updates
This commit is contained in:
@@ -30,7 +30,7 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RealmRepresentation",
|
||||
"description": "Definition contains the Keycloak RealmRepresentation. Set the realm name\nvia spec.realmName.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
@@ -54,7 +54,8 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmName": {
|
||||
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)",
|
||||
"description": "RealmName is the name of the realm in Keycloak. It is immutable once set:\nrenaming a realm in Keycloak is destructive and would orphan it.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"smtpSecretRef": {
|
||||
@@ -88,9 +89,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"realmName"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of instanceRef or clusterInstanceRef must be set",
|
||||
"rule": "has(self.instanceRef) != has(self.clusterInstanceRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.realmName is immutable once set",
|
||||
"rule": "!has(oldSelf.realmName) || self.realmName == oldSelf.realmName"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
@@ -167,6 +179,10 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"lastAppliedDefinitionHash": {
|
||||
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after SMTP credential merging). Keycloak masks\nsmtpServer.password on read, so this is the only way to detect that\nthe desired password changed and must be pushed.",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
|
||||
@@ -53,10 +53,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -71,6 +67,12 @@
|
||||
"providerId"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
|
||||
@@ -16,7 +16,8 @@
|
||||
"description": "KeycloakClientSpec defines the desired state of KeycloakClient",
|
||||
"properties": {
|
||||
"clientId": {
|
||||
"description": "ClientId is the client ID in Keycloak (defaults to metadata.name)",
|
||||
"description": "ClientId is the client ID in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"clientSecretRef": {
|
||||
@@ -61,7 +62,7 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ClientRepresentation",
|
||||
"description": "Definition contains the Keycloak ClientRepresentation. Set the client ID\nvia spec.clientId.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
@@ -71,10 +72,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -84,12 +81,29 @@
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"clientId"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.clientId is immutable once set",
|
||||
"rule": "!has(oldSelf.clientId) || self.clientId == oldSelf.clientId"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakClientStatus defines the observed state of KeycloakClient",
|
||||
"properties": {
|
||||
"clientId": {
|
||||
"description": "ClientID is the resolved client ID (clientId) in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"clientUUID": {
|
||||
"description": "ClientUUID is the Keycloak internal ID",
|
||||
"type": "string"
|
||||
|
||||
@@ -30,20 +30,21 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ClientScopeRepresentation",
|
||||
"description": "Definition contains the Keycloak ClientScopeRepresentation. Set the client\nscope name via spec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the client scope name in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -54,14 +55,29 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakClientScopeStatus defines the observed state of KeycloakClientScope",
|
||||
"properties": {
|
||||
"clientScopeName": {
|
||||
"description": "ClientScopeName is the resolved client scope name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
|
||||
@@ -29,21 +29,36 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"configSecretRef": {
|
||||
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Each secret\nvalue is wrapped as a single-element list to match ComponentRepresentation\nconfig (map[string][]string). Secret values take precedence over values\nspecified inline in definition.config.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ComponentRepresentation",
|
||||
"description": "Definition contains the Keycloak ComponentRepresentation. Set the component\nname via spec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the component name in Keycloak. Immutable once set. The\nproviderType is set in spec.definition.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -54,9 +69,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
@@ -141,6 +167,10 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"lastAppliedDefinitionHash": {
|
||||
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks secret config values\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
"description": "KeycloakGroupSpec defines the desired state of KeycloakGroup",
|
||||
"properties": {
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for top-level groups\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
@@ -30,20 +30,21 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak GroupRepresentation",
|
||||
"description": "Definition contains the Keycloak GroupRepresentation. Set the group name\nvia spec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the group name in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"parentGroupRef": {
|
||||
"description": "ParentGroupRef is a reference to a parent KeycloakGroup (for nested groups)",
|
||||
