fix: add RBAC for keycloak-operator SA to manage resources in login namespace
Validate login GitOps repo / validate (push) Successful in 10s

The upstream operator RBAC is scoped to keycloak-system only. With
QUARKUS_OPERATOR_SDK_NAMESPACES=login the operator tries to watch/manage
resources in login, so it needs a matching Role + RoleBindings there:
- keycloak-operator-role: core resources (statefulsets, secrets, services, etc)
- keycloakcontroller-cluster-role binding: keycloaks CRD access
- keycloakrealmimportcontroller-cluster-role binding: realm import CRD access
This commit is contained in:
2026-05-11 00:11:08 +01:00
parent 648c7f0266
commit 8fa904bb6c
2 changed files with 81 additions and 0 deletions
@@ -5,6 +5,7 @@ namespace: login
resources:
- ../../base/state
- keycloak-operator-rbac.yaml
- cnpg-cluster.yaml
- keycloak-instance.yaml
- keycloak-realm-home-lab.yaml