Backup lines are derived from each module's data section instead of written by hand; the holder measures declared items, reads the array under them, and deletes a retired item only after a last restore point; the Go providers say each held consumer's size so an empty replacement is seen.
187 lines
4.5 KiB
JSON
187 lines
4.5 KiB
JSON
{
|
|
"module": "keycloak",
|
|
"version": "1",
|
|
"provides": [
|
|
{
|
|
"name": "oidc-client",
|
|
"scope": "mesh",
|
|
"identity": {
|
|
"max": 255,
|
|
"in": "a Keycloak client id"
|
|
}
|
|
}
|
|
],
|
|
"requires": [
|
|
"postgres-database",
|
|
"route"
|
|
],
|
|
"contributes": {
|
|
"postgres-database": {
|
|
"name": "keycloak"
|
|
},
|
|
"route": {
|
|
"label": "keycloak",
|
|
"endpoint": "web"
|
|
}
|
|
},
|
|
"binds": {
|
|
"postgres-database": "${dir:state}/database.json",
|
|
"route": "${dir:state}/route.json"
|
|
},
|
|
"secrets": {
|
|
"postgres-database": "${dir:state}/database.secret"
|
|
},
|
|
"capabilities": [
|
|
"container-runtime"
|
|
],
|
|
"emits": [
|
|
"user.created",
|
|
"user.deleted",
|
|
"password.reset",
|
|
"client.created",
|
|
"client.retired",
|
|
"group.created",
|
|
"role.created",
|
|
"admin.repaired",
|
|
"admin.unrepaired"
|
|
],
|
|
"listens": [
|
|
{
|
|
"name": "web",
|
|
"port": 8080,
|
|
"protocol": "tcp",
|
|
"from": "mesh",
|
|
"why": "anything the mesh runs that authenticates a person"
|
|
}
|
|
],
|
|
"serves": {
|
|
"oidc-client": {
|
|
"authorization-path": "/protocol/openid-connect/auth",
|
|
"token-path": "/protocol/openid-connect/token",
|
|
"userinfo-path": "/protocol/openid-connect/userinfo",
|
|
"issuer": "${setting:issuer}"
|
|
}
|
|
},
|
|
"receives": {
|
|
"oidc-client": "${dir:grants}/mesh.json"
|
|
},
|
|
"grants": {
|
|
"oidc-client": "${dir:grants}"
|
|
},
|
|
"own-secrets": {
|
|
"admin": "${dir:state}/admin.secret"
|
|
},
|
|
"data": {
|
|
"consumers": {
|
|
"oidc-client": {
|
|
"class": "rebuildable",
|
|
"in": "postgres-database",
|
|
"why": "a consumer's client is made again from its declaration, with a new secret"
|
|
}
|
|
}
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "mesh-state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "mesh"
|
|
},
|
|
{
|
|
"id": "state",
|
|
"type": "directory",
|
|
"mode": "0700",
|
|
"place": "."
|
|
},
|
|
{
|
|
"id": "grants",
|
|
"type": "directory",
|
|
"mode": "0700"
|
|
},
|
|
{
|
|
"id": "admin-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/admin.env",
|
|
"mode": "0600",
|
|
"content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n"
|
|
},
|
|
{
|
|
"id": "database-env",
|
|
"type": "file",
|
|
"path": "${dir:state}/database.env",
|
|
"mode": "0600",
|
|
"content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/${bound:postgres-database:as}\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n"
|
|
},
|
|
{
|
|
"id": "net",
|
|
"type": "network",
|
|
"name": "keycloak"
|
|
},
|
|
{
|
|
"id": "hostname",
|
|
"type": "file",
|
|
"path": "${dir:state}/hostname.env",
|
|
"mode": "0644",
|
|
"content": "KC_HOSTNAME=https://${bound:route:name}\n"
|
|
},
|
|
{
|
|
"id": "server",
|
|
"type": "container",
|
|
"name": "keycloak",
|
|
"image": "quay.io/keycloak/keycloak@sha256:ecd43971114b0c764f8a3288dddab73f98cb473daccc4feaffe4dc14adeaf866",
|
|
"network": "keycloak",
|
|
"args": [
|
|
"start-dev"
|
|
],
|
|
"env": {
|
|
"KC_DB": "postgres",
|
|
"KC_HTTP_ENABLED": "true",
|
|
"KC_HEALTH_ENABLED": "true",
|
|
"KC_PROXY_HEADERS": "xforwarded"
|
|
},
|
|
"env-file": [
|
|
"${dir:state}/admin.env",
|
|
"${dir:state}/database.env",
|
|
"${dir:state}/hostname.env"
|
|
],
|
|
"ports": [
|
|
"8080"
|
|
],
|
|
"secrets-in-environment": "KC_DB_PASSWORD is convertible through a generated keycloak.conf (db-password=); KEYCLOAK_ADMIN_PASSWORD is env-only before Keycloak 26; not yet converted",
|
|
"restart-on": [
|
|
"hostname"
|
|
]
|
|
},
|
|
{
|
|
"id": "runtime-config",
|
|
"type": "file",
|
|
"path": "${dir:mesh-state}/config.json",
|
|
"mode": "0600",
|
|
"content": "{}\n",
|
|
"merge": "json"
|
|
}
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "code",
|
|
"kind": "bundle",
|
|
"language": "go",
|
|
"system": "arch",
|
|
"from": "cmd/keycloak-provider",
|
|
"binary": "keycloak-provider",
|
|
"loads": [
|
|
"keycloak-provider"
|
|
],
|
|
"env": {
|
|
"MESH_KEYCLOAK_URL": "http://127.0.0.1:${port:8080}",
|
|
"MESH_KEYCLOAK_CONFIG_FILE": "${dir:mesh-state}/config.json",
|
|
"MESH_KEYCLOAK_PASSWORD_FILE": "${dir:state}/admin.secret",
|
|
"MESH_RECEIVES": "${dir:grants}/mesh.json",
|
|
"MESH_KEYCLOAK_CONTAINER": "keycloak"
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|