DirectorySecurity AdvisoriesPricing
Sign in
Directory
keycloakx logoHELM

keycloakx

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# Optionally override the fully qualified name
2
fullnameOverride: ""
3
# Optionally override the name
4
nameOverride: ""
5
# Optionally override the namespace for all resources. Useful for umbrella charts that
6
# deploy multiple aliased keycloak instances each into their own namespace.
7
namespaceOverride: ""
8
# The number of replicas to create (has no effect if autoscaling enabled)
9
replicas: 1
10
# Additional labels applied to every resource in this chart, and on the StatefulSet's pods
11
commonLabels: {}
12
image:
13
# The Keycloak image repository
14
repository: chainreg.biz/chainguard-private/keycloak-fips
15
# Overrides the Keycloak image tag whose default is the chart appVersion
16
tag: 26.7.3-r1
17
# Overrides the Keycloak image tag with a specific digest
18
digest: sha256:18eea66cf4cbaad032ba98f36f49ded8aa3f39ea70b5aea6190a058854350845
19
# The Keycloak image pull policy
20
pullPolicy: IfNotPresent
21
# Image pull secrets for the Pod
22
imagePullSecrets: []
23
# - name: myRegistrKeySecretName
24
25
# Mapping between IPs and hostnames that will be injected as entries in the Pod's hosts files
26
hostAliases: []
27
# - ip: "1.2.3.4"
28
# hostnames:
29
# - "my.host.com"
30
31
# Indicates whether information about services should be injected into Pod's environment variables, matching the syntax of Docker links
32
enableServiceLinks: true
33
# Pod management policy. One of `Parallel` or `OrderedReady`
34
podManagementPolicy: OrderedReady
35
# StatefulSet's update strategy
36
updateStrategy: RollingUpdate
37
# StatefulSet's revision history limit (number of old ReplicaSets to retain). Defaults to 10 if not set
38
revisionHistoryLimit: ""
39
# Pod restart policy. One of `Always`, `OnFailure`, or `Never`
40
restartPolicy: Always
41
serviceAccount:
42
# Specifies whether a ServiceAccount should be created
43
create: true
44
# Specifies whether the ServiceAccount can get and list pods
45
allowReadPods: false
46
# The name of the service account to use.
47
# If not set and create is true, a name is generated using the fullname template
48
name: ""
49
# Additional annotations for the ServiceAccount
50
annotations: {}
51
# Additional labels for the ServiceAccount
52
labels: {}
53
# Image pull secrets that are attached to the ServiceAccount
54
imagePullSecrets: []
55
# Automount API credentials for the Service Account
56
automountServiceAccountToken: true
57
rbac:
58
create: false
59
rules: []
60
# RBAC rules for KUBE_PING
61
# - apiGroups:
62
# - ""
63
# resources:
64
# - pods
65
# verbs:
66
# - get
67
# - list
68
# SecurityContext for the entire Pod. Every container running in the Pod will inherit this SecurityContext. This might be relevant when other components of the environment inject additional containers into running Pods (service meshes are the most prominent example for this)
69
podSecurityContext:
70
fsGroup: 1000
71
# SecurityContext for the Keycloak container
72
securityContext:
73
runAsUser: 1000
74
runAsNonRoot: true
75
# Additional init containers, e. g. for providing custom themes
76
extraInitContainers: ""
