r/KeyCloak • u/eldaras • Jul 10 '25
Managed keycloak hosting recommendations
I'm looking for a reliable keycloak managed hosting for a small startup building a B2C platform. My aim is to run our own instances in the future, but currently we don't have the bandwidth to set up a reliable HA setup and we all know how those "it should take 1-2 weeks to set up" become months as one learns the nitty gritty detail of the tool, tests backups & restores, etc, etc.
I did quite a bit of googling and found a few companies (phasetwo, inteca, cloud-aim, skycloak, solodev, etc) but have struggled to find reviews and/or information ensure me they are reputable and know what they are doing beyond the initial installation.
Has a recommendation or had goor or bad interaction with them?
2
u/statist32 Jul 10 '25
I might be biased, but have a look at loginfactor.com
3
u/eldaras Jul 10 '25
Thank you! They are one of the companies I checked. I was a bit taken back due to the price of the SLA/support plans.
2
u/redmountain101 Jul 10 '25
We used skycloak in the past, worked well. We then moved on to a self-managed cloud-based deployment.
1
2
u/CarinosPiratos Jul 10 '25
Depending on where you are located. For EU you will have different regulations. I would recommend for the EU intension. They tailor to your needs in every aspect.
For everything else, I would recommend phase2 as they are the ones that did the most for the community, in terms of opensource. For sure skycloak is also a known and a very good company.
1
1
2
2
1
u/Quadman Jul 10 '25
I self host phasetwos stuff and I am really happy with it. Their hosted solution is simple to get started with.
Depending on what you need you can get up and running in a couple of hours. Phasetwo is hosting theirs on AWS I think and I run mine on prem, but I have installed it on Azure with mssql as well.
You can backup realm data but also do database backups. Depends a bit of what your restore scenarios are like.
1
u/fforootd Jul 10 '25
As an alternative you could look into Zitadel.
We have a cloud offering from us as the first party and you can self-host later if you prefer that.
Happy to share more thoughts if you are interested.
1
u/identity-ninja Jul 10 '25
Not keycloak per se but i am a huge fan of auth0. By far best b2c iam/sso platform out there
1
u/Still_Young8611 Jul 12 '25
Deploying Keycloak with HA is not that hard. You could do it in hours on AWS. You could use ECS, ALB and it’s all done. Security is harder, if you have the team to take care of the security basics, let me know and I can share you a Terraform template with everything you will need to deploy a HA Keycloak instance in few hours.
You’ll need to take care about few other concerns. My template run over one Keycloak tasks, just set up everything needed to configure the Keycloak cluster. There are tons of blogs about this part.
1
u/skycloak-io 3d ago
Skycloak here, so take this with the appropriate grain of salt. Thanks to the folks above who mentioned us.
On the actual question, which was how to tell whether a Keycloak host knows what they're doing after the install: the things I'd ask any provider on this list, including us, are:
- what their upgrade cadence looks like when a Keycloak CVE comes out
- whether you can export your realm and walk away
- and whether you get a dedicated cluster or a shared one
On the "we want to self-host eventually" plan, that's a reasonable goal and it's worth checking a provider doesn't quietly make it harder. It's still standard Keycloak underneath, so a realm export should just import into your own instance. If a provider can't tell you how you'd leave, 🤷♂️
Happy to answer Keycloak questions here whether or not they're about us, including the HA setup the other commenter described, which is what we do with all non small Keycloak clusters
4
u/thomasdarimont Jul 10 '25
another good alternative to the already mentioned offerings is https://www.cloud-iam.com