Documentation

Development

User Acquisition

Monetization

Industry

Self-Hosted Deployment

Amazon Web Services

Microsoft Azure

On premises

vpctl

Self-Hosted Deployment

​
​
Self-Hosted Deployment
  • Overview
  • Amazon Web Services
  • Microsoft Azure
  • On premises
  • Administration
    • Access the Keycloak admin console
    • Complete initial solution onboarding
    • Single sign-on
    • Organizations and projects
    • Users and service accounts
    • Groups
    • Licensing
    • upc-cli tool
    • Custom branding
  • Security
  • vpctl
  1. Self-Hosted Deployment (previously called Unity Virtual Private Cloud)
  2. Administration

Access the Keycloak admin console

Manage identity in Self-Hosted Deployment from Keycloak
Read time 1 minute
Last updated a month ago

About Keycloak

Unity Virtual Private Cloud includes an identity provider and broker component based on Keycloak. Keycloak includes these major capabilities:
  • Authentication and authorization
  • Storage of information about users and service accounts keys
Keycloak is included in the above deployment, but you must perform customer-specific postdeployment and administration tasks.

Access Keycloak from Amazon Web Services (AWS)

To access the Keycloak admin console from a browser, enter a URL in this format:
https://<domain_name>/auth/admin/master/console/
The default user is admin. To retrieve the password, run this command:
kubectl get -n asset-solutions secret keycloak -o jsonpath="{.data.admin-password}" | base64 --decode
When you sign in for the first time, change the default admin credentials.

Access Keycloak from Microsoft Azure

In Keycloak, the predefined unity realm stores all the settings and objects that are related to Virtual Private Cloud. When you open the Keycloak admin console, switch to the unity realm.

Access the admin console

To access the Keycloak admin console from a browser, enter a URL in the following format:
https://<SolutionFQDN>/auth/admin
Replace
<SolutionFQDN>
with your solution's fully qualified domain name (FQDN).

Retrieve initial admin password

The initial administrator username is
admin
. Azure generates the password during deployment. Retrieve the password from the solution key vault. The key vault is in the solution managed resource group, and the secret name is
kc-admin-password
.
To access secrets in the key vault, an administrator might require to perform these tasks:
  • Grant the Key Vault Administrator role to themselves, because the Owner role doesn't provide access to the Key Vault data plane
  • Temporarily allow access to the key vault over the internet
    By default, public access for this key vault is made unavailable. The recommended practice is to restrict this access to the IPs of specific administrators, in the key vault firewall settings, and, if possible, permanently.

Manage administrative access

Optionally, in the master realm, perform these actions:
  1. Change the password for the
    admin
    user.
    The recommended practice is to keep the password up-to-date in the key vault.
  2. Add the administrative users, as personal accounts for specific solution administrators.
To perform other changes that are related to Virtual Private Cloud settings, go to the unity realm.

Change the default admin credentials

The keycloak admin credentials are static and aren't tied to any identity provider.
When you sign in for the first time, change the default admin credentials:
  1. In the Keycloak admin console, switch to the default realm, that is, the master realm.
  2. Go to Users, and then select the
    admin
    user.
  3. On the Credentials tab, select Reset password.
  4. Enter a new password.
  5. Turn off Temporary.
  6. Record the credentials somewhere secure.

Copyright © 2026 Unity Technologies
LegalPrivacy PolicyCookiesDocumentation Terms of UseDo Not Sell or Share My Personal InformationYour Privacy Choices (Cookie Settings)

"Unity", Unity logos, and other Unity trademarks are trademarks or registered trademarks of Unity Technologies or its affiliates in the U.S and elsewhere (more info here). Other names or brands are trademarks of their respective owners.

Some pages are machine-translated for convenience, and may contain inaccuracies. In the event of conflicting information, the English version is authoritative.

  • On this page
    • About Keycloak

    • Access Keycloak from Amazon Web Services (AWS)

    • Access Keycloak from Microsoft Azure

      • Access the admin console

      • Retrieve initial admin password

      • Manage administrative access

    • Change the default admin credentials


Report a problem with this page
​
​