77
# When using service meshes which rely on a sidecar, it may be necessary to skip init containers altogether,
78
# since the sidecar doesn't start until the init containers are done, and the sidecar may be required
79
# for network access.
80
# For example, Istio in strict mTLS mode prevents the dbchecker init container from ever completing
81
skipInitContainers: false
82
# Additional sidecar containers, e. g. for a database proxy, such as Google's cloudsql-proxy
83
extraContainers: ""
84
# Lifecycle hooks for the Keycloak container
85
lifecycleHooks: ""
86
# postStart:
87
# exec:
88
# command:
89
# - /bin/sh
90
# - -c
91
# - ls
92
93
# Termination grace period in seconds for Keycloak shutdown. Clusters with a large cache might need to extend this to give Infinispan more time to rebalance
94
terminationGracePeriodSeconds: 60
95
# The internal Kubernetes cluster domain
96
clusterDomain: cluster.local
97
## Overrides the default entrypoint of the Keycloak container
98
command: []
99
## Overrides the default args for the Keycloak container
100
args: []
101
# Additional environment variables for Keycloak
102
extraEnv: ""
103
# - name: KC_LOG_LEVEL
104
# value: DEBUG
105
106
# Additional environment variables for Keycloak mapped from Secret or ConfigMap
107
extraEnvFrom: ""
108
# Pod priority class name
109
priorityClassName: ""
110
# Pod affinity
111
affinity: |
112
podAntiAffinity:
113
requiredDuringSchedulingIgnoredDuringExecution:
114
- labelSelector:
115
matchLabels:
116
{{- include "keycloak.selectorLabels" . | nindent 10 }}
117
matchExpressions:
118
- key: app.kubernetes.io/component
119
operator: NotIn
120
values:
121
- test
122
topologyKey: kubernetes.io/hostname
123
preferredDuringSchedulingIgnoredDuringExecution:
124
- weight: 100
125
podAffinityTerm:
126
labelSelector:
127
matchLabels:
128
{{- include "keycloak.selectorLabels" . | nindent 12 }}
129
matchExpressions:
130
- key: app.kubernetes.io/component
131
operator: NotIn
132
values:
133
- test
134
topologyKey: topology.kubernetes.io/zone
135
# Topology spread constraints template
136
topologySpreadConstraints:
137
# Node labels for Pod assignment
138
nodeSelector: {}
139
# Node taints to tolerate
140
tolerations: []
141
# Additional Pod labels
142
podLabels: {}
143
# Additional Pod annotations
144
podAnnotations: {}
145
# Liveness probe configuration
146
livenessProbe: |
147
httpGet:
148
path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/health/live'
149
port: '{{ .Values.http.internalPort }}'
150
scheme: '{{ .Values.http.internalScheme }}'
151
initialDelaySeconds: 0
152
timeoutSeconds: 5
153
# Readiness probe configuration
154
readinessProbe: |
155
httpGet:
156
path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/health/ready'
157
port: '{{ .Values.http.internalPort }}'
158
scheme: '{{ .Values.http.internalScheme }}'
159
initialDelaySeconds: 10
160
timeoutSeconds: 1
161
# Startup probe configuration
162
startupProbe: |
163
httpGet:
164
path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/health'
165
port: '{{ .Values.http.internalPort }}'
166
scheme: '{{ .Values.http.internalScheme }}'
167
initialDelaySeconds: 15
168
timeoutSeconds: 1
169
failureThreshold: 60
170
periodSeconds: 5
171
# Pod resource requests and limits
172
resources: {}
173
# requests:
174
# cpu: "500m"
175
# memory: "1024Mi"
176
# limits:
177
# cpu: "500m"
178
# memory: "1024Mi"
179
180
# Add additional volumes, e. g. for custom themes
181
extraVolumes: ""
182
# Add volume claim templates to the StatefulSet, e. g. for dynamic provisioning
183
volumeClaimTemplates: ""
184
# - metadata:
185
# name: themes
186
# spec:
187
# accessModes: [ "ReadWriteOncePod" ]
188
# storageClassName: "my-storage-class"
189
# resources:
190
# requests:
191
# storage: 1Gi
192
193
# Add additional volumes mounts, e. g. for custom themes
194
extraVolumeMounts: ""
195
