ayedo Identity – Keycloak

Identity
Made in Germany

Identity and access as part of your certified hosting – ayedo operates ayedo ID for ayedo Cloud services or Dedicated Keycloak in the Platform Cluster, with expert support from Germany.

Leading companies trust our technology ↘

Control identities centrally

Our identity service is based on Keycloak in the Platform Cluster – SSO without months of in-house build-out, predictable costs per realm, and one identity path instead of parallel user databases in every app. ayedo takes over operations and availability, including OIDC/SAML and LDAP or Active Directory integration.

ayedo ID

Identity provider for ayedo Cloud

The multi-tenant Keycloak of ayedo Cloud authenticates your users to GitLab, Argo CD, Harbor, OpenBao, Grafana, and other ayedo Cloud services. A single login covers all shared services.
ayedo ID SSO ayedo Cloud

Separate realm

Dedicated capabilities on shared infrastructure

A separate realm for your business applications and end-customer user management provides login, roles, and MFA – fully isolated from the ayedo ID realm of the platform services.
Realm Apps End customers

Single Sign-On

OIDC & SAML

Modern protocols enable sign-in for applications, cluster access via kubelogin, and federation to Entra ID, Google, or existing identity providers.
OIDC SAML Federation

MFA & Policies

Strong authentication

TOTP, WebAuthn, and fine-grained realm and client policies form the foundation for zero-trust architectures and audit requirements.
MFA WebAuthn Policies

Directory integration

LDAP / Active Directory

Connect your existing user directories and use identities, groups, and roles centrally for SSO and access control.
LDAP AD Groups

Kubernetes & Apps

One shared identity path

Cluster OIDC, managed apps, and business applications share the same identities. Parallel user databases become unnecessary.
K8s OIDC RBAC

EU infrastructure

Sovereign hosting

Your identity data resides on European infrastructure – GDPR-compliant and without dependency on US cloud providers for your identity provider.
EU GDPR Sovereignty

Pricing – separate realm

Billing is user-based per separate realm on ayedo Cloud. A separate realm is suitable for business-application login, end-customer user management, and additional clients – functionally comparable to a dedicated instance, operated on shared infrastructure.

up to 100 users

Separate realm · ayedo Cloud

€49.95 /month

  • €49.95/month for up to 100 users in the realm
  • Your own, isolated realm
  • Login for your business applications and end customers
  • OIDC/SAML clients, MFA, and standard policies
  • Operated in the central Platform Cluster
  • ayedo ID for the platform services remains separate

up to 250 users

Separate realm · ayedo Cloud

€99.95 /month

  • €99.95/month for up to 250 users in the realm
  • Your own, isolated realm
  • Login for your business applications and end customers
  • OIDC/SAML clients, MFA, and standard policies
  • Operated in the central Platform Cluster
  • ayedo ID for the platform services remains separate

up to 500 users

Separate realm · ayedo Cloud

€199.95 /month

  • €199.95/month for up to 500 users in the realm
  • Your own, isolated realm
  • Login for your business applications and end customers
  • OIDC/SAML clients, MFA, and standard policies
  • Operated in the central Platform Cluster
  • ayedo ID for the platform services remains separate

More isolation when needed

When a separate realm on shared infrastructure is not sufficient, you can choose a dedicated Keycloak instance or operation on your own infrastructure.

Dedicated

Dedicated Keycloak · Single-tenant

Custom

  • Your own Keycloak in a dedicated Platform Cluster
  • Isolated realms and clients exclusively for your organization
  • Custom themes & flows
  • LDAP/AD and enterprise federation
  • Custom SLAs

BYOC / On-Premises

On your infrastructure

Custom

  • Keycloak on your cloud or on-premises
  • Air-gapped support available
  • Integration with your existing identity provider landscape
  • Enterprise support
  • Compliance-ready
  • Custom SLAs

Compare with alternatives

Managed Keycloak on ayedo is a sovereign, European option compared to established identity services. The following overview presents the key differences objectively.

vs. Okta

Kriterium ayedo Okta
Jurisdiction
EU / GDPR-compliant
US / Cloud Act
ayedo Cloud integration
Native to ayedo Cloud services
Extra integrations
On-premises / BYOC
Available
Cloud-first
Support
Personal support in German and English
Primarily ticket-based

vs. Microsoft Entra ID

Kriterium ayedo Microsoft Entra ID
Vendor lock-in
Open-source Keycloak
Microsoft ecosystem
Kubernetes
Cluster OIDC integrated
Extra configuration
Multi-cloud
Cloud-agnostic
Azure-focused
Data residency
EU hosting selectable
Depends on the tenant region

vs. Auth0

Kriterium ayedo Auth0
Jurisdiction
EU hosting
US company
Self-hosted
Dedicated & BYOC
SaaS-focused
Platform SSO
One identity provider for ayedo Cloud
Integration per application
Pricing model
User-based per realm
MAU-based pricing tiers

Compliance & Regulatory Requirements

The ayedo Software Delivery Platform meets the requirements of current EU regulations. From GDPR to NIS-2 to DORA – our platform is designed for regulated industries and critical infrastructures.

GDPR-Compliant Data Processing

Privacy by Design & Default.

