Remove https related settings

This commit is contained in:
Micke Nordin 2025-01-31 10:45:10 +01:00
parent b1be4f4203
commit 3f835d6563
Signed by: Micke
GPG key ID: 0DA0A7A5708FE257
6 changed files with 3 additions and 88 deletions

View file

@ -17,22 +17,11 @@ spec:
spec:
containers:
- name: keycloak
# image: quay.io/keycloak/keycloak:23.0.1
image: quay.io/keycloak/keycloak:26.1
args:
- "start"
- "--verbose"
env:
- name: KC_HTTP_ENABLED
value: "true"
- name: KC_HOSTNAME
value: "https://keycloak.streams.sunet.se"
- name: KC_HOSTNAME_ADMIN
value: "https://keycloak.streams.sunet.se"
- name: KC_HOSTNAME_STRICT
value: "false"
- name: KC_HOSTNAME_STRICT_HTTPS
value: "false"
- name: KEYCLOAK_USER
value: admin
- name: KEYCLOAK_PASSWORD
@ -54,8 +43,6 @@ spec:
ports:
- name: http
containerPort: 8080
# - name: https
# containerPort: 8443
readinessProbe:
httpGet:
path: /health/ready
@ -66,11 +53,8 @@ spec:
successThreshold: 1 # Number of successful probes to consider the pod ready
failureThreshold: 5
volumeMounts:
# - mountPath: /opt/keycloak/data/h2/
# name: storage
- name: keycloak-tls-secret
mountPath: /etc/ssl/certs
readOnly: true
- mountPath: /opt/keycloak/data/h2/
name: storage
securityContext:
runAsUser: 1000
runAsGroup: 1000
@ -78,6 +62,3 @@ spec:
- name: storage
persistentVolumeClaim:
claimName: keycloak-pvc
- name: keycloak-tls-secret
secret:
secretName: keycloak-tls-secret

View file

@ -7,7 +7,7 @@ spec:
project: default
source:
repoURL: https://platform.sunet.se/streams/streams-manifests.git
targetRevision: streams-manifests-2025-01-31-v13
targetRevision: streams-manifests-2025-01-31-v14
path: keycloak/overlays/test
destination:
server: https://kubernetes.default.svc

View file

@ -1,7 +0,0 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: keycloak
commonLabels:
env: dev
resources:
- ../../base/

View file

@ -1,7 +0,0 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: keycloak
commonLabels:
env: prod
resources:
- ../../base/

View file

@ -1,51 +0,0 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: keycloak
namespace: keycloak
labels:
app: keycloak
spec:
replicas: 1
selector:
matchLabels:
app: keycloak
template:
metadata:
labels:
app: keycloak
spec:
containers:
- name: keycloak
image: quay.io/keycloak/keycloak:26.1
env:
- name: KC_HOSTNAME_DEBUG
value: "true"
- name: KC_HTTP_ENABLED
value: "true"
- name: KC_HOSTNAME
value: "https://keycloak-test.streams.sunet.se"
- name: KC_HOSTNAME_ADMIN
value: "https://keycloak-test.streams.sunet.se"
- name: KC_HOSTNAME_STRICT
value: "false"
- name: KC_HOSTNAME_STRICT_HTTPS
value: "false"
- name: KEYCLOAK_USER
value: admin
- name: KEYCLOAK_PASSWORD
valueFrom:
secretKeyRef:
name: keycloak-admin-secret
key: password
- name: KEYCLOAK_ADMIN
value: "admin"
- name: KEYCLOAK_ADMIN_PASSWORD
valueFrom:
secretKeyRef:
name: keycloak-admin-secret
key: password
- name: KC_HEALTH_ENABLED
value: "true"
- name: KC_PROXY
value: "edge"

View file

@ -7,4 +7,3 @@ resources:
- ../../base/
patches:
- path: keycloak-ingress.yaml
- path: keycloak-deployment.yaml