Back to articles
Technology Insight

Advanced API Security: Integrating OAuth2 Proxy with Keycloak to Protect Docker Container Endpoints on a VPS

June 3, 2026

Introduction: The Imperative of Advanced API Security

In the contemporary digital landscape, APIs serve as the foundational bedrock for modern software architecture, interconnecting microservices, mobile applications, and web platforms. However, this ubiquity makes them a primary target for malicious actors. Standard security measures, such as basic authentication or hardcoded API keys, are no longer sufficient to counter sophisticated cyber threats. For enterprise applications deployed on Virtual Private Servers (VPS), securing individual Docker containers can quickly become a management nightmare.

To mitigate these risks, organizations are shifting toward a Zero Trust Architecture. This blog post explores an advanced, production-ready security pattern: integrating OAuth2 Proxy with Keycloak to establish a centralized, bulletproof authentication layer in front of your Dockerized API endpoints. By decoupling security logic from your application code, you ensure consistent policy enforcement, minimize the attack surface, and streamline developer workflows.

The Core Components: Keycloak and OAuth2 Proxy

Before diving into the integration architecture, it is essential to understand the distinct roles these two powerful open-source tools play in our security ecosystem.

1. Keycloak: The Identity and Access Management (IAM) Engine

Keycloak is an enterprise-grade, open-source IAM solution that handles user federation, identity brokering, and centralized access control. It supports industry-standard protocols such as OAuth 2.0, OpenID Connect (OIDC), and SAML 2.0. In our architecture, Keycloak acts as the Single Sign-On (SSO) provider, managing user credentials, tokens, realms, and client permissions.

2. OAuth2 Proxy: The Gatekeeper

OAuth2 Proxy is a reverse proxy and lightweight service that handles authentication for providers like Keycloak, Google, GitHub, or OIDC compliance providers. Positioned upstream of your actual API services, it intercepts all incoming requests, validates tokens, and determines whether a request should be forwarded to the backend Docker container or redirected to the IAM provider for authentication.

Architectural Overview: How the Pieces Fit Together

Deploying this solution on a VPS involves establishing a secure request pipeline. Instead of exposing your backend Docker containers directly to the public internet, all traffic passes through a reverse proxy (such as Nginx, Traefik, or Caddy), which coordinates with OAuth2 Proxy.

The Request Lifecycle: When an unauthenticated user or client attempts to access a protected API endpoint, the reverse proxy routes the request to OAuth2 Proxy. OAuth2 Proxy detects the absence of a valid session cookie or Bearer token and redirects the client to Keycloak. After successful authentication, Keycloak issues an identity token, and OAuth2 Proxy establishes a session, securely forwarding the authorized request to the backend Docker container.

This architecture provides several distinct advantages:

  • Language Agnostic: Backend microservices do not need to implement complex OIDC libraries. Whether your API is written in Go, Python, Node.js, or Java, the security layer remains identical.
  • Centralized Auditing: All authentication logs are consolidated within Keycloak and the proxy layer, simplifying compliance and threat detection.
  • Reduced Attack Surface: Application containers remain isolated within a private Docker network, shielded from direct external access.

Step-by-Step Implementation Guide on a VPS

Let us walk through the practical configuration required to deploy this architecture using Docker Compose on a Linux VPS.

Step 1: Setting Up the Docker Network and Keycloak

First, create a dedicated Docker network to facilitate secure inter-container communication without exposing internal ports to the public interface of the VPS.

docker network create security_network

Next, configure Keycloak within your docker-compose.yml. Ensure you use strong environment variables for production environments, utilizing external volumes to persist the database state.

Step 2: Configuring Keycloak for OAuth2 Proxy

Once Keycloak is operational, access the Admin Console to configure the realm and client:

  1. Create a new Realm (e.g., Enterprise-API).
  2. Navigate to Clients and create a new client named oauth2-proxy.
  3. Set the Client Authentication toggle to On (confidential client).
  4. Configure the Valid Redirect URIs to match your proxy domain: [https://api.yourdomain.com/oauth2/callback](https://api.yourdomain.com/oauth2/callback).
  5. Go to the Credentials tab and copy the generated Client Secret. This will be required for the OAuth2 Proxy configuration.

Step 3: Deploying and Configuring OAuth2 Proxy

Now, deploy the OAuth2 Proxy container. This service must be configured with the OIDC provider URL pointing to your Keycloak realm, along with the Client ID and Client Secret acquired in the previous step.

The configuration can be managed via environment variables or a dedicated oauth2_proxy.cfg file. Essential parameters include:

  • provider: set to oidc.
  • client_id: set to oauth2-proxy.
  • client_secret: your Keycloak client secret.
  • oidc_issuer_url: the full URL of your Keycloak realm token endpoint.
  • cookie_secret: a secure, random string used to encrypt session cookies.

Step 4: Upstream API Protection

Conclude the deployment by configuring your reverse proxy (e.g., Nginx) to enforce authentication via the OAuth2 Proxy module using the auth_request directive. This ensures that any incoming request targeting your API endpoints (e.g., /api/v1/data) is verified before Nginx routes the traffic to the corresponding Docker container container backend.

Best Practices for Production Environments

Deploying advanced security infrastructure on a VPS requires careful attention to maintenance and hardening. Implement the following best practices to maximize resilience:

  • Enforce HTTPS/TLS: Never transmit authentication tokens over unencrypted HTTP channels. Utilize Let's Encrypt to automate SSL/TLS certificates across your entire domain structure.
  • Token Expiration and Rotation: Configure brief lifetimes for Access Tokens within Keycloak while relying on secure Refresh Tokens to sustain legitimate user sessions seamlessly.
  • Rate Limiting: Protect both Keycloak and your OAuth2 Proxy endpoints from brute-force and Distributed Denial of Service (DDoS) attacks by implementing rate-limiting policies at the edge proxy level.
  • Regular Security Patches: Ensure your Docker images for Keycloak and OAuth2 Proxy are routinely updated to patch newly discovered vulnerabilities.

Conclusion

Securing API endpoints in a containerized VPS environment does not require adding architectural complexity directly into your application code. By integrating OAuth2 Proxy with Keycloak, you create a robust, scalable, and standardized perimeter defense. This framework shields your Docker containers from unauthorized traffic, enforces enterprise-grade identity management, and allows your engineering teams to focus strictly on building core business features with peace of mind.

Advanced API Security: Integrating OAuth2 Proxy with Keycloak to Protect Docker Container Endpoints on a VPS | DPTCloud