Files
login/manifest/overlays/production/keycloak-instance.yaml
T
olb042 716ad61115
Validate login GitOps repo / validate (push) Successful in 12s
fix: remove hostname.admin field - not a valid URL format in KC v26
Keycloak v26 hostname-admin expects a full URL (https://...) not bare hostname.
Dropping it so KC defaults admin to the same as the main hostname.
2026-05-11 00:15:50 +01:00

77 lines
2.7 KiB
YAML

apiVersion: k8s.keycloak.org/v2alpha1
kind: Keycloak
metadata:
name: keycloak
namespace: login
spec:
# ── HA: 2 replicas with Infinispan jdbc-ping cluster discovery ────────────
instances: 2
# ── Image: pin to the same major as the operator release ─────────────────
image: quay.io/keycloak/keycloak:26.2.5
startOptimized: false
# ── Database: CNPG cluster (login-postgres) ───────────────────────────────
# CNPG auto-creates the secret <cluster-name>-app with username/password.
db:
vendor: postgres
host: login-postgres-rw
port: 5432
database: keycloak
usernameSecret:
name: login-postgres-app
key: username
passwordSecret:
name: login-postgres-app
key: password
# ── HTTP: plain HTTP backend; TLS terminated at Traefik ───────────────────
http:
httpEnabled: true
httpPort: 8080
httpsPort: 8443
# No TLS secret — Traefik handles TLS via wildcard cert
# ── Hostname ──────────────────────────────────────────────────────────────
hostname:
hostname: login.olb42.com
# admin omitted: defaults to same as hostname
# strict=false: allow X-Forwarded-Host from Traefik
strict: false
strictBackchannel: false
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
proxy:
headers: forwarded
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
bootstrapAdmin:
user:
secret: login-admin
# ── Additional Keycloak options ───────────────────────────────────────────
additionalOptions:
# jdbc-ping: DB-backed cluster discovery — no Kubernetes API/RBAC needed
- name: cache-stack
value: jdbc-ping
- name: cache
value: ispn
- name: log-level
value: INFO
# Forward client IP through Traefik X-Forwarded-For chain
- name: proxy-trusted-addresses
value: "0.0.0.0/0"
# ── Resources ─────────────────────────────────────────────────────────────
resources:
requests:
memory: 512Mi
cpu: 250m
limits:
memory: 1500Mi
cpu: "2"
# ── Ingress disabled: Traefik IngressRoute manages external access ─────────
ingress:
enabled: false