fix: three blocking issues preventing login stack from starting
Validate login GitOps repo / validate (push) Successful in 11s

- keycloak-instance: bootstrapAdminSpec -> bootstrapAdmin (correct CRD field)
- cnpg-cluster: remove barman-cloud plugin block (BarmanObjectStore CRD absent)
- operator/kustomization: patch WATCH_NAMESPACES=login so operator reconciles login ns
This commit is contained in:
2026-05-10 23:14:56 +01:00
parent 59e56be3e5
commit 67b1916012
3 changed files with 19 additions and 7 deletions
+16
View File
@@ -15,3 +15,19 @@ resources:
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
# Patch the operator Deployment to watch the 'login' namespace in addition to
# keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated
# list restricts to those namespaces. Using "login" here is explicit and safe.
patches:
- target:
group: apps
version: v1
kind: Deployment
name: keycloak-operator
patch: |-
- op: add
path: /spec/template/spec/containers/0/env/-
value:
name: WATCH_NAMESPACES
value: "login"
@@ -23,12 +23,8 @@ spec:
database: keycloak
owner: keycloak
# ── WAL archival via barman-cloud → MinIO ─────────────────────────────────
plugins:
- name: barman-cloud.cloudnative-pg.io
isWALArchiver: true
parameters:
barmanObjectName: minio-store
# WAL archival (barman-cloud → MinIO) intentionally omitted until BarmanObjectStore
# CRD is confirmed present in this cluster. Add back via plugins block once verified.
# ── PostgreSQL tuning for Keycloak workload ───────────────────────────────
postgresql:
@@ -45,7 +45,7 @@ spec:
headers: forwarded
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
bootstrapAdminSpec:
bootstrapAdmin:
secret:
name: login-admin