From 81fdbc130c29ba228d6262198e5bd603959eb04e Mon Sep 17 00:00:00 2001 From: Thomas Blarre Date: Thu, 7 Nov 2024 18:28:36 +0000 Subject: [PATCH] Added keycloak operator --- k3s-tooling/templates/keycloak-operator.yaml | 28 +++++++++ k3s-tooling/values.yaml | 5 ++ keycloak-operator/.helmignore | 23 +++++++ keycloak-operator/Chart.yaml | 6 ++ keycloak-operator/templates/_helpers.tpl | 62 +++++++++++++++++++ keycloak-operator/templates/keycloak-crd.yaml | 15 +++++ .../templates/keycloak-operator.yaml | 17 +++++ .../templates/keycloakrealmimports-crd.yaml | 15 +++++ keycloak-operator/values.yaml | 1 + 9 files changed, 172 insertions(+) create mode 100644 k3s-tooling/templates/keycloak-operator.yaml create mode 100644 keycloak-operator/.helmignore create mode 100644 keycloak-operator/Chart.yaml create mode 100644 keycloak-operator/templates/_helpers.tpl create mode 100644 keycloak-operator/templates/keycloak-crd.yaml create mode 100644 keycloak-operator/templates/keycloak-operator.yaml create mode 100644 keycloak-operator/templates/keycloakrealmimports-crd.yaml create mode 100644 keycloak-operator/values.yaml diff --git a/k3s-tooling/templates/keycloak-operator.yaml b/k3s-tooling/templates/keycloak-operator.yaml new file mode 100644 index 0000000..9f124e6 --- /dev/null +++ b/k3s-tooling/templates/keycloak-operator.yaml @@ -0,0 +1,28 @@ +{{- if .Values.keycloakOperator.enable -}} +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: keycloak-operator + namespace: {{ .Values.argocd.namespace }} + annotations: + notifications.argoproj.io/subscribe.on-sync-succeeded.telegram: "-1002270587578" +spec: + project: {{ .Values.argocd.project }} + source: + repoURL: "https://git.blarre.net/thomas/helm-charts.git" + targetRevision: HEAD + path: keycloak-operator + helm: + releaseName: keycloak-operator + destination: + server: {{ .Values.keycloakOperator.destination.server }} + namespace: {{ .Values.keycloakOperator.destination.namespace }} + syncPolicy: + automated: + prune: true # Automatically remove resources no longer in the repo + selfHeal: true # Automatically self-heal when drift is detected + syncOptions: + - ApplyOutOfSyncOnly=true + - ServerSideApply=true + - CreateNamespace=true +{{- end }} diff --git a/k3s-tooling/values.yaml b/k3s-tooling/values.yaml index 98fbd99..6f09a59 100644 --- a/k3s-tooling/values.yaml +++ b/k3s-tooling/values.yaml @@ -41,3 +41,8 @@ traefik: server: https://kubernetes.default.svc namespace: kube-system +keycloak-operator: + enable: false + destination: + server: https://kubernetes.default.svc + namespace: keycloak \ No newline at end of file diff --git a/keycloak-operator/.helmignore b/keycloak-operator/.helmignore new file mode 100644 index 0000000..0e8a0eb --- /dev/null +++ b/keycloak-operator/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/keycloak-operator/Chart.yaml b/keycloak-operator/Chart.yaml new file mode 100644 index 0000000..4176627 --- /dev/null +++ b/keycloak-operator/Chart.yaml @@ -0,0 +1,6 @@ +apiVersion: v2 +name: keycloak-operator +description: A Helm chart for the Keycloak operator +type: application +version: 0.1.0 +appVersion: "26.0.5" diff --git a/keycloak-operator/templates/_helpers.tpl b/keycloak-operator/templates/_helpers.tpl new file mode 100644 index 0000000..c8dc28c --- /dev/null +++ b/keycloak-operator/templates/_helpers.tpl @@ -0,0 +1,62 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "keycloak-operator.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "keycloak-operator.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "keycloak-operator.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "keycloak-operator.labels" -}} +helm.sh/chart: {{ include "keycloak-operator.chart" . }} +{{ include "keycloak-operator.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "keycloak-operator.selectorLabels" -}} +app.kubernetes.io/name: {{ include "keycloak-operator.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "keycloak-operator.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "keycloak-operator.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/keycloak-operator/templates/keycloak-crd.yaml b/keycloak-operator/templates/keycloak-crd.yaml new file mode 100644 index 0000000..1365223 --- /dev/null +++ b/keycloak-operator/templates/keycloak-crd.yaml @@ -0,0 +1,15 @@ +apiVersion: batch/v1 +kind: Job +metadata: + name: keycloak-crd-job +spec: + template: + spec: + containers: + - name: crd-fetcher + image: bitnami/kubectl:latest # Use Bitnami's kubectl image + command: + - "sh" + - "-c" + - "curl -fL {{ .Values.baseURL }}/{{ .Release.appVersion }}/kubernetes/keycloaks.k8s.keycloak.org-v1.yml -o /tmp/keycloak-crd.yml && kubectl apply -f /tmp/keycloak-crd.yml" + restartPolicy: OnFailure \ No newline at end of file diff --git a/keycloak-operator/templates/keycloak-operator.yaml b/keycloak-operator/templates/keycloak-operator.yaml new file mode 100644 index 0000000..68888a7 --- /dev/null +++ b/keycloak-operator/templates/keycloak-operator.yaml @@ -0,0 +1,17 @@ +apiVersion: batch/v1 +kind: Job +metadata: + name: keycloakoperator-job + annotations: + "helm.sh/hook": post-install +spec: + template: + spec: + containers: + - name: crd-fetcher + image: bitnami/kubectl:latest # Use Bitnami's kubectl image + command: + - "sh" + - "-c" + - "curl -fL {{ .Values.baseURL }}/{{ .Release.appVersion }}/kubernetes/kubernetes.yml -o /tmp/keycloakoperator.yml && kubectl apply -f /tmp/keycloakoperator.yml" + restartPolicy: OnFailure \ No newline at end of file diff --git a/keycloak-operator/templates/keycloakrealmimports-crd.yaml b/keycloak-operator/templates/keycloakrealmimports-crd.yaml new file mode 100644 index 0000000..db18a1f --- /dev/null +++ b/keycloak-operator/templates/keycloakrealmimports-crd.yaml @@ -0,0 +1,15 @@ +apiVersion: batch/v1 +kind: Job +metadata: + name: keycloakrealmimports-crd-job +spec: + template: + spec: + containers: + - name: crd-fetcher + image: bitnami/kubectl:latest # Use Bitnami's kubectl image + command: + - "sh" + - "-c" + - "curl -fL {{ .Values.baseURL }}/{{ .Release.appVersion }}/kubernetes/keycloakrealmimports.k8s.keycloak.org-v1.yml -o /tmp/keycloakrealmimports-crd.yml && kubectl apply -f /tmp/keycloakrealmimports-crd.yml" + restartPolicy: OnFailure \ No newline at end of file diff --git a/keycloak-operator/values.yaml b/keycloak-operator/values.yaml new file mode 100644 index 0000000..f2ac8bc --- /dev/null +++ b/keycloak-operator/values.yaml @@ -0,0 +1 @@ +baseURL: "https://raw.githubusercontent.com/keycloak/keycloak-k8s-resources"