# Add additional ports, e. g. for admin console or exposing JGroups ports
196
extraPorts: []
197
# Pod disruption budget
198
podDisruptionBudget: {}
199
# maxUnavailable: 1
200
# minAvailable: 1
201
202
# Annotations for the StatefulSet
203
statefulsetAnnotations: {}
204
# Additional labels for the StatefulSet
205
statefulsetLabels: {}
206
# Configuration for secrets that should be created
207
secrets: {}
208
# mysecret:
209
# type: {}
210
# annotations: {}
211
# labels: {}
212
# stringData: {}
213
# data: {}
214
215
service:
216
# Annotations for HTTP service
217
annotations: {}
218
# Additional labels for HTTP Service
219
labels: {}
220
# key: value
221
# The Service type
222
type: ClusterIP
223
# Optional IP for the load balancer. Used for services of type LoadBalancer only
224
loadBalancerIP: ""
225
# The http Service port
226
httpPort: 80
227
# The HTTP Service node port if type is NodePort
228
httpNodePort: null
229
# The HTTPS Service port
230
httpsPort: 8443
231
# The HTTPS Service node port if type is NodePort
232
httpsNodePort: null
233
# Additional Service ports, e. g. for custom admin console
234
extraPorts: []
235
# When using Service type LoadBalancer, you can restrict source ranges allowed
236
# to connect to the LoadBalancer, e. g. will result in Security Groups
237
# (or equivalent) with inbound source ranges allowed to connect
238
loadBalancerSourceRanges: []
239
# When using Service type LoadBalancer or NodePort, you can preserve the source IP seen in the container
240
# by changing the default (Cluster) to be Local.
241
# See https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
242
externalTrafficPolicy: "Cluster"
243
# Controls how traffic from internal sources is routed. Valid values: Cluster, Local.
244
# See https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
245
internalTrafficPolicy: ""
246
# Session affinity
247
# See https://kubernetes.io/docs/concepts/services-networking/service/#proxy-mode-userspace
248
sessionAffinity: ""
249
# Session affinity config
250
sessionAffinityConfig: {}
251
serviceHeadless:
252
# Annotations for headless service
253
annotations: {}
254
# Additional labels for headless service
255
labels: {}
256
# Add additional ports to the headless service, e. g. for admin console or exposing JGroups ports
257
extraPorts: []
258
# -- Expose the service via gateway-api HTTPRoute
259
# Requires Gateway API resources and suitable controller installed within the cluster
260
# (see: https://gateway-api.sigs.k8s.io/guides/)
261
httpRoute:
262
# HTTPRoute enabled.
263
enabled: false
264
# Additional HTTPRoute labels
265
labels: {}
266
# HTTPRoute annotations.
267
annotations: {}
268
# The Service port targeted by the HTTPRoute, MUST BE AN NUMBER
269
servicePort: 80
270
# Which Gateways this Route is attached to.
271
parentRefs:
272
- name: gateway
273
sectionName: http
274
# namespace: default
275
# Hostnames matching HTTP header.
276
hostnames:
277
- chart-example.local
278
# List of rules and filters applied.
279
rules:
280
- matches:
281
- path:
282
type: PathPrefix
283
value: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/'
284
# -- Create a ListenerSet resource to attach listeners to an existing Gateway
285
# without requiring write access to the Gateway resource itself. Useful for
286
# namespace-level configuration where app owners do not have Gateway write access.
287
# When enabled, the HTTPRoute parentRefs are auto-derived from the ListenerSet name,
288
# and hostnames are derived from listener hostnames; httpRoute.parentRefs and
289
# httpRoute.hostnames are unused.
290
listenerSet:
291
# If `true`, a ListenerSet resource is created alongside the HTTPRoute
292
enabled: false
293
# Additional ListenerSet labels
294
labels: {}
295
# ListenerSet annotations
296
annotations: {}
297
# The Gateway this ListenerSet attaches to
298
parentRef:
