DirectorySecurity AdvisoriesPricing
Sign in
Directory
keycloakx logoHELM

keycloakx

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Keycloak.X

Chainguard's redistribution of the Keycloak.X Helm chart, pre-configured with hardened Chainguard Images.

Prerequisites

Authentication is required. First, authenticate with Chainguard:

chainctl auth login
chainctl auth configure-docker --pull-token --save
helm registry login cgr.dev

Create an image pull secret:

kubectl create secret docker-registry cgr-pull-secret \
  --docker-server=cgr.dev \
  --docker-username="$(echo cgr.dev | docker-credential-cgr get | jq -r '.Username')" \
  --docker-password="$(echo cgr.dev | docker-credential-cgr get | jq -r '.Secret')" \
  --namespace keycloak

Installation

helm install keycloakx oci://cgr.dev/ORGANIZATION/charts/keycloakx \
  --namespace keycloak \
  --create-namespace \
  --set imagePullSecrets[0].name=cgr-pull-secret

By default the chart starts Keycloak against the dev-file database, which is not suitable for production. Point it at an external database and optionally enable the dbchecker init container, which waits for that database to accept connections before Keycloak starts:

helm install keycloakx oci://cgr.dev/ORGANIZATION/charts/keycloakx \
  --namespace keycloak \
  --create-namespace \
  --set imagePullSecrets[0].name=cgr-pull-secret \
  --set database.vendor=postgres \
  --set database.hostname=postgres \
  --set database.port=5432 \
  --set database.database=keycloak \
  --set database.username=keycloak \
  --set database.password=CHANGEME \
  --set dbchecker.enabled=true

About This Chart

This is a redistribution of the upstream Keycloak.X Helm chart. All upstream configuration options apply.

The chart deploys the Chainguard keycloak image for the Keycloak StatefulSet and the Chainguard netcat image for the optional dbchecker init container, which needs both a shell and nc to poll the database port. A FIPS variant is published as well; it deploys the keycloak-fips image and reuses the same netcat image for dbchecker, since that init container only opens a plain TCP connection and performs no cryptography.

For full documentation, see: https://github.com/codecentric/helm-charts/blob/master/charts/keycloakx/README.md

Chart versions
  • 7.3.2-fips

    Latest
  • 7.3.2

  • 7.3.1

  • 7.3-fips

View all chart versions

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.