update crds
This commit is contained in:
@@ -0,0 +1,297 @@
|
||||
{
|
||||
"description": "ClusterKeycloakInstance makes a Keycloak server known to the operator at the cluster level",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "ClusterKeycloakInstanceSpec defines the desired state of ClusterKeycloakInstance.\nIt mirrors KeycloakInstanceSpec but is cluster-scoped: secret references must\nspecify a namespace explicitly.",
|
||||
"properties": {
|
||||
"auth": {
|
||||
"description": "Auth selects how the operator authenticates to Keycloak.\nExactly one of auth.passwordGrant or auth.clientCredentials must be set.",
|
||||
"properties": {
|
||||
"clientCredentials": {
|
||||
"description": "ClusterClientCredentialsSpec configures OAuth2 client_credentials\nauthentication for cluster-scoped instances.",
|
||||
"properties": {
|
||||
"clientId": {
|
||||
"description": "ClientID, when set, overrides secretRef.clientIdKey.",
|
||||
"type": "string"
|
||||
},
|
||||
"secretRef": {
|
||||
"description": "ClusterClientCredentialsSecretRefSpec references a client-credentials Secret.\nNamespace is required because the resource is cluster-scoped.",
|
||||
"properties": {
|
||||
"clientIdKey": {
|
||||
"default": "client-id",
|
||||
"type": "string"
|
||||
},
|
||||
"clientSecretKey": {
|
||||
"default": "client-secret",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"namespace"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretRef"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"passwordGrant": {
|
||||
"description": "ClusterPasswordGrantSpec configures password-grant authentication\nfor cluster-scoped instances.",
|
||||
"properties": {
|
||||
"secretRef": {
|
||||
"description": "ClusterPasswordGrantSecretRefSpec references an admin-credentials Secret.\nNamespace is required because the resource is cluster-scoped.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"type": "string"
|
||||
},
|
||||
"passwordKey": {
|
||||
"default": "password",
|
||||
"type": "string"
|
||||
},
|
||||
"usernameKey": {
|
||||
"default": "username",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"namespace"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"username": {
|
||||
"description": "Username, when set, overrides secretRef.usernameKey.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretRef"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of auth.passwordGrant or auth.clientCredentials must be set",
|
||||
"rule": "has(self.passwordGrant) != has(self.clientCredentials)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"baseUrl": {
|
||||
"description": "BaseUrl is the URL of the Keycloak server (e.g., http://keycloak:8080)",
|
||||
"type": "string"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm is the admin realm (defaults to \"master\")",
|
||||
"type": "string"
|
||||
},
|
||||
"tls": {
|
||||
"description": "TLS configures how the operator verifies the Keycloak server certificate.",
|
||||
"properties": {
|
||||
"caCert": {
|
||||
"description": "ClusterCACertSource references a Secret or ConfigMap key containing a\nPEM-encoded CA bundle. Exactly one of secretRef or configMapRef must be set.",
|
||||
"properties": {
|
||||
"configMapRef": {
|
||||
"description": "ClusterCACertConfigMapRefSpec is the cluster-scoped variant; namespace required.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"default": "ca.crt",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"namespace"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"secretRef": {
|
||||
"description": "ClusterCACertSecretRefSpec is the cluster-scoped variant; namespace required.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"default": "ca.crt",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"namespace"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of caCert.secretRef or caCert.configMapRef must be set",
|
||||
"rule": "has(self.secretRef) != has(self.configMapRef)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"insecureSkipVerify": {
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"token": {
|
||||
"description": "Token contains optional token caching configuration",
|
||||
"properties": {
|
||||
"expiresKey": {
|
||||
"description": "ExpiresKey is the key in the secret for the token expiration",
|
||||
"type": "string"
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the secret to cache the token",
|
||||
"type": "string"
|
||||
},
|
||||
"tokenKey": {
|
||||
"description": "TokenKey is the key in the secret for the token",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"auth",
|
||||
"baseUrl"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "ClusterKeycloakInstanceStatus defines the observed state of ClusterKeycloakInstance",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information about the status",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the Keycloak instance is accessible",
|
||||
"type": "boolean"
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the API path for this resource",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
},
|
||||
"version": {
|
||||
"description": "Version is the Keycloak server version",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,199 @@
|
||||
{
|
||||
