Generally, all self-hosting docs are in the self-hosting section of the docs: https://www.ory.sh/docs/ecosystem/projects
Ory Kratos does not do everything that we offer in the managed service. In particular the admin UI is not available (but the APIs and business logic are!), and the things we built around multi-region and multi-tenancy are not available in the open source self-hosted version.
> Any reason to pick this over keycloak?
Keycloak is an awesome open-source project! I never used Keycloak myself in a large production system. Here is a bit of feedback we hear from users who approach us. Keycloak
- is great for small-to-medium user bases (e.g. for employee management which it was originally designed for) but has issues when scaling to millions of users / customer-facing
- has a larger footprint due to Java
- has no managed service
- is tied to IBM (can be both good and bad, as we see with the RHEL changes. Can happen to any project though)
Generally speaking, Ory is more componetized and domain driven. If you don't want OAuth2, you don't need it. If you only want OAuth2, you don't need to also use sign in from Ory. And so on!
There's probably more differences but I think others with operational Keycloak experience can answer this better than me.
Generally speaking, both projects have their place. If you're looking more for web-based customer identity management I would go in Ory's direction. If it's about enterprise employee management, Keycloak is an easier plug-and-play solution.