Keycloak Setup and Configuration
Budget: $3,000 – $5,000 USD
1. Project Overview
The objective of this project is to design, implement, and configure a secure and highly available Keycloak Identity and Access Management (IAM) solution for our infrastructure. This will serve as a central identity provider (IdP) for our applications and services, with support for load balancing, external identity federation, and potential peer-to-peer or multi-instance federation between environments.
2. Requirements
2.1 Infrastructure Setup
•
Deploy single production-grade instance of Keycloak behind a load balancer.
•
Configure Keycloak with a dedicated domain name (e.g., auth.example.com) accessible by all internal and external servers/services.
•
Ensure SSL/TLS termination and secure communication across all components.
•
Provide automation (Docker, Kubernetes, or VM-based deployment scripts) for reproducibility.
2.2 High Availability & Scalability
•
Configure clustered Keycloak nodes behind the load balancer to ensure redundancy and failover.
•
Support for scaling horizontally to handle increased authentication loads.
•
Ensure session replication or sticky session handling for user logins.
2.3 Multi-Instance / Federation Setup
•
Support cases where two or more Keycloak instances may need to connect (peer-to-peer or central hub model).
•
Configure trust relationships between instances to allow users authenticated in one Keycloak instance to access services in another.
•
Document synchronization or brokering setup across Keycloak instances.
2.4 Identity Management and Identity Federation
•
Configure Keycloak to act as a default identity provider in the absence of enterprise OAuth/OpenID service.
•
Configure federated identity providers for external authentication:
o
Google (OAuth2/OpenID Connect)
o
Microsoft Azure AD / Entra ID (SAML or OpenID Connect)
•
Allow Single Sign-On (SSO) with these providers for designated client applications.
2.5 Client & Realm Configuration
•
Create standard realm and client templates for new applications.
•
Document and demonstrate integration with at least two test applications (sample web app and sample API).
•
Define user roles, groups, and basic policies to serve as a reference model.
•
Ensure that machine-to-machine authentication capability is provisioned. In particular, client frontends must be able to authenticate seamlessly (single sign on) with backends/API’s without undertaking a login flow. Links to 2.3. above.
2.6 Security & Compliance
•
Enforce best practices for password policies, session management, and MFA support.
•
Enable audit logging and monitoring of Keycloak activity.
•
Ensure GDPR-compliant user data management (account deletion, consent, etc.).
2.7 License Expiry Warning and Monitoring
•
Implement monitoring for Keycloak license expiration to proactively detect and alert on approaching license expiry dates.
•
Configure automated email notifications or dashboard alerts to notify the administrator and stakeholders at defined intervals before the license expiration (e.g., 90, 60, 30, and 7 days prior).
•
Provide clear documentation on how to verify license status and renew the Keycloak license to avoid service disruption.
•
Include recommendations for contingency plans in case of license expiration, such as failover procedures or temporary access restrictions.
2.8 Documentation & Handover
•
Provide detailed documentation covering:
o
Deployment and architecture diagrams
o
Configuration steps and scripts
o
Integration guide for new applications
o
Federation setup procedures
•
Conduct a knowledge transfer session with our internal team.
3. Deliverables
•
Production-ready Keycloak environment behind load balancer
•
Configured domain and SSL certificates
•
Federation with Google and Microsoft identity providers
•
Optional multi-instance federation setup
•
Documentation and handover session
4. Consultant Responsibilities
•
Propose the deployment architecture (VM-based, Docker, Kubernetes, etc.) suitable for high availability and scaling.
•
Implement Keycloak against existing services after deployment architecture recommendation.
•
Provide estimated timelines and costs.
•
Offer ongoing support/maintenance options (if available).
5. Evaluation Criteria
•
Proven experience deploying and managing Keycloak in production environments
•
Demonstrated expertise with SSO, OAuth2, OIDC, and SAML
•
Familiarity with identity federation (Google, Microsoft, etc.)
•
Clear and competitive pricing structure
The objective of this project is to design, implement, and configure a secure and highly available Keycloak Identity and Access Management (IAM) solution for our infrastructure. This will serve as a central identity provider (IdP) for our applications and services, with support for load balancing, external identity federation, and potential peer-to-peer or multi-instance federation between environments.
2. Requirements
2.1 Infrastructure Setup
•
Deploy single production-grade instance of Keycloak behind a load balancer.
•
Configure Keycloak with a dedicated domain name (e.g., auth.example.com) accessible by all internal and external servers/services.
•
Ensure SSL/TLS termination and secure communication across all components.
•
Provide automation (Docker, Kubernetes, or VM-based deployment scripts) for reproducibility.
2.2 High Availability & Scalability
•
Configure clustered Keycloak nodes behind the load balancer to ensure redundancy and failover.
•
Support for scaling horizontally to handle increased authentication loads.
•
Ensure session replication or sticky session handling for user logins.
2.3 Multi-Instance / Federation Setup
•
Support cases where two or more Keycloak instances may need to connect (peer-to-peer or central hub model).
•
Configure trust relationships between instances to allow users authenticated in one Keycloak instance to access services in another.
•
Document synchronization or brokering setup across Keycloak instances.
2.4 Identity Management and Identity Federation
•
Configure Keycloak to act as a default identity provider in the absence of enterprise OAuth/OpenID service.
•
Configure federated identity providers for external authentication:
o
Google (OAuth2/OpenID Connect)
o
Microsoft Azure AD / Entra ID (SAML or OpenID Connect)
•
Allow Single Sign-On (SSO) with these providers for designated client applications.
2.5 Client & Realm Configuration
•
Create standard realm and client templates for new applications.
•
Document and demonstrate integration with at least two test applications (sample web app and sample API).
•
Define user roles, groups, and basic policies to serve as a reference model.
•
Ensure that machine-to-machine authentication capability is provisioned. In particular, client frontends must be able to authenticate seamlessly (single sign on) with backends/API’s without undertaking a login flow. Links to 2.3. above.
2.6 Security & Compliance
•
Enforce best practices for password policies, session management, and MFA support.
•
Enable audit logging and monitoring of Keycloak activity.
•
Ensure GDPR-compliant user data management (account deletion, consent, etc.).
2.7 License Expiry Warning and Monitoring
•
Implement monitoring for Keycloak license expiration to proactively detect and alert on approaching license expiry dates.
•
Configure automated email notifications or dashboard alerts to notify the administrator and stakeholders at defined intervals before the license expiration (e.g., 90, 60, 30, and 7 days prior).
•
Provide clear documentation on how to verify license status and renew the Keycloak license to avoid service disruption.
•
Include recommendations for contingency plans in case of license expiration, such as failover procedures or temporary access restrictions.
2.8 Documentation & Handover
•
Provide detailed documentation covering:
o
Deployment and architecture diagrams
o
Configuration steps and scripts
o
Integration guide for new applications
o
Federation setup procedures
•
Conduct a knowledge transfer session with our internal team.
3. Deliverables
•
Production-ready Keycloak environment behind load balancer
•
Configured domain and SSL certificates
•
Federation with Google and Microsoft identity providers
•
Optional multi-instance federation setup
•
Documentation and handover session
4. Consultant Responsibilities
•
Propose the deployment architecture (VM-based, Docker, Kubernetes, etc.) suitable for high availability and scaling.
•
Implement Keycloak against existing services after deployment architecture recommendation.
•
Provide estimated timelines and costs.
•
Offer ongoing support/maintenance options (if available).
5. Evaluation Criteria
•
Proven experience deploying and managing Keycloak in production environments
•
Demonstrated expertise with SSO, OAuth2, OIDC, and SAML
•
Familiarity with identity federation (Google, Microsoft, etc.)
•
Clear and competitive pricing structure