feat: initial scaffold from helm-template
Validate login GitOps repo / validate (push) Successful in 9s
Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
This commit is contained in:
@@ -0,0 +1,100 @@
|
||||
apiVersion: k8s.keycloak.org/v2alpha1
|
||||
kind: KeycloakRealmImport
|
||||
metadata:
|
||||
name: home-lab
|
||||
namespace: login
|
||||
spec:
|
||||
keycloakCRName: keycloak
|
||||
|
||||
# ── Realm definition ──────────────────────────────────────────────────────
|
||||
# This is a Keycloak realm export JSON embedded as a structured spec.
|
||||
# The operator applies this on startup and reconciles on changes.
|
||||
# Add clients, groups, and roles here; per-app clients can be managed in
|
||||
# their own app repos by adding additional KeycloakRealmImport resources
|
||||
# targeting this same keycloakCRName.
|
||||
realm:
|
||||
realm: home-lab
|
||||
displayName: "Home Lab"
|
||||
enabled: true
|
||||
loginWithEmailAllowed: true
|
||||
duplicateEmailsAllowed: false
|
||||
resetPasswordAllowed: true
|
||||
editUsernameAllowed: false
|
||||
bruteForceProtected: true
|
||||
permanentLockout: false
|
||||
maxFailureWaitSeconds: 900
|
||||
minimumQuickLoginWaitSeconds: 60
|
||||
waitIncrementSeconds: 60
|
||||
quickLoginCheckMilliSeconds: 1000
|
||||
maxDeltaTimeSeconds: 43200
|
||||
failureFactor: 10
|
||||
|
||||
# ── Session settings ──────────────────────────────────────────────────
|
||||
ssoSessionIdleTimeout: 1800
|
||||
ssoSessionMaxLifespan: 36000
|
||||
accessTokenLifespan: 300
|
||||
accessTokenLifespanForImplicitFlow: 900
|
||||
offlineSessionIdleTimeout: 2592000
|
||||
offlineSessionMaxLifespanEnabled: false
|
||||
|
||||
# ── Password policy ───────────────────────────────────────────────────
|
||||
passwordPolicy: "length(12) and notUsername(undefined)"
|
||||
|
||||
# ── Groups ────────────────────────────────────────────────────────────
|
||||
groups:
|
||||
- name: homelab-admin
|
||||
path: /homelab-admin
|
||||
- name: homelab-user
|
||||
path: /homelab-user
|
||||
- name: transmission-users
|
||||
path: /transmission-users
|
||||
- name: media-users
|
||||
path: /media-users
|
||||
- name: monitoring-users
|
||||
path: /monitoring-users
|
||||
|
||||
# ── Default client scopes ─────────────────────────────────────────────
|
||||
defaultDefaultClientScopes:
|
||||
- web-origins
|
||||
- acr
|
||||
- roles
|
||||
- profile
|
||||
- basic
|
||||
- email
|
||||
|
||||
# ── Clients ───────────────────────────────────────────────────────────
|
||||
# traefik-oidc: shared client for traefikoidc middleware (SSO cookie domain)
|
||||
# Per-app clients with dedicated redirect URIs and claim mappers should be
|
||||
# added as additional KeycloakRealmImport resources in each app's repo.
|
||||
clients:
|
||||
- clientId: traefik-oidc
|
||||
name: "Traefik OIDC"
|
||||
description: "Shared OIDC client for Traefik traefikoidc middleware"
|
||||
enabled: true
|
||||
publicClient: false
|
||||
standardFlowEnabled: true
|
||||
implicitFlowEnabled: false
|
||||
directAccessGrantsEnabled: false
|
||||
serviceAccountsEnabled: false
|
||||
authorizationServicesEnabled: false
|
||||
redirectUris:
|
||||
- "https://transmission-ng.olb42.com/oauth2/callback"
|
||||
- "https://home.olb42.com/oauth2/callback"
|
||||
- "https://dozzle.olb42.com/oauth2/callback"
|
||||
- "https://pgadmin4.olb42.com/oauth2/callback"
|
||||
webOrigins:
|
||||
- "+"
|
||||
attributes:
|
||||
pkce.code.challenge.method: "S256"
|
||||
post.logout.redirect.uris: "+"
|
||||
protocolMappers:
|
||||
- name: groups
|
||||
protocol: openid-connect
|
||||
protocolMapper: oidc-group-membership-mapper
|
||||
consentRequired: false
|
||||
config:
|
||||
full.path: "false"
|
||||
id.token.claim: "true"
|
||||
access.token.claim: "true"
|
||||
claim.name: "groups"
|
||||
userinfo.token.claim: "true"
|
||||
Reference in New Issue
Block a user