Files
olb042 8fa904bb6c
Validate login GitOps repo / validate (push) Successful in 10s
fix: add RBAC for keycloak-operator SA to manage resources in login namespace
The upstream operator RBAC is scoped to keycloak-system only. With
QUARKUS_OPERATOR_SDK_NAMESPACES=login the operator tries to watch/manage
resources in login, so it needs a matching Role + RoleBindings there:
- keycloak-operator-role: core resources (statefulsets, secrets, services, etc)
- keycloakcontroller-cluster-role binding: keycloaks CRD access
- keycloakrealmimportcontroller-cluster-role binding: realm import CRD access
2026-05-11 00:11:08 +01:00

18 lines
374 B
YAML

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: login
resources:
- ../../base/state
- keycloak-operator-rbac.yaml
- cnpg-cluster.yaml
- keycloak-instance.yaml
- keycloak-realm-home-lab.yaml
- ingressroute.yaml
- admin.sealed.secret.yaml
commonLabels:
app.kubernetes.io/part-of: login
app.kubernetes.io/environment: production