Why the hosting question is different with Keycloak
With Auth0, Okta, or Microsoft Entra you rent a service: the provider runs the servers, applies updates, and guarantees availability β and you pay per active user. Keycloak flips that relationship. You get software, not a service. Our overview article explains what Keycloak is and which systems it replaces. This article is about the follow-up question: who runs it?
That question is no side issue, because an identity system is critical infrastructure: if Keycloak goes down, nobody can log in β to any connected application. The hosting decision therefore settles three things at once: running costs, availability, and data location. Three paths are open: running it yourself, a managed provider, or skipping Keycloak in favor of a SaaS IdP. This article lays all three side by side.
A word on method: all prices in this article are list prices from the providers' pages, checked on September 28, 2026. Effort figures come from our own projects and are labeled as such β take them as orientation, not as a standard.
Self-hosting: what you actually operate
First, the building blocks: Keycloak runs as a container on the Quarkus runtime and needs four things around it β a PostgreSQL database, a reverse proxy with TLS, SMTP access for mails such as password resets, and monitoring that wakes you before your users do. With that, a single instance on a virtual EU server is set up in a day. That is the easy part.
A word on the database: it is the real state store β users, credentials, sessions, configuration. Keycloak containers are replaceable; the PostgreSQL behind them is not. Daily backups are mandatory, and rehearsed ones at that: a backup you have never restored is a hope, not a backup.
High availability is the real cost driver
For internal tools, a single instance with a solid backup is enough. As soon as customers log in, the math changes: you need at least two Keycloak nodes with a clustered Infinispan cache, a replicated database, and a load balancer in front. Whether failover actually works only shows in a rehearsed node outage β hoping does not count.
The rule to remember: without a second node, your login is the single point of failure for every connected application. A portal that runs but lets nobody in is, from your customers' view, a portal that does not run.
VM or Kubernetes?
That leaves the platform question. For a single instance, a virtual machine with Docker Compose is enough: easy to grasp, quick to restore, no cluster knowledge required. Kubernetes pays off when high availability is required or a cluster already exists; the official Keycloak Operator then handles rollouts and configuration. Introducing Kubernetes just for Keycloak, though, we usually consider oversized β that is a judgment from projects, not a law of nature.
The update obligation
As of September 2026, Keycloak stands at version 26.7.4; the project ships several releases a year plus security patches in between. Unlike with a SaaS IdP, nobody applies them for you. Deferring updates means running a security system with documented gaps β for an identity system, not a tenable position. Plan a fixed rhythm, say one maintenance window per quarter. How to plan, test, and roll back upgrades is covered in our article on Keycloak major upgrades.
Effort in numbers: what our projects show
For orientation, explicitly labeled as our own numbers: a single instance on an EU server (at Hetzner, say) costs us two to five person-days to set up, then about half a person-day to one per month for updates, monitoring, and backup drills. An HA cluster on Kubernetes sits closer to five to ten person-days to build, with running effort above that accordingly.
The infrastructure itself stays cheap: a low two-digit euro amount per month covers a single instance, and an HA setup sits in the low three-digit range. The expensive part of self-hosting is not the server β it is the responsibility.
Managed Keycloak: providers and prices (as of September 2026)
Between running it yourself and a SaaS IdP lies a third path: a provider operates your dedicated Keycloak, while realms, flows, and extensions remain yours to configure. The market for this is small but real. We checked four providers against their pricing pages on September 28, 2026:
| Provider | Entry price (list) | Model | EU angle |
|---|---|---|---|
| Cloud-IAM | freemium up to 100 users; dedicated HA clusters from β¬225/month | priced by cluster and SLA (99% to 99.98%), user quota per plan with soft limits | French provider, hosting at Scaleway and Outscale among others, ISO 27001 |
| Phase Two | from $149/month (up to 15,000 active users) | dedicated clusters, tiers up to 250,000 MAU for $2,499/month | EU data residency as an option, SOC 2 Type 2, ISO 27001 |
| Skycloak | from $29/month (Developer), $149/month (Launch) | priced by cluster size, unlimited users | EU region not stated on the pricing page |
| Elestio | from $11/month | managed VM with auto-updates and backups, not an IAM specialist | provider choice includes Hetzner, Netcup, and Open Telekom Cloud |
The spread from $11 to $2,499 per month is not a contradiction but a difference in category. Elestio runs a virtual machine with Keycloak on it for you: updates and backups happen automatically, the IAM responsibility stays with you. Cloud-IAM and Phase Two sell identity as a product β with an SLA, incident readiness, and Keycloak expertise in support. Skycloak sits in between: dedicated clusters, unlimited users, a slimmer enterprise layer on top.
