fix: use correct QUARKUS_OPERATOR_SDK_NAMESPACES env var for operator namespace watch
Validate login GitOps repo / validate (push) Successful in 12s
Validate login GitOps repo / validate (push) Successful in 12s
WATCH_NAMESPACES is not a JOSDK env var. The Quarkus JOSDK extension reads QUARKUS_OPERATOR_SDK_NAMESPACES (maps to quarkus.operator-sdk.namespaces). Also: update CNPG anti-affinity topology key from kubernetes.io/hostname to topology.kubernetes.io/zone to spread primary and replica across pve-1 / pve-2.
This commit is contained in:
@@ -16,9 +16,11 @@ resources:
|
|||||||
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
|
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
|
||||||
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
|
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
|
||||||
|
|
||||||
# Patch the operator Deployment to watch the 'login' namespace in addition to
|
# Patch the operator Deployment so it reconciles CRs in the 'login' namespace.
|
||||||
# keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated
|
# The Keycloak Operator uses Quarkus JOSDK — the correct env var is
|
||||||
# list restricts to those namespaces. Using "login" here is explicit and safe.
|
# QUARKUS_OPERATOR_SDK_NAMESPACES (maps to quarkus.operator-sdk.namespaces).
|
||||||
|
# A comma-separated list, or "*" for all namespaces. The operator already has
|
||||||
|
# ClusterRoles so it has the RBAC to watch any namespace.
|
||||||
patches:
|
patches:
|
||||||
- target:
|
- target:
|
||||||
group: apps
|
group: apps
|
||||||
@@ -29,5 +31,5 @@ patches:
|
|||||||
- op: add
|
- op: add
|
||||||
path: /spec/template/spec/containers/0/env/-
|
path: /spec/template/spec/containers/0/env/-
|
||||||
value:
|
value:
|
||||||
name: WATCH_NAMESPACES
|
name: QUARKUS_OPERATOR_SDK_NAMESPACES
|
||||||
value: "login"
|
value: "login"
|
||||||
|
|||||||
@@ -12,10 +12,13 @@ spec:
|
|||||||
storageClass: local-postgres
|
storageClass: local-postgres
|
||||||
size: 8Gi
|
size: 8Gi
|
||||||
|
|
||||||
# ── Spread replicas across nodes ──────────────────────────────────────────
|
# ── Spread replicas across Proxmox zones (pve-1 / pve-2) ─────────────────
|
||||||
|
# Prevents both instances landing on the same physical host.
|
||||||
|
# Zone labels: k8s-worker1=pve-1, k8s-worker2=pve-1,
|
||||||
|
# k8s-worker3=pve-2, k8s-worker4=pve-2
|
||||||
affinity:
|
affinity:
|
||||||
enablePodAntiAffinity: true
|
enablePodAntiAffinity: true
|
||||||
topologyKey: kubernetes.io/hostname
|
topologyKey: topology.kubernetes.io/zone
|
||||||
|
|
||||||
# ── Bootstrap: create the keycloak database and owner role ───────────────
|
# ── Bootstrap: create the keycloak database and owner role ───────────────
|
||||||
bootstrap:
|
bootstrap:
|
||||||
|
|||||||
Reference in New Issue
Block a user