Validate login GitOps repo / validate (push) Successful in 9s
- Keycloak Operator v26 deployed to keycloak-system namespace - Keycloak HA instance (2 replicas, jdbc-ping cluster discovery) - Dedicated CNPG cluster (local-postgres storage, 2 instances) - KeycloakRealmImport: home-lab realm with groups and traefik-oidc client - Traefik IngressRoute: login.olb42.com (CF Access bypass) - Admin credentials placeholder (seal before first deploy) - ArgoCD ApplicationSets: login-operator + login
101 lines
4.1 KiB
YAML
101 lines
4.1 KiB
YAML
apiVersion: k8s.keycloak.org/v2alpha1
|
|
kind: KeycloakRealmImport
|
|
metadata:
|
|
name: home-lab
|
|
namespace: login
|
|
spec:
|
|
keycloakCRName: keycloak
|
|
|
|
# ── Realm definition ──────────────────────────────────────────────────────
|
|
# This is a Keycloak realm export JSON embedded as a structured spec.
|
|
# The operator applies this on startup and reconciles on changes.
|
|
# Add clients, groups, and roles here; per-app clients can be managed in
|
|
# their own app repos by adding additional KeycloakRealmImport resources
|
|
# targeting this same keycloakCRName.
|
|
realm:
|
|
realm: home-lab
|
|
displayName: "Home Lab"
|
|
enabled: true
|
|
loginWithEmailAllowed: true
|
|
duplicateEmailsAllowed: false
|
|
resetPasswordAllowed: true
|
|
editUsernameAllowed: false
|
|
bruteForceProtected: true
|
|
permanentLockout: false
|
|
maxFailureWaitSeconds: 900
|
|
minimumQuickLoginWaitSeconds: 60
|
|
waitIncrementSeconds: 60
|
|
quickLoginCheckMilliSeconds: 1000
|
|
maxDeltaTimeSeconds: 43200
|
|
failureFactor: 10
|
|
|
|
# ── Session settings ──────────────────────────────────────────────────
|
|
ssoSessionIdleTimeout: 1800
|
|
ssoSessionMaxLifespan: 36000
|
|
accessTokenLifespan: 300
|
|
accessTokenLifespanForImplicitFlow: 900
|
|
offlineSessionIdleTimeout: 2592000
|
|
offlineSessionMaxLifespanEnabled: false
|
|
|
|
# ── Password policy ───────────────────────────────────────────────────
|
|
passwordPolicy: "length(12) and notUsername(undefined)"
|
|
|
|
# ── Groups ────────────────────────────────────────────────────────────
|
|
groups:
|
|
- name: homelab-admin
|
|
path: /homelab-admin
|
|
- name: homelab-user
|
|
path: /homelab-user
|
|
- name: transmission-users
|
|
path: /transmission-users
|
|
- name: media-users
|
|
path: /media-users
|
|
- name: monitoring-users
|
|
path: /monitoring-users
|
|
|
|
# ── Default client scopes ─────────────────────────────────────────────
|
|
defaultDefaultClientScopes:
|
|
- web-origins
|
|
- acr
|
|
- roles
|
|
- profile
|
|
- basic
|
|
- email
|
|
|
|
# ── Clients ───────────────────────────────────────────────────────────
|
|
# traefik-oidc: shared client for traefikoidc middleware (SSO cookie domain)
|
|
# Per-app clients with dedicated redirect URIs and claim mappers should be
|
|
# added as additional KeycloakRealmImport resources in each app's repo.
|
|
clients:
|
|
- clientId: traefik-oidc
|
|
name: "Traefik OIDC"
|
|
description: "Shared OIDC client for Traefik traefikoidc middleware"
|
|
enabled: true
|
|
publicClient: false
|
|
standardFlowEnabled: true
|
|
implicitFlowEnabled: false
|
|
directAccessGrantsEnabled: false
|
|
serviceAccountsEnabled: false
|
|
authorizationServicesEnabled: false
|
|
redirectUris:
|
|
- "https://transmission-ng.olb42.com/oauth2/callback"
|
|
- "https://home.olb42.com/oauth2/callback"
|
|
- "https://dozzle.olb42.com/oauth2/callback"
|
|
- "https://pgadmin4.olb42.com/oauth2/callback"
|
|
webOrigins:
|
|
- "+"
|
|
attributes:
|
|
pkce.code.challenge.method: "S256"
|
|
post.logout.redirect.uris: "+"
|
|
protocolMappers:
|
|
- name: groups
|
|
protocol: openid-connect
|
|
protocolMapper: oidc-group-membership-mapper
|
|
consentRequired: false
|
|
config:
|
|
full.path: "false"
|
|
id.token.claim: "true"
|
|
access.token.claim: "true"
|
|
claim.name: "groups"
|
|
userinfo.token.claim: "true"
|