diff --git a/keycloak-argocd-apps/.helmignore b/keycloak-argocd-apps/.helmignore new file mode 100644 index 0000000..0e8a0eb --- /dev/null +++ b/keycloak-argocd-apps/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/keycloak-argocd-apps/Chart.yaml b/keycloak-argocd-apps/Chart.yaml new file mode 100644 index 0000000..5769ff4 --- /dev/null +++ b/keycloak-argocd-apps/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v2 +name: keycloak-argocd-apps +description: A Helm chart for deploying the different argocd apps to deploy Keycloak +type: application +version: 0.1.0 diff --git a/keycloak-argocd-apps/templates/_helpers.tpl b/keycloak-argocd-apps/templates/_helpers.tpl new file mode 100644 index 0000000..2e5a1c0 --- /dev/null +++ b/keycloak-argocd-apps/templates/_helpers.tpl @@ -0,0 +1,62 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "keycloak-argocd-apps.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "keycloak-argocd-apps.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "keycloak-argocd-apps.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "keycloak-argocd-apps.labels" -}} +helm.sh/chart: {{ include "keycloak-argocd-apps.chart" . }} +{{ include "keycloak-argocd-apps.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "keycloak-argocd-apps.selectorLabels" -}} +app.kubernetes.io/name: {{ include "keycloak-argocd-apps.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "keycloak-argocd-apps.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "keycloak-argocd-apps.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/keycloak-argocd-apps/templates/keycloak-deployment-app.yaml b/keycloak-argocd-apps/templates/keycloak-deployment-app.yaml new file mode 100644 index 0000000..f2d32d1 --- /dev/null +++ b/keycloak-argocd-apps/templates/keycloak-deployment-app.yaml @@ -0,0 +1,31 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: keycloak-deployment + namespace: {{ .Values.argocd.namespace }} + annotations: + argocd.argoproj.io/sync-wave: "0" + notifications.argoproj.io/subscribe.on-sync-succeeded.telegram: "-1002270587578" +spec: + project: {{ .Values.argocd.project }} + source: + repoURL: "https://git.blarre.net/thomas/helm-charts.git" + targetRevision: HEAD + path: keycloak-deployment + helm: + releaseName: keycloak-deployment + valuesObject: + keycloakDeployment: + numInstances: {{ .Values.keycloakDeployment.numInstances }} + hostname: {{ .Values.keycloakDeployment.hostname }} + destination: + server: {{ .Values.mainDestination }} + namespace: {{ .Values.mainNamespace }} + syncPolicy: + automated: + prune: true # Automatically remove resources no longer in the repo + selfHeal: true # Automatically self-heal when drift is detected + syncOptions: + - ApplyOutOfSyncOnly=true + - ServerSideApply=true + - CreateNamespace=true diff --git a/keycloak-argocd-apps/templates/keycloak-postinstall-app.yaml b/keycloak-argocd-apps/templates/keycloak-postinstall-app.yaml new file mode 100644 index 0000000..80c7180 --- /dev/null +++ b/keycloak-argocd-apps/templates/keycloak-postinstall-app.yaml @@ -0,0 +1,30 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: keycloak-postinstall + namespace: {{ .Values.argocd.namespace }} + annotations: + argocd.argoproj.io/sync-wave: "1" + notifications.argoproj.io/subscribe.on-sync-succeeded.telegram: "-1002270587578" +spec: + project: {{ .Values.argocd.project }} + source: + repoURL: "https://git.blarre.net/thomas/helm-charts.git" + targetRevision: HEAD + path: keycloak-postinstall + helm: + releaseName: keycloak-postinstall + valuesObject: + tailscaleIngresses: + keycloakHostname: {{ .Values.tailscaleIngresses.keycloakHostname }} + destination: + server: {{ .Values.mainDestination }} + namespace: {{ .Values.mainNamespace }} + syncPolicy: + automated: + prune: true # Automatically remove resources no longer in the repo + selfHeal: true # Automatically self-heal when drift is detected + syncOptions: + - ApplyOutOfSyncOnly=true + - ServerSideApply=true + - CreateNamespace=true diff --git