Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Keycloak + PostgreSQL Docker Compose Stack

A Docker Compose setup demonstrating a multi-service architecture with health-based service dependencies, persistent storage, and secure logging configuration.

Architecture

  • Postgres: backing database for Keycloak, with data persisted outside Docker's default volume location via a bind mount.
  • Keycloak: Identity and Access Management (IAM) service, connected to Postgres for persistent storage of realms, users, and clients.
  • curl-service: a lightweight utility container that stays alive and only starts once both Postgres and Keycloak report a healthy status.

Key design decisions

  • Bind mount instead of named volume: Postgres data is stored in ./db-data rather than Docker's default volume path, for easier inspection and backup.
  • Health-based startup order: depends_on uses condition: service_healthy to ensure Keycloak only starts after Postgres is truly ready, and curl-service only starts after both services are healthy — not just "running".
  • Non-JSON logging: the default json-file logging driver was replaced with local, which is more space-efficient and avoids storing logs as JSON.
  • Log rotation limits: max-file: 20 caps the number of retained log files. Note: Docker's built-in logging drivers rotate by file count/size, not by calendar day — for true daily rotation, an external tool like logrotate would be required on the host.
  • Minimal exposed surface: only Keycloak's port (8080) is exposed to the host. Postgres and the curl service are reachable only within the internal Docker network.

Getting started

  1. Copy the example environment file and fill in your own values:
   cp .env.example .env
  1. Start the stack:
   docker compose up -d
  1. Check service health:
   docker compose ps
  1. Access the Keycloak login page:
http://localhost:8080

Notes

This project was built as a hands-on exercise to practice Docker Compose service orchestration, health checks, and secure defaults — concepts directly relevant to DevOps/DevSecOps workflows.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors