{ "module": "keycloak", "version": "1", "provides": [ { "name": "oidc-client", "scope": "mesh" } ], "requires": [ "postgres-database", "route" ], "contributes": { "postgres-database": { "name": "keycloak" }, "route": { "label": "keycloak", "endpoint": "web" } }, "binds": { "postgres-database": "${dir:state}/database.json", "route": "${dir:state}/route.json" }, "secrets": { "postgres-database": "${dir:state}/database.secret" }, "capabilities": [ "container-runtime" ], "emits": [ "user.created", "user.deleted", "password.reset", "client.created", "group.created", "role.created" ], "listens": [ { "name": "web", "port": 8080, "protocol": "tcp", "from": "mesh", "why": "anything the mesh runs that authenticates a person" } ], "serves": { "oidc-client": { "authorization-path": "/protocol/openid-connect/auth", "token-path": "/protocol/openid-connect/token", "userinfo-path": "/protocol/openid-connect/userinfo" } }, "receives": { "oidc-client": "${dir:grants}/mesh.json" }, "grants": { "oidc-client": "${dir:grants}" }, "own-secrets": { "admin": "${dir:state}/admin.secret", "broker": "/var/lib/mesh/keycloak/broker" }, "resources": [ { "id": "mesh-state", "type": "directory", "path": "/var/lib/mesh/keycloak", "mode": "0700" }, { "id": "state", "type": "directory", "mode": "0700", "place": "." }, { "id": "grants", "type": "directory", "mode": "0700" }, { "id": "admin-env", "type": "file", "path": "${dir:state}/admin.env", "mode": "0600", "content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n" }, { "id": "database-env", "type": "file", "path": "${dir:state}/database.env", "mode": "0600", "content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n" }, { "id": "net", "type": "network", "name": "keycloak" }, { "id": "hostname", "type": "file", "path": "${dir:state}/hostname.env", "mode": "0644", "content": "KC_HOSTNAME=https://${bound:route:name}\n" }, { "id": "server", "type": "container", "name": "keycloak", "image": "quay.io/keycloak/keycloak@sha256:ecd43971114b0c764f8a3288dddab73f98cb473daccc4feaffe4dc14adeaf866", "network": "keycloak", "args": [ "start-dev" ], "env": { "KC_DB": "postgres", "KC_HTTP_ENABLED": "true", "KC_HEALTH_ENABLED": "true", "KC_PROXY_HEADERS": "xforwarded" }, "env-file": [ "${dir:state}/admin.env", "${dir:state}/database.env", "${dir:state}/hostname.env" ], "ports": [ "8080" ], "secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted", "restart-on": [ "hostname" ] }, { "id": "runtime-config", "type": "file", "path": "/var/lib/mesh/keycloak/config.json", "mode": "0600", "content": "{}\n", "merge": "json" }, { "id": "runtime", "type": "container", "name": "mesh-keycloak", "network": "host", "volumes": [ "/var/lib/mesh/keycloak/broker:/run/secrets/broker:ro", "/var/lib/mesh/keycloak/config.json:/run/config/config.json:ro", "${dir:state}/admin.secret:/run/secrets/admin:ro", "${dir:grants}:${dir:grants}:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}", "MESH_KEYCLOAK_CONFIG_FILE": "/run/config/config.json", "MESH_KEYCLOAK_PASSWORD_FILE": "/run/secrets/admin", "MESH_RECEIVES": "${dir:grants}/mesh.json" }, "restart-on": [ "runtime-config" ], "artifact": "runtime" } ], "build": { "on": [ { "arg": "BUILD_BASE", "module": "mesh-tools", "artifact": "build" }, { "arg": "RUNTIME_BASE", "module": "mesh-tools", "artifact": "runtime" } ], "artifacts": [ { "name": "runtime", "kind": "image", "from": "Dockerfile" } ] } }