5 ms·
> I didn't want to mess around with JVM dependencies and 100% didn't want to start messing around with k8s for such a small project. That's what the docker ima
by faangsticle 3y ago
> I didn't want to mess around with JVM dependencies and 100% didn't want to start messing around with k8s for such a small project.
That's what the docker image is for: https://www.keycloak.org/getting-started/getting-started-docker https://www.keycloak.org/getting-started/getting-started-doc...
docker run -p 8080:8080 -e KEYCLOAK_ADMIN=admin -e KEYCLOAK_ADMIN_PASSWORD=admin quay.io/keycloak/keycloak:21.1.1 start-dev
And off you go
- lordofgibbons 3y agoI've only used docker for local dev environments, so I'm curious what happens if the process crashes? Does the docker daemon perform health checks to restart it, or is that the domain of k8s? It's pretty simple to do with systemd.
- vbezhenar 3y agoDocker and kubernetes are different things. But both systems can restart crashed containers. That's not an issue at all. Kubernetes does it automatically. Docker does not do it automatically but you just need to supply proper option for `run` (or just in docker-compose.yaml).
- nine_k 3y agoPlain systemd can run docker containers, and keep them up if they crash. (Yes, systemd can be a useful thing sometimes!) Also, Docker and Podman know how to restart containers if needed, depending on a policy you set. If you want something even smaller, take https://github.com/containers/bubblewrap https://github.com/containers/bubblewrap or https://github.com/arachsys/containers https://github.com/arachsys/containers and run them under the process monitor of your choice, like runit or s6.
- faangsticle 3y agoSimplest form is `docker run --restart=unless-stopped` and `systemctl enable docker` They will restart when crash, and after reboot.
- vbezhenar 3y agoThis is worst docker image ever. It's starting multiple minutes. You're supposed to "compile" it, creating your own image, hosting it somewhere (and it's huge). And then this "compiled" image will be fast. Well, fast in Java terms.
- chromatin 3y agoAgree I was shocked when I read the instructions and realized I had to build a secondary container. On top of this, there are some keycloak options (parameters and env vars) which are valid only at the time of compiling a new container, where others are valid only at runtime
- faangsticle 3y agoYou absolutely don't have to build a container. You can, and it makes startup a few seconds faster so they recommend it, since it's hardly a pain anyway if you already have CI in place. Anyway, they changed the default behavior a few releases ago. In the past you had to pass --auto-build to avoid having to build, but now the default behavior is to auto build. If you instead want to optimize you have to do extra steps: https://www.keycloak.org/server/configuration https://www.keycloak.org/server/configuration
- chromatin 3y agoThat's great to hear -- thank you for the update!
- nine_k 3y agoIf you `docker pull` an image, you already "host" it. It's a bunch of local files right on your machine. Starting a few minutes? It looks like there must be some DNS problem somewhere. Or maybe it's the download build time? In any case, I'd measure the second startup time. Java can be blazingly fast if done right. (And C++ can be stupidly slow if done wrong.)
- technion 3y ago