apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization # Keycloak Operator v26 — official Kubernetes manifests. # Pin to a specific release tag; bump here when upgrading Keycloak. # Full release list: https://github.com/keycloak/keycloak-k8s-resources/releases # # These resources include: # - keycloaks.k8s.keycloak.org CRD # - keycloakrealmimports.k8s.keycloak.org CRD # - keycloak-operator Deployment + RBAC (deployed to keycloak-system namespace # as defined in the upstream manifest; operator watches all namespaces) resources: - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml - https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml # Patch the operator Deployment to watch the 'login' namespace in addition to # keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated # list restricts to those namespaces. Using "login" here is explicit and safe. patches: - target: group: apps version: v1 kind: Deployment name: keycloak-operator patch: |- - op: add path: /spec/template/spec/containers/0/env/- value: name: WATCH_NAMESPACES value: "login"