keycloak: full nox module — client, tools and events (ADR 0044/0046)

Identity provider. 22 admin tools (realms, users, clients + secrets, groups,
roles) over the admin API, moved out of the shared sdk. Emits user created/
deleted, password reset, client/group/role created — from the write tools
themselves, since Keycloak's value is the changes it makes, not pollable
state. Consumes nothing: it is upstream of everything that authenticates
against it. Typechecks; manifest parses.
This commit is contained in:
2026-09-04 02:30:40 +02:00
parent 1498a22c94
commit 4d98da18a0
6 changed files with 677 additions and 1 deletions
+10 -1
View File
@@ -18,6 +18,14 @@
"capabilities": [
"container-runtime"
],
"emits": [
"module.keycloak.user.created",
"module.keycloak.user.deleted",
"module.keycloak.password.reset",
"module.keycloak.client.created",
"module.keycloak.group.created",
"module.keycloak.role.created"
],
"listens": [
{
"port": 8080,
@@ -27,7 +35,8 @@
}
],
"own-secrets": {
"admin": "/var/lib/keycloak/admin.secret"
"admin": "/var/lib/keycloak/admin.secret",
"broker": "/var/lib/keycloak/broker"
},
"resources": [
{