299
name: gateway
300
# namespace: envoy-gateway-system
301
# Listeners to attach to the Gateway. Passed through as-is.
302
# Listener hostnames are used to populate the HTTPRoute hostnames field.
303
listeners: []
304
# - name: http
305
# hostname: keycloak.example.com
306
# port: 80
307
# protocol: HTTP
308
# allowedRoutes:
309
# namespaces:
310
# from: Same
311
# HTTPRoute for console only (/auth/admin)
312
console:
313
# If `true`, an HTTPRoute is created for console path only
314
enabled: false
315
# Additional HTTPRoute labels
316
labels: {}
317
# HTTPRoute annotations.
318
annotations: {}
319
# Which Gateways this Route is attached to.
320
parentRefs:
321
- name: gateway
322
sectionName: http
323
# namespace: default
324
# Hostnames matching HTTP header.
325
hostnames:
326
- chart-example.local
327
# List of rules and filters applied.
328
rules:
329
- matches:
330
- path:
331
type: PathPrefix
332
value: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/admin'
333
ingress:
334
# If `true`, an Ingress is created
335
enabled: false
336
# The name of the Ingress Class associated with this ingress
337
ingressClassName: ""
338
# The Service port targeted by the Ingress
339
servicePort: http
340
# Ingress annotations
341
annotations: {}
342
## Resolve HTTP 502 error using ingress-nginx:
343
## See https://www.ibm.com/support/pages/502-error-ingress-keycloak-response
344
# nginx.ingress.kubernetes.io/proxy-buffer-size: 128k
345
346
# Additional Ingress labels
347
labels: {}
348
# List of rules for the Ingress
349
rules:
350
- # Ingress host
351
host: '{{ .Release.Name }}.keycloak.example.com'
352
# Paths for the host
353
paths:
354
- path: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/'
355
pathType: Prefix
356
# serviceName: "" # Optional: Override backend service name (e.g., for AWS ALB action annotations)
357
# servicePort: "" # Optional: Override backend service port name
358
# TLS configuration
359
tls: []
360
# - hosts:
361
# - keycloak.example.com
362
# secretName: ""
363
364
# ingress for console only (/auth/admin)
365
console:
366
# If `true`, an Ingress is created for console path only
367
enabled: false
368
# The name of Ingress Class associated with the console ingress only
369
ingressClassName: ""
370
# Ingress annotations for console ingress only
371
# Useful to set nginx.ingress.kubernetes.io/whitelist-source-range particularly
372
annotations: {}
373
# Additional Ingress labels for console path only
374
labels: {}
375
rules:
376
- # Ingress host
377
host: '{{ .Release.Name }}.keycloak.example.com'
378
# Paths for the host
379
paths:
380
- path: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/admin'
381
pathType: Prefix
382
# serviceName: "" # Optional: Override backend service name (e.g., for AWS ALB action annotations)
383
# servicePort: "" # Optional: Override backend service port name
384
# Console TLS configuration
385
tls: []
386
# - hosts:
387
# - console.keycloak.example.com
388
# secretName: ""
389
## Network policy configuration
390
# https://kubernetes.io/docs/concepts/services-networking/network-policies/
391
networkPolicy:
392
# If true, the Network policies are deployed
393
enabled: false
394
# Additional Network policy labels
395
labels: {}
396
# Define all other external allowed source
397
# See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#networkpolicypeer-v1-networking-k8s-io
398
extraFrom: []
399
# Define egress networkpolicies for the Keycloak pods (external database for example)
400
# See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#networkpolicyegressrule-v1-networking-k8s-io
401
# egress:
402
# - to:
403
# - ipBlock:
404
# cidr: 192.168.1.30/32
405
# ports:
406
# - protocol: TCP
407
# port: 3306
408
egress: []
409
route:
410
# If `true`, an OpenShift Route is created
411
enabled: false
412
# Path for the Route
413
path: /
414
# Route annotations
415
annotations: {}
416
# Additional Route labels
417
labels: {}
418
# Host name for the Route
419
host: ""
420
# TLS configuration
421
tls:
422
# If `true`, TLS is enabled for the Route
423
enabled: true
424
# Insecure edge termination policy of the Route. Can be `None`, `Redirect`, or `Allow`
425
insecureEdgeTerminationPolicy: Redirect
426
# TLS termination of the route. Can be `edge`, `passthrough`, or `reencrypt`
427
termination: edge
428
dbchecker:
429
enabled: false
