Skip to content

Best VPS for Keycloak in 2026

Updated Oct 2026 · 8 plans compared

We earn commissions when you shop through the links below. Full disclosure →

Keycloak is the enterprise-standard identity server — Java and Quarkus under the hood, with the deepest SAML and LDAP federation of any open-source IdP, backed by over a decade of production use at banks and large organizations. That maturity comes with real weight: a JVM process, an admin console, and (once you leave dev mode) an external Postgres database all need to run reliably, because an IdP going down locks you out of everything behind it. If Keycloak's enterprise depth feels like more than you need, the authentik-vs-Keycloak and Keycloak-vs-Zitadel comparisons cover the lighter alternatives; the picks below assume you've decided Keycloak is the right tool and just need a box that runs it well.

Prefer to try before you commit? Kamatera's free tier lets you spin one up now.Start free on Kamatera → (opens in new tab)
What to look for
  • Keycloak's start-dev quickstart uses an embedded H2 database — fine for a five-minute trial, wrong for anything real. Production Keycloak needs an external Postgres instance, so size and budget for both the JVM process and a database, not just the container.
  • The JVM has its own memory behavior: a cold start and realm import both spike RAM well above Keycloak's steady-state footprint. Don't size to the idle number — give it headroom for startup and for the admin console under load.
  • Every OIDC/SAML client Keycloak serves depends on it being reachable — that's the trade of running your own IdP instead of authentik or Zitadel. Put TLS in front of it from day one (redirect URIs have to be https) and take backups of the database seriously; losing the realm config locks every downstream app out at once.
  • If Keycloak's Java footprint and admin-console depth are more than your use case needs, it's worth reading how it stacks up against authentik's flow-based builder or Zitadel's Go-based, multi-tenant design before committing a VPS to it.

The picks

KamateraBest overallfree tierpaid link

The $6/mo 2 GB plan (1 vCPU / 2 GB / 30 GB NVMe) is custom-sized instead of over-provisioned, and the 30-day free trial is a reasonable way to test an OIDC or SAML realm migration before paying for it.

From $4/mo · 1 vCPU / 1 GB / 20 GB · US + EU + AsiaStart free on Kamatera → (opens in new tab)
Hetzner CloudEasiest to start

CPX12 (1 vCPU / 2 GB / 40 GB NVMe, $14.09/mo) is the Hetzner box you can order today — the $7.09 CX23 has been out of stock since 2026-09 — and it costs more than the others here, but it's the natural pick if you're already running other self-hosted apps on Hetzner and want Keycloak on the same account rather than splitting providers.

From $23.59/mo · 2 vCPU / 4 GB / 80 GB · EU + USGet Hetzner Cloud (opens in new tab)
OVHcloudRunner-up

VPS-1 (2 vCPU / 4 GB / 40 GB NVMe, $4.54/mo) is the cheapest plan here that clears Keycloak's real footprint with room to spare for a companion Postgres instance, and unlimited traffic is one less thing to budget for once federated logins are flowing through it.

From $4.54/mo (12-month term) · 2 vCPU / 4 GB / 40 GB · US + EU + Canada + Asia + AustraliaGet OVHcloud (opens in new tab)
ContaboAlso good

Cloud VPS 4 (4 vCPU / 8 GB / 100 GB NVMe, $4.95/mo) is a rounding error more than OVHcloud but doubles the RAM and cores — useful headroom for the JVM's startup memory spike and for running Postgres on the same box instead of a second server.

From $4.95/mo (24-month term) · 4 vCPU / 8 GB / 100 GB · EU + US + UK + Asia + AustraliaGet Contabo (opens in new tab)
affiliate disclosure

The picks, side by side

KamateraBest overall
From$4.00/movCPU1RAM1 GBStorage20 GBRegionsUS, EU, Asia
Hetzner CloudEasiest to start
From$23.59/movCPU2RAM4 GBStorage80 GBRegionsEU, US
OVHcloudRunner-up
From$4.54/movCPU2RAM4 GBStorage40 GBRegionsUS, EU, Canada, Asia, Australia
ContaboAlso good
From$4.95/movCPU4RAM8 GBStorage100 GBRegionsEU, US, UK, Asia, Australia

Prices verified Oct 2026 · How we benchmark →

Common questions

How much RAM does Keycloak need?

Keycloak's own minimum is 1 GB, but that's the JVM process alone. Once you add an external Postgres database (required in production — the embedded H2 database is dev-only) and headroom for the JVM's startup memory spike, a 2 GB VPS is the realistic floor.

Can I run Keycloak's embedded database in production?

No. The start-dev quickstart uses an embedded H2 database, which the Keycloak project explicitly scopes to evaluation and local development. A production deployment needs an external Postgres (or another supported database) that you back up independently of the app server.

Is Keycloak overkill for a small self-hosted setup?

Often, yes. Keycloak's depth is enterprise SAML and LDAP federation — if you just need OIDC login across a handful of self-hosted apps, authentik's flow-based builder or Zitadel's lighter Go-based design (see the authentik-vs-Keycloak and Keycloak-vs-Zitadel comparisons) get you there with less to run and less to lock yourself out of.

We use analytics cookies (Google Analytics, PostHog) to see which guides are useful. No ad networks, no cross-site tracking. See our privacy policy.