Identity
Made in Germany

Identity and access as part of your certified hosting – ayedo operates ayedo ID for ayedo Cloud services or Dedicated Keycloak in the Platform Cluster, with expert support from Germany.

Made in Germany ISO 27001 ISO 9001 DSGVO-konform DORA Compliant 24/7 Support
UDSVolkswagenLiebherrT-SystemsVendureecoConnextPortainerUelzener VersicherungenFJDDWTOCCReiner SCTCyrus IndustrialDGSIEMnanocosmosSplixSchwarzgruppeINHHadesHiOrg-Serverown3dTikfinityProgram51Buben & MädchenPrime InsightsTELTECElevantiqMoovitCFToolsStadt KölnVivavisAvemio

Control identities centrally

Our identity service is based on Keycloak in the Platform Cluster – SSO without months of in-house build-out, predictable costs per realm, and one identity path instead of parallel user databases in every app. ayedo takes over operations and availability, including OIDC/SAML and LDAP or Active Directory integration.

ayedo ID

Identity provider for ayedo Cloud

The multi-tenant Keycloak of ayedo Cloud authenticates your users to GitLab, Argo CD, Harbor, OpenBao, Grafana, and other ayedo Cloud services. A single login covers all shared services.

ayedo IDSSOayedo Cloud

Separate realm

Dedicated capabilities on shared infrastructure

A separate realm for your business applications and end-customer user management provides login, roles, and MFA – fully isolated from the ayedo ID realm of the platform services.

RealmAppsEnd customers

Single Sign-On

OIDC & SAML

Modern protocols enable sign-in for applications, cluster access via kubelogin, and federation to Entra ID, Google, or existing identity providers.

OIDCSAMLFederation

MFA & Policies

Strong authentication

TOTP, WebAuthn, and fine-grained realm and client policies form the foundation for zero-trust architectures and audit requirements.

MFAWebAuthnPolicies

Directory integration

LDAP / Active Directory

Connect your existing user directories and use identities, groups, and roles centrally for SSO and access control.

LDAPADGroups

Kubernetes & Apps

One shared identity path

Cluster OIDC, managed apps, and business applications share the same identities. Parallel user databases become unnecessary.

K8sOIDCRBAC

EU infrastructure

Sovereign hosting

Your identity data resides on European infrastructure – GDPR-compliant and without dependency on US cloud providers for your identity provider.

EUGDPRSovereignty

Pricing – separate realm

Billing is user-based per separate realm on ayedo Cloud. A separate realm is suitable for business-application login, end-customer user management, and additional clients – functionally comparable to a dedicated instance, operated on shared infrastructure.

up to 250 users

Separate realm · ayedo Cloud
  • €99.95/month for up to 250 users in the realm

  • Your own, isolated realm

  • Login for your business applications and end customers

  • OIDC/SAML clients, MFA, and standard policies

  • Operated in the central Platform Cluster

  • ayedo ID for the platform services remains separate

up to 500 users

Separate realm · ayedo Cloud
  • €199.95/month for up to 500 users in the realm

  • Your own, isolated realm

  • Login for your business applications and end customers

  • OIDC/SAML clients, MFA, and standard policies

  • Operated in the central Platform Cluster

  • ayedo ID for the platform services remains separate

More isolation when needed

When a separate realm on shared infrastructure is not sufficient, you can choose a dedicated Keycloak instance or operation on your own infrastructure.

Dedicated

Dedicated Keycloak · Single-tenant
  • Your own Keycloak in a dedicated Platform Cluster

  • Isolated realms and clients exclusively for your organization

  • Custom themes & flows

  • LDAP/AD and enterprise federation

  • Custom SLAs

BYOC / On-Premises

On your infrastructure
  • Keycloak on your cloud or on-premises

  • Air-gapped support available

  • Integration with your existing identity provider landscape

  • Enterprise support

  • Compliance-ready

  • Custom SLAs

Compare with alternatives

Managed Keycloak on ayedo is a sovereign, European option compared to established identity services. The following overview presents the key differences objectively.

vs. Okta

Criterion ayedo Okta
Jurisdiction EU / GDPR-compliant US / Cloud Act
ayedo Cloud integration Native to ayedo Cloud services Extra integrations
On-premises / BYOC Available Cloud-first
Support Personal support in German and English Primarily ticket-based

vs. Microsoft Entra ID

Criterion ayedo Microsoft Entra ID
Vendor lock-in Open-source Keycloak Microsoft ecosystem
Kubernetes Cluster OIDC integrated Extra configuration
Multi-cloud Cloud-agnostic Azure-focused
Data residency EU hosting selectable Depends on the tenant region

vs. Auth0

Criterion ayedo Auth0
Jurisdiction EU hosting US company
Self-hosted Dedicated & BYOC SaaS-focused
Platform SSO One identity provider for ayedo Cloud Integration per application
Pricing model User-based per realm MAU-based pricing tiers

Compliance & regulatorische Anforderungen

Die ayedo Software Delivery Platform erfüllt die Anforderungen aktueller EU-Verordnungen. Von GDPR über NIS-2 bis DORA – designed für regulierte Branchen und kritische Infrastrukturen.

