Editorial desk
Keycloak Ops Editorial
Keycloak Ops Editorial is the publishing identity for Keycloak Ops. It is a desk, not a person: no named author, no biography, no professional certifications.
Articles published under this byline are researched from primary sources — vendor and project documentation, published standards and specifications, research papers, and measurements published by whoever took them — drafted with AI assistance, and edited against those cited sources before publication. Nothing here is based on first-hand testing in a private lab, and any figure that appears is attributed to the source it came from.
Corrections go to [email protected]. More detail is on the about page and the editorial disclosure.
Posts (4)
- Troubleshooting
Keycloak Behind a Reverse Proxy: Fix 403 and Hostname Errors
Why Keycloak returns 403 behind a proxy, rejects redirect URIs, and issues tokens with the wrong issuer, and the exact options that resolve each case.
- Sizing
Keycloak Memory Usage and Heap Sizing Explained
What actually consumes Keycloak memory, the documented 1250 MB baseline, the 70 percent heap rule, and how to turn login rates into node sizing.
- Comparisons
Keycloak vs authentik vs Authelia: What to Self-Host
A protocol, architecture and footprint comparison of three self-hosted identity servers, and the deployment shapes each one is actually built for.
- Fundamentals
Keycloak Realms, Clients and Token Design Fundamentals
How Keycloak realms, clients, flows and token lifetimes fit together, plus the caching, session and clustering decisions that bite operators later on.