KeycloakPro

Open Source · Upstream Keycloak

Open source identity, with no strings attached

Everything we build runs on the same Keycloak the community ships — no proprietary fork, no closed add-ons you can't leave. Your realms, themes and extensions live as code in your repositories, and you can take operations in-house whenever you choose.

  • Apache 2.0 licensed
  • No proprietary fork
  • Everything as code, owned by you

Standards & integrations

  • Apache License 2.0
  • CNCF
  • Quarkus
  • Keycloak Operator
  • Terraform / OpenTofu
  • Helm
  • OCI container images

Overview

Why we only work on upstream Keycloak

Keycloak is Apache 2.0 licensed and developed in the open as a CNCF project, with a Quarkus-based distribution and a public release history. We deliberately don't fork it or wrap it in a proprietary layer: every configuration, theme and extension we write targets upstream APIs, sits in your repositories and runs on the official images. If you ever part ways with us, nothing has to be rebuilt — your team, or another partner, picks it up exactly where it stands.

What we deliver

  • Upstream readiness audit of your current setup
  • Realm configuration as code (Terraform / OpenTofu)
  • Deployment manifests for the Keycloak Operator or Helm
  • Themes and SPI extensions in versioned repositories
  • Upgrade runbook aligned with upstream releases
  • Hand-over documentation for in-house operations

Capabilities

What Upstream Keycloak covers

Configured, tested and documented on upstream Keycloak — then handed over or operated by us.

  • Unmodified upstream

    We run the official Keycloak distribution and container images, so security fixes and new releases reach you without waiting on a vendor's fork.

  • Configuration as code

    Realms, clients, flows and identity providers are managed with Terraform or OpenTofu, reviewed in pull requests and applied through your pipeline.

  • Your infrastructure, your choice

    Deploy with the Keycloak Operator, Helm or plain containers on your own Kubernetes, cloud account or on-premises estate.

  • Extensions through SPIs

    Custom behaviour is built against Keycloak's public Service Provider Interfaces and shipped as versioned JARs from your repository, never as patches to the core.

  • Upgrades along upstream

    We follow upstream releases, read the migration notes, rehearse each upgrade in staging and keep themes and extensions compatible as Keycloak moves forward.

  • Hand-over at any time

    Runbooks, architecture docs and admin access are yours from day one, so bringing operations in-house is a planned hand-over, not a migration.

How it works

From first call to production

  1. Audit what you run today

    We review your current Keycloak or identity platform, flag forks, core patches and manual configuration, and plan a path onto clean upstream.

  2. Codify and standardise

    Configuration moves into Terraform or OpenTofu, themes and extensions into versioned repositories, and deployment onto the official images.

  3. Operate or hand over

    We run it with you on an agreed upgrade rhythm, or train your team and hand over the runbooks — your choice, and you can change it later.

Use cases

Where teams put it to work

  • Leaving a proprietary IdP

    Move off a closed identity service onto open source you control, without trading one form of lock-in for another.

  • Cleaning up a forked Keycloak

    Bring a patched or long-unupgraded Keycloak back onto upstream, replacing core modifications with supported SPI extensions.

  • Self-hosted and sovereign identity

    Keep identity inside your own cloud account or data centre, on software whose source anyone on your team can inspect.

FAQ

Upstream Keycloak questions, answered

Is Keycloak really free to use commercially?

Yes. Keycloak is released under the Apache License 2.0, which permits commercial use, modification and redistribution. You engage us for expertise and operations, not for a licence.

Do you maintain your own Keycloak fork?

No. We run the official upstream distribution. Anything custom is built as an extension through Keycloak's public SPIs, so it can be upgraded, replaced or removed on its own.

What happens if we stop working with KeycloakPro?

Nothing breaks. The configuration, themes, extensions and runbooks already live in your repositories and your infrastructure, so your team or another provider can carry on from there.

How do you handle Keycloak upgrades?

We track upstream releases, review the upgrade notes for breaking changes, update themes and extensions, and rehearse every upgrade in staging before it reaches production.

Ready to roll out Upstream Keycloak?

Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.

Browse all products