"description": "ClusterKeycloakRealm defines a realm within a KeycloakInstance at the cluster level",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "ClusterKeycloakRealmSpec defines the desired state of ClusterKeycloakRealm",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is a reference to a ClusterKeycloakInstance\nOne of instanceRef or clusterInstanceRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RealmRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is a reference to a namespaced KeycloakInstance\nOne of instanceRef or clusterInstanceRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"namespace"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmName": {
|
||||
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)",
|
||||
"type": "string"
|
||||
},
|
||||
"smtpSecretRef": {
|
||||
"description": "SmtpSecretRef is a reference to a Kubernetes Secret containing SMTP credentials.\nWhen set, the secret values are injected into definition.smtpServer.user and\ndefinition.smtpServer.password before syncing to Keycloak.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the Kubernetes Secret (required for cluster-scoped resources)",
|
||||
"type": "string"
|
||||
},
|
||||
"passwordKey": {
|
||||
"default": "password",
|
||||
"description": "PasswordKey is the key in the secret for the SMTP password (defaults to \"password\")",
|
||||
"type": "string"
|
||||
},
|
||||
"userKey": {
|
||||
"default": "user",
|
||||
"description": "UserKey is the key in the secret for the SMTP username (defaults to \"user\")",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name",
|
||||
"namespace"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "ClusterKeycloakRealmStatus defines the observed state of ClusterKeycloakRealm",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the realm is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realmName": {
|
||||
"description": "RealmName is the actual realm name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this realm",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,199 @@
|
||||
{
|
||||
"description": "KeycloakAuthenticationFlow manages a Keycloak authentication flow.",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakAuthenticationFlowSpec defines the desired state of KeycloakAuthenticationFlow",
|
||||
"properties": {
|
||||
"alias": {
|
||||
"description": "Alias is the unique identifier for this flow within the realm.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm.\nOne of realmRef or clusterRealmRef must be specified.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"description": {
|
||||
"description": "Description is a human-readable description of the flow.",
|
||||
"type": "string"
|
||||
},
|
||||
"executions": {
|
||||
"description": "Executions is the ordered list of executions for this flow as a JSON\narray. Each entry is either a leaf authenticator or a nested sub-flow.\n\nLeaf authenticator (object fields):\n\n authenticator: Keycloak provider ID, e.g. \"auth-cookie\".\n requirement: REQUIRED | ALTERNATIVE | DISABLED | CONDITIONAL.\n authenticatorConfig: optional map[string]string applied to the\n execution after creation.\n\nSub-flow (object fields):\n\n subFlow: { alias, providerId, description? } \u2014 the\n child flow definition. providerId is typically\n \"basic-flow\" or \"form-flow\"; \"form-flow\" is\n required when the children are FormAction\n providers (e.g. registration-user-creation).\n requirement: REQUIRED | ALTERNATIVE | DISABLED | CONDITIONAL.\n executions: ordered list of child executions, recursively\n using the same shape. As a convenience, child\n executions may also be placed inside\n subFlow.executions; if both are present, the\n inline list precedes the sibling list.\n\nNesting depth is unconstrained.",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"providerId": {
|
||||
"description": "ProviderId is the top-level flow type. Keycloak ships with \"basic-flow\"\nand \"client-flow\"; sub-flows may additionally use \"form-flow\".",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm.\nOne of realmRef or clusterRealmRef must be specified.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"alias",
|
||||
"providerId"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakAuthenticationFlowStatus defines the observed state of KeycloakAuthenticationFlow",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations.",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"flowID": {
|
||||
"description": "FlowID is the Keycloak internal ID of the top-level flow.",
|
||||
"type": "string"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference.",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information.",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed.",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the flow is synchronized with Keycloak.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference.",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this flow.",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,213 @@
|
||||
{
|
||||
"description": "KeycloakClient defines a client within a KeycloakRealm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakClientSpec defines the desired state of KeycloakClient",
|
||||
"properties": {
|
||||
"clientId": {
|
||||