"description": "ParentGroupRef is a reference to a parent KeycloakGroup for nested groups.\nThe realm is derived from the parent chain, so realmRef and clusterRealmRef\nmust not be set alongside it.\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -53,15 +54,11 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"description": "RealmRef is a reference to a KeycloakRealm for top-level groups\nOne of realmRef, clusterRealmRef, or parentGroupRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -72,9 +69,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef, clusterRealmRef, or parentGroupRef must be set",
|
||||
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.parentGroupRef) ? 1 : 0) == 1"
|
||||
},
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
@@ -140,6 +148,10 @@
|
||||
"description": "GroupID is the Keycloak internal group ID",
|
||||
"type": "string"
|
||||
},
|
||||
"groupName": {
|
||||
"description": "GroupName is the resolved group name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"instance": {
|
||||
"description": "Instance contains the resolved instance reference",
|
||||
"properties": {
|
||||
|
||||
@@ -15,6 +15,11 @@
|
||||
"spec": {
|
||||
"description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider",
|
||||
"properties": {
|
||||
"alias": {
|
||||
"description": "Alias is the identity provider alias in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
@@ -33,7 +38,7 @@
|
||||
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret",
|
||||
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
@@ -44,20 +49,30 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak IdentityProviderRepresentation",
|
||||
"description": "Definition contains the Keycloak IdentityProviderRepresentation. Set the\nalias via spec.alias.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"organizationRef": {
|
||||
"description": "OrganizationRef references a KeycloakOrganization in the same namespace.\nThe organization's status.organizationID is injected as organizationId\non the identity provider. Requires Keycloak 26 or later. Do not set\norganizationId in definition; use this field instead.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -85,14 +100,29 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"alias",
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.alias is immutable once set",
|
||||
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
"description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider",
|
||||
"properties": {
|
||||
"alias": {
|
||||
"description": "Alias is the resolved identity provider alias in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"conditions": {
|
||||
"description": "Conditions represent the latest available observations",
|
||||
"items": {
|
||||
@@ -164,10 +194,18 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"lastAppliedDefinitionHash": {
|
||||
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks config.clientSecret\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
},
|
||||
"organizationID": {
|
||||
"description": "OrganizationID is the resolved Keycloak organization ID when\nspec.organizationRef is set.",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the identity provider is ready",
|
||||
"type": "boolean"
|
||||
|
||||
@@ -15,8 +15,22 @@
|
||||
"spec": {
|
||||
"description": "KeycloakIdentityProviderMapperSpec defines the desired state of KeycloakIdentityProviderMapper",
|
||||
"properties": {
|
||||
"configSecretRef": {
|
||||
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak IdentityProviderMapperRepresentation.\nThe identityProviderAlias field is auto-injected from the parent\nKeycloakIdentityProvider at reconcile time and does not need to be set\nhere.",
|
||||
"description": "Definition contains the Keycloak IdentityProviderMapperRepresentation. The\nidentityProviderAlias field is injected from the parent KeycloakIdentityProvider\nat reconcile time. Set the mapper name via spec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
@@ -26,10 +40,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -37,13 +47,25 @@
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the mapper name in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition",
|
||||
"identityProviderRef"
|
||||
"identityProviderRef",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
|
||||
@@ -30,20 +30,21 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak OrganizationRepresentation",
|
||||
"description": "Definition contains the Keycloak OrganizationRepresentation. Set the\norganization name via spec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the organization name in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -54,9 +55,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
@@ -146,6 +158,10 @@
|
||||
"description": "OrganizationID is the Keycloak internal organization ID",
|
||||
"type": "string"
|
||||
},
|
||||
"organizationName": {
|
||||
"description": "OrganizationName is the resolved organization name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"ready": {
|
||||
"description": "Ready indicates if the organization is ready",
|
||||
"type": "boolean"
|
||||
|
||||
@@ -21,10 +21,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -39,9 +35,19 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"configSecretRef": {
|
||||
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
@@ -52,15 +58,31 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak ProtocolMapperRepresentation",
|
||||
"description": "Definition contains the Keycloak ProtocolMapperRepresentation. Set the\nmapper name via spec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the protocol mapper name in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of clientRef or clientScopeRef must be set",
|
||||
"rule": "has(self.clientRef) != has(self.clientScopeRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
|
||||
@@ -30,7 +30,7 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RealmRepresentation",
