{ ... }:
{
  services.keycloak = {
    enable = true;
    settings = {
      hostname = "id.nekover.se";
      hostname-admin = "keycloak-admin.nekover.se";
      hostname-strict-backchannel = true;
      proxy = "edge";
      http-host = "127.0.0.1";
      http-port = 8080;
    };
    database.passwordFile = "/secrets/keycloak-database-password.secret";
  };
}