"description": "ClientId is the client ID in Keycloak (defaults to metadata.name)",
|
||||
"type": "string"
|
||||
},
|
||||
"clientSecretRef": {
|
||||
"description": "ClientSecretRef configures the Kubernetes Secret for client credentials.\nIf the secret exists, its value is used. If it doesn't exist and Create is true,\nthe operator auto-generates a secret and creates it.\nFor public clients (publicClient: true) the Secret is still materialised\nwhen ClientSecretRef is set, but only contains the client-id key \u2014 there\nis no client_secret to store.",
|
||||
"properties": {
|
||||
"clientIdKey": {
|
||||
"description": "ClientIdKey is the key for the client ID in the secret.\nDefaults to \"client-id\".",
|
||||
"type": "string"
|
||||
},
|
||||
"clientSecretKey": {
|
||||
"description": "ClientSecretKey is the key for the client secret value in the secret.\nDefaults to \"client-secret\".",
|
||||
"type": "string"
|
||||
},
|
||||
"create": {
|
||||
"default": true,
|
||||
"description": "Create determines behavior when the secret doesn't exist.\nIf true (default): auto-generate a secret and create the Secret.\nIf false: error if the secret doesn't exist (strict mode for GitOps).",
|
||||
"type": "boolean"
|
||||
},
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ClientRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakClientStatus defines the observed state of KeycloakClient",
|
||||
"properties": {
|
||||
"clientUUID": {
|
||||
"description": "ClientUUID is the Keycloak internal ID",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the client is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this client",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,176 @@
|
||||
{
|
||||
"description": "KeycloakClientScope defines a client scope within a KeycloakRealm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakClientScopeSpec defines the desired state of KeycloakClientScope",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ClientScopeRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakClientScopeStatus defines the observed state of KeycloakClientScope",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the client scope is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this client scope",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,193 @@
|
||||
{
|
||||
"description": "KeycloakComponent defines a component within a KeycloakRealm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakComponentSpec defines the desired state of KeycloakComponent",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ComponentRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakComponentStatus defines the observed state of KeycloakComponent",
|
||||
"properties": {
|
||||
"componentID": {
|
||||
"description": "ComponentID is the Keycloak internal component ID",
|
||||
"type": "string"
|
||||
},
|
||||
"componentName": {
|
||||
"description": "ComponentName is the component name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"providerType": {
|
||||
"description": "ProviderType is the component provider type",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the component is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this component",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,198 @@
|
||||
{
|
||||
"description": "KeycloakGroup defines a group within a KeycloakRealm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakGroupSpec defines the desired state of KeycloakGroup",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak GroupRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"parentGroupRef": {
|
||||
"description": "ParentGroupRef is a reference to a parent KeycloakGroup (for nested groups)",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakGroupStatus defines the observed state of KeycloakGroup",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"groupID": {
|
||||
"description": "GroupID is the Keycloak internal group ID",
|
||||
"type": "string"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the group is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this group",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,234 @@
|
||||
{
|
||||
"description": "KeycloakIdentityProvider defines an identity provider within a KeycloakRealm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"configSecretRef": {
|
||||
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak IdentityProviderRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"tokenExchange": {
|
||||
"description": "TokenExchange configures fine-grained-authz so that exactly the listed\nclients (and no others) may exchange tokens with this IdP as\n`subject_issuer`. Omit the field to leave token-exchange permissions\nunmanaged (whatever was clicked manually stays). Set to a list (possibly\nempty) to have the operator enable IdP permissions and bind a Client-type\npolicy listing the allowed clients on the `token-exchange` scope\npermission in the realm-management authz resource server.",
|
||||
"properties": {
|
||||
"allowedClients": {
|
||||
