Skip to main content
Upstream source: Current installation guide. Keycloak needs PostgreSQL and a production start command. Towbar routes HTTPS to Keycloak’s internal HTTP port; its hostname and proxy-header settings must match that route. The database is a private Compose service here, not a Towbar-managed Datastore.

Towbar manifest

.towbar/services/keycloak.compose.yml

Compose project

deploy/keycloak/compose.yml

Configure

  1. Prepare the example server, connect the repository, and map production to the branch containing these files. Replace the example server IP and domain.
  2. Commit every file shown below under deploy/keycloak/. The Towbar manifest points to the Compose file; it does not create it for you.
  3. Sync the repository and inspect the resolved Compose project. Save the runtime values below if this example declares any.
  4. Use start, never start-dev, for this public hostname. Replace the hostname in the Compose file and Towbar route together.
  5. Back up the PostgreSQL volume before changing Keycloak versions. The example uses the standard image; an optimized custom image is an optional later improvement.
  6. Deploy it manually and run the verification below before enabling auto-deploy.

Runtime values

Save these values on the Compose project after the repository sync. The manifest declares required keys, not their values.

Verify

Finish the administrator login, create a realm and test user, then confirm the realm remains after redeployment. Verify external redirect URLs use HTTPS. For field constraints, see Compose guide.
Last modified on September 27, 2026