---
title: "Cloud server with Keycloak"
sidebar_label: "Keycloak"
sidebar_position: 15
toc_max_heading_level: 3
description: "How to create a cloud server to manage user authentication and authorization"
---

import EditIcon from '@selectel/docux/icons/edit'
import CheckIcon from '@selectel/docux/icons/check'
import Tabs from '@theme/Tabs'
import TabItem from '@theme/TabItem'
import {TabItemLabel} from '@selectel/docux/components'
import {CustomTable} from '@selectel/docux/components'
import Formbricks from '@theme/MDXComponents/Formbricks'
import CopyIcon from '@selectel/docux/icons/copy'
import CreateServer from '@site/i18n/en/docusaurus-plugin-content-docs/current/_partials/cloud-servers/applications/create-server-for-apps.mdx'

# Cloud server with Keycloak

Keycloak is an open-source platform for managing user authentication and authorization in applications, and for implementing Single Sign-On.

You can [create a cloud server with a ready-made Keycloak application](#create-cloud-server-with-keycloak).

Before creating a cloud server with an application, review the [software license agreements](https://423.selcdn.ru/kb/license-agreements-for-application-images-LANG.pdf) included in the image.

## Minimum resource requirements \{#minimum-requirements}

<CustomTable>
  <table>
    <tbody>
      <tr>
        <th>Number of vCPUs</th><td>2</td>
      </tr>

      <tr>
        <th>RAM</th><td>4 GB</td>
      </tr>

      <tr>
        <th>Boot volume</th><td>30 GB</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

## Create a cloud server with Keycloak \{#create-cloud-server-with-keycloak}

:::info

The cloud server with Keycloak will be available via SSH on port 22022.

:::

For Keycloak to work, the cloud server must be accessible from the internet. To do this, when creating a server, you must create a private subnet and attach a public floating IP address. To configure Keycloak, you must specify the application parameters when creating the server.

After the server with Keycloak is created, a free [TLS certificate from Let’s Encrypt®](/certificates-manager/certificates/lets-encrypt.mdx) will be automatically issued for the domain you specify. To issue the certificate, you need to add an A record for the domain and specify the server's public floating IP address as the record value. You can add the domain to [Selectel DNS Hosting (actual](/dns-hosting/)).

1. [Create a public floating IP address](#create-floating-ip).

2. [Add an A record for the domain](#add-a-record).

3. [Create a cloud server with Keycloak](#create-keycloak-server).

### 1. Create a public floating IP address \{#create-floating-ip}

Create a public floating IP address to make the Keycloak cloud server accessible from the internet.

Use the [Create a public floating IP address](/cloud-servers/cloud-networks/public-floating-ip-addresses.mdx#create-public-floating-ip) section of the [Public floating IP addresses](/cloud-servers/cloud-networks/public-floating-ip-addresses.mdx) guide.

### 2. Add an A record for the domain⁠ \{#add-a-record}

[Add a resource record](/dns-hosting/records/add-record.mdx) to access Keycloak by domain.

Specify:

* [resource record type](/dns-hosting/records/add-record.mdx#record-types) — A;
* record value — the public floating IP address you [created in step 1](#create-floating-ip).

### 3. Create a cloud server with Keycloak \{#create-keycloak-server}

<CreateServer AppNameInPanel="Cloud Keycloak" MinConfig="2 vCPU, RAM starting from 4 GB and a boot disk size starting from 30 GB" OptionalVolumes="Optional: add an additional" VolumeSize="Specify the size of the network disk in GB or TB">
  4. Fill in the application parameters:

     4.1. In the **Domain Zone** field, enter the domain for accessing Keycloak that you [added in step 2](#add-a-record).

     4.2. Enter the Keycloak administrator email address to create an account and receive Let’s Encrypt® notifications.

     4.3. Enter the Keycloak administrator username. If the parameter is not set, the default value is `admin`.

     4.4. Enter the Keycloak administrator password.

     4.5. Optional: откройте блок **Дополнительные параметры** and введите IP-адреса or CIDR администратора, with которых будет доступна панель Keycloak. Если параметр не задан, панель будет доступна with любого IP-адреса.
</CreateServer>

<Formbricks />