"description": "AllowedClients is the list of clientIds (text, not UUIDs) in the same\nrealm as the IdP that are permitted to perform token-exchange against\nthis IdP. An empty list creates a policy that matches no clients,\neffectively denying all (useful as an explicit lockdown). Omitting the\nparent `tokenExchange` field entirely leaves Keycloak permissions\nuntouched.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"allowedClients"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the identity provider is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this identity provider",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
},
|
||||
"tokenExchange": {
|
||||
"description": "TokenExchange contains the observed state of the token-exchange\npermission wiring, populated only when spec.tokenExchange is set.",
|
||||
"properties": {
|
||||
"enabled": {
|
||||
"description": "Enabled reflects whether fine-grained authz permissions are enabled on\nthis IdP in Keycloak.",
|
||||
"type": "boolean"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message carries the last token-exchange reconcile error, if any. Set\nonly when token-exchange reconcile fails \u2014 the parent `status.ready`\nstill reflects the IdP itself, not the TE side.",
|
||||
"type": "string"
|
||||
},
|
||||
"permissionID": {
|
||||
"description": "PermissionID is the ID of the `token-exchange` scope permission auto-\ncreated in the realm-management authz resource server when permissions\nare enabled on this IdP.",
|
||||
"type": "string"
|
||||
},
|
||||
"policyID": {
|
||||
"description": "PolicyID is the ID of the Client-type authz policy managed by the\noperator (carries the AllowedClients list).",
|
||||
"type": "string"
|
||||
},
|
||||
"policyName": {
|
||||
"description": "PolicyName is the name of the managed policy, useful for admins\nlooking the resource up in the Keycloak UI.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,180 @@
|
||||
{
|
||||
"description": "KeycloakIdentityProviderMapper defines a mapper attached to a KeycloakIdentityProvider",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakIdentityProviderMapperSpec defines the desired state of KeycloakIdentityProviderMapper",
|
||||
"properties": {
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak IdentityProviderMapperRepresentation.\nThe identityProviderAlias field is auto-injected from the parent\nKeycloakIdentityProvider at reconcile time and does not need to be set\nhere.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"identityProviderRef": {
|
||||
"description": "IdentityProviderRef is a reference to a KeycloakIdentityProvider that owns\nthis mapper. The realm and Keycloak instance are derived from the parent\nidentity provider.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition",
|
||||
"identityProviderRef"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakIdentityProviderMapperStatus defines the observed state of KeycloakIdentityProviderMapper",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"identityProviderAlias": {
|
||||
"description": "IdentityProviderAlias is the alias of the parent identity provider",
|
||||
"type": "string"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"mapperID": {
|
||||
"description": "MapperID is the Keycloak internal mapper ID",
|
||||
"type": "string"
|
||||
},
|
||||
"mapperName": {
|
||||
"description": "MapperName is the mapper name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the identity provider mapper is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this identity provider mapper",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,300 @@
|
||||
{
|
||||
"description": "KeycloakInstance makes a Keycloak server known to the operator",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakInstanceSpec defines the desired state of KeycloakInstance",
|
||||
"properties": {
|
||||
"auth": {
|
||||
"description": "Auth selects how the operator authenticates to Keycloak.\nExactly one of auth.passwordGrant or auth.clientCredentials must be set.",
|
||||
"properties": {
|
||||
"clientCredentials": {
|
||||
"description": "ClientCredentials configures OAuth2 client_credentials grant\nauthentication via a confidential client / service account.",
|
||||
"properties": {
|
||||
"clientId": {
|
||||
"description": "ClientID, when set, overrides the value read from secretRef.clientIdKey.\nThe client ID is not a secret, so providing it inline is allowed.",
|
||||
"type": "string"
|
||||
},
|
||||
"secretRef": {
|
||||
"description": "ClientCredentialsSecretRefSpec references a Secret containing client credentials.",
|
||||
"properties": {
|
||||
"clientIdKey": {
|
||||
"default": "client-id",
|
||||
"description": "ClientIdKey is ignored when ClientCredentialsSpec.ClientID is set.",
|
||||
"type": "string"
|
||||
},
|
||||
"clientSecretKey": {
|
||||
"default": "client-secret",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defaults to the KeycloakInstance namespace when unset.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretRef"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"passwordGrant": {
|
||||
"description": "PasswordGrant configures resource-owner password grant authentication\nagainst a user account (typically the master-realm admin).",
|
||||
"properties": {
|
||||
"secretRef": {
|
||||
"description": "PasswordGrantSecretRefSpec references a Secret containing admin credentials.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defaults to the KeycloakInstance namespace when unset.",