GDPR-konforme Datenverarbeitung

Privacy by Design & Default.

EU-Datenhaltung (Deutschland), Customer-Managed Keys (BYOK/BYOHSM), Verschlüsselung at rest/in transit. ISO 27001-zertifiziertes Datenschutz-Management. Mehr zur GDPR.

NIS-2-konformer Betrieb

Resilienz für kritische Infrastrukturen.

24/7 Monitoring, Incident-Response, BCP/DR-Prozesse, Supply-Chain-Transparenz (SBOM). Mehr zu NIS-2.

DORA-ready für Finanzinstitute

IKT-Resilienz nach Maß.

IKT-Risikomanagement, dokumentierte Exit-Strategien, Drittpartei-Risiko-Management, TLPT-Readiness. Mehr zu DORA.

CRA-konforme Software Supply Chain

Security by Design über den gesamten Lifecycle.

SBOM-Generation, CVE-Scanning, signierte Container-Images, GitOps-basierte Audit-Trails. Mehr zum CRA.

Cloud Sovereignty Framework

Digitale Souveränität messbar gemacht.

EU-basierte Operations, offene Standards, Exit-Fähigkeit ohne Lock-in. Mehr zum Framework.

Data Act-konforme Portabilität

Switching ohne Hürden.

Offene APIs, standardisierte Formate, vollständige Exit-Runbooks. Mehr zum Data Act.

Integrierte Compliance-Roadmap

Ganzheitlicher Ansatz.

Wie ayedo GDPR, NIS-2, DORA, CRA, Data Act und ISO 27001/9001 systematisch adressiert. Zur Übersicht.

Part of the Software Delivery Platform

Identity is the shared authentication layer for Platform, Code Repository, Delivery, Container Registry, Secrets Management, and Observability.

Platform

Big picture

Get an overview of the platform cluster, the operating models, and all building blocks of the Software Delivery Platform (SDP).

SDPOverview

Managed Kubernetes

Cluster OIDC

Secure your workload clusters against the same identity provider – for consistent identities from the platform to the application.

KubernetesOIDC

Keycloak App

Managed app in detail

You can find the technical specification and block reference on the page of the Keycloak managed app.

KeycloakManaged App

Documentation

Access control

Further documentation on identity provider and OIDC topics is available at docs.ayedo.de.

DocsOIDC

You build it. We run it.

Excellent performance and maximum uptime - that's what we wake up for. And sometimes even in the middle of the night.

100+ clusters

under Management

We operate more than 100 Kubernetes clusters in production for our customers.

300+ databases

under Management

We operate, monitor, and protect more than 300 production databases.

1 Petabyte Object-Storage

under Management

We operate one petabyte of object storage for backups, artifacts, and application data.

100 million timeseries

on average

Our monitoring systems ingest 4 million datapoints per second.

38.000+ Logs

per second

Our collectors capture logs continuously and store them GDPR-compliant — over 100 billion entries per month.

5.000+ Backups

per day

We write more than 5,000 backups every day to encrypted long-term storage — about 150 terabytes of backup volume per month.

270 million end users

per month

More than 9 million end users use software we operate every day, on the internet or on-premises.

99,99% Uptime

annual average

Our managed services are unavailable for less than one hour per year on average.

MTTD < 5 minutes

on average

Our alerting typically detects faults and outages within a few minutes.

Frequently asked questions

Answers to common questions about ayedo ID, Dedicated Keycloak, and identity in the context of the Software Delivery Platform.

What is the difference between ayedo ID, a separate realm, and Dedicated Keycloak?

ayedo ID authenticates users to the ayedo Cloud services (GitLab, Argo CD, Harbor, OpenBao, Grafana, and more). A separate realm on ayedo Cloud is priced per user and covers business applications, end-customer login, and user management – functionally comparable to a dedicated instance, but operated on shared infrastructure. Dedicated Keycloak is your own Keycloak instance in a dedicated platform cluster, offering maximum isolation, custom themes, federations, and custom SLAs.

What is a separate realm used for?

A separate realm is suitable for login to your business applications, end-customer user management, additional OIDC/SAML clients, and multi-tenant scenarios – fully separated from the ayedo ID realm of the platform services. Pricing: €49.95 up to 100 users, €99.95 up to 250 users, €199.95 up to 500 users – each per month and realm.

Do business applications need to use the same IdP?

We recommend it, as this avoids parallel user databases. Business applications can receive their own clients in your separate realm or be connected via federation. SSO for the platform services continues to run via ayedo ID.

Can we connect our existing Active Directory?

Yes. Integration works via LDAP/AD user federation or as an identity broker (OIDC/SAML) to Entra ID and other identity providers. This scenario is typical for Dedicated and BYOC/on-premises environments.

Why identity from day one?

Without a well-considered identity concept, local user accounts accumulate in every application on the platform. Consolidating them later is considerably more effort than establishing a clean OIDC path when rolling out the Software Delivery Platform.