Keycloak on Aruba Cloud
Deploy Keycloak — enterprise identity and access management — on Aruba Cloud using Terraform and cloud-init. Keycloak runs in production Quarkus mode backed by a local PostgreSQL database.
Provider version: arubacloud/arubacloud
~> 1.0| Terraform: ≥ 1.9
Introduction
Keycloak is a CNCF-graduated open-source IAM platform providing SSO, OIDC, OAuth2, and SAML 2.0. This example deploys Keycloak with:
- Keycloak Quarkus distribution in production server mode — not dev mode, no ephemeral H2 database
- Local PostgreSQL — Keycloak officially supports PostgreSQL and MariaDB. Managed MySQL from the ArubaCloud DBaaS is not on the Keycloak support matrix and is not used here
- nginx reverse proxy on ports 80/443 with correct forwarding headers (
X-Forwarded-*), while Keycloak binds to127.0.0.1:8080 - Admin user created automatically on first start via systemd environment file — log in immediately after bootstrap
- Optional ACME HTTPS via an ACME provider such as Actalis or Let's Encrypt when a custom domain is provided
Architecture Overview
Infrastructure Created
| Resource | Name pattern | Description |
|---|---|---|
arubacloud_project | kc-prod | Project container |
arubacloud_vpc | kc-prod-vpc | Virtual Private Cloud |
arubacloud_subnet | kc-prod-subnet | Basic subnet |
arubacloud_securitygroup | kc-prod-vm-sg | Security group |
arubacloud_securityrule | kc-prod-vm-ssh | SSH ingress |
arubacloud_securityrule | kc-prod-vm-http | HTTP ingress |
arubacloud_securityrule | kc-prod-vm-https | HTTPS ingress |
arubacloud_elasticip | kc-prod-vm-eip | VM public IP |
arubacloud_blockstorage | kc-prod-boot | 50 GB boot disk (Performance) |
arubacloud_keypair | kc-prod-keypair | SSH public key |
arubacloud_cloudserver | kc-prod-vm | CloudServer VM |
Estimated Monthly Cost
| Resource | Spec | Est. cost/mo |
|---|---|---|
| CloudServer VM | CSO4A8 — 4 vCPU / 8 GB | ~€36 |
| Boot disk | 50 GB Performance | ~€6 |
| Elastic IP |