Hosting Keycloak: Self-Hosting, Managed Providers, and the EU Factor

You get Keycloak as software, not as a service: the hosting question is the real decision. Three paths: self-hosting (2–5 person-days of setup in our experience), managed providers from Elestio (from $11/month) via Phase Two (from $149) to Cloud-IAM (from €225, as of 09/2026) β€” or a SaaS IdP. Data location and the DPA chain argue for the first two.
7 min readMatthias RadscheitMatthias Radscheit
Happycodingen-US

TL;DR

You get Keycloak as software, not as a service: the hosting question is the real decision. Three paths: self-hosting (2–5 person-days of setup in our experience), managed providers from Elestio (from $11/month) via Phase Two (from $149) to Cloud-IAM (from €225, as of 09/2026) β€” or a SaaS IdP. Data location and the DPA chain argue for the first two.

  • You get Keycloak as software, not as a service: the hosting decision (run it yourself, have it run for you, or use a SaaS IdP) sets costs, availability, and data location at once.
  • Self-hosting honestly counted (numbers from our projects): 2–5 person-days of setup for a single instance, then 0.5–1 person-day per month; an HA cluster sits well above that.
  • Managed market as of September 2026: Elestio from $11/month (managed VM), Skycloak from $29, Phase Two from $149 (up to 15,000 MAU), Cloud-IAM from €225/month with dedicated HA clusters.
  • The EU factor: self-hosting or EU providers settle data location and the DPA chain structurally β€” with US SaaS IdPs, your compliance hangs on the Data Privacy Framework.
  • High availability is the true cost driver: without a second node, the login is the single point of failure for every connected application.

Why the hosting question is different with Keycloak

With Auth0, Okta, or Microsoft Entra you rent a service: the provider runs the servers, applies updates, and guarantees availability β€” and you pay per active user. Keycloak flips that relationship. You get software, not a service. Our overview article explains what Keycloak is and which systems it replaces. This article is about the follow-up question: who runs it?

That question is no side issue, because an identity system is critical infrastructure: if Keycloak goes down, nobody can log in β€” to any connected application. The hosting decision therefore settles three things at once: running costs, availability, and data location. Three paths are open: running it yourself, a managed provider, or skipping Keycloak in favor of a SaaS IdP. This article lays all three side by side.

A word on method: all prices in this article are list prices from the providers' pages, checked on September 28, 2026. Effort figures come from our own projects and are labeled as such β€” take them as orientation, not as a standard.

Self-hosting: what you actually operate

First, the building blocks: Keycloak runs as a container on the Quarkus runtime and needs four things around it β€” a PostgreSQL database, a reverse proxy with TLS, SMTP access for mails such as password resets, and monitoring that wakes you before your users do. With that, a single instance on a virtual EU server is set up in a day. That is the easy part.

A word on the database: it is the real state store β€” users, credentials, sessions, configuration. Keycloak containers are replaceable; the PostgreSQL behind them is not. Daily backups are mandatory, and rehearsed ones at that: a backup you have never restored is a hope, not a backup.

High availability is the real cost driver

For internal tools, a single instance with a solid backup is enough. As soon as customers log in, the math changes: you need at least two Keycloak nodes with a clustered Infinispan cache, a replicated database, and a load balancer in front. Whether failover actually works only shows in a rehearsed node outage β€” hoping does not count.

The rule to remember: without a second node, your login is the single point of failure for every connected application. A portal that runs but lets nobody in is, from your customers' view, a portal that does not run.

VM or Kubernetes?

That leaves the platform question. For a single instance, a virtual machine with Docker Compose is enough: easy to grasp, quick to restore, no cluster knowledge required. Kubernetes pays off when high availability is required or a cluster already exists; the official Keycloak Operator then handles rollouts and configuration. Introducing Kubernetes just for Keycloak, though, we usually consider oversized β€” that is a judgment from projects, not a law of nature.

The update obligation

As of September 2026, Keycloak stands at version 26.7.4; the project ships several releases a year plus security patches in between. Unlike with a SaaS IdP, nobody applies them for you. Deferring updates means running a security system with documented gaps β€” for an identity system, not a tenable position. Plan a fixed rhythm, say one maintenance window per quarter. How to plan, test, and roll back upgrades is covered in our article on Keycloak major upgrades.

