如何在Heroku环境部署Keycloak独立服务器适配Spring Boot 2项目?
Hey there! Let me walk you through how to get Keycloak up and running on Heroku to handle auth for your Spring Boot 2 app—since you’re already using Heroku with GitHub auto-deploys, this should fit right into your existing workflow smoothly.
Prerequisites
- Your existing Heroku account (you’ve got this covered!)
- Heroku CLI installed on your local machine
- A basic understanding of Keycloak’s core concepts (realms, clients, etc.)
Step 1: Set Up a New Heroku App for Keycloak
It’s best to keep Keycloak isolated from your Spring Boot app, so let’s create a dedicated Heroku app:
heroku create your-keycloak-app-name
Pick a name that makes sense for your project—like my-app-keycloak or something similar.
Step 2: Add a Managed PostgreSQL Database
Keycloak’s default H2 database isn’t suitable for production (or even persistent development use). Heroku’s Postgres add-on is perfect here:
heroku addons:create heroku-postgresql:hobby-dev -a your-keycloak-app-name
This will automatically set up environment variables like DATABASE_URL that we’ll use to connect Keycloak to the database.
Step 3: Configure Keycloak to Use Heroku’s Environment
Heroku doesn’t let you hardcode configs easily, so we’ll use a startup script to dynamically set up Keycloak’s database connection and port.
Create a
start-keycloak.shfile in your Keycloak project root with this content:#!/bin/bash # Parse Heroku's DATABASE_URL into Keycloak-friendly format DB_USER=$(echo $DATABASE_URL | cut -d':' -f2 | cut -d'/' -f3) DB_PASS=$(echo $DATABASE_URL | cut -d':' -f3 | cut -d'@' -f1) DB_HOST=$(echo $DATABASE_URL | cut -d'@' -f2 | cut -d':' -f1) DB_PORT=$(echo $DATABASE_URL | cut -d':' -f4 | cut -d'/' -f1) DB_NAME=$(echo $DATABASE_URL | cut -d'/' -f4) DB_JDBC_URL="jdbc:postgresql://$DB_HOST:$DB_PORT/$DB_NAME?user=$DB_USER&password=$DB_PASS" # Start Keycloak with Heroku-specific configs ./bin/standalone.sh \ -b 0.0.0.0 \ -Djboss.http.port=$PORT \ -Ddb.url=$DB_JDBC_URL \ -Ddb.driver=org.postgresql.Driver \ -Ddb.user=$DB_USER \ -Ddb.password=$DB_PASS \ -Dkeycloak.migration.action=import \ -Dkeycloak.migration.provider=dir \ -Dkeycloak.migration.dir=./imports \ -Dkeycloak.migration.strategy=OVERWRITE_EXISTINGThe migration flags are optional but useful if you want to import pre-configured realms/clients on startup—just add your JSON configs to an
importsfolder.Make the script executable:
chmod +x start-keycloak.sh
Step 4: Create a Procfile for Heroku
Heroku uses a Procfile to know how to start your app. Create this file in your root directory:
web: ./start-keycloak.sh
This tells Heroku to run our startup script as the web process.
Step 5: Connect GitHub for Auto-Deploys
Since you’re already using GitHub auto-deploys for your Spring Boot app, do the same for Keycloak:
- Push your Keycloak code (including
Procfile,start-keycloak.sh, and any import files) to a new GitHub repository. - Go to your Keycloak Heroku app’s dashboard → Deploy tab.
- Connect your GitHub repo, then enable Automatic deploys so every code push triggers a new deployment.
Step 6: Post-Deployment Setup
Once Keycloak is live:
- Access the admin console at
https://your-keycloak-app-name.herokuapp.com/auth/admin(note the/authpath—Keycloak uses this by default). - Create a new realm for your Spring Boot app, then add a client with the correct redirect URI pointing to your Spring Boot app’s Heroku URL (e.g.,
https://your-spring-boot-app.herokuapp.com/*). - Update your Spring Boot app’s
application.properties(orapplication.yml) with Keycloak configs:keycloak.auth-server-url=https://your-keycloak-app-name.herokuapp.com/auth keycloak.realm=your-realm-name keycloak.resource=your-client-id keycloak.public-client=true
Key Things to Keep in Mind
- Hobby Dyno Sleep: Free Heroku dynos sleep after 30 minutes of inactivity. For production, upgrade to a paid dyno to keep Keycloak running 24/7.
- SSL: Heroku automatically provides SSL for
herokuapp.comdomains, so you can safely usehttpsfor your Keycloak URL without extra setup. - Data Persistence: The hobby-dev Postgres plan has limits (like 10k rows), so upgrade to a higher tier if you need more storage or performance for production.
内容的提问来源于stack exchange,提问作者Hmerac