a/keycloak-argocd-apps/templates/keycloak-requirements-app.yaml b/keycloak-argocd-apps/templates/keycloak-requirements-app.yaml new file mode 100644 index 0000000..22ca19a --- /dev/null +++ b/keycloak-argocd-apps/templates/keycloak-requirements-app.yaml @@ -0,0 +1,31 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: keycloak-requirements + namespace: {{ .Values.argocd.namespace }} + annotations: + argocd.argoproj.io/sync-wave: "-1" + notifications.argoproj.io/subscribe.on-sync-succeeded.telegram: "-1002270587578" +spec: + project: {{ .Values.argocd.project }} + source: + repoURL: "https://git.blarre.net/thomas/helm-charts.git" + targetRevision: HEAD + path: keycloak-requirements + helm: + releaseName: keycloak-requirements + valuesObject: + dbCluster: + size: {{ .Values.dbCluster.size }} + numInstances: {{ .Values.dbCluster.numInstances }} + destination: + server: {{ .Values.mainDestination }} + namespace: {{ .Values.mainNamespace }} + syncPolicy: + automated: + prune: true # Automatically remove resources no longer in the repo + selfHeal: true # Automatically self-heal when drift is detected + syncOptions: + - ApplyOutOfSyncOnly=true + - ServerSideApply=true + - CreateNamespace=true diff --git a/keycloak-argocd-apps/values.yaml b/keycloak-argocd-apps/values.yaml new file mode 100644 index 0000000..1a0377d --- /dev/null +++ b/keycloak-argocd-apps/values.yaml @@ -0,0 +1,9 @@ +dbCluster: + size: 1Gi + numInstances: 3 +mainNamespace: keycloak +keycloakDeployment: + numInstances: 1 + hostname: sso.domain.net +tailscaleIngresses: + keycloakHostname: sso \ No newline at end of file diff --git a/keycloak-deployment/.helmignore b/keycloak-deployment/.helmignore new file mode 100644 index 0000000..0e8a0eb --- /dev/null +++ b/keycloak-deployment/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/keycloak-deployment/Chart.yaml b/keycloak-deployment/Chart.yaml new file mode 100644 index 0000000..7e85ea2 --- /dev/null +++ b/keycloak-deployment/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v2 +name: keycloak-deployment +description: A Helm chart for deploying the actual keycloak pod through the keycloak operator +type: application +version: 0.1.0 \ No newline at end of file diff --git a/keycloak-deployment/templates/_helpers.tpl b/keycloak-deployment/templates/_helpers.tpl new file mode 100644 index 0000000..0602af3 --- /dev/null +++ b/keycloak-deployment/templates/_helpers.tpl @@ -0,0 +1,62 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "keycloak-deployment.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "keycloak-deployment.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "keycloak-deployment.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "keycloak-deployment.labels" -}} +helm.sh/chart: {{ include "keycloak-deployment.chart" . }} +{{ include "keycloak-deployment.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "keycloak-deployment.selectorLabels" -}} +app.kubernetes.io/name: {{ include "keycloak-deployment.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "keycloak-deployment.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "keycloak-deployment.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/keycloak-deployment/templates/keycloak-deployment.yaml b/keycloak-deployment/templates/keycloak-deployment.yaml new file mode 100644 index 0000000..0ff8ea5 --- /dev/null +++ b/keycloak-deployment/templates/keycloak-deployment.yaml @@ -0,0 +1,25 @@ +apiVersion: k8s.keycloak.org/v2alpha1 +kind: Keycloak +metadata: + name: linode-keycloak +spec: + instances: {{ .Values.keycloakDeployment.numInstances }} + db: + vendor: postgres + host: keycloak-db-rw + usernameSecret: + name: keycloak-db-app + key: user + passwordSecret: + name: keycloak-db-app + key: password + database: app + ingress: + enabled: false + http: + httpEnabled: true + hostname: + hostname: {{ .Values.keycloakDeployment.hostname }} + strict: false + proxy: + headers: xforwarded # double check your reverse proxy sets and overwrites the X-Forwarded-* headers diff --git a/keycloak-deployment/values.yaml