Skip to search

Keycloak

k8s.keycloak.org / v2beta1

apiVersion: k8s.keycloak.org/v2beta1 kind: Keycloak metadata: name: example
View raw schema
spec object
additionalOptions []object
Configuration of the Keycloak server. expressed as a keys (reference: https://www.keycloak.org/server/all-config) and values that can be either direct values or references to secrets.
name string
secret object
key string
name string
optional boolean
value string
admin object
In this section you can find all properties related to making admin connections from the operator to the server. These settings are not used by the server.
tlsSecret string
If mTLS is required, this references a secret containing the client TLS configuration for the admin client. Reference: https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets.
automountServiceAccountToken boolean
Set this to to false to disable automounting the default ServiceAccount Token and Service CA. This is enabled by default.
bootstrapAdmin object
In this section you can configure Keycloak's bootstrap admin - will be used only for initial cluster creation.
service object
Configures the bootstrap admin service account
secret string
Name of the Secret that contains the client-id and client-secret keys
user object
Configures the bootstrap admin user
secret string
Name of the Secret that contains the username and password keys
cache object
In this section you can configure Keycloak's cache
configMapFile object
key string
name string
optional boolean
db object
In this section you can find all properties related to connect to a database.
database string
Sets the database name of the default JDBC URL of the chosen vendor. If the `url` option is set, this option is ignored.
host string
Sets the hostname of the default JDBC URL of the chosen vendor. If the `url` option is set, this option is ignored.
passwordSecret object
The reference to a secret holding the password of the database user.
key string
name string
optional boolean
poolInitialSize integer
The initial size of the connection pool.
poolMaxSize integer
The maximum size of the connection pool.
poolMinSize integer
The minimal size of the connection pool.
port integer
Sets the port of the default JDBC URL of the chosen vendor. If the `url` option is set, this option is ignored.
schema string
The database schema to be used.
url string
The full database JDBC URL. If not provided, a default URL is set based on the selected database vendor. For instance, if using 'postgres', the default JDBC URL would be 'jdbc:postgresql://localhost/keycloak'.
usernameSecret object
The reference to a secret holding the username of the database user.
key string
name string
optional boolean
vendor string
The database vendor.
env []object
Environment variables for the Keycloak server. Values can be either direct values or references to secrets. Use additionalOptions for first-class options rather than KC_ values here.
name string
secret object
key string
name string
optional boolean
value string
features object
In this section you can configure Keycloak features, which should be enabled/disabled.
disabled []string
Disabled Keycloak features
enabled []string
Enabled Keycloak features
hostname object
In this section you can configure Keycloak hostname and related properties.
admin string
The hostname for accessing the administration console. Applicable for Hostname v1 and v2.
adminUrl string
DEPRECATED. Sets the base URL for accessing the administration console, including scheme, host, port and path. Applicable for Hostname v1.
backchannelDynamic boolean
Enables dynamic resolving of backchannel URLs, including hostname, scheme, port and context path. Set to true if your application accesses Keycloak via a private network. Applicable for Hostname v2.
hostname string
Hostname for the Keycloak server. Applicable for Hostname v1 and v2.
strict boolean
Disables dynamically resolving the hostname from request headers. Applicable for Hostname v1 and v2.
strictBackchannel boolean
DEPRECATED. By default backchannel URLs are dynamically resolved from request headers to allow internal and external applications. Applicable for Hostname v1.
http object
In this section you can configure Keycloak features related to HTTP and HTTPS
annotations object
Annotations to be appended to the Service object
httpEnabled boolean
Enables the HTTP listener.
httpPort integer
The used HTTP port.
httpsPort integer
The used HTTPS port.
labels object
Labels to be appended to the Service object
serviceHttpPort integer
The HTTP port exposed on the Kubernetes Service. When set, the Service will use this port while the pod still listens on httpPort.
serviceHttpsPort integer
The HTTPS port exposed on the Kubernetes Service. When set, the Service will use this port while the pod still listens on httpsPort.
serviceName string
The name of the Kubernetes Service. When not set, the name defaults to the Keycloak CR name with a "-service" suffix.
tlsSecret string
A secret containing the TLS configuration for HTTPS. Reference: https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets.
httpManagement object
In this section you can configure Keycloak's management interface setting.
port integer
Port of the management interface.
image string
Custom Keycloak image to be used.
imagePullSecrets []object
Secret(s) that might be used when pulling an image from a private container image registry or repository.
name string
import object
In this section you can configure import Jobs
scheduling object
In this section you can configure import jobs scheduling
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
weight integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
priorityClassName string
tolerations []object
effect string
key string
operator string
tolerationSeconds integer
value string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
maxSkew integer
minDomains integer
nodeAffinityPolicy string
nodeTaintsPolicy string
topologyKey string
whenUnsatisfiable string
ingress object
The deployment is, by default, exposed through a basic ingress. You can change this behaviour by setting the enabled property to false.
annotations object
Additional annotations to be appended to the Ingress object
className string
enabled boolean
labels object
Additional labels to be appended to the Ingress object
tlsSecret string