|
||||
"type": "string"
|
||||
},
|
||||
"passwordKey": {
|
||||
"default": "password",
|
||||
"type": "string"
|
||||
},
|
||||
"usernameKey": {
|
||||
"default": "username",
|
||||
"description": "UsernameKey is ignored when PasswordGrantSpec.Username is set.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"username": {
|
||||
"description": "Username, when set, overrides the value read from secretRef.usernameKey.\nThe admin username is not a secret, so providing it inline is allowed.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretRef"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of auth.passwordGrant or auth.clientCredentials must be set",
|
||||
"rule": "has(self.passwordGrant) != has(self.clientCredentials)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"baseUrl": {
|
||||
"description": "BaseUrl is the URL of the Keycloak server (e.g., http://keycloak:8080)",
|
||||
"type": "string"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm is the admin realm (defaults to \"master\")",
|
||||
"type": "string"
|
||||
},
|
||||
"tls": {
|
||||
"description": "TLS configures how the operator verifies the Keycloak server certificate.",
|
||||
"properties": {
|
||||
"caCert": {
|
||||
"description": "CACert references a Secret or ConfigMap holding a PEM-encoded CA bundle\nused to verify the Keycloak server certificate.",
|
||||
"properties": {
|
||||
"configMapRef": {
|
||||
"description": "CACertConfigMapRefSpec references a ConfigMap key holding a PEM-encoded CA\nbundle (e.g. kube-root-ca.crt or a cert-manager CA bundle).",
|
||||
"properties": {
|
||||
"key": {
|
||||
"default": "ca.crt",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defaults to the KeycloakInstance namespace when unset.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"secretRef": {
|
||||
"description": "CACertSecretRefSpec references a Secret key holding a PEM-encoded CA bundle.",
|
||||
"properties": {
|
||||
"key": {
|
||||
"default": "ca.crt",
|
||||
"type": "string"
|
||||
},
|
||||
"name": {
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace defaults to the KeycloakInstance namespace when unset.",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of caCert.secretRef or caCert.configMapRef must be set",
|
||||
"rule": "has(self.secretRef) != has(self.configMapRef)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"insecureSkipVerify": {
|
||||
"description": "InsecureSkipVerify disables TLS certificate verification. Do not enable\nin production.",
|
||||
"type": "boolean"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"token": {
|
||||
"description": "Token contains optional token caching configuration",
|
||||
"properties": {
|
||||
"expiresKey": {
|
||||
"description": "ExpiresKey is the key in the secret for the token expiration",
|
||||
"type": "string"
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the secret to cache the token",
|
||||
"type": "string"
|
||||
},
|
||||
"tokenKey": {
|
||||
"description": "TokenKey is the key in the secret for the token",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"auth",
|
||||
"baseUrl"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakInstanceStatus defines the observed state of KeycloakInstance",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information about the status",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the Keycloak instance is accessible",
|
||||
"type": "boolean"
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the API path for this resource",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
},
|
||||
"version": {
|
||||
"description": "Version is the Keycloak server version",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,185 @@
|
||||
{
|
||||
"description": "KeycloakOrganization defines an organization within a KeycloakRealm\nNOTE: Organizations require Keycloak 26.0.0 or later",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakOrganizationSpec defines the desired state of KeycloakOrganization",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak OrganizationRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakOrganizationStatus defines the observed state of KeycloakOrganization",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"organizationID": {
|
||||
"description": "OrganizationID is the Keycloak internal organization ID",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the organization is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this organization",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,201 @@
|
||||
{
|
||||
"description": "KeycloakProtocolMapper defines a protocol mapper within a KeycloakClient or KeycloakClientScope",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakProtocolMapperSpec defines the desired state of KeycloakProtocolMapper",
|
||||
"properties": {
|
||||
"clientRef": {
|
||||
"description": "ClientRef is a reference to a KeycloakClient\nOne of clientRef or clientScopeRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"clientScopeRef": {
|
||||
"description": "ClientScopeRef is a reference to a KeycloakClientScope\nOne of clientRef or clientScopeRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ProtocolMapperRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakProtocolMapperStatus defines the observed state of KeycloakProtocolMapper",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"mapperID": {
