Where Does Keycloak Store Config and Data?
Keycloak keeps config in conf keycloak.conf and runtime data in data. Realm imports drop into data import for startup.
Last updated
A Keycloak distribution centers on two folders under its install root. The conf folder holds keycloak.conf plus the TLS keystore, while data holds the H2 database, transaction logs, and the import drop folder. Production swaps the file database for Postgres via config keys.
Containers mirror the same tree under opt keycloak. Providers drop into the providers folder before the build step, and realm json files mount into data import. Environment variables with the KC prefix override file values at runtime.
Where Keycloak stores this, by platform
/opt/keycloak/conf/keycloak.conf
Main server config plus TLS keystore. Every option also maps to a KC prefixed env var or CLI flag.
/opt/keycloak/data
Runtime data for dev file installs: H2 database, transaction logs, and tmp. Production Postgres moves this data out of the folder.
/opt/keycloak/data/import
Realm import drop folder. Mount json here with the import realm flag to seed on startup.
Frequently asked questions
How do I back up Keycloak?
Back up conf plus the external database dump together. The data folder only matters for dev file installs. Realm export files round out portable backups.
How do I auto import a realm?
Mount files into data import and add the import realm startup flag. Dev mode imports on boot, which suits seeding fresh environments.
Notice an outdated path? Let us know.