This commit is contained in:
2026-09-28 16:28:35 +01:00
parent 666b1ff877
commit e27aa106fd
76 changed files with 5634 additions and 906 deletions
@@ -28,10 +28,6 @@
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
}
},
"required": [
@@ -49,6 +45,12 @@
"name"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "at most one of clientRef or clientId may be set",
"rule": "!(has(self.clientRef) && has(self.clientId))"
}
],
"additionalProperties": false
},
"roleRef": {
@@ -57,10 +59,6 @@
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
}
},
"required": [
@@ -78,9 +76,19 @@
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
}
},
"required": [
"name"
],
"type": "object",
"additionalProperties": false
},
"serviceAccountRef": {
"description": "ServiceAccountRef references a KeycloakClient to assign roles to its\nauto-created service account user. This avoids needing an intermediate\nKeycloakUser CR for clients with serviceAccountsEnabled: true.",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
}
},
@@ -96,10 +104,6 @@
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
}
},
"required": [
@@ -110,6 +114,12 @@
}
},
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of userRef, groupRef, or serviceAccountRef must be set",
"rule": "(has(self.userRef) ? 1 : 0) + (has(self.groupRef) ? 1 : 0) + (has(self.serviceAccountRef) ? 1 : 0) == 1"
}
],
"additionalProperties": false
}
},
@@ -117,6 +127,12 @@
"subject"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of role or roleRef must be set",
"rule": "has(self.role) != has(self.roleRef)"
}
],
"additionalProperties": false
},
"status": {