Customize Themes
Keycloak themes control the look and feel of the login page, account console, admin console, and email templates. This guide covers customizing themes in a Kubernetes Operator-managed deployment.
TOC
Theme TypesSelect a ThemeCreate a Custom ThemeTheme Directory Structuretheme.propertiesCustom CSS ExampleOverride Text LabelsDeploy Themes in KubernetesOption A: Custom Keycloak Image (Recommended for Production)Option B: ConfigMap (Development and Testing Only)Customize Email TemplatesOverride an Email TemplateEmail Message CustomizationInternationalization (i18n)Theme Types
Select a Theme
To switch between built-in themes:
- In the Admin Console, go to Realm Settings > Themes tab.
- Select the desired theme for each type (Login, Account, Admin, Email).
- Click Save.
Built-in themes include keycloak (default) and keycloak.v2 (for the new account console).
Create a Custom Theme
A custom theme is a directory (or JAR archive) containing the files that override or extend a base theme.
Theme Directory Structure
theme.properties
Custom CSS Example
Create resources/css/custom.css:
Override Text Labels
Create messages/messages_en.properties:
Deploy Themes in Kubernetes
In a Kubernetes Operator-managed deployment, custom themes must be made available to the Keycloak Pods. The recommended approach is to build a custom container image. A ConfigMap-based alternative exists for development and testing only.
Option A: Custom Keycloak Image (Recommended for Production)
Build a custom container image with the theme pre-installed:
Build and push the image:
Update the Keycloak CR to use the custom image:
When using a custom image, you must include all required build-time options (such as --health-enabled=true and --metrics-enabled=true) in the kc.sh build command inside the Dockerfile. Build-time options specified via additionalOptions in the Keycloak CR are ignored when a pre-built custom image is used, because the Operator does not re-run the build step.
You must also rebuild and redeploy the image whenever Keycloak is upgraded to a new version. Ensure your CI/CD pipeline includes this step.
Option B: ConfigMap (Development and Testing Only)
For quick iteration during development, you can mount a theme via ConfigMap and the unsupported.podTemplate field:
-
Package the theme directory into a ConfigMap:
-
Mount the ConfigMap into the Keycloak Pod via the
KeycloakCR: -
Apply the updated CR and wait for Pods to restart.
-
In the Admin Console, go to Realm Settings > Themes and select
my-custom-theme.
This approach uses the unsupported.podTemplate field, which is not part of the stable Keycloak Operator API. It may change or be removed in future versions without notice. Additionally:
- ConfigMaps have a 1 MiB size limit, which may not accommodate themes with images.
- The
unsupportedfield is not covered by standard support and upgrade compatibility guarantees. - Rolling updates may temporarily cause Pods with mismatched theme versions.
For production deployments, always use the custom image approach (Option A).
Customize Email Templates
Email templates use FreeMarker (.ftl) syntax and are part of the email theme type.
Override an Email Template
- In your custom theme, create
email/html/andemail/text/directories. - Copy the template you want to customize from the default theme.
- Modify the template content.
Common email templates:
Email Message Customization
Override email subject lines and body text in messages/messages_en.properties:
Internationalization (i18n)
Keycloak themes support multiple languages via message properties files.
- Enable internationalization in Realm Settings > Localization tab.
- Add supported locales.
- In your custom theme, create message files for each locale:
messages/messages_en.propertiesmessages/messages_zh_CN.propertiesmessages/messages_ja.properties
- Set the default locale in the Realm settings.