Files
login/manifest/operator/kustomization.yaml
T
olb042 67b1916012
Validate login GitOps repo / validate (push) Successful in 11s
fix: three blocking issues preventing login stack from starting
- keycloak-instance: bootstrapAdminSpec -> bootstrapAdmin (correct CRD field)
- cnpg-cluster: remove barman-cloud plugin block (BarmanObjectStore CRD absent)
- operator/kustomization: patch WATCH_NAMESPACES=login so operator reconciles login ns
2026-05-10 23:14:56 +01:00

34 lines
1.4 KiB
YAML

apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
# Keycloak Operator v26 — official Kubernetes manifests.
# Pin to a specific release tag; bump here when upgrading Keycloak.
# Full release list: https://github.com/keycloak/keycloak-k8s-resources/releases
#
# These resources include:
# - keycloaks.k8s.keycloak.org CRD
# - keycloakrealmimports.k8s.keycloak.org CRD
# - keycloak-operator Deployment + RBAC (deployed to keycloak-system namespace
# as defined in the upstream manifest; operator watches all namespaces)
resources:
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloaks.k8s.keycloak.org-v1.yml
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml
- https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources/26.2.5/kubernetes/kubernetes.yml
# Patch the operator Deployment to watch the 'login' namespace in addition to
# keycloak-system. WATCH_NAMESPACES="" means all namespaces; a comma-separated
# list restricts to those namespaces. Using "login" here is explicit and safe.
patches:
- target:
group: apps
version: v1
kind: Deployment
name: keycloak-operator
patch: |-
- op: add
path: /spec/template/spec/containers/0/env/-
value:
name: WATCH_NAMESPACES
value: "login"