Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
100 lines
3.1 KiB
YAML
100 lines
3.1 KiB
YAML
# ── ApplicationSet 1: Keycloak Operator (CRDs + controller) ──────────────────
|
|
# Deploys the Keycloak Operator into its own namespace so it can manage
|
|
# Keycloak instances cluster-wide. The operator install includes cluster-scoped
|
|
# resources (CRDs, ClusterRoles) which must be applied with ServerSideApply.
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: ApplicationSet
|
|
metadata:
|
|
name: login-operator
|
|
namespace: argocd
|
|
spec:
|
|
ignoreApplicationDifferences:
|
|
- jsonPointers:
|
|
- /spec/syncPolicy
|
|
goTemplate: true
|
|
goTemplateOptions: ["missingkey=error"]
|
|
generators:
|
|
- list:
|
|
elements:
|
|
- environment: production
|
|
namespace: keycloak-system
|
|
template:
|
|
metadata:
|
|
name: 'login-operator-{{ .environment }}'
|
|
labels:
|
|
app.kubernetes.io/managed-by: argocd
|
|
app.kubernetes.io/name: login-operator
|
|
spec:
|
|
project: default
|
|
source:
|
|
repoURL: http://gitea-ha-http.apps:3000/olb42/login.git
|
|
targetRevision: main
|
|
path: manifest/operator
|
|
kustomize:
|
|
commonAnnotationsEnvsubst: true
|
|
commonAnnotations:
|
|
app-source: ${ARGOCD_APP_SOURCE_REPO_URL}
|
|
app-revision: ${ARGOCD_APP_SOURCE_TARGET_REVISION}
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: '{{ .namespace }}'
|
|
syncPolicy:
|
|
automated:
|
|
prune: false
|
|
selfHeal: true
|
|
enabled: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
- ApplyOutOfSyncOnly=true
|
|
- ServerSideApply=true
|
|
- Replace=false
|
|
---
|
|
# ── ApplicationSet 2: login Keycloak instance ────────────────────────────────
|
|
# Deploys the Keycloak CR, CNPG cluster, IngressRoute, and realm config.
|
|
# Depends on login-operator being synced first (CRDs must exist).
|
|
apiVersion: argoproj.io/v1alpha1
|
|
kind: ApplicationSet
|
|
metadata:
|
|
name: login
|
|
namespace: argocd
|
|
spec:
|
|
ignoreApplicationDifferences:
|
|
- jsonPointers:
|
|
- /spec/syncPolicy
|
|
goTemplate: true
|
|
goTemplateOptions: ["missingkey=error"]
|
|
generators:
|
|
- list:
|
|
elements:
|
|
- environment: production
|
|
namespace: login
|
|
template:
|
|
metadata:
|
|
name: 'login-{{ .environment }}'
|
|
labels:
|
|
app.kubernetes.io/managed-by: argocd
|
|
app.kubernetes.io/name: login
|
|
spec:
|
|
project: default
|
|
source:
|
|
repoURL: http://gitea-ha-http.apps:3000/olb42/login.git
|
|
targetRevision: main
|
|
path: 'manifest/overlays/{{ .environment }}'
|
|
kustomize:
|
|
commonAnnotationsEnvsubst: true
|
|
commonAnnotations:
|
|
app-source: ${ARGOCD_APP_SOURCE_REPO_URL}
|
|
app-revision: ${ARGOCD_APP_SOURCE_TARGET_REVISION}
|
|
destination:
|
|
server: https://kubernetes.default.svc
|
|
namespace: '{{ .namespace }}'
|
|
syncPolicy:
|
|
automated:
|
|
prune: true
|
|
selfHeal: true
|
|
enabled: true
|
|
syncOptions:
|
|
- CreateNamespace=true
|
|
- ApplyOutOfSyncOnly=true
|
|
- ServerSideApply=true
|