Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
2.0 KiB
2.0 KiB
login — Keycloak Operator-managed instance
Keycloak HA deployment for login.olb42.com, managed by the official
Keycloak Operator. Backs all OIDC authentication across the home-lab.
Architecture
- Namespace:
login - Operator namespace:
keycloak-system - Database: CNPG cluster
login-postgres(2 instances,local-postgresstorage) - Replicas: 2 Keycloak pods with Infinispan jdbc-ping cluster discovery
- Ingress:
login.olb42.comvia Traefik IngressRoute (no CF Access — bypass)
Bootstrap order
- ArgoCD applies
login-operatorApplicationSet → Keycloak Operator deployed - ArgoCD applies
loginApplicationSet → CRDs reconciled:- CNPG Cluster
login-postgrescreated KeycloakCR reconciled → Operator deploys Keycloak podsKeycloakRealmImportapplied →home-labrealm created- IngressRoute activates
login.olb42.com
- CNPG Cluster
Sealing the admin secret
# Edit admin.secret.plain.yaml with your chosen password, then:
kubeseal --context homelab-argocd \
--secret-file manifest/overlays/production/admin.secret.plain.yaml \
--sealed-secret-file manifest/overlays/production/admin.sealed.secret.yaml
Adding a per-app Keycloak client
Create a KeycloakRealmImport in the app's own repo:
apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakRealmImport
metadata:
name: my-app-client
namespace: login # must match the Keycloak CR namespace
spec:
keycloakCRName: keycloak # must match the Keycloak CR name
realm:
realm: home-lab
clients:
- clientId: traefik-oidc-my-app
...
ArgoCD syncs the KeycloakRealmImport → Operator registers the client in
Keycloak → Operator writes traefik-oidc-my-app secret → traefikoidc
Middleware references it.
Upgrading Keycloak
- Update
image: quay.io/keycloak/keycloak:<new-version>inkeycloak-instance.yaml - Update the operator remote URL version in
manifest/operator/kustomization.yaml - Commit and push — ArgoCD self-heals both ApplicationSets in order