About Keycloak Ops
Realms, sessions and proxies in production.
What this site covers
Keycloak Ops is an operations reference for Keycloak as identity infrastructure. It is written for the person who has to run it: realm and client structure, the caching and heap behaviour that decides node count, the hostname and proxy configuration that has to be correct before anything works, and the federation paths into existing directories.
- Realm and client design
- Infinispan session caches and heap sizing
- OAuth2 and OIDC token contents and size
- Hostname and reverse proxy configuration
- LDAP and Active Directory federation
- Clustering and high availability
Good places to start:
- Realms, clients and token design fundamentals
- Keycloak memory usage and heap sizing
- Keycloak hostname and proxy errors
- Keycloak vs authentik vs Authelia
The site also publishes a free memory and heap sizing calculator, which turns a peak session count and realm count into a per-node heap figure, a container memory limit and a node count. It runs entirely in the browser, stores nothing, and lists every constant it uses.
4 articles are published so far. New ones are announced on the RSS feed.
How these articles are produced
Articles here are researched from primary sources: vendor and project documentation, published standards and specifications, research papers and preprints, and measurements published by whoever took them. Drafts are produced with AI assistance and then edited against those cited sources before anything is published.
No article on this site is based on first-hand testing in a private lab, and nothing here should be read as a measurement report of its own. Where a number appears, it comes from a source that is named, so you can check the original instead of taking this site's word for it.
Everything is published under a single editorial byline. That byline is a publishing identity for the site, not a claim about a named individual, and it does not carry professional credentials.
Corrections
Corrections are welcome. If something here is wrong, out of date, or attributed to the wrong source, email editor@keycloakops.com with the page address and what it should say. Substantive corrections are made in the article itself rather than quietly dropped.
How this site is funded
This site currently runs no affiliate links, sponsored posts, display advertising or paid placements. If that changes, the disclosure page will say so.
Contact
Email: editor@keycloakops.com
Site: keycloakops.com
Published by: Keycloak Ops Editorial
See also the privacy policy, the terms of use, and the editorial disclosure.