430
image:
431
# Docker image used to check Database readiness at startup
432
repository: chainreg.biz/chainguard-private/netcat
433
# Image tag for the dbchecker image
434
tag: 1.238-r1@sha256:e3cbf859cb046eb2058a6f8b19f3656b11a961154944c98c1de3ad58d4a5cd6a
435
# Image pull policy for the dbchecker image
436
pullPolicy: IfNotPresent
437
# SecurityContext for the dbchecker container
438
securityContext:
439
allowPrivilegeEscalation: false
440
runAsUser: 1000
441
runAsGroup: 1000
442
runAsNonRoot: true
443
# Resource requests and limits for the dbchecker container
444
resources:
445
requests:
446
cpu: "20m"
447
memory: "32Mi"
448
limits:
449
cpu: "20m"
450
memory: "32Mi"
451
database:
452
# don't create secret for db password. Instead use existing k8s secret
453
# existingSecret: "my-existent-dbpass-secret"
454
# existingSecretKey: "password"
455
existingSecret: ""
456
existingSecretKey: ""
457
# E.g. dev-file, dev-mem, mariadb, mssql, mysql, oracle or postgres
458
vendor:
459
hostname:
460
port:
461
database:
462
username:
463
password:
464
cache:
465
# Use "custom" to disable automatic cache configuration
466
stack: default
467
proxy:
468
enabled: true
469
mode: forwarded
470
http:
471
enabled: true
472
metrics:
473
enabled: true
474
health:
475
enabled: true
476
http:
477
# For backwards compatibility reasons we set this to the value used by previous Keycloak versions.
478
relativePath: "/auth"
479
# Set the relative path for Keycloak's management interface (KC_HTTP_MANAGEMENT_RELATIVE_PATH).
480
# This controls the path prefix for health and metrics endpoints served on the management port (9000).
481
# When empty, the env var is not set and Keycloak inherits the value from `http.relativePath`.
482
# Set to "/" to serve management endpoints at the root (e.g. /health, /metrics).
483
managementRelativePath: ""
484
internalPort: http-internal
485
internalScheme: HTTP
486
serviceMonitor:
487
# If `true`, a ServiceMonitor resource for the prometheus-operator is created
488
enabled: false
489
# Optionally sets a target namespace in which to deploy the ServiceMonitor resource
490
namespace: ""
491
# Optionally sets a namespace for the ServiceMonitor
492
namespaceSelector: {}
493
# Annotations for the ServiceMonitor
494
annotations: {}
495
# Additional labels for the ServiceMonitor
496
labels: {}
497
# Interval at which Prometheus scrapes metrics
498
interval: 10s
499
# Timeout for scraping
500
scrapeTimeout: 10s
501
# Relabelings for the Servicemonitor
502
relabelings: []
503
# metricRelabelings for the Servicemonitor
504
metricRelabelings: []
505
# The path at which metrics are served
506
path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/metrics'
507
# The Service port at which metrics are served
508
port: '{{ .Values.http.internalPort }}'
509
# The scheme to use for scraping metrics ("http" or "https"); if not set, the `http.internalScheme` value is used
510
scheme: ""
511
extraServiceMonitor:
512
# If `true`, a ServiceMonitor resource for the prometheus-operator is created
513
enabled: false
514
# Optionally sets a target namespace in which to deploy the ServiceMonitor resource
515
namespace: ""
516
# Optionally sets a namespace for the ServiceMonitor
517
namespaceSelector: {}
518
# Annotations for the ServiceMonitor
519
annotations: {}
520
# Additional labels for the ServiceMonitor
521
labels: {}
522
# Interval at which Prometheus scrapes metrics
523
interval: 10s
524
# Timeout for scraping
525
scrapeTimeout: 10s
526
# Relabelings for the Servicemonitor
527
relabelings: []
528
# metricRelabelings for the Servicemonitor
529
metricRelabelings: []
530
# The path at which metrics are served
531
path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/metrics'
532
# The Service port at which metrics are served
533
port: '{{ .Values.http.internalPort }}'
534
# The scheme to use for scraping metrics ("http" or "https"); if not set, the `http.internalScheme` value is used
535
scheme: ""
536
prometheusRule:
537
# If `true`, a PrometheusRule resource for the prometheus-operator is created
538
enabled: false
539
# Optionally sets a target namespace in which to deploy the ServiceMonitor resource
540
namespace: ""
541
# Annotations for the PrometheusRule
542
annotations: {}
543
# Additional labels for the PrometheusRule
544
labels: {}
545
# List of rules for Prometheus
546
rules: []