Effort in numbers: what our projects show

For orientation, explicitly labeled as our own numbers: a single instance on an EU server (at Hetzner, say) costs us two to five person-days to set up, then about half a person-day to one per month for updates, monitoring, and backup drills. An HA cluster on Kubernetes sits closer to five to ten person-days to build, with running effort above that accordingly.

The infrastructure itself stays cheap: a low two-digit euro amount per month covers a single instance, and an HA setup sits in the low three-digit range. The expensive part of self-hosting is not the server β€” it is the responsibility.

Managed Keycloak: providers and prices (as of September 2026)

Between running it yourself and a SaaS IdP lies a third path: a provider operates your dedicated Keycloak, while realms, flows, and extensions remain yours to configure. The market for this is small but real. We checked four providers against their pricing pages on September 28, 2026:

ProviderEntry price (list)ModelEU angle
Cloud-IAMfreemium up to 100 users; dedicated HA clusters from €225/monthpriced by cluster and SLA (99% to 99.98%), user quota per plan with soft limitsFrench provider, hosting at Scaleway and Outscale among others, ISO 27001
Phase Twofrom $149/month (up to 15,000 active users)dedicated clusters, tiers up to 250,000 MAU for $2,499/monthEU data residency as an option, SOC 2 Type 2, ISO 27001
Skycloakfrom $29/month (Developer), $149/month (Launch)priced by cluster size, unlimited usersEU region not stated on the pricing page
Elestiofrom $11/monthmanaged VM with auto-updates and backups, not an IAM specialistprovider choice includes Hetzner, Netcup, and Open Telekom Cloud

The spread from $11 to $2,499 per month is not a contradiction but a difference in category. Elestio runs a virtual machine with Keycloak on it for you: updates and backups happen automatically, the IAM responsibility stays with you. Cloud-IAM and Phase Two sell identity as a product β€” with an SLA, incident readiness, and Keycloak expertise in support. Skycloak sits in between: dedicated clusters, unlimited users, a slimmer enterprise layer on top.

What to look for when choosing: an SLA with a number instead of good intentions, a documented update policy (who decides when which version runs), an exit path with export of realms and user data including password hashes β€” and the data location, more on that in a moment.

A note on pricing dynamics: managed Keycloak is a young market and plans change fast β€” check the pricing pages again yourself before deciding. Testing is low-risk almost everywhere: Cloud-IAM offers a freemium up to 100 users, Phase Two a 30-day trial, Skycloak 21 days.

The EU factor: data location, DPAs, and the line to SaaS IdPs

Identity data is personal data in concentrated form: names, email addresses, password hashes, login history. Where it lives is therefore no detail question β€” least of all when your users are in the EU and the GDPR applies. To set expectations: what follows is a feasibility perspective from projects, not legal advice. The assessment of your individual case belongs with your data protection officer.

Self-hosting settles data location structurally: with Keycloak on a server in Germany, identity data never leaves the EU. No third-country transfer, no dependence on adequacy decisions β€” the question is answered by the architecture before a lawyer has to ask it.

The second building block next to location is the data processing agreement (DPA): the contract under Art. 28 GDPR that governs what a service provider may do with your data. With self-hosting you sign it with the data center; with a managed provider, additionally with them. The shorter the chain, the easier the answer when a customer or a supervisory authority asks.

With managed providers, two questions count: where are the servers, and who operates them? Cloud-IAM on Scaleway or Outscale keeps both in the EU. Phase Two offers EU data residency as an option; clarify in the DPA whether support access from third countries is foreseen. With Elestio you pick the provider yourself β€” with Hetzner, the data sits in Germany.

The line to SaaS IdPs: Auth0, Okta, and Entra External ID are services of US companies. The data transfer rests on the Data Privacy Framework β€” an agreement whose fate is decided in Washington and Brussels, not in your company. That path is workable too. But your compliance then hangs on a treaty instead of your architecture: data sovereignty you configure beats data sovereignty you negotiate.

