This commit is contained in:
2026-09-28 16:28:35 +01:00
parent 666b1ff877
commit e27aa106fd
76 changed files with 5634 additions and 906 deletions
@@ -15,6 +15,11 @@
"spec": {
"description": "KeycloakIdentityProviderSpec defines the desired state of KeycloakIdentityProvider",
"properties": {
"alias": {
"description": "Alias is the identity provider alias in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": {
@@ -33,7 +38,7 @@
"description": "ConfigSecretRef is a reference to a Kubernetes Secret whose data entries\nare merged into definition.config before syncing to Keycloak. This allows\nsensitive configuration values (e.g. clientId, clientSecret) to be stored\nin a Secret rather than in plaintext in the CR. Secret values take\nprecedence over values specified inline in definition.config.",
"properties": {
"name": {
"description": "Name of the Kubernetes Secret",
"description": "Name of the Kubernetes Secret in the same namespace as the CR",
"type": "string"
}
},
@@ -44,20 +49,30 @@
"additionalProperties": false
},
"definition": {
"description": "Definition contains the Keycloak IdentityProviderRepresentation",
"description": "Definition contains the Keycloak IdentityProviderRepresentation. Set the\nalias via spec.alias.",
"type": "object",
"x-kubernetes-preserve-unknown-fields": true
},
"organizationRef": {
"description": "OrganizationRef references a KeycloakOrganization in the same namespace.\nThe organization's status.organizationID is injected as organizationId\non the identity provider. Requires Keycloak 26 or later. Do not set\norganizationId in definition; use this field instead.",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
}
},
"required": [
@@ -85,14 +100,29 @@
}
},
"required": [
"alias",
"definition"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef or clusterRealmRef must be set",
"rule": "has(self.realmRef) != has(self.clusterRealmRef)"
},
{
"message": "spec.alias is immutable once set",
"rule": "!has(oldSelf.alias) || self.alias == oldSelf.alias"
}
],
"additionalProperties": false
},
"status": {
"description": "KeycloakIdentityProviderStatus defines the observed state of KeycloakIdentityProvider",
"properties": {
"alias": {
"description": "Alias is the resolved identity provider alias in Keycloak",
"type": "string"
},
"conditions": {
"description": "Conditions represent the latest available observations",
"items": {
@@ -164,10 +194,18 @@
"type": "object",
"additionalProperties": false
},
"lastAppliedDefinitionHash": {
"description": "LastAppliedDefinitionHash is a hash of the last successfully applied\ndefinition (after secret merging). Keycloak masks config.clientSecret\non read, so this is the only way to detect that the desired secret\nchanged and must be pushed.",
"type": "string"
},
"message": {
"description": "Message contains additional information",
"type": "string"
},
"organizationID": {
"description": "OrganizationID is the resolved Keycloak organization ID when\nspec.organizationRef is set.",
"type": "string"
},
"ready": {
"description": "Ready indicates if the identity provider is ready",
"type": "boolean"