Keycloak is an Open Source Identity and Access Management solution for modern Applications and Services. In this step by step guide I will show you how to install Keycloak legacy version on your Synology NAS using Docker. Keycloak legacy: This is the legacy distribution of Keycloak which uses WildFly as Runtime engine. At STEP 19, you also have the option to download a compose to use the Keycloak Quarkus which uses Quarkus as Runtime environment.
STEP 1
Please Support My work by Making a Donation.
STEP 2
InstallĀ Portainer using my step by step guide. If you already have Portainer installed on your Synology NAS, skip this STEP. Attention: Make sure you have installed the latest Portainer version.
STEP 3
Make sure you have a synology.me Wildcard Certificate. Follow my guide to get a Wildcard Certificate. If you already have a synology.me Wildcard certificate, skip this STEP.
STEP 4
Go toĀ Control PanelĀ /Ā Login PortalĀ /Ā AdvancedĀ Tab / clickĀ Reverse Proxy. Follow the instructions in the image below.
STEP 5
Now click the āCreateā button. Follow the instructions in the image below.
STEP 6
After you click the Create button, the window below will open. Follow the instructions in the image below.
On the General area, set the Reverse Proxy Name description: type in Keycloak. After that, add the following instructions:
Source:
Protocol:Ā HTTPS
Hostname: keycloak.yourname.synology.me
Port:Ā 443
Check Enable HSTS
Destination:
Protocol:Ā HTTP
Hostname:Ā localhost
Port:Ā 8711
STEP 7
On the Reverse Proxy Rules click the Custom HeaderĀ tab. ClickĀ CreateĀ and then, from the drop-down menu, clickĀ WebSocket. After you click on WebSocket, two Header Names and two Values will be automatically added. ClickĀ Save. Follow the instructions in the image below.
STEP 8
Go to Control Panel / Network / Connectivity tab/ Check Enable HTTP/2 then click Apply. Follow the instructions in the image below.
STEP 9
Go to Control Panel / Security / Advanced tab/ Check Enable HTTP CompressionĀ then click Apply. Follow the instructions in the image below.
STEP 10
Go toĀ File StationĀ and open the docker folder. Inside the docker folder, create one new folder and name itĀ keycloakdb. Follow the instructions in the image below.
Note: Be careful to enter only lowercase, not uppercase letters.
STEP 11
Log into Portainer using your username and password. On the left sidebar in Portainer, click on StacksĀ thenĀ + Add stack. Follow the instructions in the image below.
STEP 12
In the Name field type in keycloak. Follow the instructions in the image below.
version: "3.9" services: db: image: postgres:16 container_name: Keycloak-DB hostname: keycloak-db mem_limit: 1g cpu_shares: 1024 security_opt: - no-new-privileges:true healthcheck: test: ["CMD", "pg_isready", "-q", "-d", "keycloak", "-U", "keycloakuser"] timeout: 45s interval: 10s retries: 10 volumes: - /volume1/docker/keycloakdb:/var/lib/postgresql/data:rw environment: POSTGRES_DB: keycloak POSTGRES_USER: keycloakuser POSTGRES_PASSWORD: keycloakpass restart: on-failure:5 keycloak: image: quay.io/keycloak/keycloak:legacy container_name: Keycloak restart: on-failure:5 healthcheck: test: curl -f http://localhost:8080/ || exit 1 environment: DB_VENDOR: POSTGRES DB_ADDR: db DB_DATABASE: keycloak DB_USER: keycloakuser DB_SCHEMA: public DB_PASSWORD: keycloakpass KEYCLOAK_USER: marius KEYCLOAK_PASSWORD: mariushosting PROXY_ADDRESS_FORWARDING: true ports: - 8711:8080 depends_on: - db
Note: Before you paste the code above in the Web editor area, change the value for KEYCLOAK_USER and add your own username. marius is an example for a username. You have to insert your own username.
Note: Before you paste the code above in the Web editor area, change the value for KEYCLOAK_PASSWORDĀ and add your own password. mariushosting is an example for a password. You have to insert your own password.
STEP 13
Scroll down on the page until you see a button namedĀ Deploy the stack. Click on it. Follow the instructions in the image below. The installation process can take up to a few minutes. It will depend on your Internet speed connection.
STEP 14
If everything goes right, you will see the following message at the top right of your screen: āSuccess Stack successfully deployedā.
STEP 15
š¢Please Support My work by Making a Donation. Almost 99,9% of the people that install something using my guidesĀ forget to support my work, or justĀ ignoreĀ STEP 1. Iāve been very honest about this aspect of my work since the beginning: I donāt run any ADS, I donāt require subscriptions, paid or otherwise, I donāt collect IPs, emails, and I donāt have any referral links from Amazon or other merchants. I also donāt have any POP-UPs or COOKIES. I have repeatedly been told over the years how much I have contributed to the community. Itās something I love doing and have been honest about my passion since the beginning. But I also Need The Community to Support me Back to be able to continue doing this work.
STEP 16
Please waitĀ approximately 3 minutes for the installation to be completed or you will get a blank page if you try to connect too soon. Now open your browser and type in your HTTPS/SSL certificate like this https://keycloak.yourname.synology.me In my case it’s https://keycloak.mariushosting.synology.me If everything goes right, you will see the Keycloak homepage. Click Administration Console. Follow the instructions in the image below.
STEP 17
Add your own username and password that you have previously created at STEP 12. Click Sign In. Follow the instructions in the image below.
STEP 18
Your Keycloak info at a glance!
STEP 19
Download (click on the blue link below) to download the docker compose for Keycloak that uses the latest Keycloak version built on Quarkus. This version of Keycloak uses Quarkus as Runtime environment šNote: Support my work to unlock the password. You can use this password to download any file on mariushosting forever!
Enjoy Keycloak!
If you encounter issues by using this container, make sure to check out the Common Docker issuesĀ article.
Note: Make sure RULE 5 an RULE 6 is correctly applied on your Synology NAS Firewall configuration.
Note: Find outĀ how to update the Keycloak containerĀ with the latest image.
Note: How to Back Up Docker Containers on your Synology NAS.
Note: Can I run Docker on my Synology NAS?Ā See the supported models.
Note: How to Free Disk Space on Your NAS if You Run Docker.
Note: How to Schedule Start & Stop For Docker Containers.
Note: How to Activate Email Notifications.
Note: How to Add Access Control Profile on Your NAS.
Note: How to Change Docker Containers Restart Policy.
Note: How to Use Docker Containers With VPN.
Note: Convert Docker Run Into Docker Compose.
Note: How to Clean Docker.
Note: How to Clean Docker Automatically.
Note: Best Practices When Using Docker and DDNS.
Note: Some Docker Containers Need WebSocket.
Note: Find out the Best NAS Models For Docker.
Note: Activate Gmail SMTP For Docker Containers.
This post was updated on Monday / January 6th, 2025 at 4:20 PM