KeycloakInstance
keycloak.hostzero.com / v1beta1
apiVersion: keycloak.hostzero.com/v1beta1
kind: KeycloakInstance
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object
KeycloakInstanceSpec defines the desired state of KeycloakInstance
auth object required
Auth selects how the operator authenticates to Keycloak.
Exactly one of auth.passwordGrant or auth.clientCredentials must be set.
clientCredentials object
ClientCredentials configures OAuth2 client_credentials grant
authentication via a confidential client / service account.
clientId
string
ClientID, when set, overrides the value read from secretRef.clientIdKey.
The client ID is not a secret, so providing it inline is allowed.
secretRef object required
ClientCredentialsSecretRefSpec references a Secret containing client credentials.
clientIdKey
string
ClientIdKey is ignored when ClientCredentialsSpec.ClientID is set.
clientSecretKey
string
name
string required
namespace
string
Namespace defaults to the KeycloakInstance namespace when unset.
passwordGrant object
PasswordGrant configures resource-owner password grant authentication
against a user account (typically the master-realm admin).
secretRef object required
PasswordGrantSecretRefSpec references a Secret containing admin credentials.
name
string required
namespace
string
Namespace defaults to the KeycloakInstance namespace when unset.
passwordKey
string
usernameKey
string
UsernameKey is ignored when PasswordGrantSpec.Username is set.
username
string
Username, when set, overrides the value read from secretRef.usernameKey.
The admin username is not a secret, so providing it inline is allowed.
baseUrl
string required
BaseUrl is the URL of the Keycloak server (e.g., http://keycloak:8080)
realm
string
Realm is the admin realm (defaults to "master")
tls object
TLS configures how the operator verifies the Keycloak server certificate.
caCert object
CACert references a Secret or ConfigMap holding a PEM-encoded CA bundle
used to verify the Keycloak server certificate.
configMapRef object
CACertConfigMapRefSpec references a ConfigMap key holding a PEM-encoded CA
bundle (e.g. kube-root-ca.crt or a cert-manager CA bundle).
key
string
name
string required
namespace
string
Namespace defaults to the KeycloakInstance namespace when unset.
secretRef object
CACertSecretRefSpec references a Secret key holding a PEM-encoded CA bundle.
key
string
name
string required
namespace
string
Namespace defaults to the KeycloakInstance namespace when unset.
insecureSkipVerify
boolean
InsecureSkipVerify disables TLS certificate verification. Do not enable
in production.
token object
Token contains optional token caching configuration
expiresKey
string
ExpiresKey is the key in the secret for the token expiration
secretName
string
SecretName is the name of the secret to cache the token
tokenKey
string
TokenKey is the key in the secret for the token
status object
KeycloakInstanceStatus defines the observed state of KeycloakInstance
conditions []object
Conditions represent the latest available observations
lastTransitionTime
string required
lastTransitionTime is the last time the condition transitioned from one status to another.
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
format:
date-time
message
string required
message is a human readable message indicating details about the transition.
This may be an empty string.
maxLength:
32768
observedGeneration
integer
observedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64minimum:
0
reason
string required
reason contains a programmatic identifier indicating the reason for the condition's last transition.
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
pattern:
^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$minLength:
1maxLength:
1024
status
string required
status of the condition, one of True, False, Unknown.
enum:
True, False, Unknown
type
string required
type of condition in CamelCase or in foo.example.com/CamelCase.
pattern:
^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$maxLength:
316
message
string
Message contains additional information about the status
ready
boolean required
Ready indicates if the Keycloak instance is accessible
resourcePath
string
ResourcePath is the API path for this resource
status
string
Status is a human-readable status message
version
string
Version is the Keycloak server version
No matches. Try .spec.auth for an exact path