Articles about keycloak-operations from the Skycloak team.
Keep secrets out of Keycloak config: use the Keycloak vault SPI to resolve database, SMTP, and client secrets from a…
Keycloak 26.7's stateless preview kills the external Infinispan requirement for multi-cluster. We tested it on YugabyteDB and mapped a multi-cloud…
Migrate from the legacy WildFly Keycloak distribution to Quarkus: config conversion, the removed /auth path, custom provider changes, and a…
The difference between the Skycloak and community keycloak/keycloak Terraform providers, when to use each, and how to run both in…
Fix Keycloak database connection pool exhaustion: size the Quarkus datasource pool, handle DB restarts and leaks, and detect connections growing…
Run Keycloak on OpenShift and Azure Red Hat OpenShift in production: operator vs Helm, HA clustering, TLS route modes, and…
How many realms one Keycloak cluster can handle, measured: the cache settings to reach thousands, why restarts hit 7.5 minutes,…
How to back up and restore Keycloak: why the database is the source of truth, backing up PostgreSQL, realm exports…
Locke is an Apache 2.0 distribution of Keycloak that ships with both embedded Infinispan and a Redis cache backend, selectable…
A production benchmark of Keycloak caching on Redis (Locke) vs embedded Infinispan: ~100% throughput parity, sub-second node-loss recovery vs 31-40s.
Get tutorials, product updates, and Keycloak tips delivered to your inbox.