Concerns about Exposure of Keycloak API Endpoints (e.g., TLS Certificate Revocation)

Is it possible to restrict the exposure of Keycloak’s TLS certificate revocation endpoints and other potentially sensitive API endpoints to prevent public access? If so, what are the recommended configurations or best practices to secure these endpoints without impacting system functionality?