|
||||
"description": "MapperID is the Keycloak internal mapper ID",
|
||||
"type": "string"
|
||||
},
|
||||
"mapperName": {
|
||||
"description": "MapperName is the mapper name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"parentID": {
|
||||
"description": "ParentID is the parent client or clientScope ID",
|
||||
"type": "string"
|
||||
},
|
||||
"parentType": {
|
||||
"description": "ParentType indicates if parent is \"client\" or \"clientScope\"",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the protocol mapper is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this protocol mapper",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,189 @@
|
||||
{
|
||||
"description": "KeycloakRealm defines a realm within a KeycloakInstance",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakRealmSpec defines the desired state of KeycloakRealm",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is a reference to a ClusterKeycloakInstance\nOne of instanceRef or clusterInstanceRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RealmRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is a reference to a KeycloakInstance\nOne of instanceRef or clusterInstanceRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmName": {
|
||||
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)",
|
||||
"type": "string"
|
||||
},
|
||||
"smtpSecretRef": {
|
||||
"description": "SmtpSecretRef is a reference to a Kubernetes Secret containing SMTP credentials.\nWhen set, the secret values are injected into definition.smtpServer.user and\ndefinition.smtpServer.password before syncing to Keycloak, so credentials\ndo not need to appear in plaintext in the CR.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret",
|
||||
"type": "string"
|
||||
},
|
||||
"passwordKey": {
|
||||
"default": "password",
|
||||
"description": "PasswordKey is the key in the secret for the SMTP password (defaults to \"password\")",
|
||||
"type": "string"
|
||||
},
|
||||
"userKey": {
|
||||
"default": "user",
|
||||
"description": "UserKey is the key in the secret for the SMTP username (defaults to \"user\")",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakRealmStatus defines the observed state of KeycloakRealm",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the realm is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this realm",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,185 @@
|
||||
{
|
||||
"description": "KeycloakRequiredAction manages a required action provider within a Keycloak realm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakRequiredActionSpec defines the desired state of KeycloakRequiredAction",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RequiredActionProviderRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakRequiredActionStatus defines the observed state of KeycloakRequiredAction",
|
||||
"properties": {
|
||||
"alias": {
|
||||
"description": "Alias is the required action alias in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the required action is synchronized",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this required action",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,215 @@
|
||||
{
|
||||
"description": "KeycloakRole defines a role within a KeycloakRealm or KeycloakClient",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakRoleSpec defines the desired state of KeycloakRole",
|
||||
"properties": {
|
||||
"clientRef": {
|
||||
"description": "ClientRef is a reference to a KeycloakClient for client-level roles\nIf not specified, the role is a realm-level role",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RoleRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakRoleStatus defines the observed state of KeycloakRole",
|
||||
"properties": {
|
||||
"clientID": {
|
||||
"description": "ClientID is the client ID if this is a client role",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"isClientRole": {
|
||||
"description": "IsClientRole indicates if this is a client role",
|
||||
"type": "boolean"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the role is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this role",
|
||||
"type": "string"
|
||||
},
|
||||
"roleID": {
|
||||
"description": "RoleID is the Keycloak internal role ID",
|
||||
"type": "string"
|
||||
},
|
||||
"roleName": {
|
||||
"description": "RoleName is the role name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,257 @@
|
||||
{
|
||||
"description": "KeycloakRoleMapping maps a role to a user or group",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakRoleMappingSpec defines the desired state of KeycloakRoleMapping",
|
||||
"properties": {
|
||||
"role": {
|
||||
"description": "Role defines the role to assign (inline definition)\nEither Role or RoleRef must be specified",
|
||||
"properties": {
|
||||
"clientId": {
|
||||
"description": "ClientID is the client ID for client-level roles (alternative to ClientRef)",
|
||||
"type": "string"
|
||||
},
|
||||
"clientRef": {
|
||||
"description": "ClientRef references a KeycloakClient for client-level roles\nIf not specified, the role is a realm-level role",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the role name",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"roleRef": {
