fix: three blocking issues preventing login stack from starting
Validate login GitOps repo / validate (push) Successful in 11s
Validate login GitOps repo / validate (push) Successful in 11s
- keycloak-instance: bootstrapAdminSpec -> bootstrapAdmin (correct CRD field) - cnpg-cluster: remove barman-cloud plugin block (BarmanObjectStore CRD absent) - operator/kustomization: patch WATCH_NAMESPACES=login so operator reconciles login ns
This commit is contained in:
@@ -15,3 +15,19 @@ resources:
|
|||||||
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml
|
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml
|
||||||
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
|
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
|
||||||
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
|
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
|
||||||
|
|
||||||
|
# Patch the operator Deployment to watch the 'login' namespace in addition to
|
||||||
|
# keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated
|
||||||
|
# list restricts to those namespaces. Using "login" here is explicit and safe.
|
||||||
|
patches:
|
||||||
|
- target:
|
||||||
|
group: apps
|
||||||
|
version: v1
|
||||||
|
kind: Deployment
|
||||||
|
name: keycloak-operator
|
||||||
|
patch: |-
|
||||||
|
- op: add
|
||||||
|
path: /spec/template/spec/containers/0/env/-
|
||||||
|
value:
|
||||||
|
name: WATCH_NAMESPACES
|
||||||
|
value: "login"
|
||||||
|
|||||||
@@ -23,12 +23,8 @@ spec:
|
|||||||
database: keycloak
|
database: keycloak
|
||||||
owner: keycloak
|
owner: keycloak
|
||||||
|
|
||||||
# ── WAL archival via barman-cloud → MinIO ─────────────────────────────────
|
# WAL archival (barman-cloud → MinIO) intentionally omitted until BarmanObjectStore
|
||||||
plugins:
|
# CRD is confirmed present in this cluster. Add back via plugins block once verified.
|
||||||
- name: barman-cloud.cloudnative-pg.io
|
|
||||||
isWALArchiver: true
|
|
||||||
parameters:
|
|
||||||
barmanObjectName: minio-store
|
|
||||||
|
|
||||||
# ── PostgreSQL tuning for Keycloak workload ───────────────────────────────
|
# ── PostgreSQL tuning for Keycloak workload ───────────────────────────────
|
||||||
postgresql:
|
postgresql:
|
||||||
|
|||||||
@@ -45,7 +45,7 @@ spec:
|
|||||||
headers: forwarded
|
headers: forwarded
|
||||||
|
|
||||||
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
|
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
|
||||||
bootstrapAdminSpec:
|
bootstrapAdmin:
|
||||||
secret:
|
secret:
|
||||||
name: login-admin
|
name: login-admin
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user