The decision: self-hosted, managed, or SaaS IdP?

To close, the criteria side by side. The table condenses what is laid out above β€” take it as the starting point for your trade-off, not as its replacement:

CriterionSelf-hostedManaged KeycloakSaaS IdP
Software cost€0 (open source)subscription by cluster size, from $11 to €225 and up per monthper-active-user pricing
Operations effortyours (from about 0.5 person-days/month, our experience)the provider'sthe provider's
Data locationyour choice, e.g. GermanyEU region possible depending on providerprovider's regions, US parent company
Customization (SPIs, themes, flows)fullextensive, provider-dependentlimited to product features
Update controlyou decide and do the workthe provider, partly with a saynone, but no work either
Fits when …ops capacity and data sovereignty requirements existyou want Keycloak's feature set without your own ops teamstandard auth is enough and per-user costs stay bearable

Our rule of thumb from B2B projects: a single lean application rarely needs its own Keycloak β€” built-in authentication is often enough there, the way we use it in Supabase projects. Keycloak pays off once you need SSO across several applications, directory integration, or fine-grained roles. And then: with ops capacity, self-hosted; without it, managed, with a provider whose data location fits.

Also run the numbers over three years, not one month: with a SaaS IdP the bill grows with every user, with a managed provider with cluster size, with self-hosting it stays nearly constant β€” provided you count the person-days honestly, or the cheapest path is only cheap on paper. The full math including project costs is in What does Keycloak cost?.

A reassuring side effect of all three Keycloak paths: you can switch. A realm export takes configuration and users with it β€” from a managed provider to self-hosting or the other way round. With a SaaS IdP the way back is harder, because flows and extensions are product-specific. Keep that door open deliberately.

Next steps

You want to know which of the three paths fits your project? Then let's run the numbers: user counts, compliance requirements, available ops capacity β€” that is all a first solid recommendation needs. We run Keycloak ourselves on EU infrastructure and have handed setups over to client teams; both perspectives feed in. Book a free intro call: in 30 minutes we sort out whether self-hosting, managed, or a SaaS IdP adds up for you.

Frequently asked questions

What does managed Keycloak cost per month?
As of September 2026, the range runs from $11 (Elestio, managed VM) via $29 to $149 (Skycloak, Phase Two) to €225 and up (Cloud-IAM, dedicated HA clusters); enterprise tiers sit at $2,499 and more. The price difference reflects operational depth: VM hosting with auto-updates at one end, identity operations with an SLA and incident readiness at the other.
Is a single Keycloak instance enough?
For internal applications with tolerable maintenance windows: yes, with a daily and rehearsed backup. As soon as customers log in, you need high availability with at least two nodes and a replicated database β€” otherwise a login outage takes down every connected application at once.
Can managed Keycloak be run in a GDPR-compliant way?
That hangs on data location, the DPA, and your processes, not on the product name. It gets structurally simple with EU providers or EU regions: Cloud-IAM hosts at Scaleway and Outscale in France, Phase Two offers EU data residency as an option, and with Elestio you pick Hetzner in Germany. The case-by-case assessment belongs with your data protection officer.
How much effort is Keycloak self-hosting really?
From our projects: two to five person-days to set up a single instance, then half a person-day to one per month for updates, monitoring, and backup drills. An HA cluster on Kubernetes sits well above that. If you lack that capacity long term, a managed provider is the more honest path.
Can I leave a managed provider later?
Yes, and that is the structural advantage over SaaS IdPs: under the hood it is standard Keycloak. Realm exports take configuration and users with them, and password hashes can be carried over. Still, check before signing whether the provider commits to full exports β€” it also tells you how seriously they mean data sovereignty.
Can I run Keycloak on Hetzner?
Yes, that is our usual path: a single instance or cluster on Hetzner servers in Germany, so identity data stays entirely within the country. The route via Elestio also works with Hetzner as the target provider, if you do not want to own auto-updates and backups yourself.

Sources

Related articles

Open for select projects

Let's talk about your project

Book a no-obligation call, send us an email, or use the form – we'd love to hear from you.

150+
Completed projects
15
Years of experience
8
Senior‑level team members