|
||||
"description": "RoleRef references an existing KeycloakRole resource\nEither Role or RoleRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"subject": {
|
||||
"description": "Subject defines who the role is assigned to (user or group)",
|
||||
"properties": {
|
||||
"groupRef": {
|
||||
"description": "GroupRef references a KeycloakGroup",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"userRef": {
|
||||
"description": "UserRef references a KeycloakUser",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"subject"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakRoleMappingStatus defines the observed state of KeycloakRoleMapping",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the role mapping is applied",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this role mapping",
|
||||
"type": "string"
|
||||
},
|
||||
"roleName": {
|
||||
"description": "RoleName is the resolved role name",
|
||||
"type": "string"
|
||||
},
|
||||
"roleType": {
|
||||
"description": "RoleType is either \"realm\" or \"client\"",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
},
|
||||
"subjectID": {
|
||||
"description": "SubjectID is the Keycloak ID of the subject",
|
||||
"type": "string"
|
||||
},
|
||||
"subjectType": {
|
||||
"description": "SubjectType is either \"user\" or \"group\"",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,252 @@
|
||||
{
|
||||
"description": "KeycloakUser defines a user within a KeycloakRealm",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakUserSpec defines the desired state of KeycloakUser",
|
||||
"properties": {
|
||||
"clientRef": {
|
||||
"description": "ClientRef is a reference to a KeycloakClient for service account users\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this to manage the service account user associated with a client",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users with cluster-scoped realms",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak UserRepresentation",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"initialPassword": {
|
||||
"description": "InitialPassword sets the initial password for the user (only on creation)",
|
||||
"properties": {
|
||||
"temporary": {
|
||||
"description": "Temporary indicates if the user must change password on first login",
|
||||
"type": "boolean"
|
||||
},
|
||||
"value": {
|
||||
"description": "Value is the password value",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"value"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"userSecret": {
|
||||
"description": "UserSecret configures where to store user credentials",
|
||||
"properties": {
|
||||
"generatePassword": {
|
||||
"description": "GeneratePassword indicates whether to generate a password",
|
||||
"type": "boolean"
|
||||
},
|
||||
"passwordKey": {
|
||||
"description": "PasswordKey is the key for the password (defaults to \"password\")",
|
||||
"type": "string"
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the Kubernetes secret to create",
|
||||
"type": "string"
|
||||
},
|
||||
"usernameKey": {
|
||||
"description": "UsernameKey is the key for the username in the secret (defaults to \"username\")",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretName"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakUserStatus defines the observed state of KeycloakUser",
|
||||
"properties": {
|
||||
"clientID": {
|
||||
"description": "ClientID is the client UUID if this is a service account user",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"isServiceAccount": {
|
||||
"description": "IsServiceAccount indicates if this user is a service account for a client",
|
||||
"type": "boolean"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the user is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this user",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
},
|
||||
"userID": {
|
||||
"description": "UserID is the Keycloak internal user ID",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
@@ -0,0 +1,229 @@
|
||||
{
|
||||
"description": "KeycloakUserCredential manages credentials for a KeycloakUser",
|
||||
"properties": {
|
||||
"apiVersion": {
|
||||
"description": "APIVersion defines the versioned schema of this representation of an object.\nServers should convert recognized schemas to the latest internal value, and\nmay reject unrecognized values.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources",
|
||||
"type": "string"
|
||||
},
|
||||
"kind": {
|
||||
"description": "Kind is a string value representing the REST resource this object represents.\nServers may infer this from the endpoint the client submits requests to.\nCannot be updated.\nIn CamelCase.\nMore info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds",
|
||||
"type": "string"
|
||||
},
|
||||
"metadata": {
|
||||
"type": "object"
|
||||
},
|
||||
"spec": {
|
||||
"description": "KeycloakUserCredentialSpec defines the desired state of KeycloakUserCredential",
|
||||
"properties": {
|
||||
"userRef": {
|
||||
"description": "UserRef is a reference to a KeycloakUser",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"userSecret": {
|
||||
