Files
login/OPERATIONS.md
olb042 6f29be2987
Validate login GitOps repo / validate (push) Successful in 9s
feat: initial scaffold from helm-template
- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
2026-05-10 22:32:49 +01:00

60 lines
2.0 KiB
Markdown

# login — Keycloak Operator-managed instance
Keycloak HA deployment for `login.olb42.com`, managed by the official
Keycloak Operator. Backs all OIDC authentication across the home-lab.
## Architecture
- **Namespace**: `login`
- **Operator namespace**: `keycloak-system`
- **Database**: CNPG cluster `login-postgres` (2 instances, `local-postgres` storage)
- **Replicas**: 2 Keycloak pods with Infinispan jdbc-ping cluster discovery
- **Ingress**: `login.olb42.com` via Traefik IngressRoute (no CF Access — bypass)
## Bootstrap order
1. ArgoCD applies `login-operator` ApplicationSet → Keycloak Operator deployed
2. ArgoCD applies `login` ApplicationSet → CRDs reconciled:
- CNPG Cluster `login-postgres` created
- `Keycloak` CR reconciled → Operator deploys Keycloak pods
- `KeycloakRealmImport` applied → `home-lab` realm created
- IngressRoute activates `login.olb42.com`
## Sealing the admin secret
```bash
# Edit admin.secret.plain.yaml with your chosen password, then:
kubeseal --context homelab-argocd \
--secret-file manifest/overlays/production/admin.secret.plain.yaml \
--sealed-secret-file manifest/overlays/production/admin.sealed.secret.yaml
```
## Adding a per-app Keycloak client
Create a `KeycloakRealmImport` in the app's own repo:
```yaml
apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakRealmImport
metadata:
name: my-app-client
namespace: login # must match the Keycloak CR namespace
spec:
keycloakCRName: keycloak # must match the Keycloak CR name
realm:
realm: home-lab
clients:
- clientId: traefik-oidc-my-app
...
```
ArgoCD syncs the `KeycloakRealmImport` → Operator registers the client in
Keycloak → Operator writes `traefik-oidc-my-app` secret → traefikoidc
Middleware references it.
## Upgrading Keycloak
1. Update `image: quay.io/keycloak/keycloak:<new-version>` in `keycloak-instance.yaml`
2. Update the operator remote URL version in `manifest/operator/kustomization.yaml`
3. Commit and push — ArgoCD self-heals both ApplicationSets in order