chore(keyclok): switch to using a secret for admin credentials, try to use Postgres instead of SQLite

This commit is contained in:
David Landry 2024-03-28 12:17:20 -05:00
parent dbc1b6b4b9
commit da2cb9a4df
2 changed files with 98 additions and 3 deletions

View file

@ -1,4 +1,14 @@
apiVersion: v1 apiVersion: v1
data:
password: YkJiNXU3NXRaYUR0ZHVudw==
username: YWRtaW4=
kind: Secret
metadata:
name: keycloak-admin
type: kubernetes.io/basic-auth
---
apiVersion: v1
kind: Service kind: Service
metadata: metadata:
name: keycloak name: keycloak
@ -12,6 +22,7 @@ spec:
selector: selector:
app: keycloak app: keycloak
type: LoadBalancer type: LoadBalancer
--- ---
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
@ -35,11 +46,47 @@ spec:
args: ["start-dev"] args: ["start-dev"]
env: env:
- name: KEYCLOAK_ADMIN - name: KEYCLOAK_ADMIN
value: "admin" valueFrom:
secretKeyRef:
key: username
name: keycloak-admin
- name: KEYCLOAK_ADMIN_PASSWORD - name: KEYCLOAK_ADMIN_PASSWORD
value: "bBb5u75tZaDtdunw" valueFrom:
secretKeyRef:
key: password
name: keycloak-admin
- name: KC_PROXY - name: KC_PROXY
value: "edge" value: "edge"
- name: KC_HEALTH_ENABLED
value: "true"
- name: KC_METRICS_ENABLED
value: "true"
- name: KC_HOSTNAME_STRICT_HTTPS
value: "true"
- name: KC_LOG_LEVEL
value: INFO
- name: KC_DB
value: postgres
- name: POSTGRES_DB
valueFrom:
secretKeyRef:
name: keycloak-pg-cluster-app
key: username
- name: KC_DB_URL
valueFrom:
secretKeyRef:
name: keycloak-pg-cluster-app
key: jdbc-uri
- name: KC_DB_USERNAME
valueFrom:
secretKeyRef:
name: keycloak-pg-cluster-app
key: username
- name: KC_DB_PASSWORD
valueFrom:
secretKeyRef:
name: keycloak-pg-cluster-app
key: password
ports: ports:
- name: http - name: http
containerPort: 8080 containerPort: 8080

View file

@ -1,9 +1,57 @@
apiVersion: v1
kind: Secret
metadata:
name: backup-creds
data:
ACCESS_KEY_ID: a2V5X2lk
ACCESS_SECRET_KEY: c2VjcmV0X2tleQ==
---
apiVersion: postgresql.cnpg.io/v1 apiVersion: postgresql.cnpg.io/v1
kind: Cluster kind: Cluster
metadata: metadata:
name: keycloak name: keycloak-pg-cluster
spec: spec:
instances: 1 instances: 1
storage: storage:
size: 1Gi size: 1Gi
bootstrap:
initdb:
database: keycloak
# enableSuperuserAccess: true
# backup:
# barmanObjectStore:
# destinationPath: s3://cluster-example-full-backup/
# endpointURL: http://custom-endpoint:1234
# s3Credentials:
# accessKeyId:
# name: backup-creds
# key: ACCESS_KEY_ID
# secretAccessKey:
# name: backup-creds
# key: ACCESS_SECRET_KEY
# wal:
# compression: gzip
# encryption: AES256
# data:
# compression: gzip
# encryption: AES256
# immediateCheckpoint: false
# jobs: 2
# retentionPolicy: "30d"
# resources:
# requests:
# memory: "512Mi"
# cpu: "1"
# limits:
# memory: "1Gi"
# cpu: "2"
# affinity:
# enablePodAntiAffinity: true
# topologyKey: failure-domain.beta.kubernetes.io/zone