Files
mesh-controller/examples/modules/keycloak.json
T
jschoubben a4090014f3 An example may not name an image nothing builds
Found by reading the manifests rather than by running them. Two of the
provisioner images the examples name had no way to be produced: the
object store's had a Dockerfile and no target, and Keycloak's did not
exist at all — no image, no Dockerfile, no program.

A module naming an image nothing produces resolves, plans, pushes and
stops on the machine at `docker pull`, which is the fault arriving as
far from its cause as it can get.

The object store's target is added. Keycloak's provisioner is removed
from its manifest, because writing a manifest for a program that does
not exist is the same mistake as the .env files: it parses, it resolves,
and it could never work.

That makes keycloak's manifest true about today — a server the mesh
runs, with its database and its admin credential — and it makes the gap
loud. Keycloak no longer claims to provide oidc-client, so a consumer
asking for one is refused at plan time by name, rather than resolving
cleanly and never having a client created.

The check covers only images beginning `mesh-`. Postgres and the rest
come from a registry and are somebody else's to build; what this bounds
is the set this repository is responsible for and might forget.
2026-09-01 03:12:49 +02:00

42 lines
1.6 KiB
JSON

{
"module": "keycloak",
"version": "1",
"requires": ["postgres-database"],
"contributes": {
"postgres-database": {"name": "keycloak"}
},
"binds": {"postgres-database": "/var/lib/keycloak/database.json"},
"secrets": {"postgres-database": "/var/lib/keycloak/database.secret"},
"capabilities": ["container-runtime"],
"listens": [
{"port": 8080, "protocol": "tcp", "from": "mesh",
"why": "anything the mesh runs that authenticates a person"}
],
"own-secrets": {"admin": "/var/lib/keycloak/admin.secret"},
"resources": [
{"id": "state", "type": "directory", "path": "/var/lib/keycloak", "mode": "0700"},
{"id": "admin-env", "type": "file", "path": "/var/lib/keycloak/admin.env", "mode": "0600",
"content": "KEYCLOAK_ADMIN=admin\nKEYCLOAK_ADMIN_PASSWORD=${secret:admin}\n"},
{"id": "database-env", "type": "file", "path": "/var/lib/keycloak/database.env", "mode": "0600",
"content": "KC_DB_URL=jdbc:postgresql://${bound:postgres-database:at}:${bound:postgres-database:port}/keycloak\nKC_DB_USERNAME=${bound:postgres-database:as}\nKC_DB_PASSWORD=${secret:postgres-database}\n"},
{"id": "net", "type": "network", "name": "keycloak"},
{"id": "server", "type": "container", "name": "keycloak",
"image": "keycloak@sha256:0000000000000000000000000000000000000000000000000000000000000000",
"network": "keycloak",
"args": ["start-dev"],
"env": {"KC_DB": "postgres", "KC_HTTP_ENABLED": "true", "KC_HEALTH_ENABLED": "true"},
"env-file": ["/var/lib/keycloak/admin.env", "/var/lib/keycloak/database.env"],
"ports": ["8080:8080"],
"restart-on": ["admin-env", "database-env"]}
]
}