diff --git a/manifest/operator/kustomization.yaml b/manifest/operator/kustomization.yaml index cbbe104..da6ec44 100644 --- a/manifest/operator/kustomization.yaml +++ b/manifest/operator/kustomization.yaml @@ -16,9 +16,11 @@ resources: - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml -# Patch the operator Deployment to watch the 'login' namespace in addition to -# keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated -# list restricts to those namespaces. Using "login" here is explicit and safe. +# Patch the operator Deployment so it reconciles CRs in the 'login' namespace. +# The Keycloak Operator uses Quarkus JOSDK — the correct env var is +# QUARKUS_OPERATOR_SDK_NAMESPACES (maps to quarkus.operator-sdk.namespaces). +# A comma-separated list, or "*" for all namespaces. The operator already has +# ClusterRoles so it has the RBAC to watch any namespace. patches: - target: group: apps @@ -29,5 +31,5 @@ patches: - op: add path: /spec/template/spec/containers/0/env/- value: - name: WATCH_NAMESPACES + name: QUARKUS_OPERATOR_SDK_NAMESPACES value: "login" diff --git a/manifest/overlays/production/cnpg-cluster.yaml b/manifest/overlays/production/cnpg-cluster.yaml index c8e9cc1..792b409 100644 --- a/manifest/overlays/production/cnpg-cluster.yaml +++ b/manifest/overlays/production/cnpg-cluster.yaml @@ -12,10 +12,13 @@ spec: storageClass: local-postgres size: 8Gi - # ── Spread replicas across nodes ────────────────────────────────────────── + # ── Spread replicas across Proxmox zones (pve-1 / pve-2) ───────────────── + # Prevents both instances landing on the same physical host. + # Zone labels: k8s-worker1=pve-1, k8s-worker2=pve-1, + # k8s-worker3=pve-2, k8s-worker4=pve-2 affinity: enablePodAntiAffinity: true - topologyKey: kubernetes.io/hostname + topologyKey: topology.kubernetes.io/zone # ── Bootstrap: create the keycloak database and owner role ─────────────── bootstrap: