// the find
keycloak/terraform-provider-keycloak
Terraform provider for Keycloak
Terraform provider for managing Keycloak realms, clients, users, roles, identity providers, and authorization policies as code. It's the project's own official successor to the abandoned mrparkers/keycloak fork, and it's the tool you reach for if you're provisioning Keycloak instances via IaC instead of clicking through the admin console.
Resource coverage is genuinely wide — LDAP federation, custom user storage providers, fine-grained admin permissions (FGAP), workflows, keystores, all the OIDC/SAML protocol mapper variants. Acceptance tests actually run against real Keycloak instances across eight minor versions in CI rather than relying on mocked HTTP responses, which catches real API drift. It supports several distinct auth flows to the Keycloak API itself (password grant, client credentials, mTLS client cert, pre-issued access token), which matters if you're running Keycloak behind mTLS or want short-lived tokens in CI rather than long-lived service account secrets.
Only the latest three minor Keycloak versions are officially supported — if you're on an LTS-style older install, you're explicitly told it 'may still work' with no guarantee. Migrating off the old mrparkers/keycloak fork is a manual terraform state replace-provider operation with no migration guide covering schema differences between the two providers. The resource and data-source file naming (data_source_keycloak_x.go, resource_keycloak_x.go) matches the legacy Terraform Plugin SDKv2 conventions rather than the newer Plugin Framework, which means you inherit SDKv2's known rough edges around diff suppression and typed state (there's a diff_suppress_test.go dedicated to working around exactly that). Acceptance tests need a live Keycloak instance with different env var combinations per auth mode, so a lot of the auth code paths only get exercised in CI, not via any offline unit test.