EU data residency (Germany), Customer-Managed Keys (BYOK/BYOHSM), encryption at rest/in transit. ISO 27001-certified data protection management. Support for data subject rights, DPA, incident response. More about GDPR .

NIS-2-Compliant Operations

Resilience for critical infrastructures.

24/7 monitoring, incident response, BCP/DR processes, supply chain transparency (SBOM). EU-based operations, MFA/PAM, vulnerability management, patch processes. Ideal for essential/important entities. More about NIS-2 .

DORA-Ready for Financial Institutions

ICT resilience tailored.

ICT risk management framework, documented exit strategies, third-party risk management, TLPT readiness. Structured incident reporting chains, continuous resilience testing, ISO 27001-certified. More about DORA .

CRA-Compliant Software Supply Chain

Security by Design across the entire lifecycle.

SBOM generation, CVE scanning, vulnerability disclosure processes, update management. Signed container images, GitOps-based audit trails, transparent supply chain. More about CRA .

Cloud Sovereignty Framework

Digital sovereignty made measurable.

EU-based operations, open standards, exit capability without lock-in. Designed for SEAL-4 (Full Digital Sovereignty) across all eight sovereignty objectives. No dependencies on non-EU control. More about the Framework .

Data Act-Compliant Portability

Switching without barriers.

Open APIs (OpenAPI), standardized formats (YAML/JSON/OCI), complete exit runbooks, Infrastructure-as-Code portability. Multi-cloud capable, no egress fees, functional equivalence. More about Data Act .

Integrated Compliance Roadmap

Holistic approach.

How ayedo systematically addresses GDPR, NIS-2, DORA, CRA, Data Act, Cloud Sovereignty Framework, ISO 27001/9001. Certifications, processes, technical measures, audit readiness. To overview .

Part of the Software Delivery Platform

Identity is the shared authentication layer for Platform , Code Repository , Delivery , Container Registry , Secrets Management , and Observability .

Platform

Big picture

Get an overview of the platform cluster, the operating models, and all building blocks of the Software Delivery Platform (SDP).
SDP Overview

Managed Kubernetes

Cluster OIDC

Secure your workload clusters against the same identity provider – for consistent identities from the platform to the application.
Kubernetes OIDC
https://icons.ayedo.de/svg/keycloak.svg

Keycloak App

Managed app in detail

You can find the technical specification and block reference on the page of the Keycloak managed app .
Keycloak Managed App

Documentation

Access control

Further documentation on identity provider and OIDC topics is available at docs.ayedo.de .
Docs OIDC

You build it. We run it.

Excellent performance and maximum uptime - that’s what we wake up for. And sometimes even in the middle of the night.

100+ Clusters

under management

We operate more than 100 Kubernetes clusters in production for our customers.

300+ Databases

under management

We operate, monitor, and back up more than 300 databases in production.

1 Petabyte Object Storage

under management

We operate one petabyte of object storage for backups, artifacts, and application data.

100 Million Timeseries

on average

4 million datapoints per second are ingested by our monitoring systems.

38,000+ Logs

per second

Our collectors continuously ingest logs and store them in a GDPR-compliant way – more than 100 billion entries per month.

5,000+ Backups

per day

We secure more than 5,000 backups every day on encrypted long-term storage – around 150 terabytes of backup volume per month.

270 Million End Users

per month

More than 9 million end users use software we deploy every day, on the internet or on-premise.

99.99% Uptime

annual average

Our managed services are unavailable for less than 1 hour per year on average.

MTTD < 5 Minutes

on average

Our alerting typically detects errors and outages within a few minutes.

Frequently asked questions

Answers to common questions about ayedo ID, Dedicated Keycloak, and identity in the context of the Software Delivery Platform.

What is the difference between ayedo ID, a separate realm, and Dedicated Keycloak?

ayedo ID authenticates users to the ayedo Cloud services (GitLab, Argo CD, Harbor, OpenBao, Grafana, and more). A separate realm on ayedo Cloud is priced per user and covers business applications, end-customer login, and user management – functionally comparable to a dedicated instance, but operated on shared infrastructure. Dedicated Keycloak is your own Keycloak instance in a dedicated platform cluster, offering maximum isolation, custom themes, federations, and custom SLAs.

What is a separate realm used for?

A separate realm is suitable for login to your business applications, end-customer user management, additional OIDC/SAML clients, and multi-tenant scenarios – fully separated from the ayedo ID realm of the platform services. Pricing: €49.95 up to 100 users, €99.95 up to 250 users, €199.95 up to 500 users – each per month and realm.

Do business applications need to use the same IdP?

We recommend it, as this avoids parallel user databases. Business applications can receive their own clients in your separate realm or be connected via federation. SSO for the platform services continues to run via ayedo ID.

Can we connect our existing Active Directory?

Yes. Integration works via LDAP/AD user federation or as an identity broker (OIDC/SAML) to Entra ID and other identity providers. This scenario is typical for Dedicated and BYOC/on-premises environments.

Why identity from day one?

Without a well-considered identity concept, local user accounts accumulate in every application on the platform. Consolidating them later is considerably more effort than establishing a clean OIDC path when rolling out the Software Delivery Platform.
Kontakt aufnehmen