Just remember that properly upgrading Keycloak without downtime is nearly impossible without booting up a second instance on a clone of your database and moving traffic over there, so if you have anything that needs to work 24/7, wait for HA upgrades feature that's supposedly coming soon.
If you're using a common web framework, there's almost certainly packages/plugins that will manage SSO and 2fa, and despite the constant fud, dealing with user accounts really isn't all that hard. More importantly, understanding the mechanics of your user account system will pay dividends as your product grows and new authN/Z requirements arise.
Okta works really well in your use case. I recommend trying it out yourself.
Since you mention YubiKeys, I’d also suggest that you try removing passwords from your setup entirely by using YubiKeys and one or more other factors.
If you don’t want to use Okta, I’m also happy to give you my take on the alternatives to consider. Feel free to reach out to me directly.