// Bitnami alternatives / keycloak
Bitnami Keycloak alternative
Replacing bitnamilegacy/keycloak
The bitnamilegacy/keycloak image has had about 2.4 million pulls since Bitnami moved it to the legacy repository, and it receives no updates. Switching to the official quay.io/keycloak/keycloak image means changing environment variables and the data path. Get either wrong and the new container starts empty.
Trusted globally by enterprises




Bitnami Keycloak variables and their official equivalents
Bitnami Keycloak image to official quay.io/keycloak/keycloak:
| Setting | Bitnami | Official image |
|---|---|---|
| Bootstrap admin user | KEYCLOAK_ADMIN_USER | KC_BOOTSTRAP_ADMIN_USERNAME |
| Bootstrap admin password | KEYCLOAK_BOOTSTRAP_ADMIN_PASSWORD | KC_BOOTSTRAP_ADMIN_PASSWORD |
| Database credentials | KC_DB_USERNAME / KC_DB_PASSWORD | KC_DB_USERNAME / KC_DB_PASSWORD |
| Data path | /bitnami/keycloak | External database; no local data volume |
What breaks when you switch
- The Keycloak project publishes its own image on quay.io, not Docker Hub.
- Bitnami's KEYCLOAK_* variables map onto Keycloak's own KC_* options; the KC_* options carry over unchanged.
- The Bitnami chart bundles a PostgreSQL dependency that also pulls a Bitnami image.
What happened to the Bitnami Keycloak image
For years, bitnami/keycloak on Docker Hub was one of the most common ways to deploy Keycloak on Kubernetes, usually through the Bitnami Keycloak Helm chart. On 28 August 2025 Broadcom moved every versioned Bitnami container image, including this one, to the bitnamilegacy repository, and removed the public docker.io/bitnami catalog on 29 September 2025. The free tier now offers only latest tags of a limited set of images for development.
The legacy Docker image still pulls, so existing deployments keep working. It no longer receives updates, which means every vulnerability disclosed since the move stays open in the Keycloak binary, in the base image and in every bundled dependency. Container scanners will report a growing count at every audit, and a workload that depends on a frozen public repository is one registry change away from ImagePullBackOff.
How to migrate Keycloak off Bitnami safely
- Find every reference to bitnami/keycloak and bitnamilegacy/keycloak in running workloads, Helm values files and CI pipelines, including init containers.
- Record the Keycloak version each deployment pins. Versions past upstream end of life are not covered by the free open source images.
- Take a backup and test a restore before touching a stateful workload.
- Mirror the replacement container images into your own registry, and scan them before you deploy.
- Move one replica or one environment at a time, and confirm the data path, file ownership and credentials on the new image.
- Remove every remaining legacy reference so nothing falls back to the archive on the next deploy.
Your options
Ask for an OSSeva drop-in image
OSSeva does not ship a Keycloak image yet. Tell us you need one; we prioritise new images by the number of teams asking.
Official quay.io/keycloak/keycloak image
Free and maintained for current versions. Apply the mapping above and move the volume.
Keycloak Operator
The Keycloak project's own Kubernetes operator.
Bitnami Secure Images
Broadcom's paid catalog keeps the Bitnami layout for supported versions, sold within TrueSource.
Repoint the Bitnami Keycloak Helm chart
# values-override.yaml
image:
registry: registry.example.com # your mirror of the replacement image
repository: keycloak
tag: "<pinned version>"
global:
security:
allowInsecureImages: true # recent Bitnami charts reject non-Bitnami images without thisThis works only with an image that keeps Bitnami's layout. With the official image, rewrite the chart or move to an operator. See replacing bitnamilegacy images for the full inventory and rollout steps.
Frequently asked questions
What is the best alternative to the Bitnami Keycloak image?
The official quay.io/keycloak/keycloak image, or Keycloak Operator on Kubernetes. Map the Bitnami variables and data path first, as shown on this page.
Is bitnamilegacy/keycloak still getting security updates?
No. Bitnami moved versioned images to the bitnamilegacy repository on 28 August 2025 and describes it as receiving no further updates. It had about 2.4 million pulls by September 2026.
Can I keep using the Bitnami Keycloak Helm chart?
Yes, with a maintained image that keeps Bitnami's layout. Set image.registry and image.repository in your values file, and set global.security.allowInsecureImages to true, because recent Bitnami charts refuse non-Bitnami images otherwise.
Is Bitnami no longer free?
Not for production. Since 28 August 2025, versioned Bitnami images live in the bitnamilegacy repository with no updates, and the free tier offers latest tags of a limited set of images for development. Maintained, versioned images are sold as Bitnami Secure Images, which Broadcom prices by quote.
Where does the Bitnami Keycloak image store data?
Under /bitnami/keycloak. The official image uses External database; no local data volume, so the volume mount must change when you switch images.
Need a maintained Keycloak image?
Send us your image list and versions; we reply with coverage and a migration plan within five working days.