|
||||
"description": "Definition contains the Keycloak RealmRepresentation. Set the realm name\nvia spec.realmName.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
@@ -40,10 +40,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -53,7 +49,8 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"realmName": {
|
||||
"description": "RealmName is the name of the realm in Keycloak (defaults to metadata.name)",
|
||||
"description": "RealmName is the name of the realm in Keycloak. It is immutable once set:\nrenaming a realm in Keycloak is destructive and would orphan it.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"smtpSecretRef": {
|
||||
@@ -82,9 +79,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"realmName"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of instanceRef or clusterInstanceRef must be set",
|
||||
"rule": "has(self.instanceRef) != has(self.clusterInstanceRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.realmName is immutable once set",
|
||||
"rule": "!has(oldSelf.realmName) || self.realmName == oldSelf.realmName"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
@@ -161,6 +169,10 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"lastAppliedDefinitionHash": {
|
||||
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after SMTP credential merging). Keycloak masks\nsmtpServer.password on read, so this is the only way to detect that\nthe desired password changed and must be pushed.",
|
||||
"type": "string"
|
||||
},
|
||||
"message": {
|
||||
"description": "Message contains additional information",
|
||||
"type": "string"
|
||||
@@ -169,6 +181,10 @@
|
||||
"description": "Ready indicates if the realm is ready",
|
||||
"type": "boolean"
|
||||
},
|
||||
"realmName": {
|
||||
"description": "RealmName is the resolved realm name in Keycloak",
|
||||
"type": "string"
|
||||
},
|
||||
"resourcePath": {
|
||||
"description": "ResourcePath is the Keycloak API path for this realm",
|
||||
"type": "string"
|
||||
|
||||
@@ -15,6 +15,11 @@
|
||||
"spec": {
|
||||
"description": "KeycloakRequiredActionSpec defines the desired state of KeycloakRequiredAction",
|
||||
"properties": {
|
||||
"alias": {
|
||||
"description": "Alias is the required action alias in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"properties": {
|
||||
@@ -29,8 +34,22 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"configSecretRef": {
|
||||
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. Secret\nvalues take precedence over values specified inline in definition.config.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RequiredActionProviderRepresentation",
|
||||
"description": "Definition contains the Keycloak RequiredActionProviderRepresentation. Set\nthe alias via spec.alias.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
@@ -40,10 +59,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -54,9 +69,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"alias",
|
||||
"definition"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef or clusterRealmRef must be set",
|
||||
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
|
||||
},
|
||||
{
|
||||
"message": "spec.alias is immutable once set",
|
||||
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
|
||||
@@ -16,15 +16,11 @@
|
||||
"description": "KeycloakRoleSpec defines the desired state of KeycloakRole",
|
||||
"properties": {
|
||||
"clientRef": {
|
||||
"description": "ClientRef is a reference to a KeycloakClient for client-level roles\nIf not specified, the role is a realm-level role",
|
||||
"description": "ClientRef is a reference to a KeycloakClient for client-level roles.\nThe realm is derived from the referenced client, so realmRef and\nclusterRealmRef must not be set alongside it.\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -34,7 +30,7 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the cluster-scoped resource",
|
||||
@@ -48,20 +44,21 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak RoleRepresentation",
|
||||
"description": "Definition contains the Keycloak RoleRepresentation. Set the role name via\nspec.name.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"name": {
|
||||
"description": "Name is the role name in Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
},
|
||||
"realmRef": {
|
||||
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
|
||||
"description": "RealmRef is a reference to a KeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -72,9 +69,20 @@
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"definition"
|
||||
"definition",
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
|
||||
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
|
||||
},
|
||||
{
|
||||
"message": "spec.name is immutable once set",
|
||||
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
|
||||
@@ -28,10 +28,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -49,6 +45,12 @@
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "at most one of clientRef or clientId may be set",
|
||||
"rule": "!(has(self.clientRef) && has(self.clientId))"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"roleRef": {
|
||||
@@ -57,10 +59,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -78,9 +76,19 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
"name"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"serviceAccountRef": {
|
||||
"description": "ServiceAccountRef references a KeycloakClient to assign roles to its\nauto-created service account user. This avoids needing an intermediate\nKeycloakUser CR for clients with serviceAccountsEnabled: true.",
|
||||
"properties": {
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
@@ -96,10 +104,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -110,6 +114,12 @@
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of userRef, groupRef, or serviceAccountRef must be set",
|
||||
"rule": "(has(self.userRef) ? 1 : 0) + (has(self.groupRef) ? 1 : 0) + (has(self.serviceAccountRef) ? 1 : 0) == 1"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
}
|
||||
},
|
||||
@@ -117,6 +127,12 @@
|
||||
"subject"
|
||||
],
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of role or roleRef must be set",
|
||||
"rule": "has(self.role) != has(self.roleRef)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
|
||||
@@ -21,10 +21,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -33,6 +29,16 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"clientRoles": {
|
||||
"additionalProperties": {
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"description": "ClientRoles maps a client's clientId to the authoritative set of\nclient-level role names for this user. When omitted, client roles are not\nmanaged; when set, roles on clients absent from the map are removed.\nDo not combine with KeycloakRoleMapping resources targeting the same user.",
|
||||
"type": "object"
|
||||
},
|
||||
"clusterRealmRef": {
|
||||
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef, clusterRealmRef, or clientRef must be specified\nUse this for regular realm users with cluster-scoped realms",
|
||||
"properties": {
|
||||
@@ -48,12 +54,19 @@
|
||||
"additionalProperties": false
|
||||
},
|
||||
"definition": {
|
||||
"description": "Definition contains the Keycloak UserRepresentation",
|
||||
"description": "Definition contains the Keycloak UserRepresentation. Set the username via\nspec.username; role and group assignments go in spec.realmRoles,\nspec.clientRoles, and spec.groups.",
|
||||
"type": "object",
|
||||
"x-kubernetes-preserve-unknown-fields": true
|
||||
},
|
||||
"groups": {
|
||||
"description": "Groups is the authoritative set of group names this user belongs to,\nreconciled via the Keycloak group-membership endpoints. When omitted,\ngroup memberships are not managed; an empty list removes all memberships.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"type": "array"
|
||||
},
|
||||
"initialPassword": {
|
||||
"description": "InitialPassword sets the initial password for the user (only on creation)",
|
||||
"description": "InitialPassword sets the initial password for the user (only on creation).\nFor managed credentials stored in a Kubernetes secret, use KeycloakUserCredential.",
|
||||
"properties": {
|
||||
"temporary": {
|
||||
"description": "Temporary indicates if the user must change password on first login",
|
||||
@@ -76,10 +89,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
@@ -88,34 +97,34 @@
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
},
|
||||
"userSecret": {
|
||||
"description": "UserSecret configures where to store user credentials",
|
||||
"properties": {
|
||||
"generatePassword": {
|
||||
"description": "GeneratePassword indicates whether to generate a password",
|
||||
"type": "boolean"
|
||||
},
|
||||
"passwordKey": {
|
||||
"description": "PasswordKey is the key for the password (defaults to \"password\")",
|
||||
"type": "string"
|
||||
},
|
||||
"secretName": {
|
||||
"description": "SecretName is the name of the Kubernetes secret to create",
|
||||
"type": "string"
|
||||
},
|
||||
"usernameKey": {
|
||||
"description": "UsernameKey is the key for the username in the secret (defaults to \"username\")",
|
||||
"type": "string"
|
||||
}
|
||||
"realmRoles": {
|
||||
"description": "RealmRoles is the authoritative set of realm-level role names for this\nuser, reconciled via the Keycloak role-mapping endpoints. When omitted,\nrealm roles are not managed; an empty list removes all realm roles.\nPointer types so an explicit empty value survives JSON round-trips.\nDo not combine with KeycloakRoleMapping resources targeting the same user.",
|
||||
"items": {
|
||||
"type": "string"
|
||||
},
|
||||
"required": [
|
||||
"secretName"
|
||||
],
|
||||
"type": "object",
|
||||
"additionalProperties": false
|
||||
"type": "array"
|
||||
},
|
||||
"username": {
|
||||
"description": "Username is the username in Keycloak. Required for regular realm users;\nomit it for service account users, which are identified by clientRef and\nwhose username is derived by Keycloak. Immutable once set.",
|
||||
"minLength": 1,
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"type": "object",
|
||||
"x-kubernetes-validations": [
|
||||
{
|
||||
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
|
||||
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
|
||||
},
|
||||
{
|
||||
"message": "spec.username is required unless spec.clientRef is set (service account user)",
|
||||
"rule": "has(self.clientRef) || (has(self.username) && size(self.username) > 0)"
|
||||
},
|
||||
{
|
||||
"message": "spec.username is immutable once set",
|
||||
"rule": "!has(oldSelf.username) || (has(self.username) && self.username == oldSelf.username)"
|
||||
}
|
||||
],
|
||||
"additionalProperties": false
|
||||
},
|
||||
"status": {
|
||||
@@ -239,6 +248,10 @@
|
||||
"userID": {
|
||||
"description": "UserID is the Keycloak internal user ID",
|
||||
"type": "string"
|
||||
},
|
||||
"username": {
|
||||
"description": "Username is the resolved username in Keycloak",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
|
||||
@@ -21,10 +21,6 @@
|
||||
"name": {
|
||||
"description": "Name of the resource",
|
||||
"type": "string"
|
||||
},
|
||||
"namespace": {
|
||||
"description": "Namespace of the resource (optional, defaults to the same namespace)",
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
|
||||
Reference in New Issue
Block a user