Keycloak: 4. Create the service

This documentation is part of the Automate with the CLI guide. You can view the complete guide here: Start Keycloak, retrieve its credentials, and modify its configuration programmatically using the Stackhero CLI.

👋 Welcome to the Stackhero documentation!

Stackhero offers a Keycloak cloud service that makes it easy to deploy a production-ready identity provider in just 2 minutes:

  • Unlimited users, realms, and clients
  • Supports OpenID Connect, OAuth 2.0, SAML 2.0, social login, LDAP, and Active Directory federation
  • Custom domain name with built-in HTTPS for secure access (for example, https://login.your-company.com)
  • Custom themes: easily brand your login pages, account console, and emails with the included online editor
  • Dedicated email server with SPF, DKIM, and DMARC, so account confirmations and password resets are handled for you
  • Built-in PostgreSQL database, with the administration console available on its own dedicated, closable port
  • One-click updates keep your system up to date without manual intervention

Spend your time building, not configuring: you can try out Stackhero's Keycloak cloud solution in less than 5 minutes.

Below is a sample script that creates a stack, adds your Keycloak service to it, waits for it to start, retrieves its configuration (including generated credentials), and then applies a new configuration.

#!/bin/bash
set -e

export STACKHERO_TOKEN="usr-xxxxxx:your-token"

serviceStore="keycloak"   # The Keycloak service store name (see step 2)
instance="..."                # An instance size from step 3
region="europe"               # A region name from step 3

# Create a stack for your service (uses your default organization; add --organization if needed)
stackId=$(stackhero --format=script stack-create \
  --name="My Keycloak stack")
echo "Stack created: ${stackId}"

# Add Keycloak to the stack (names are resolved automatically)
serviceId=$(stackhero --format=script service-add \
  --stack="My Keycloak stack" \
  --service-store="${serviceStore}" \
  --instance="${instance}" \
  --region="${region}")
echo "Service added: keycloak"

# Wait for the service to be fully operational (this may take a few minutes)
stackhero service-wait-for --service="keycloak"

# Retrieve the service configuration, including generated credentials
stackhero service-configuration-get --service="keycloak" --format=json