What to look for when choosing: an SLA with a number instead of good intentions, a documented update policy (who decides when which version runs), an exit path with export of realms and user data including password hashes β and the data location, more on that in a moment.
A note on pricing dynamics: managed Keycloak is a young market and plans change fast β check the pricing pages again yourself before deciding. Testing is low-risk almost everywhere: Cloud-IAM offers a freemium up to 100 users, Phase Two a 30-day trial, Skycloak 21 days.
The EU factor: data location, DPAs, and the line to SaaS IdPs
Identity data is personal data in concentrated form: names, email addresses, password hashes, login history. Where it lives is therefore no detail question β least of all when your users are in the EU and the GDPR applies. To set expectations: what follows is a feasibility perspective from projects, not legal advice. The assessment of your individual case belongs with your data protection officer.
Self-hosting settles data location structurally: with Keycloak on a server in Germany, identity data never leaves the EU. No third-country transfer, no dependence on adequacy decisions β the question is answered by the architecture before a lawyer has to ask it.
The second building block next to location is the data processing agreement (DPA): the contract under Art. 28 GDPR that governs what a service provider may do with your data. With self-hosting you sign it with the data center; with a managed provider, additionally with them. The shorter the chain, the easier the answer when a customer or a supervisory authority asks.
With managed providers, two questions count: where are the servers, and who operates them? Cloud-IAM on Scaleway or Outscale keeps both in the EU. Phase Two offers EU data residency as an option; clarify in the DPA whether support access from third countries is foreseen. With Elestio you pick the provider yourself β with Hetzner, the data sits in Germany.
The line to SaaS IdPs: Auth0, Okta, and Entra External ID are services of US companies. The data transfer rests on the Data Privacy Framework β an agreement whose fate is decided in Washington and Brussels, not in your company. That path is workable too. But your compliance then hangs on a treaty instead of your architecture: data sovereignty you configure beats data sovereignty you negotiate.
The decision: self-hosted, managed, or SaaS IdP?
To close, the criteria side by side. The table condenses what is laid out above β take it as the starting point for your trade-off, not as its replacement:
| Criterion | Self-hosted | Managed Keycloak | SaaS IdP |
|---|---|---|---|
| Software cost | β¬0 (open source) | subscription by cluster size, from $11 to β¬225 and up per month | per-active-user pricing |
| Operations effort | yours (from about 0.5 person-days/month, our experience) | the provider's | the provider's |
| Data location | your choice, e.g. Germany | EU region possible depending on provider | provider's regions, US parent company |
| Customization (SPIs, themes, flows) | full | extensive, provider-dependent | limited to product features |
| Update control | you decide and do the work | the provider, partly with a say | none, but no work either |
| Fits when β¦ | ops capacity and data sovereignty requirements exist | you want Keycloak's feature set without your own ops team | standard auth is enough and per-user costs stay bearable |
Our rule of thumb from B2B projects: a single lean application rarely needs its own Keycloak β built-in authentication is often enough there, the way we use it in Supabase projects. Keycloak pays off once you need SSO across several applications, directory integration, or fine-grained roles. And then: with ops capacity, self-hosted; without it, managed, with a provider whose data location fits.
Also run the numbers over three years, not one month: with a SaaS IdP the bill grows with every user, with a managed provider with cluster size, with self-hosting it stays nearly constant β provided you count the person-days honestly, or the cheapest path is only cheap on paper. The full math including project costs is in What does Keycloak cost?.
A reassuring side effect of all three Keycloak paths: you can switch. A realm export takes configuration and users with it β from a managed provider to self-hosting or the other way round. With a SaaS IdP the way back is harder, because flows and extensions are product-specific. Keep that door open deliberately.
Next steps
You want to know which of the three paths fits your project? Then let's run the numbers: user counts, compliance requirements, available ops capacity β that is all a first solid recommendation needs. We run Keycloak ourselves on EU infrastructure and have handed setups over to client teams; both perspectives feed in. Book a free intro call: in 30 minutes we sort out whether self-hosting, managed, or a SaaS IdP adds up for you.
