77 lines
2.7 KiB
YAML
77 lines
2.7 KiB
YAML
apiVersion: k8s.keycloak.org/v2alpha1
|
|
kind: Keycloak
|
|
metadata:
|
|
name: keycloak
|
|
namespace: login
|
|
spec:
|
|
# ── HA: 2 replicas with Infinispan jdbc-ping cluster discovery ────────────
|
|
instances: 2
|
|
|
|
# ── Image: pin to the same major as the operator release ─────────────────
|
|
image: quay.io/keycloak/keycloak:26.2.5
|
|
startOptimized: false
|
|
|
|
# ── Database: CNPG cluster (login-postgres) ───────────────────────────────
|
|
# CNPG auto-creates the secret <cluster-name>-app with username/password.
|
|
db:
|
|
vendor: postgres
|
|
host: login-postgres-rw
|
|
port: 5432
|
|
database: keycloak
|
|
usernameSecret:
|
|
name: login-postgres-app
|
|
key: username
|
|
passwordSecret:
|
|
name: login-postgres-app
|
|
key: password
|
|
|
|
# ── HTTP: plain HTTP backend; TLS terminated at Traefik ───────────────────
|
|
http:
|
|
httpEnabled: true
|
|
httpPort: 8080
|
|
httpsPort: 8443
|
|
# No TLS secret — Traefik handles TLS via wildcard cert
|
|
|
|
# ── Hostname ──────────────────────────────────────────────────────────────
|
|
hostname:
|
|
hostname: login.olb42.com
|
|
admin: login.olb42.com
|
|
# strict=false: allow X-Forwarded-Host from Traefik
|
|
strict: false
|
|
strictBackchannel: false
|
|
|
|
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
|
|
proxy:
|
|
headers: forwarded
|
|
|
|
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
|
|
bootstrapAdmin:
|
|
user:
|
|
secret: login-admin
|
|
|
|
# ── Additional Keycloak options ───────────────────────────────────────────
|
|
additionalOptions:
|
|
# jdbc-ping: DB-backed cluster discovery — no Kubernetes API/RBAC needed
|
|
- name: cache-stack
|
|
value: jdbc-ping
|
|
- name: cache
|
|
value: ispn
|
|
- name: log-level
|
|
value: INFO
|
|
# Forward client IP through Traefik X-Forwarded-For chain
|
|
- name: proxy-trusted-addresses
|
|
value: "0.0.0.0/0"
|
|
|
|
# ── Resources ─────────────────────────────────────────────────────────────
|
|
resources:
|
|
requests:
|
|
memory: 512Mi
|
|
cpu: 250m
|
|
limits:
|
|
memory: 1500Mi
|
|
cpu: "2"
|
|
|
|
# ── Ingress disabled: Traefik IngressRoute manages external access ─────────
|
|
ingress:
|
|
enabled: false
|