Files
olb042 648c7f0266
Validate login GitOps repo / validate (push) Successful in 12s
fix: use correct QUARKUS_OPERATOR_SDK_NAMESPACES env var for operator namespace watch
WATCH_NAMESPACES is not a JOSDK env var. The Quarkus JOSDK extension reads
QUARKUS_OPERATOR_SDK_NAMESPACES (maps to quarkus.operator-sdk.namespaces).

Also: update CNPG anti-affinity topology key from kubernetes.io/hostname to
topology.kubernetes.io/zone to spread primary and replica across pve-1 / pve-2.
2026-05-11 00:06:33 +01:00

36 lines
1.5 KiB
YAML

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
# Keycloak Operator v26 — official Kubernetes manifests.
# Pin to a specific release tag; bump here when upgrading Keycloak.
# Full release list: https://github.com/keycloak/keycloak-k8s-resources/releases
#
# These resources include:
# - keycloaks.k8s.keycloak.org CRD
# - keycloakrealmimports.k8s.keycloak.org CRD
# - keycloak-operator Deployment + RBAC (deployed to keycloak-system namespace
# as defined in the upstream manifest; operator watches all namespaces)
resources:
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
# Patch the operator Deployment so it reconciles CRs in the 'login' namespace.
# The Keycloak Operator uses Quarkus JOSDK — the correct env var is
# QUARKUS_OPERATOR_SDK_NAMESPACES (maps to quarkus.operator-sdk.namespaces).
# A comma-separated list, or "*" for all namespaces. The operator already has
# ClusterRoles so it has the RBAC to watch any namespace.
patches:
- target:
group: apps
version: v1
kind: Deployment
name: keycloak-operator
patch: |-
- op: add
path: /spec/template/spec/containers/0/env/-
value:
name: QUARKUS_OPERATOR_SDK_NAMESPACES
value: "login"