Files
login/manifest/overlays/production/keycloak-operator-rbac.yaml
T
olb042 8fa904bb6c
Validate login GitOps repo / validate (push) Successful in 10s
fix: add RBAC for keycloak-operator SA to manage resources in login namespace
The upstream operator RBAC is scoped to keycloak-system only. With
QUARKUS_OPERATOR_SDK_NAMESPACES=login the operator tries to watch/manage
resources in login, so it needs a matching Role + RoleBindings there:
- keycloak-operator-role: core resources (statefulsets, secrets, services, etc)
- keycloakcontroller-cluster-role binding: keycloaks CRD access
- keycloakrealmimportcontroller-cluster-role binding: realm import CRD access
2026-05-11 00:11:08 +01:00

81 lines
2.5 KiB
YAML

# RBAC for the Keycloak Operator SA (keycloak-system:keycloak-operator) to
# manage resources in the 'login' namespace.
#
# The upstream kubernetes.yml scopes the operator's Role/RoleBinding to the
# keycloak-system namespace only. When QUARKUS_OPERATOR_SDK_NAMESPACES is set
# to 'login', the operator tries to watch and manage resources here too, so it
# needs equivalent permissions.
#
# Three bindings are needed:
# 1. keycloak-operator-role — core Kubernetes resources (statefulsets, secrets,
# services, pods, jobs, ingresses, configmaps)
# 2. keycloakcontroller-cluster-role — keycloaks CRD access
# 3. keycloakrealmimportcontroller-cluster-role — keycloakrealmimports CRD access
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: keycloak-operator-role
namespace: login
rules:
- apiGroups: ["apps"]
resources: ["statefulsets"]
verbs: ["get", "list", "watch", "create", "delete", "patch", "update"]
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list", "watch"]
- apiGroups: [""]
resources: ["secrets", "services"]
verbs: ["get", "list", "watch", "create", "delete", "patch", "update"]
- apiGroups: [""]
resources: ["pods"]
verbs: ["list"]
- apiGroups: ["batch"]
resources: ["jobs"]
verbs: ["get", "list", "watch", "create", "delete", "patch", "update"]
- apiGroups: ["networking.k8s.io"]
resources: ["ingresses"]
verbs: ["get", "list", "watch", "create", "delete", "patch", "update"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: keycloak-operator-role-binding
namespace: login
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: keycloak-operator-role
subjects:
- kind: ServiceAccount
name: keycloak-operator
namespace: keycloak-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: keycloakcontroller-role-binding
namespace: login
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: keycloakcontroller-cluster-role
subjects:
- kind: ServiceAccount
name: keycloak-operator
namespace: keycloak-system
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: keycloakrealmimportcontroller-role-binding
namespace: login
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: keycloakrealmimportcontroller-cluster-role
subjects:
- kind: ServiceAccount
name: keycloak-operator
namespace: keycloak-system