2 Commits
Author SHA1 Message Date
olb042 8fa904bb6c fix: add RBAC for keycloak-operator SA to manage resources in login namespace
Validate login GitOps repo / validate (push) Successful in 10s
The upstream operator RBAC is scoped to keycloak-system only. With
QUARKUS_OPERATOR_SDK_NAMESPACES=login the operator tries to watch/manage
resources in login, so it needs a matching Role + RoleBindings there:
- keycloak-operator-role: core resources (statefulsets, secrets, services, etc)
- keycloakcontroller-cluster-role binding: keycloaks CRD access
- keycloakrealmimportcontroller-cluster-role binding: realm import CRD access
2026-05-11 00:11:08 +01:00
olb042 6f29be2987 feat: initial scaffold from helm-template
Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
2026-05-10 22:32:49 +01:00