# Best practice for securing the admin console

**URL:** <https://forum.keycloak.org/t/best-practice-for-securing-the-admin-console/2732>\
**Category:** Miscellanaeous\
**Created:** [May 14, 2020, 10:57am UTC](https://forum.keycloak.org/t/best-practice-for-securing-the-admin-console/2732 "2020-05-14T10:57:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cubestephen](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@cubestephen](https://forum.keycloak.org/u/cubestephen)\
**Post date:** [May 14, 2020, 10:57am UTC](https://forum.keycloak.org/t/best-practice-for-securing-the-admin-console/2732/1 "2020-05-14T10:57:26Z")

</div>

We would like to use the jboss\keycloak docker image in production deployment. What is best practice to ensure that the admin console is accessible for support and management but not accessible publicly?

---

<div class="post-metadata">

**Author:** ![jangaraj](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jangaraj/32/5175_2.png) [@jangaraj](https://forum.keycloak.org/u/jangaraj)\
**Post date:** [May 14, 2020, 1:03pm UTC](https://forum.keycloak.org/t/best-practice-for-securing-the-admin-console/2732/2 "2020-05-14T13:03:38Z")

</div>

Use reverse proxy in front of Keycloak service and use custom “routing” for `/auth/admin/` path. E.g. enable proxying for intranet network and deny access for the rest of networks. Of course you may use also another options: mutual TLS, basic auth, …