"description": "UserSecret defines the secret containing the credentials",
|
||||
"properties": {
|
||||
"create": {
|
||||
"description": "Create indicates whether to create the secret if it doesn't exist",
|
||||
"type": "boolean"
|
||||
},
|
||||
"emailKey": {
|
||||
"description": "EmailKey is the key for the email in the secret",
|
||||
"type": "string"
|
||||
},
|
||||
"passwordKey": {
|
||||
"default": "password",
|
||||
"description": "PasswordKey is the key for the password in the secret",
|
||||
"type": "string"
|
||||
},
|
||||
"passwordPolicy": {
|
||||
"description": "PasswordPolicy configures password generation",
|
||||
"properties": {
|
||||
"includeNumbers": {
|
||||
"default": true,
|
||||
"description": "IncludeNumbers includes numbers in the password",
|
||||
"type": "boolean"
|
||||
},
|
||||
"includeSymbols": {
|
||||
"default": true,
|
||||
"description": "IncludeSymbols includes symbols in the password",
|
||||
"type": "boolean"
|
||||
},
|
||||
"length": {
|
||||
"default": 24,
|
||||
"description": "Length is the password length (default 24)",
|
||||
"type": "integer"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the Kubernetes secret",
|
||||
"type": "string"
|
||||
},
|
||||
"usernameKey": {
|
||||
"default": "username",
|
||||
"description": "UsernameKey is the key for the username in the secret",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"secretName"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"userRef",
|
||||
"userSecret"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakUserCredentialStatus defines the observed state of KeycloakUserCredential",
|
||||
"properties": {
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
"description": "Condition contains details for one aspect of the current state of this API Resource.",
|
||||
"properties": {
|
||||
"lastTransitionTime": {
|
||||
"description": "lastTransitionTime is the last time the condition transitioned from one status to another.\nThis should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.",
|
||||
"format": "date-time",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "message is a human readable message indicating details about the transition.\nThis may be an empty string.",
|
||||
"maxLength": 32768,
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "observedGeneration represents the .metadata.generation that the condition was set based upon.\nFor instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date\nwith respect to the current state of the instance.",
|
||||
"format": "int64",
|
||||
"minimum": 0,
|
||||
"type": "integer"
|
||||
},
|
||||
"reason": {
|
||||
"description": "reason contains a programmatic identifier indicating the reason for the condition's last transition.\nProducers of specific condition types may define expected values and meanings for this field,\nand whether the values are considered a guaranteed API.\nThe value should be a CamelCase string.\nThis field may not be empty.",
|
||||
"maxLength": 1024,
|
||||
"minLength": 1,
|
||||
"pattern": "^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "status of the condition, one of True, False, Unknown.",
|
||||
"enum": [
|
||||
"True",
|
||||
"False",
|
||||
"Unknown"
|
||||
],
|
||||
"type": "string"
|
||||
},
|
||||
"type": {
|
||||
"description": "type of condition in CamelCase or in foo.example.com/CamelCase.",
|
||||
"maxLength": 316,
|
||||
"pattern": "^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"lastTransitionTime",
|
||||
"message",
|
||||
"reason",
|
||||
"status",
|
||||
"type"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
"clusterInstanceRef": {
|
||||
"description": "ClusterInstanceRef is the name of the cluster instance",
|
||||
"type": "string"
|
||||
},
|
||||
"instanceRef": {
|
||||
"description": "InstanceRef is the name of the namespaced instance",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"observedGeneration": {
|
||||
"description": "ObservedGeneration is the generation of the spec that was last processed",
|
||||
"format": "int64",
|
||||
"type": "integer"
|
||||
},
|
||||
"passwordHash": {
|
||||
"description": "PasswordHash is a hash of the last synchronized password (for change detection)",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the credentials are synchronized",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realm": {
|
||||
"description": "Realm contains the resolved realm reference",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is the name of the cluster realm",
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is the name of the namespaced realm",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for the user",
|
||||
"type": "string"
|
||||
},
|
||||
"secretCreated": {
|
||||
"description": "SecretCreated indicates if the secret was created by the operator",
|
||||
"type": "boolean"
|
||||
},
|
||||
"secretResourceVersion": {
|
||||
"description": "SecretResourceVersion is the resource version of the secret when last synced",
|
||||
"type": "string"
|
||||
},
|
||||
"status": {
|
||||
"description": "Status is a human-readable status message",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"ready"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"type": "object"
|
||||
}
|
||||
Reference in New Issue
Block a user