From 5a906b757de6b347c6a67a266d4e8c987e2d1e8f Mon Sep 17 00:00:00 2001 From: jochens Date: Wed, 30 Sep 2026 00:49:08 +0200 Subject: [PATCH] keycloak, grafana: their public names come from the mesh, not the manifest MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GF_SERVER_ROOT_URL=https://grafana.zurag.be, KC_HOSTNAME=https://keycloak.novox.be and the served issuer's novox default were domains in definitions — wrong on every other machine (ADR 0112). The names now come from ${bound:route:name} (mesh-controller #149, hq 122): grafana's in oidc.env, keycloak's in a hostname.env its server reads. The issuer includes the realm and stays the assignment's, with no default: unset, a consumer asking for it is refused and the provisioner says so, rather than both quietly using novox's URL. Rendered through mesh-controller #149 from these manifests on a zurag.be node: KC_HOSTNAME=https://keycloak.zurag.be, GF_SERVER_ROOT_URL= https://grafana.zurag.be, OIDC URLs from the issuer setting. Needs #149 merged and rolled out first. --- modules/grafana/module.json | 2 +- modules/keycloak/module.json | 19 ++++++++++++++----- 2 files changed, 15 insertions(+), 6 deletions(-) diff --git a/modules/grafana/module.json b/modules/grafana/module.json index 0cd6f36..469c216 100644 --- a/modules/grafana/module.json +++ b/modules/grafana/module.json @@ -60,7 +60,7 @@ "type": "file", "path": "${dir:state}/oidc.env", "mode": "0644", - "content": "GF_SERVER_ROOT_URL=https://grafana.zurag.be\nGF_AUTH_GENERIC_OAUTH_ENABLED=true\nGF_AUTH_GENERIC_OAUTH_NAME=Keycloak\nGF_AUTH_GENERIC_OAUTH_CLIENT_ID=${bound:oidc-client:as}\nGF_AUTH_GENERIC_OAUTH_CLIENT_SECRET__FILE=/run/secrets/oidc-client\nGF_AUTH_GENERIC_OAUTH_SCOPES=openid email profile roles\nGF_AUTH_GENERIC_OAUTH_AUTH_URL=${bound:oidc-client:issuer}${bound:oidc-client:authorization-path}\nGF_AUTH_GENERIC_OAUTH_TOKEN_URL=${bound:oidc-client:issuer}${bound:oidc-client:token-path}\nGF_AUTH_GENERIC_OAUTH_API_URL=${bound:oidc-client:issuer}${bound:oidc-client:userinfo-path}\nGF_AUTH_GENERIC_OAUTH_ROLE_ATTRIBUTE_PATH=contains(roles[*], 'admin') && 'Admin' || contains(realm_access.roles[*], 'admin') && 'Admin' || 'Viewer'\nGF_AUTH_GENERIC_OAUTH_USE_PKCE=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN=true\n" + "content": "GF_SERVER_ROOT_URL=https://${bound:route:name}\nGF_AUTH_GENERIC_OAUTH_ENABLED=true\nGF_AUTH_GENERIC_OAUTH_NAME=Keycloak\nGF_AUTH_GENERIC_OAUTH_CLIENT_ID=${bound:oidc-client:as}\nGF_AUTH_GENERIC_OAUTH_CLIENT_SECRET__FILE=/run/secrets/oidc-client\nGF_AUTH_GENERIC_OAUTH_SCOPES=openid email profile roles\nGF_AUTH_GENERIC_OAUTH_AUTH_URL=${bound:oidc-client:issuer}${bound:oidc-client:authorization-path}\nGF_AUTH_GENERIC_OAUTH_TOKEN_URL=${bound:oidc-client:issuer}${bound:oidc-client:token-path}\nGF_AUTH_GENERIC_OAUTH_API_URL=${bound:oidc-client:issuer}${bound:oidc-client:userinfo-path}\nGF_AUTH_GENERIC_OAUTH_ROLE_ATTRIBUTE_PATH=contains(roles[*], 'admin') && 'Admin' || contains(realm_access.roles[*], 'admin') && 'Admin' || 'Viewer'\nGF_AUTH_GENERIC_OAUTH_USE_PKCE=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true\nGF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN=true\n" }, { "id": "server", diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index d9fd2fc..010a0a5 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -49,7 +49,6 @@ ], "serves": { "oidc-client": { - "issuer": "https://keycloak.novox.be/realms/master", "authorization-path": "/protocol/openid-connect/auth", "token-path": "/protocol/openid-connect/token", "userinfo-path": "/protocol/openid-connect/userinfo" @@ -103,6 +102,13 @@ "type": "network", "name": "keycloak" }, + { + "id": "hostname", + "type": "file", + "path": "/var/lib/keycloak/hostname.env", + "mode": "0644", + "content": "KC_HOSTNAME=https://${bound:route:name}\n" + }, { "id": "server", "type": "container", @@ -116,24 +122,27 @@ "KC_DB": "postgres", "KC_HTTP_ENABLED": "true", "KC_HEALTH_ENABLED": "true", - "KC_HOSTNAME": "https://keycloak.novox.be", "KC_PROXY_HEADERS": "xforwarded" }, "env-file": [ "/var/lib/keycloak/admin.env", - "/var/lib/keycloak/database.env" + "/var/lib/keycloak/database.env", + "/var/lib/keycloak/hostname.env" ], "ports": [ "8080" ], - "secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted" + "secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted", + "restart-on": [ + "hostname" + ] }, { "id": "runtime-config", "type": "file", "path": "/var/lib/mesh/keycloak/config.json", "mode": "0600", - "content": "{\n \"issuer\": \"https://keycloak.novox.be/realms/master\"\n}\n", + "content": "{}\n", "merge": "json" }, {