The hourly release of ADR 0229's brake still ended in the mesh acting alone on a mistake. A consumer now stays active until the same unasked set holds for five passes, waits for a person past three or half of those held, is disabled and marked rather than withdrawn, comes back as it was when asked again, and is deleted only through the provider's delete tool. The backend keeps the mark, so a restart forgets nothing and finds what was withdrawn before.
178 lines
4.2 KiB
JSON
178 lines
4.2 KiB
JSON
{
|
|
"module": "keycloak",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "oidc-client",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 255,
|
|
"in": "a Keycloak client id"
|
|
}
|
|
}
|
|
],
|
|
"requires": [
|
|
"postgres-database",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "keycloak"
|
|
},
|
|
"route": {
|
|
"label": "keycloak",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "${dir:state}/database.json",
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "${dir:state}/database.secret"
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"user.created",
|
|
"user.deleted",
|
|
"password.reset",
|
|
"client.created",
|
|
"client.retired",
|
|
"group.created",
|
|
"role.created",
|
|
"admin.repaired",
|
|
"admin.unrepaired"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 8080,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "anything the mesh runs that authenticates a person"
|
|
}
|
|
],
|
|
"serves": {
|
|
"oidc-client": {
|
|
"authorization-path": "/protocol/openid-connect/auth",
|
|
"token-path": "/protocol/openid-connect/token",
|
|
"userinfo-path": "/protocol/openid-connect/userinfo",
|
|
"issuer": "${setting:issuer}"
|
|
}
|
|
},
|
|
"receives": {
|
|
"oidc-client": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"oidc-client": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"admin": "${dir:state}/admin.secret"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "admin-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/admin.env",
|
|
"mode": "0600",
|
|
"content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n"
|
|
},
|
|
{
|
|
"id": "database-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/database.env",
|
|
"mode": "0600",
|
|
"content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "keycloak"
|
|
},
|
|
{
|
|
"id": "hostname",
|
|
"type": "file",
|
|
"path": "${dir:state}/hostname.env",
|
|
"mode": "0644",
|
|
"content": "KC_HOSTNAME=https://${bound:route:name}\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "keycloak",
|
|
"image": "quay.io/keycloak/keycloak@sha256:ecd43971114b0c764f8a3288dddab73f98cb473daccc4feaffe4dc14adeaf866",
|
|
"network": "keycloak",
|
|
"args": [
|
|
"start-dev"
|
|
],
|
|
"env": {
|
|
"KC_DB": "postgres",
|
|
"KC_HTTP_ENABLED": "true",
|
|
"KC_HEALTH_ENABLED": "true",
|
|
"KC_PROXY_HEADERS": "xforwarded"
|
|
},
|
|
"env-file": [
|
|
"${dir:state}/admin.env",
|
|
"${dir:state}/database.env",
|
|
"${dir:state}/hostname.env"
|
|
],
|
|
"ports": [
|
|
"8080"
|
|
],
|
|
"secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted",
|
|
"restart-on": [
|
|
"hostname"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/keycloak-provider",
|
|
"binary": "keycloak-provider",
|
|
"loads": [
|
|
"keycloak-provider"
|
|
],
|
|
"env": {
|
|
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
|
|
"MESH_KEYCLOAK_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
|
"MESH_KEYCLOAK_PASSWORD_FILE": "${dir:state}/admin.secret",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_KEYCLOAK_CONTAINER": "keycloak"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|