This commit is contained in:
Jan Krebs 2021-05-21 10:43:56 +02:00
parent 1c3719c2c7
commit b51812eef2
3 changed files with 77 additions and 60 deletions

View file

@ -1,36 +0,0 @@
apiVersion: batch/v1
kind: CronJob
metadata:
name: keycloak-cron
labels:
app.kubernetes.io/name: k8s-keycloak
spec:
schedule: "* */15 * * *"
successfulJobsHistoryLimit: 5
failedJobsHistoryLimit: 5
concurrencyPolicy: Replace
jobTemplate:
spec:
template:
spec:
volumes:
- name: config-volume
configMap:
name: keycloak
containers:
- image: domaindrivenarchitecture/keycloak
name: keycloak
env:
- name: MASTODON_BOT_CREDENTIALS
value: /credentials.edn
volumeMounts:
- name: config-volume
mountPath: /config.edn
subPath: config.edn
readOnly: true
- name: config-volume
mountPath: /credentials.edn
subPath: credentials.edn
readOnly: true
restartPolicy: Never

View file

@ -1,35 +1,49 @@
apiVersion: v1
kind: Service
metadata:
name: keycloak
labels:
app: keycloak
spec:
ports:
- name: http
port: 8080
targetPort: 8080
selector:
app: keycloak
type: LoadBalancer
---
apiVersion: apps/v1 apiVersion: apps/v1
kind: Deployment kind: Deployment
metadata: metadata:
name: k8s-keycloak name: keycloak
namespace: default
labels:
app: keycloak
spec: spec:
replicas: 1
selector: selector:
matchLabels: matchLabels:
app.kubernetes.io/name: k8s-keycloak app: keycloak
strategy:
type: Recreate
template: template:
metadata: metadata:
labels: labels:
app.kubernetes.io/name: k8s-keycloak app: keycloak
spec: spec:
volumes:
- name: config-volume
configMap:
name: keycloak
containers: containers:
- image: domaindrivenarchitecture/keycloak - name: keycloak
name: keycloak image: quay.io/keycloak/keycloak:13.0.0
env: env:
- name: MASTODON_BOT_CREDENTIALS - name: KEYCLOAK_USER
value: /credentials.edn value: "admin"
volumeMounts: - name: KEYCLOAK_PASSWORD
- name: config-volume value: "admin"
mountPath: /config.edn - name: PROXY_ADDRESS_FORWARDING
subPath: config.edn value: "true"
readOnly: true ports:
- name: config-volume - name: http
mountPath: /credentials.edn containerPort: 8080
subPath: credentials.edn readinessProbe:
readOnly: true httpGet:
path: /auth/realms/master
port: 8080

View file

@ -0,0 +1,39 @@
apiVersion: cert-manager.io/v1alpha2
kind: Certificate
metadata:
name: keycloak-cert
namespace: default
spec:
secretName: keycloak-secret
commonName: fqdn
dnsNames:
- fqdn
issuerRef:
name: letsencrypt-staging-issuer
kind: ClusterIssuer
---
apiVersion: networking.k8s.io/v1beta1
kind: Ingress
metadata:
name: ingress-cloud
annotations:
cert-manager.io/cluster-issuer: letsencrypt-staging-issuer
nginx.ingress.kubernetes.io/proxy-body-size: "256m"
nginx.ingress.kubernetes.io/ssl-redirect: "true"
nginx.ingress.kubernetes.io/rewrite-target: /
nginx.ingress.kubernetes.io/proxy-connect-timeout: "300"
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
namespace: default
spec:
tls:
- hosts:
- fqdn
secretName: keycloak-secret
rules:
- host: fqdn
http:
paths:
- backend:
serviceName: keycloak
servicePort: 8080