From 48d41889273de273c2bc024c18133fad8e42f171 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 6 Oct 2026 00:17:35 +0200 Subject: [PATCH] keycloak repair: remove the temporary admin even when the bootstrap failed after making it The bootstrap once created the temporary admin and then failed on a held port; marked only after it succeeded, the cleanup did not know the admin existed and left it. --- modules/keycloak/cmd/keycloak-provider/admin.go | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/modules/keycloak/cmd/keycloak-provider/admin.go b/modules/keycloak/cmd/keycloak-provider/admin.go index abfd829..c9ccaec 100644 --- a/modules/keycloak/cmd/keycloak-provider/admin.go +++ b/modules/keycloak/cmd/keycloak-provider/admin.go @@ -349,6 +349,12 @@ user_id() { cleanup() { rc=$? set +e + if [ -z "$logged_in" ] && [ -n "$bootstrapped" ]; then + # The bootstrap may have made the temporary admin and failed after (it did once, on a held port): + # log in as it anyway, so it is removed rather than left behind. + "$bin/kcadm.sh" config credentials --config "$cfg" --server http://localhost:8080 --realm master \ + --user "$TMP_USER" --password "$TMP_PW" >/dev/null 2>&1 && logged_in=1 + fi if [ -n "$logged_in" ]; then tid=$(user_id "$TMP_USER" 2>/dev/null) if [ -n "$tid" ] && "$bin/kcadm.sh" delete "users/$tid" -r master --config "$cfg" >&2; then @@ -364,8 +370,8 @@ cleanup() { } trap cleanup EXIT step bootstrap-admin -"$bin/kc.sh" bootstrap-admin user --username "$TMP_USER" --password:env TMP_PW --http-management-port="$MGMT_PORT" >&2 bootstrapped=1 +"$bin/kc.sh" bootstrap-admin user --username "$TMP_USER" --password:env TMP_PW --http-management-port="$MGMT_PORT" >&2 step login "$bin/kcadm.sh" config credentials --config "$cfg" --server http://localhost:8080 --realm master --user "$TMP_USER" --password "$TMP_PW" >&2 logged_in=1