# RBAC for the Keycloak Operator SA (keycloak-system:keycloak-operator) to # manage resources in the 'login' namespace. # # The upstream kubernetes.yml scopes the operator's Role/RoleBinding to the # keycloak-system namespace only. When QUARKUS_OPERATOR_SDK_NAMESPACES is set # to 'login', the operator tries to watch and manage resources here too, so it # needs equivalent permissions. # # Three bindings are needed: # 1. keycloak-operator-role — core Kubernetes resources (statefulsets, secrets, # services, pods, jobs, ingresses, configmaps) # 2. keycloakcontroller-cluster-role — keycloaks CRD access # 3. keycloakrealmimportcontroller-cluster-role — keycloakrealmimports CRD access --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: keycloak-operator-role namespace: login rules: - apiGroups: ["apps"] resources: ["statefulsets"] verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] - apiGroups: [""] resources: ["configmaps"] verbs: ["get", "list", "watch"] - apiGroups: [""] resources: ["secrets", "services"] verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] - apiGroups: [""] resources: ["pods"] verbs: ["list"] - apiGroups: ["batch"] resources: ["jobs"] verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] - apiGroups: ["networking.k8s.io"] resources: ["ingresses"] verbs: ["get", "list", "watch", "create", "delete", "patch", "update"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: keycloak-operator-role-binding namespace: login roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: keycloak-operator-role subjects: - kind: ServiceAccount name: keycloak-operator namespace: keycloak-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: keycloakcontroller-role-binding namespace: login roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: keycloakcontroller-cluster-role subjects: - kind: ServiceAccount name: keycloak-operator namespace: keycloak-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: keycloakrealmimportcontroller-role-binding namespace: login roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: keycloakrealmimportcontroller-cluster-role subjects: - kind: ServiceAccount name: keycloak-operator namespace: keycloak-system