A secret containing the TLS configuration for re-encrypt or TLS termination scenarios. Reference: https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets.
instances integer
Number of Keycloak instances. Default is 1.
livenessProbe object
Configuration for liveness probe, by default it is 10 for periodSeconds and 3 for failureThreshold
failureThreshold integer
periodSeconds integer
networkPolicy object
Controls the ingress traffic flow into Keycloak pods.
enabled boolean
Enables or disables the ingress traffic control.
http []object
A list of sources which should be able to access this endpoint. Items in this list are combined using a logical OR operation. If this field is empty or missing, this rule matches all sources (traffic not restricted by source). If this field is present and contains at least one item, this rule allows traffic only if the traffic matches at least one item in the from list.
ipBlock object
cidr string
except []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
podSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
https []object
A list of sources which should be able to access this endpoint. Items in this list are combined using a logical OR operation. If this field is empty or missing, this rule matches all sources (traffic not restricted by source). If this field is present and contains at least one item, this rule allows traffic only if the traffic matches at least one item in the from list.
ipBlock object
cidr string
except []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
podSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
management []object
A list of sources which should be able to access this endpoint. Items in this list are combined using a logical OR operation. If this field is empty or missing, this rule matches all sources (traffic not restricted by source). If this field is present and contains at least one item, this rule allows traffic only if the traffic matches at least one item in the from list.
ipBlock object
cidr string
except []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
podSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
proxy object
In this section you can configure Keycloak's reverse proxy setting
headers string
The proxy headers that should be accepted by the server. Misconfiguration might leave the server exposed to security vulnerabilities.
readinessProbe object
Configuration for readiness probe, by default it is 10 for periodSeconds and 3 for failureThreshold
failureThreshold integer
periodSeconds integer
resources object
Compute Resources required by Keycloak container
claims []object
name string
request string
limits object
requests object
scheduling object
In this section you can configure Keycloak's scheduling
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
weight integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
priorityClassName string
tolerations []object
effect string
key string
operator string
tolerationSeconds integer
value string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
maxSkew integer
minDomains integer
nodeAffinityPolicy string
nodeTaintsPolicy string
topologyKey string
whenUnsatisfiable string
serviceMonitor object
Configuration related to the generated ServiceMonitor
annotations object
Annotations to be appended to the Service object
enabled boolean
Enables or disables the creation of the ServiceMonitor.
interval string
Interval at which metrics should be scraped
labels object
Labels to be appended to the Service object
scrapeTimeout string
Timeout after which the scrape is ended
startOptimized boolean
Set to force the behavior of the --optimized flag for the start command. If left unspecified the operator will assume custom images have already been augmented.
startupProbe object
Configuration for startup probe, by default it is 1 for periodSeconds and 600 for failureThreshold
failureThreshold integer
periodSeconds integer
telemetry object
In this section you can configure general shared OpenTelemetry settings for Keycloak.
endpoint string
OpenTelemetry endpoint to connect to.
protocol string
OpenTelemetry protocol used for the telemetry data (default 'grpc'). For more information, check the OpenTelemetry guide.
resourceAttributes object
OpenTelemetry resource attributes present in the exported telemetry data to characterize the telemetry producer.
serviceName string
OpenTelemetry service name. Takes precedence over 'service.name' defined in the 'resourceAttributes' map.
tracing object
In this section you can configure OpenTelemetry Tracing for Keycloak.
compression string
OpenTelemetry compression method used to compress payloads. If unset, compression is disabled. Possible values are: gzip, none.
enabled boolean
Enables the OpenTelemetry tracing.
endpoint string
OpenTelemetry endpoint to connect to.
protocol string
OpenTelemetry protocol used for the telemetry data (default 'grpc'). For more information, check the Tracing guide.
resourceAttributes object
DEPRECATED - use the 'telemetry.resourceAttributes' instead. OpenTelemetry resource attributes present in the exported trace to characterize the telemetry producer.
samplerRatio number
OpenTelemetry sampler ratio. Probability that a span will be sampled. Expected double value in interval [0,1].
samplerType string
OpenTelemetry sampler to use for tracing (default 'traceidratio'). For more information, check the Tracing guide.
serviceName string
DEPRECATED - use the 'telemetry.serviceName' instead. OpenTelemetry service name. Takes precedence over 'service.name' defined in the 'resourceAttributes' map.
transaction object
In this section you can find all properties related to the settings of transaction behavior.
xaEnabled boolean
Determine whether Keycloak should use a non-XA datasource in case the database does not support XA transactions.
truststores object
In this section you can configure Keycloak truststores.
unsupported object
In this section you can configure podTemplate advanced features, not production-ready, and not supported settings. Use at your own risk and open an issue with your use-case if you don't find an alternative way.
podTemplate object
You can configure that will be merged with the one configured by default by the operator. Use at your own risk, we reserve the possibility to remove/change the way any field gets merged in future releases without notice. