Our subscription models
Keycloak LTS Image
from €220 / month
For teams that need a secure and regularly updated standard image for their own Keycloak operation.
Suitable for:
- Self-Hosting
- Kubernetes
- OpenShift
- Docker und Podman
- own Cloud-Accounts
- Private cloud environments
- Production-related and productive deployments
Contain:
- Keycloak LTS Container Image
- regular micro-release updates
- Security- and Wartungsupdates
- Provision via a coordinated repository
- Use as a base image for your own deployments
- clear LTS-oriented versioning strategy
Custom LTS Image
from €295 / month
For teams that want to integrate their individual extensions, SPIs or themes directly into their own Keycloak image through intension.
The Custom LTS Image includes all the features of the Keycloak LTS Image and adds customer-specific components.
Suitable for:
- custom Keycloak extensions
- custom login themes
- custom SPIs
- productive IAM setups with customizing
- Platforms with individual requirements
Also included:
- Integration of customer-specific extensions
- Integration of individual themes
- customized image
- A separate deployment process for your custom image
- A suitable basis for productive Keycloak setups with individual extensions
Important: Building a custom image with your extensions or themes is an optional service. You can, of course, also use our Keycloak LTS image as a base image and build your own extensions on top of it.
Enterprise LTS Image
from €890 / month
For companies that want to deploy a secure Keycloak LTS image company-wide for multiple product instances.
Suitable for:
- multiple Keycloak product instances
- central platform teams
- internal product landscapes
- standardized IAM operating models
- Organizations with multiple deployments
- Companies with recurring Keycloak instances
Contain:
- Business license
- Use for all product instances
- unified Keycloak LTS image
- central image strategy
- Plannable update and maintenance logic
- stable foundation for multiple productive deployments
clear LTS-oriented versioning strategy. With our subscription, you retain full control over your infrastructure while using a security-oriented, regularly updated Keycloak Container Image from intension.
Especially for companies with high demands on compliance, data protection and digital sovereignty, this creates an operating model where you determine hosting, deployment and security processes yourself.
intension provides the stable image foundation for this – with LTS-oriented versioning, micro-updates and optional support for individual extensions or themes.
What you get

Keycloak LTS Images for production environments
You will receive a near-production container image for Keycloak, based on supported LTS-oriented release lines and regularly supplied with relevant micro-updates.

Clear LTS strategy
The subscription follows a defined lifecycle logic. It supports selected release lines that are particularly suitable for stable and predictable production operation.

Security and maintenance updates
We incorporate qualified security patches, important bug fixes, and container stack updates. This reduces your effort for maintaining your own image and performing security-related updates.

Use as a base image
You can use our LTS image directly as the foundation for your own operation. If you want to integrate your own extensions or themes, you can either build them yourself based on our image or optionally have them integrated into a custom LTS image by intension.
Why this is relevant for compliance and sovereignty
Operation in your infrastructure
You decide where Keycloak runs: in your own cloud account, in your own Kubernetes cluster, in a private cloud, or in your own data center. This keeps the technical operating environment under your control.
Transparent update strategy
The subscription follows a clear LTS-oriented release logic. This simplifies planning, internal approvals, test cycles, and documentation of updates.
Open Source instead of Blackbox
Keycloak remains open source. You use a professionally provided image, but not a closed, proprietary IAM platform. This reduces vendor lock-in and supports a sovereign IAM architecture.
Clear division of responsibilities
You retain control over operations, deployment, data storage, and infrastructure. intension provides the updated and security-oriented image foundation. This clear separation integrates well into governance, audit, and supplier processes.
Security-oriented image foundation
The image reduces the in-house effort required for CVE assessment, security patches, and micro-updates. This creates a more reliable foundation for the productive operation of a central IAM component.
Suitable for regulated operating models
Especially when faced with requirements from internal security policies, ISO 27001-compliant operating models, DORA or NIS2 contexts, a controlled image lifecycle is helpful: defined release lines, planned updates, security focus and a clear source for the central IAM image.
This is how collaboration works

Short technical discussion
We’ll determine which model best suits your setup: Keycloak LTS Image, Custom LTS Image, or Enterprise LTS Image.

Set deployment model
We will decide which repository and target environments the image should be provided for.

Optional: Include custom artifacts
If you would like to integrate your own extensions, SPIs or themes directly into your image, we will jointly examine the integration into a custom LTS image.

