feat: initial scaffold from helm-template
Validate login GitOps repo / validate (push) Successful in 9s

- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
This commit is contained in:
2026-05-10 22:32:49 +01:00
commit 6f29be2987
21 changed files with 750 additions and 0 deletions
@@ -0,0 +1,25 @@
apiVersion: bitnami.com/v1alpha1
kind: SealedSecret
metadata:
name: login-admin
namespace: login
annotations:
sealedsecrets.bitnami.com/managed: "true"
spec:
encryptedData:
# Seal from admin.secret.plain.yaml:
# kubeseal --context homelab-argocd \
# --secret-file manifest/overlays/production/admin.secret.plain.yaml \
# --sealed-secret-file manifest/overlays/production/admin.sealed.secret.yaml
username: REPLACE_WITH_KUBESEAL_OUTPUT
password: REPLACE_WITH_KUBESEAL_OUTPUT
template:
metadata:
name: login-admin
namespace: login
annotations:
sealedsecrets.bitnami.com/managed: "true"
labels:
app.kubernetes.io/part-of: login
app.kubernetes.io/environment: production
type: Opaque