diff --git a/manifest/operator/kustomization.yaml b/manifest/operator/kustomization.yaml index 185011c..cbbe104 100644 --- a/manifest/operator/kustomization.yaml +++ b/manifest/operator/kustomization.yaml @@ -15,3 +15,19 @@ resources: - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml + +# Patch the operator Deployment to watch the 'login' namespace in addition to +# keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated +# list restricts to those namespaces. Using "login" here is explicit and safe. +patches: + - target: + group: apps + version: v1 + kind: Deployment + name: keycloak-operator + patch: |- + - op: add + path: /spec/template/spec/containers/0/env/- + value: + name: WATCH_NAMESPACES + value: "login" diff --git a/manifest/overlays/production/cnpg-cluster.yaml b/manifest/overlays/production/cnpg-cluster.yaml index e1018a4..c8e9cc1 100644 --- a/manifest/overlays/production/cnpg-cluster.yaml +++ b/manifest/overlays/production/cnpg-cluster.yaml @@ -23,12 +23,8 @@ spec: database: keycloak owner: keycloak - # ── WAL archival via barman-cloud → MinIO ───────────────────────────────── - plugins: - - name: barman-cloud.cloudnative-pg.io - isWALArchiver: true - parameters: - barmanObjectName: minio-store + # WAL archival (barman-cloud → MinIO) intentionally omitted until BarmanObjectStore + # CRD is confirmed present in this cluster. Add back via plugins block once verified. # ── PostgreSQL tuning for Keycloak workload ─────────────────────────────── postgresql: diff --git a/manifest/overlays/production/keycloak-instance.yaml b/manifest/overlays/production/keycloak-instance.yaml index 899e5dd..623d134 100644 --- a/manifest/overlays/production/keycloak-instance.yaml +++ b/manifest/overlays/production/keycloak-instance.yaml @@ -45,7 +45,7 @@ spec: headers: forwarded # ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml) - bootstrapAdminSpec: + bootstrapAdmin: secret: name: login-admin