Keycloak Setup and Configuration

Job ID: 39781761

Budget: $3,000 – $5,000 USD

1. Project Overview
The objective of this project is to design, implement, and configure a secure and highly available Keycloak Identity and Access Management (IAM) solution for our infrastructure. This will serve as a central identity provider (IdP) for our applications and services, with support for load balancing, external identity federation, and potential peer-to-peer or multi-instance federation between environments.
2. Requirements
2.1 Infrastructure Setup

Deploy single production-grade instance of Keycloak behind a load balancer.

Configure Keycloak with a dedicated domain name (e.g., auth.example.com) accessible by all internal and external servers/services.

Ensure SSL/TLS termination and secure communication across all components.

Provide automation (Docker, Kubernetes, or VM-based deployment scripts) for reproducibility.
2.2 High Availability & Scalability

Configure clustered Keycloak nodes behind the load balancer to ensure redundancy and failover.

Support for scaling horizontally to handle increased authentication loads.

Ensure session replication or sticky session handling for user logins.

2.3 Multi-Instance / Federation Setup

Support cases where two or more Keycloak instances may need to connect (peer-to-peer or central hub model).

Configure trust relationships between instances to allow users authenticated in one Keycloak instance to access services in another.

Document synchronization or brokering setup across Keycloak instances.
2.4 Identity Management and Identity Federation

Configure Keycloak to act as a default identity provider in the absence of enterprise OAuth/OpenID service.

Configure federated identity providers for external authentication:
o
Google (OAuth2/OpenID Connect)
o
Microsoft Azure AD / Entra ID (SAML or OpenID Connect)

Allow Single Sign-On (SSO) with these providers for designated client applications.
2.5 Client & Realm Configuration

Create standard realm and client templates for new applications.

Document and demonstrate integration with at least two test applications (sample web app and sample API).

Define user roles, groups, and basic policies to serve as a reference model.

Ensure that machine-to-machine authentication capability is provisioned. In particular, client frontends must be able to authenticate seamlessly (single sign on) with backends/API’s without undertaking a login flow. Links to 2.3. above.
2.6 Security & Compliance

Enforce best practices for password policies, session management, and MFA support.

Enable audit logging and monitoring of Keycloak activity.

Ensure GDPR-compliant user data management (account deletion, consent, etc.).
2.7 License Expiry Warning and Monitoring

Implement monitoring for Keycloak license expiration to proactively detect and alert on approaching license expiry dates.

Configure automated email notifications or dashboard alerts to notify the administrator and stakeholders at defined intervals before the license expiration (e.g., 90, 60, 30, and 7 days prior).

Provide clear documentation on how to verify license status and renew the Keycloak license to avoid service disruption.

Include recommendations for contingency plans in case of license expiration, such as failover procedures or temporary access restrictions.
2.8 Documentation & Handover

Provide detailed documentation covering:
o
Deployment and architecture diagrams
o
Configuration steps and scripts
o
Integration guide for new applications
o
Federation setup procedures

Conduct a knowledge transfer session with our internal team.
3. Deliverables

Production-ready Keycloak environment behind load balancer

Configured domain and SSL certificates

Federation with Google and Microsoft identity providers

Optional multi-instance federation setup

Documentation and handover session
4. Consultant Responsibilities

Propose the deployment architecture (VM-based, Docker, Kubernetes, etc.) suitable for high availability and scaling.

Implement Keycloak against existing services after deployment architecture recommendation.

Provide estimated timelines and costs.

Offer ongoing support/maintenance options (if available).
5. Evaluation Criteria

Proven experience deploying and managing Keycloak in production environments

Demonstrated expertise with SSO, OAuth2, OIDC, and SAML

Familiarity with identity federation (Google, Microsoft, etc.)

Clear and competitive pricing structure