Files
login/manifest/overlays/production/keycloak-instance.yaml
T
olb042 6f29be2987
Validate login GitOps repo / validate (push) Successful in 9s
feat: initial scaffold from helm-template
- Keycloak Operator v26 deployed to keycloak-system namespace
- Keycloak HA instance (2 replicas, jdbc-ping cluster discovery)
- Dedicated CNPG cluster (local-postgres storage, 2 instances)
- KeycloakRealmImport: home-lab realm with groups and traefik-oidc client
- Traefik IngressRoute: login.olb42.com (CF Access bypass)
- Admin credentials placeholder (seal before first deploy)
- ArgoCD ApplicationSets: login-operator + login
2026-05-10 22:32:49 +01:00

77 lines
2.7 KiB
YAML

apiVersion: k8s.keycloak.org/v2alpha1
kind: Keycloak
metadata:
name: keycloak
namespace: login
spec:
# ── HA: 2 replicas with Infinispan jdbc-ping cluster discovery ────────────
instances: 2
# ── Image: pin to the same major as the operator release ─────────────────
image: quay.io/keycloak/keycloak:26.2.5
startOptimized: false
# ── Database: CNPG cluster (login-postgres) ───────────────────────────────
# CNPG auto-creates the secret <cluster-name>-app with username/password.
db:
vendor: postgres
host: login-postgres-rw
port: 5432
database: keycloak
usernameSecret:
name: login-postgres-app
key: username
passwordSecret:
name: login-postgres-app
key: password
# ── HTTP: plain HTTP backend; TLS terminated at Traefik ───────────────────
http:
httpEnabled: true
httpPort: 8080
httpsPort: 8443
# No TLS secret — Traefik handles TLS via wildcard cert
# ── Hostname ──────────────────────────────────────────────────────────────
hostname:
hostname: login.olb42.com
admin: login.olb42.com
# strict=false: allow X-Forwarded-Host from Traefik
strict: false
strictBackchannel: false
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
proxy:
headers: forwarded
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
bootstrapAdminSpec:
secret:
name: login-admin
# ── Additional Keycloak options ───────────────────────────────────────────
additionalOptions:
# jdbc-ping: DB-backed cluster discovery — no Kubernetes API/RBAC needed
- name: cache-stack
value: jdbc-ping
- name: cache
value: ispn
- name: log-level
value: INFO
# Forward client IP through Traefik X-Forwarded-For chain
- name: proxy-trusted-addresses
value: "0.0.0.0/0"
# ── Resources ─────────────────────────────────────────────────────────────
resources:
requests:
memory: 512Mi
cpu: 250m
limits:
memory: 1500Mi
cpu: "2"
# ── Ingress disabled: Traefik IngressRoute manages external access ─────────
ingress:
enabled: false