547
# - alert: keycloak-IngressHigh5xxRate
548
# annotations:
549
# message: The percentage of 5xx errors for keycloak over the last 5 minutes is over 1%.
550
# expr: |
551
# (
552
# sum(
553
# rate(
554
# nginx_ingress_controller_response_duration_seconds_count{exported_namespace="mynamespace",ingress="mynamespace-keycloak",status=~"5[0-9]{2}"}[1m]
555
# )
556
# )
557
# /
558
# sum(
559
# rate(
560
# nginx_ingress_controller_response_duration_seconds_count{exported_namespace="mynamespace",ingress="mynamespace-keycloak"}[1m]
561
# )
562
# )
563
# ) * 100 > 1
564
# for: 5m
565
# labels:
566
# severity: warning
567
autoscaling:
568
# If `true`, an autoscaling/v2 HorizontalPodAutoscaler resource is created (requires Kubernetes 1.23 or above)
569
# Autoscaling seems to be most reliable when using KUBE_PING service discovery (see README for details)
570
# This disables the `replicas` field in the StatefulSet
571
enabled: false
572
# Additional HorizontalPodAutoscaler labels
573
labels: {}
574
# The minimum and maximum number of replicas for the Keycloak StatefulSet
575
minReplicas: 3
576
maxReplicas: 10
577
# The metrics to use for scaling
578
metrics:
579
- type: Resource
580
resource:
581
name: cpu
582
target:
583
type: Utilization
584
averageUtilization: 80
585
# The scaling policy to use. This will scale up quickly but only scale down a single Pod per 5 minutes.
586
# This is important because caches are usually only replicated to 2 Pods and if one of those Pods is terminated this will give the cluster time to recover.
587
behavior:
588
scaleDown:
589
stabilizationWindowSeconds: 300
590
policies:
591
- type: Pods
592
value: 1
593
periodSeconds: 300
594
test:
595
# If `true`, test resources are created
596
enabled: false
597
image:
598
# The image for the test Pod
599
repository: docker.io/selenium/standalone-chromium
600
# The tag for the test Pod image
601
tag: "147.0"
602
# The image pull policy for the test Pod image
603
pullPolicy: IfNotPresent
604
# SecurityContext for the entire test Pod
605
podSecurityContext:
606
fsGroup: 1200 # UID of seluser in selenium/standalone-chromium
607
# SecurityContext for the test container
608
securityContext:
609
runAsUser: 1200 # UID of seluser in selenium/standalone-chromium
610
runAsNonRoot: true
611
# See https://helm.sh/docs/topics/charts_hooks/#hook-deletion-policies
612
deletionPolicy: before-hook-creation
613
## -- Extra Kubernetes objects to deploy with the helm chart
614
extraManifests: []
615
# - |
616
# apiVersion: v1
617
# kind: ConfigMap
618
# metadata:
619
# name: {{ include "keycloak.fullname" . }}-tpl
620
# data:
621
# foo: bar
622
# - apiVersion: v1
623
# kind: ConfigMap
624
# metadata:
625
# name: "{{ include \"keycloak.fullname\" . }}-tpl"
626
# data:
627
# foo: bar
628

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.