apiVersion: k8s.keycloak.org/v2alpha1 kind: KeycloakRealmImport metadata: name: home-lab namespace: login spec: keycloakCRName: keycloak # ── Realm definition ────────────────────────────────────────────────────── # This is a Keycloak realm export JSON embedded as a structured spec. # The operator applies this on startup and reconciles on changes. # Add clients, groups, and roles here; per-app clients can be managed in # their own app repos by adding additional KeycloakRealmImport resources # targeting this same keycloakCRName. realm: realm: home-lab displayName: "Home Lab" enabled: true loginWithEmailAllowed: true duplicateEmailsAllowed: false resetPasswordAllowed: true editUsernameAllowed: false bruteForceProtected: true permanentLockout: false maxFailureWaitSeconds: 900 minimumQuickLoginWaitSeconds: 60 waitIncrementSeconds: 60 quickLoginCheckMilliSeconds: 1000 maxDeltaTimeSeconds: 43200 failureFactor: 10 # ── Session settings ────────────────────────────────────────────────── ssoSessionIdleTimeout: 1800 ssoSessionMaxLifespan: 36000 accessTokenLifespan: 300 accessTokenLifespanForImplicitFlow: 900 offlineSessionIdleTimeout: 2592000 offlineSessionMaxLifespanEnabled: false # ── Password policy ─────────────────────────────────────────────────── passwordPolicy: "length(12) and notUsername(undefined)" # ── Groups ──────────────────────────────────────────────────────────── groups: - name: homelab-admin path: /homelab-admin - name: homelab-user path: /homelab-user - name: transmission-users path: /transmission-users - name: media-users path: /media-users - name: monitoring-users path: /monitoring-users # ── Default client scopes ───────────────────────────────────────────── defaultDefaultClientScopes: - web-origins - acr - roles - profile - basic - email # ── Clients ─────────────────────────────────────────────────────────── # traefik-oidc: shared client for traefikoidc middleware (SSO cookie domain) # Per-app clients with dedicated redirect URIs and claim mappers should be # added as additional KeycloakRealmImport resources in each app's repo. clients: - clientId: traefik-oidc name: "Traefik OIDC" description: "Shared OIDC client for Traefik traefikoidc middleware" enabled: true publicClient: false standardFlowEnabled: true implicitFlowEnabled: false directAccessGrantsEnabled: false serviceAccountsEnabled: false authorizationServicesEnabled: false redirectUris: - "https://transmission-ng.olb42.com/oauth2/callback" - "https://home.olb42.com/oauth2/callback" - "https://dozzle.olb42.com/oauth2/callback" - "https://pgadmin4.olb42.com/oauth2/callback" webOrigins: - "+" attributes: pkce.code.challenge.method: "S256" post.logout.redirect.uris: "+" protocolMappers: - name: groups protocol: openid-connect protocolMapper: oidc-group-membership-mapper consentRequired: false config: full.path: "false" id.token.claim: "true" access.token.claim: "true" claim.name: "groups" userinfo.token.claim: "true"