You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Heroku环境部署Keycloak独立服务器适配Spring Boot 2项目?

Deploying Keycloak on Heroku for Your Spring Boot 2 Project

Hey there! Let me walk you through how to get Keycloak up and running on Heroku to handle auth for your Spring Boot 2 app—since you’re already using Heroku with GitHub auto-deploys, this should fit right into your existing workflow smoothly.

Prerequisites

  • Your existing Heroku account (you’ve got this covered!)
  • Heroku CLI installed on your local machine
  • A basic understanding of Keycloak’s core concepts (realms, clients, etc.)

Step 1: Set Up a New Heroku App for Keycloak

It’s best to keep Keycloak isolated from your Spring Boot app, so let’s create a dedicated Heroku app:

heroku create your-keycloak-app-name

Pick a name that makes sense for your project—like my-app-keycloak or something similar.

Step 2: Add a Managed PostgreSQL Database

Keycloak’s default H2 database isn’t suitable for production (or even persistent development use). Heroku’s Postgres add-on is perfect here:

heroku addons:create heroku-postgresql:hobby-dev -a your-keycloak-app-name

This will automatically set up environment variables like DATABASE_URL that we’ll use to connect Keycloak to the database.

Step 3: Configure Keycloak to Use Heroku’s Environment

Heroku doesn’t let you hardcode configs easily, so we’ll use a startup script to dynamically set up Keycloak’s database connection and port.

  1. Create a start-keycloak.sh file in your Keycloak project root with this content:

    #!/bin/bash
    # Parse Heroku's DATABASE_URL into Keycloak-friendly format
    DB_USER=$(echo $DATABASE_URL | cut -d':' -f2 | cut -d'/' -f3)
    DB_PASS=$(echo $DATABASE_URL | cut -d':' -f3 | cut -d'@' -f1)
    DB_HOST=$(echo $DATABASE_URL | cut -d'@' -f2 | cut -d':' -f1)
    DB_PORT=$(echo $DATABASE_URL | cut -d':' -f4 | cut -d'/' -f1)
    DB_NAME=$(echo $DATABASE_URL | cut -d'/' -f4)
    
    DB_JDBC_URL="jdbc:postgresql://$DB_HOST:$DB_PORT/$DB_NAME?user=$DB_USER&password=$DB_PASS"
    
    # Start Keycloak with Heroku-specific configs
    ./bin/standalone.sh \
      -b 0.0.0.0 \
      -Djboss.http.port=$PORT \
      -Ddb.url=$DB_JDBC_URL \
      -Ddb.driver=org.postgresql.Driver \
      -Ddb.user=$DB_USER \
      -Ddb.password=$DB_PASS \
      -Dkeycloak.migration.action=import \
      -Dkeycloak.migration.provider=dir \
      -Dkeycloak.migration.dir=./imports \
      -Dkeycloak.migration.strategy=OVERWRITE_EXISTING
    

    The migration flags are optional but useful if you want to import pre-configured realms/clients on startup—just add your JSON configs to an imports folder.

  2. Make the script executable:

    chmod +x start-keycloak.sh
    

Step 4: Create a Procfile for Heroku

Heroku uses a Procfile to know how to start your app. Create this file in your root directory:

web: ./start-keycloak.sh

This tells Heroku to run our startup script as the web process.

Step 5: Connect GitHub for Auto-Deploys

Since you’re already using GitHub auto-deploys for your Spring Boot app, do the same for Keycloak:

  • Push your Keycloak code (including Procfile, start-keycloak.sh, and any import files) to a new GitHub repository.
  • Go to your Keycloak Heroku app’s dashboard → Deploy tab.
  • Connect your GitHub repo, then enable Automatic deploys so every code push triggers a new deployment.

Step 6: Post-Deployment Setup

Once Keycloak is live:

  1. Access the admin console at https://your-keycloak-app-name.herokuapp.com/auth/admin (note the /auth path—Keycloak uses this by default).
  2. Create a new realm for your Spring Boot app, then add a client with the correct redirect URI pointing to your Spring Boot app’s Heroku URL (e.g., https://your-spring-boot-app.herokuapp.com/*).
  3. Update your Spring Boot app’s application.properties (or application.yml) with Keycloak configs:
    keycloak.auth-server-url=https://your-keycloak-app-name.herokuapp.com/auth
    keycloak.realm=your-realm-name
    keycloak.resource=your-client-id
    keycloak.public-client=true
    

Key Things to Keep in Mind

  • Hobby Dyno Sleep: Free Heroku dynos sleep after 30 minutes of inactivity. For production, upgrade to a paid dyno to keep Keycloak running 24/7.
  • SSL: Heroku automatically provides SSL for herokuapp.com domains, so you can safely use https for your Keycloak URL without extra setup.
  • Data Persistence: The hobby-dev Postgres plan has limits (like 10k rows), so upgrade to a higher tier if you need more storage or performance for production.

内容的提问来源于stack exchange,提问作者Hmerac

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:50:41