This commit is contained in:
2026-09-28 16:28:35 +01:00
parent 666b1ff877
commit e27aa106fd
76 changed files with 5634 additions and 906 deletions
@@ -16,15 +16,11 @@
"description": "KeycloakRoleSpec defines the desired state of KeycloakRole",
"properties": {
"clientRef": {
"description": "ClientRef is a reference to a KeycloakClient for client-level roles\nIf not specified, the role is a realm-level role",
"description": "ClientRef is a reference to a KeycloakClient for client-level roles.\nThe realm is derived from the referenced client, so realmRef and\nclusterRealmRef must not be set alongside it.\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
}
},
"required": [
@@ -34,7 +30,7 @@
"additionalProperties": false
},
"clusterRealmRef": {
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"description": "ClusterRealmRef is a reference to a ClusterKeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": {
"name": {
"description": "Name of the cluster-scoped resource",
@@ -48,20 +44,21 @@
"additionalProperties": false
},
"definition": {
"description": "Definition contains the Keycloak RoleRepresentation",
"description": "Definition contains the Keycloak RoleRepresentation. Set the role name via\nspec.name.",
"type": "object",
"x-kubernetes-preserve-unknown-fields": true
},
"name": {
"description": "Name is the role name in Keycloak. Immutable once set.",
"minLength": 1,
"type": "string"
},
"realmRef": {
"description": "RealmRef is a reference to a KeycloakRealm\nOne of realmRef or clusterRealmRef must be specified",
"description": "RealmRef is a reference to a KeycloakRealm for realm-level roles\nOne of realmRef, clusterRealmRef, or clientRef must be specified",
"properties": {
"name": {
"description": "Name of the resource",
"type": "string"
},
"namespace": {
"description": "Namespace of the resource (optional, defaults to the same namespace)",
"type": "string"
}
},
"required": [
@@ -72,9 +69,20 @@
}
},
"required": [
"definition"
"definition",
"name"
],
"type": "object",
"x-kubernetes-validations": [
{
"message": "exactly one of realmRef, clusterRealmRef, or clientRef must be set",
"rule": "(has(self.realmRef) ? 1 : 0) + (has(self.clusterRealmRef) ? 1 : 0) + (has(self.clientRef) ? 1 : 0) == 1"
},
{
"message": "spec.name is immutable once set",
"rule": "!has(oldSelf.name) || self.name == oldSelf.name"
}
],
"additionalProperties": false
},
"status": {