feat: initial scaffold from helm-template
Validate login GitOps repo / validate (push) Successful in 9s
Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
This commit is contained in:
@@ -0,0 +1,76 @@
|
||||
apiVersion: k8s.keycloak.org/v2alpha1
|
||||
kind: Keycloak
|
||||
metadata:
|
||||
name: keycloak
|
||||
namespace: login
|
||||
spec:
|
||||
# ── HA: 2 replicas with Infinispan jdbc-ping cluster discovery ────────────
|
||||
instances: 2
|
||||
|
||||
# ── Image: pin to the same major as the operator release ─────────────────
|
||||
image: quay.io/keycloak/keycloak:26.2.5
|
||||
startOptimized: false
|
||||
|
||||
# ── Database: CNPG cluster (login-postgres) ───────────────────────────────
|
||||
# CNPG auto-creates the secret <cluster-name>-app with username/password.
|
||||
db:
|
||||
vendor: postgres
|
||||
host: login-postgres-rw
|
||||
port: 5432
|
||||
database: keycloak
|
||||
usernameSecret:
|
||||
name: login-postgres-app
|
||||
key: username
|
||||
passwordSecret:
|
||||
name: login-postgres-app
|
||||
key: password
|
||||
|
||||
# ── HTTP: plain HTTP backend; TLS terminated at Traefik ───────────────────
|
||||
http:
|
||||
httpEnabled: true
|
||||
httpPort: 8080
|
||||
httpsPort: 8443
|
||||
# No TLS secret — Traefik handles TLS via wildcard cert
|
||||
|
||||
# ── Hostname ──────────────────────────────────────────────────────────────
|
||||
hostname:
|
||||
hostname: login.olb42.com
|
||||
admin: login.olb42.com
|
||||
# strict=false: allow X-Forwarded-Host from Traefik
|
||||
strict: false
|
||||
strictBackchannel: false
|
||||
|
||||
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
|
||||
proxy:
|
||||
headers: forwarded
|
||||
|
||||
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
|
||||
bootstrapAdminSpec:
|
||||
secret:
|
||||
name: login-admin
|
||||
|
||||
# ── Additional Keycloak options ───────────────────────────────────────────
|
||||
additionalOptions:
|
||||
# jdbc-ping: DB-backed cluster discovery — no Kubernetes API/RBAC needed
|
||||
- name: cache-stack
|
||||
value: jdbc-ping
|
||||
- name: cache
|
||||
value: ispn
|
||||
- name: log-level
|
||||
value: INFO
|
||||
# Forward client IP through Traefik X-Forwarded-For chain
|
||||
- name: proxy-trusted-addresses
|
||||
value: "0.0.0.0/0"
|
||||
|
||||
# ── Resources ─────────────────────────────────────────────────────────────
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 250m
|
||||
limits:
|
||||
memory: 1500Mi
|
||||
cpu: "2"
|
||||
|
||||
# ── Ingress disabled: Traefik IngressRoute manages external access ─────────
|
||||
ingress:
|
||||
enabled: false
|
||||
Reference in New Issue
Block a user