Files
login/OPERATIONS.md
olb042 6f29be2987
Validate login GitOps repo / validate (push) Successful in 9s
feat: initial scaffold from helm-template
- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
2026-05-10 22:32:49 +01:00

2.0 KiB

login — Keycloak Operator-managed instance

Keycloak HA deployment for login.olb42.com, managed by the official Keycloak Operator. Backs all OIDC authentication across the home-lab.

Architecture

  • Namespace: login
  • Operator namespace: keycloak-system
  • Database: CNPG cluster login-postgres (2 instances, local-postgres storage)
  • Replicas: 2 Keycloak pods with Infinispan jdbc-ping cluster discovery
  • Ingress: login.olb42.com via Traefik IngressRoute (no CF Access — bypass)

Bootstrap order

  1. ArgoCD applies login-operator ApplicationSet → Keycloak Operator deployed
  2. ArgoCD applies login ApplicationSet → CRDs reconciled:
    • CNPG Cluster login-postgres created
    • Keycloak CR reconciled → Operator deploys Keycloak pods
    • KeycloakRealmImport applied → home-lab realm created
    • IngressRoute activates login.olb42.com

Sealing the admin secret

# Edit admin.secret.plain.yaml with your chosen password, then:
kubeseal --context homelab-argocd \
  --secret-file manifest/overlays/production/admin.secret.plain.yaml \
  --sealed-secret-file manifest/overlays/production/admin.sealed.secret.yaml

Adding a per-app Keycloak client

Create a KeycloakRealmImport in the app's own repo:

apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakRealmImport
metadata:
  name: my-app-client
  namespace: login          # must match the Keycloak CR namespace
spec:
  keycloakCRName: keycloak  # must match the Keycloak CR name
  realm:
    realm: home-lab
    clients:
      - clientId: traefik-oidc-my-app
        ...

ArgoCD syncs the KeycloakRealmImport → Operator registers the client in Keycloak → Operator writes traefik-oidc-my-app secret → traefikoidc Middleware references it.

Upgrading Keycloak

  1. Update image: quay.io/keycloak/keycloak:<new-version> in keycloak-instance.yaml
  2. Update the operator remote URL version in manifest/operator/kustomization.yaml
  3. Commit and push — ArgoCD self-heals both ApplicationSets in order