keycloak repair: remove the temporary admin even when the bootstrap failed after making it

The bootstrap once created the temporary admin and then failed on a held port; marked only after
it succeeded, the cleanup did not know the admin existed and left it.
This commit is contained in:
jochen
2026-10-06 00:17:35 +02:00
parent 77fb1ecfb2
commit 48d4188927
@@ -349,6 +349,12 @@ user_id() {
cleanup() {
rc=$?
set +e
if [ -z "$logged_in" ] && [ -n "$bootstrapped" ]; then
# The bootstrap may have made the temporary admin and failed after (it did once, on a held port):
# log in as it anyway, so it is removed rather than left behind.
"$bin/kcadm.sh" config credentials --config "$cfg" --server http://localhost:8080 --realm master \
--user "$TMP_USER" --password "$TMP_PW" >/dev/null 2>&1 && logged_in=1
fi
if [ -n "$logged_in" ]; then
tid=$(user_id "$TMP_USER" 2>/dev/null)
if [ -n "$tid" ] && "$bin/kcadm.sh" delete "users/$tid" -r master --config "$cfg" >&2; then
@@ -364,8 +370,8 @@ cleanup() {
}
trap cleanup EXIT
step bootstrap-admin
"$bin/kc.sh" bootstrap-admin user --username "$TMP_USER" --password:env TMP_PW --http-management-port="$MGMT_PORT" >&2
bootstrapped=1
"$bin/kc.sh" bootstrap-admin user --username "$TMP_USER" --password:env TMP_PW --http-management-port="$MGMT_PORT" >&2
step login
"$bin/kcadm.sh" config credentials --config "$cfg" --server http://localhost:8080 --realm master --user "$TMP_USER" --password "$TMP_PW" >&2
logged_in=1