realmlint

Keycloak fixes

Keycloak fix · high

"You are logged in as a temporary admin user": replacing Keycloak's bootstrap admin

Keycloak 26 creates a temporary admin on first start and asks you to replace it. Here is how to create a permanent admin with a second factor and delete the temporary one safely.

realmlint check temporary-admin-presentKeycloak 26Updated

Since Keycloak 26, the admin console shows a banner on the master realm: You are logged in as a temporary admin user. To harden security, create a permanent admin account and delete the temporary one. Many instances never do. This article walks through the replacement without locking yourself out.

What realmlint reports

  HIGH      Temporary bootstrap admin still exists [temporary-admin-present]
            - user "admin": temporary bootstrap admin account is still present
  HIGH      Admin account has no second factor [admin-without-mfa]
            - user "admin": admin user has no OTP or WebAuthn credential

The two usually appear together. realmlint needs a full export that includes users, made with kc.sh export; the admin console's partial export leaves users out.

Why it matters

Keycloak creates the first admin from the KC_BOOTSTRAP_ADMIN_USERNAME and KC_BOOTSTRAP_ADMIN_PASSWORD environment variables and marks it as temporary. In practice the username is often admin, and the password sits in a Docker Compose file, a Helm values file or a CI variable that several people can read. That account has full control of the master realm, and through it every other realm.

Replace it

Do this while logged in as the temporary admin, in the master realm.

  1. Go to Users and click Add user. Use a personal username, not admin, and your email address. Click Create.
  2. On the new user's Credentials tab, click Set password. Turn Temporary off and save.
  3. On the Role mapping tab, click Assign role, choose Filter by realm roles, select admin and click Assign.
  4. On the Details tab, add Configure OTP to Required user actions and save. You will be asked to set up an authenticator app at your next login.
  5. Sign out, then sign in to the admin console as the new user and complete the OTP setup.
  6. Check that you can open another realm and change a setting. Only then go on.
  7. Go to Users, open the temporary admin, and use the action menu to Delete user.

Finally, remove KC_BOOTSTRAP_ADMIN_USERNAME and KC_BOOTSTRAP_ADMIN_PASSWORD from your deployment files, and rotate wherever that password was stored. Keycloak only uses them to create the first admin, so they do nothing useful once a permanent admin exists.

Locked out? Keycloak 26 can create a new temporary admin from the command line with kc.sh bootstrap-admin user, run against the same database. Use it, then repeat the steps above.

Check it worked

kc.sh export --realm master --file master.json
realmlint check master.json

Both temporary-admin-present and admin-without-mfa should be gone. If admin-without-mfa remains for other admins, ask them to add OTP or a security key in the same way.