only for hours used.
    epoksystems.com
    Helpful?

    Vendor refund policy

    We do not currently support refunds, but you can cancel at any time.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Version release notes

    Additional details

    Usage instructions

    1. Launch an EC2 instance using this AMI (t3.medium or larger, with a key pair and a security group allowing SSH on port 22 and HTTPS on port 8443)
    2. Connect via SSH with your key pair using the default ubuntu account
    3. Retrieve the auto-generated admin credentials with sudo cat /etc/keycloak/.admin-credentials
    4. Access the admin console at https://<instance-ip>:8443 (self-signed certificate)
    5. Verify the service is healthy with curl -k https://127.0.0.1:9000/health 
    6. (Optional) Point Keycloak at your own PostgreSQL via /etc/keycloak/env.conf
    7. (Optional) Full documentation: https://epoksystems.com/cloud/documentation/keycloak-2670-ubuntu-minimal/keycloak-2670-ubuntu-minimal/ 

    Support

    Vendor support

    Need help? Contact our experts at support@epoksystems.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.