Managed Keycloak
Managed Keycloak Hosting in Germany
SSO / IAM operated as a core system
Open-source IAM, without the operational overhead. We run dedicated Keycloak instances on ISO 27001–certified infrastructure in Germany – including updates, backups, monitoring, and optional private connectivity via WireGuard or IPsec.
- Germany / Switzerland
- Data location
- ISO 27001 certified
- Operations
- SLA per package
- Availability
Operations
How we operate Keycloak
Identity is a core system. We operate Keycloak with a production-grade day‑2 model.
Secure baseline
Hardened configuration, TLS, and least-privilege access patterns.
Dedicated instance and isolation
Every Keycloak instance belongs to one customer – no shared realm, no shared database with other tenants. Depending on the tier, parts of the underlying infrastructure may be shared or dedicated. Enterprise customers additionally get dedicated HA nodes and a custom operational model.
OIDC & SAML
SSO for your apps and services via standard protocols.
LDAP, Active Directory, and identity brokering
Keycloak ships with native user federation for LDAP and Active Directory, plus identity brokering to external providers (e.g. Azure AD, Google) via OIDC or SAML. We set up the connection for you end-to-end – you provide access and details.
HA, PostgreSQL, and scaling
Enterprise instances run as multi-node clusters with an external PostgreSQL database – Keycloak's built-in Infinispan cache distributes sessions across nodes. We run the PostgreSQL database highly available. You scale on demand, without planning the underlying infrastructure yourself.
Backups, RPO, and restore
All tiers get daily, encrypted backups of configuration and data – retention runs from 48 hours (Starter) through 7 days (Professional) up to extended options (Enterprise). With daily backups, RPO is 24 hours or less. We test restores regularly. Contact support to restore.
Update and security patch policy
We update Keycloak regularly in defined maintenance windows; security patches within 48 hours. CVEs in Keycloak core and its dependencies feed directly into our patch prioritization.
Monitoring
Health and performance monitoring aligned with SLA tiers.
Themes and extensions
Custom themes and custom SPI extensions are part of normal operations: you provide the theme or extension, we deploy it in a controlled rollout process.
Migration from existing identity providers
We support migrating from existing identity providers such as Auth0, Okta, or Microsoft Entra ID to Managed Keycloak – scope depends on your source system and client configuration, with a defined process: planning, test migration, controlled cutover. Migration effort is billed transparently by time: €125 per hour (net).
Exit and data portability
You can export and leave at any time. We support structured offboarding: exports/backups, an agreed handover period, and deletion after confirmation. Standard: realm export (JSON), plus a database dump on request.
Private connectivity
Keycloak doesn't have to be publicly reachable. On the Enterprise tier, we connect your instance to your office, data center, or cloud via WireGuard or IPsec – authentication stays inside your network, without public internet exposure.
Data protection, DPA, and ISO 27001
b'nerd and our data center partners are ISO 27001 certified. For business customers we provide the standard contractual documents for GDPR-compliant processing, including a data processing agreement (DPA).
Pricing
Three tiers with a clear baseline. Final sizing depends on users, connected clients and availability requirements.
All prices excl. VAT. Business customers only.
Starter
Single environment, basic SSO needs.
- 1 environment (prod)
- up to 5 clients
- 2 vCPU / 4 GB RAM baseline
- Daily backups (48h retention)
- Updates & monitoring
- Email support
- 99.5% availability (SLA)
Professional
Multiple apps/clients and higher usage — incl. staging.
- 2 environments (prod + staging)
- up to 20 clients
- 2 vCPU / 8 GB RAM baseline
- Daily backups (7d retention)
- Phone support
- Slack Connect / Teams
- 99.5% availability (SLA)
Enterprise
Mission-critical identity and compliance requirements.
- 3 environments (dev + staging + prod)
- VPN access (WireGuard or IPsec)
- HA options (multiple nodes)
- Security hardening & policies
- Extended retention options
- Custom operational model
- 99.9% availability (SLA)
Keycloak – FAQs
Typical questions about SSO, operations and responsibility.
-
Yes. Managed Keycloak is hosted centrally by b'nerd and operated with clear responsibility.
-
Yes. We support both protocols depending on your applications and IdP strategy.
-
Yes. Integration options depend on your setup (e.g., LDAP/AD) and security requirements.
-
Every instance belongs to one customer. Depending on the tier, parts of the underlying infrastructure may be shared or dedicated.
-
Yes — WebAuthn/passkeys and classic MFA methods are natively built into Keycloak and can be enabled in your realm.
-
Multi-node clusters with an external PostgreSQL database (Enterprise). We run the PostgreSQL database highly available.
-
Daily, encrypted; RPO ≤ 24 hours. We test restores regularly.
-
Regular updates in maintenance windows, security patches within 48 hours.
-
Yes, depending on source system and client configuration – with a defined process: planning, test migration, controlled cutover.
-
Yes, structured offboarding including deletion after confirmation.
Do you have questions or would you like a personalized offer? We are happy to advise you.
Contact
Contact
Our cloud experts are happy to provide personalized advice.
- Our Office
-
Sillemstraße 76A
20257 Hamburg, Deutschland
Mon - Fri: 09:00 AM - 06:00 PM
- Telefon
- +49 40 239 69 754 0
- hello@bnerd.com