feat: initial scaffold from helm-template
Validate login GitOps repo / validate (push) Successful in 9s

- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
This commit is contained in:
2026-05-10 22:32:49 +01:00
commit 6f29be2987
21 changed files with 750 additions and 0 deletions
@@ -0,0 +1,100 @@
apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakRealmImport
metadata:
name: home-lab
namespace: login
spec:
keycloakCRName: keycloak
# ── Realm definition ──────────────────────────────────────────────────────
# This is a Keycloak realm export JSON embedded as a structured spec.
# The operator applies this on startup and reconciles on changes.
# Add clients, groups, and roles here; per-app clients can be managed in
# their own app repos by adding additional KeycloakRealmImport resources
# targeting this same keycloakCRName.
realm:
realm: home-lab
displayName: "Home Lab"
enabled: true
loginWithEmailAllowed: true
duplicateEmailsAllowed: false
resetPasswordAllowed: true
editUsernameAllowed: false
bruteForceProtected: true
permanentLockout: false
maxFailureWaitSeconds: 900
minimumQuickLoginWaitSeconds: 60
waitIncrementSeconds: 60
quickLoginCheckMilliSeconds: 1000
maxDeltaTimeSeconds: 43200
failureFactor: 10
# ── Session settings ──────────────────────────────────────────────────
ssoSessionIdleTimeout: 1800
ssoSessionMaxLifespan: 36000
accessTokenLifespan: 300
accessTokenLifespanForImplicitFlow: 900
offlineSessionIdleTimeout: 2592000
offlineSessionMaxLifespanEnabled: false
# ── Password policy ───────────────────────────────────────────────────
passwordPolicy: "length(12) and notUsername(undefined)"
# ── Groups ────────────────────────────────────────────────────────────
groups:
- name: homelab-admin
path: /homelab-admin
- name: homelab-user
path: /homelab-user
- name: transmission-users
path: /transmission-users
- name: media-users
path: /media-users
- name: monitoring-users
path: /monitoring-users
# ── Default client scopes ─────────────────────────────────────────────
defaultDefaultClientScopes:
- web-origins
- acr
- roles
- profile
- basic
- email
# ── Clients ───────────────────────────────────────────────────────────
# traefik-oidc: shared client for traefikoidc middleware (SSO cookie domain)
# Per-app clients with dedicated redirect URIs and claim mappers should be
# added as additional KeycloakRealmImport resources in each app's repo.
clients:
- clientId: traefik-oidc
name: "Traefik OIDC"
description: "Shared OIDC client for Traefik traefikoidc middleware"
enabled: true
publicClient: false
standardFlowEnabled: true
implicitFlowEnabled: false
directAccessGrantsEnabled: false
serviceAccountsEnabled: false
authorizationServicesEnabled: false
redirectUris:
- "https://transmission-ng.olb42.com/oauth2/callback"
- "https://home.olb42.com/oauth2/callback"
- "https://dozzle.olb42.com/oauth2/callback"
- "https://pgadmin4.olb42.com/oauth2/callback"
webOrigins:
- "+"
attributes:
pkce.code.challenge.method: "S256"
post.logout.redirect.uris: "+"
protocolMappers:
- name: groups
protocol: openid-connect
protocolMapper: oidc-group-membership-mapper
consentRequired: false
config:
full.path: "false"
id.token.claim: "true"
access.token.claim: "true"
claim.name: "groups"
userinfo.token.claim: "true"