Integrate image
You integrate the provided image into your existing deployment processes. Alternatively, you can use our image as a base image and build your own extensions on top of it.

Use ongoing updates
As part of the subscription, we provide updated LTS images that you can integrate into your environment in a controlled manner.
Who is the Keycloak LTS Container Subscription ideal for?

For platform and DevOps teams
You run Keycloak yourself, but don’t want to build your own permanent process for image builds, CVE assessment, and LTS maintenance.

For companies with their own cloud strategy
You want to run Keycloak in your own cloud, your own Kubernetes cluster or your own data center – and still use a professional image foundation.

For regulated organizations
You need traceable update and maintenance processes for a central IAM component.
.

For product providers
You use Keycloak as part of your own software or platform solution and want to use a standardized, secure and regularly updated image for it.

For teams with individual extensions
You use your own Keycloak SPIs, extensions, or themes. You can use our image as a base image and build your extensions yourself – or optionally commission intension to build a custom LTS image for you.
FAQ
Is this a full Keycloak Managed Service?
No. The subscription provides you with a secure Keycloak LTS image. Operation, deployment, infrastructure, and data storage remain with you. If you wish, you can later upgrade to a managed service or Keycloak as a Service.
Which Keycloak versions are supported?
We are using selected even minor versions of Keycloak as a guide. Examples of such lines are 26.0, 26.2, 26.4, 27.0, 27.2, or 27.4.
Odd minor versions such as 26.1, 26.3, 27.1 or 27.3 are not the focus of LTS-oriented care.
A supported minor version is typically provided with relevant micro-updates until the second subsequent even minor version is available.
Example:
Version 26.0 is supported until version 26.4 is available.
Version 26.2 will be supported until version 26.6 is available.
Version 26.4 is supported until version 26.8 is available.
This creates a predictable update path: You don’t have to adopt every short-term version, but can rely on more stable release lines.
These lines are better suited for planned, long-term care-oriented treatment than any single short-term community version.
How exactly does the LTS strategy work?
A supported minor version is typically provided with relevant micro-updates, security patches, and important bug fixes until the second subsequent even minor version is available.
Example:
Version 26.0 is supported until version 26.4 is available.
Version 26.2 will be supported until version 26.6 is available.
Version 26.4 is supported until version 26.8 is available.
This creates a predictable timeframe for updates, tests, and migrations.
Why are the currently supported version numbers not listed on the page?
Because supported Keycloak versions change regularly, the subscription follows a lifecycle logic instead of a static version list. This ensures the information remains accurate without requiring page updates after each release.
What does "even minor version" mean?
This refers to release lines following the pattern Major.0, Major.2, Major.4, and so on. For Keycloak, these would be, for example, 26.0, 26.2, 26.4, 27.0, 27.2, or 27.4.
Odd lines such as 26.1, 26.3, 27.1 or 27.3 are not the focus of this LTS-oriented strategy.
Can custom extensions or themes be integrated?
Yes. That’s what the Custom LTS Image is designed for. Custom extensions, SPIs, or themes can be integrated into a customer-specific image after consultation with intension.
Alternatively, you can simply use our Keycloak LTS image as a base image and build your own extensions on top of it.
What does an additional pipeline cost?
An additional pipeline costs €75 per month.
This is only relevant if you want intension to integrate your custom extensions or themes directly into a custom image and provide an additional custom build pipeline for this purpose. If you are simply using our image as a base image and building your extensions on top of it yourself, you do not need an additional pipeline from intension.
Who is the Enterprise LTS image intended for?
For companies that want to use a secure Keycloak LTS image company-wide for multiple product instances.
Can I use the image in my own cloud?
Yes. The subscription is specifically designed for your own operations – for example, in your cloud, your Kubernetes cluster, your private cloud, or your own data center.
What does LTS mean in our Keycloak image?
By LTS we mean a stability-oriented release and maintenance strategy for production Keycloak container images.
Instead of adopting every new community version immediately, we focus on selected, stable Keycloak release lines. Within these lines, we regularly provide relevant micro-updates, security patches, and important bug fixes.
This allows us to avoid unnecessarily frequent version jumps and create a predictable, reliable basis for productive Keycloak deployments.
In short:
You get a stable image foundation for your own business without having to evaluate, build and maintain each Keycloak version yourself.
Other services:
Keycloak consulting

