ClusterKeycloakInstance
keycloak.hostzero.com / v1beta1
apiVersion: keycloak.hostzero.com/v1beta1
kind: ClusterKeycloakInstance
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object
ClusterKeycloakInstanceSpec defines the desired state of ClusterKeycloakInstance.
It mirrors KeycloakInstanceSpec but is cluster-scoped: secret references must
specify a namespace explicitly.
auth object required
Auth selects how the operator authenticates to Keycloak.
Exactly one of auth.passwordGrant or auth.clientCredentials must be set.
clientCredentials object
ClusterClientCredentialsSpec configures OAuth2 client_credentials
authentication for cluster-scoped instances.
clientId
string
ClientID, when set, overrides secretRef.clientIdKey.
secretRef object required
ClusterClientCredentialsSecretRefSpec references a client-credentials Secret.
Namespace is required because the resource is cluster-scoped.
clientIdKey
string
clientSecretKey
string
name
string required
namespace
string required
passwordGrant object
ClusterPasswordGrantSpec configures password-grant authentication
for cluster-scoped instances.
secretRef object required
ClusterPasswordGrantSecretRefSpec references an admin-credentials Secret.
Namespace is required because the resource is cluster-scoped.
name
string required
namespace
string required
passwordKey
string
usernameKey
string
username
string
Username, when set, overrides secretRef.usernameKey.
baseUrl
string required
BaseUrl is the URL of the Keycloak server (e.g., http://keycloak:8080)
realm
string
Realm is the admin realm (defaults to "master")
tls object
TLS configures how the operator verifies the Keycloak server certificate.
caCert object
ClusterCACertSource references a Secret or ConfigMap key containing a
PEM-encoded CA bundle. Exactly one of secretRef or configMapRef must be set.
configMapRef object
ClusterCACertConfigMapRefSpec is the cluster-scoped variant; namespace required.
key
string
name
string required
namespace
string required
secretRef object
ClusterCACertSecretRefSpec is the cluster-scoped variant; namespace required.
key
string
name
string required
namespace
string required
insecureSkipVerify
boolean
token object
Token contains optional token caching configuration
expiresKey
string
ExpiresKey is the key in the secret for the token expiration
secretName
string
SecretName is the name of the secret to cache the token
tokenKey
string
TokenKey is the key in the secret for the token
status object
ClusterKeycloakInstanceStatus defines the observed state of ClusterKeycloakInstance
conditions []object
Conditions represent the latest available observations
lastTransitionTime
string required
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format:
date-time
message
string required
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength:
32768
observedGeneration
integer
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64minimum:
0
reason
string required
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
pattern:
^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$minLength:
1maxLength:
1024
status
string required
status of the condition, one of True, False, Unknown.
enum:
True, False, Unknown
type
string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern:
^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$maxLength:
316
message
string
Message contains additional information about the status
ready
boolean required
Ready indicates if the Keycloak instance is accessible
resourcePath
string
ResourcePath is the API path for this resource
status
string
Status is a human-readable status message
version
string
Version is the Keycloak server version
No matches. Try .spec.auth for an exact path