b/keycloak-deployment/values.yaml new file mode 100644 index 0000000..1311011 --- /dev/null +++ b/keycloak-deployment/values.yaml @@ -0,0 +1,3 @@ +keycloakDeployment: + numInstances: 1 + hostname: sso.domain.net \ No newline at end of file diff --git a/keycloak-postinstall/.helmignore b/keycloak-postinstall/.helmignore new file mode 100644 index 0000000..0e8a0eb --- /dev/null +++ b/keycloak-postinstall/.helmignore @@ -0,0 +1,23 @@ +# Patterns to ignore when building packages. +# This supports shell glob matching, relative path matching, and +# negation (prefixed with !). Only one pattern per line. +.DS_Store +# Common VCS dirs +.git/ +.gitignore +.bzr/ +.bzrignore +.hg/ +.hgignore +.svn/ +# Common backup files +*.swp +*.bak +*.tmp +*.orig +*~ +# Various IDEs +.project +.idea/ +*.tmproj +.vscode/ diff --git a/keycloak-postinstall/Chart.yaml b/keycloak-postinstall/Chart.yaml new file mode 100644 index 0000000..c261c18 --- /dev/null +++ b/keycloak-postinstall/Chart.yaml @@ -0,0 +1,5 @@ +apiVersion: v2 +name: keycloak-postinstall +description: A Helm chart for after deploying keycloak - mainly ingress +type: application +version: 0.1.0 diff --git a/keycloak-postinstall/templates/_helpers.tpl b/keycloak-postinstall/templates/_helpers.tpl new file mode 100644 index 0000000..3554e32 --- /dev/null +++ b/keycloak-postinstall/templates/_helpers.tpl @@ -0,0 +1,62 @@ +{{/* +Expand the name of the chart. +*/}} +{{- define "keycloak-postinstall.name" -}} +{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Create a default fully qualified app name. +We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec). +If release name contains chart name it will be used as a full name. +*/}} +{{- define "keycloak-postinstall.fullname" -}} +{{- if .Values.fullnameOverride }} +{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- $name := default .Chart.Name .Values.nameOverride }} +{{- if contains $name .Release.Name }} +{{- .Release.Name | trunc 63 | trimSuffix "-" }} +{{- else }} +{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }} +{{- end }} +{{- end }} +{{- end }} + +{{/* +Create chart name and version as used by the chart label. +*/}} +{{- define "keycloak-postinstall.chart" -}} +{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }} +{{- end }} + +{{/* +Common labels +*/}} +{{- define "keycloak-postinstall.labels" -}} +helm.sh/chart: {{ include "keycloak-postinstall.chart" . }} +{{ include "keycloak-postinstall.selectorLabels" . }} +{{- if .Chart.AppVersion }} +app.kubernetes.io/version: {{ .Chart.AppVersion | quote }} +{{- end }} +app.kubernetes.io/managed-by: {{ .Release.Service }} +{{- end }} + +{{/* +Selector labels +*/}} +{{- define "keycloak-postinstall.selectorLabels" -}} +app.kubernetes.io/name: {{ include "keycloak-postinstall.name" . }} +app.kubernetes.io/instance: {{ .Release.Name }} +{{- end }} + +{{/* +Create the name of the service account to use +*/}} +{{- define "keycloak-postinstall.serviceAccountName" -}} +{{- if .Values.serviceAccount.create }} +{{- default (include "keycloak-postinstall.fullname" .) .Values.serviceAccount.name }} +{{- else }} +{{- default "default" .Values.serviceAccount.name }} +{{- end }} +{{- end }} diff --git a/keycloak-postinstall/templates/ts-ingress.yaml b/keycloak-postinstall/templates/ts-ingress.yaml new file mode 100644 index 0000000..49dd4f0 --- /dev/null +++ b/keycloak-postinstall/templates/ts-ingress.yaml @@ -0,0 +1,16 @@ +apiVersion: networking.k8s.io/v1 +kind: Ingress +metadata: + name: ts-keycloak + annotations: + tailscale.com/funnel: "true" +spec: + defaultBackend: + service: + name: linode-keycloak-service + port: + number: 8080 + ingressClassName: tailscale + tls: + - hosts: + - {{ .Values.tailscaleIngresses.keycloakHostname }} diff --git a/keycloak-postinstall/values.yaml b/keycloak-postinstall/values.yaml new file mode 100644 index 0000000..cb822e9 --- /dev/null +++ b/keycloak-postinstall/values.yaml @@ -0,0 +1,2 @@ +tailscaleIngresses: + keycloakHostname: sso \ No newline at end of file