KON-618 HowToRun
diff --git a/deploy/keycloak/addKeycloakUsersCDB.sh b/deploy/keycloak/addKeycloakUsersCDB.sh
new file mode 100644
index 0000000..b2618ae
--- /dev/null
+++ b/deploy/keycloak/addKeycloakUsersCDB.sh
@@ -0,0 +1,54 @@
+#!/bin/sh
+echo ------- Login Keycloak -------
+sh kcadm.sh config credentials --server http://localhost:8380/auth --realm master --user admin --password admin
+realmVar="OpenKRealm"
+# ***************** CREATING NEW USER *****************
+usernameVar="finia_r"
+echo ------- Creating User: $usernameVar -------
+sh kcadm.sh create users -s username=$usernameVar -s firstName=Finia -s lastName=Reader  -s enabled=true -r $realmVar
+sh kcadm.sh set-password -r $realmVar --username $usernameVar --new-password $usernameVar
+echo pwd set
+sh kcadm.sh add-roles --uusername $usernameVar --rolename kon-access --rolename kon-reader -r $realmVar
+echo roles set
+# ***************** CREATING NEW USER *****************
+usernameVar="emilia_w"
+echo ------- Creating User: $usernameVar -------
+sh kcadm.sh create users -s username=$usernameVar -s firstName=Emilia -s lastName=Writer  -s enabled=true -r $realmVar
+sh kcadm.sh set-password -r $realmVar --username $usernameVar --new-password $usernameVar
+echo pwd set
+sh kcadm.sh add-roles --uusername $usernameVar --rolename kon-access --rolename kon-writer -r $realmVar
+echo roles set
+# ***************** CREATING NEW USER *****************
+usernameVar="lea_a"
+echo ------- Creating User: $usernameVar -------
+sh kcadm.sh create users -s username=$usernameVar -s firstName=Lea -s lastName=Admin  -s enabled=true -r $realmVar
+sh kcadm.sh set-password -r $realmVar --username $usernameVar --new-password $usernameVar
+echo pwd set
+sh kcadm.sh add-roles --uusername $usernameVar --rolename kon-access --rolename kon-admin -r $realmVar
+echo roles set
+# ***************** CREATING NEW USER *****************
+usernameVar="leon_r"
+echo ------- Creating User: $usernameVar -------
+sh kcadm.sh create users -s username=$usernameVar -s firstName=Leon -s lastName=Reader  -s enabled=true -r $realmVar
+sh kcadm.sh set-password -r $realmVar --username $usernameVar --new-password $usernameVar
+echo pwd set
+sh kcadm.sh add-roles --uusername $usernameVar --rolename kon-access --rolename kon-reader -r $realmVar
+echo roles set
+# ***************** CREATING NEW USER *****************
+usernameVar="david_w"
+echo ------- Creating User: $usernameVar -------
+sh kcadm.sh create users -s username=$usernameVar -s firstName=David -s lastName=Writer  -s enabled=true -r $realmVar
+sh kcadm.sh set-password -r $realmVar --username $usernameVar --new-password $usernameVar
+echo pwd set
+sh kcadm.sh add-roles --uusername $usernameVar --rolename kon-access --rolename kon-writer -r $realmVar
+echo roles set
+# ***************** CREATING NEW USER *****************
+usernameVar="anton_a"
+echo ------- Creating User: $usernameVar -------
+sh kcadm.sh create users -s username=$usernameVar -s firstName=Anton -s lastName=Admin  -s enabled=true -r $realmVar
+sh kcadm.sh set-password -r $realmVar --username $usernameVar --new-password $usernameVar
+echo pwd set
+sh kcadm.sh add-roles --uusername $usernameVar --rolename kon-access --rolename kon-admin -r $realmVar
+echo roles set
+
+echo ------- Finished -------
diff --git a/src/main/asciidoc/howto/howtoRun.adoc b/src/main/asciidoc/howto/howtoRun.adoc
index 6ab858a..c703116 100644
--- a/src/main/asciidoc/howto/howtoRun.adoc
+++ b/src/main/asciidoc/howto/howtoRun.adoc
@@ -18,6 +18,19 @@
 
 * *To see this application running you have to run Portal application too.* The reason is the authentication, which happened in the Portal login phase.
 
+== Configure Keycloak
+Login into your Keycloak Admin Console and add the following Roles:
+
+* kon-access
+* kon-admin
+* kon-reader
+* kon-writer
+
+* Option 1: Add/Edit users manually to/in Keycloak (see *Portal (Auth n Auth)* documents (not included here)) with the according roles.
+* Option 2: You can also use the  `deploy/keycloak/addKeycloakUsersCDB.sh` script to add users. Adjust the script accordingly.
+The script has to be copied and executed within the bin folder of the Keycloak installation `[keycloakRootFolder]/bin`.
+
+
 == Install and configure Apache Tomcat
 Tomcat is an open-source Java Servlet Container and provides a "pure Java" HTTP web server environment in which Java code can run.