Skip to content

fix(keycloak): keep warm DB connections in production - #331

Merged
mahdi2ba merged 1 commit into
Greenstand:masterfrom
mahdi2ba:fix/prod-keycloak-db-pool
Oct 6, 2026
Merged

mahdi2ba merged 1 commit into
Greenstand:masterfrom
mahdi2ba:fix/prod-keycloak-db-pool

Conversation

@mahdi2ba

@mahdi2ba mahdi2ba commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Prod Keycloak logs "Acquisition timeout while waiting for new connection" several times a day since 4 Oct, mostly on cleanup tasks, once on a login.

Cause: Keycloak keeps no idle connection, so each task or login opens a new one (DNS, TLS, auth) inside the 5 s acquisition timeout, and prod cluster DNS sometimes answers late.

Fix: keep 5 connections open.

  • KC_DB_POOL_INITIAL_SIZE=5, KC_DB_POOL_MIN_SIZE=5, KC_DB_POOL_MAX_SIZE=20
  • image pinned to dadiorchen/keycloak:1.5, the one running in prod today, so applying the overlay does not upgrade it by accident

…uction

Prod Keycloak logs 'Acquisition timeout while waiting for new connection'
several times a day since 2026-10-04 (scheduled tasks, once on a login).
Prod CoreDNS shows intermittent upstream i/o timeouts, including for the
database host, and Keycloak had no minimum pool size, so every idle task or
login had to resolve DNS and open a new TLS connection inside the 5 s
acquisition timeout.

- KC_DB_POOL_INITIAL_SIZE=5, KC_DB_POOL_MIN_SIZE=5, KC_DB_POOL_MAX_SIZE=20
- image pinned to dadiorchen/keycloak:1.5, which is what runs in prod today
  (the base says mohmin/keycloak-23; the upgrade stays a separate step)

kubectl diff against prod shows only the three env vars as a change.
@mahdi2ba
mahdi2ba requested a review from dadiorchen October 5, 2026 19:42
@mahdi2ba
mahdi2ba merged commit c49f067 into Greenstand:master Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants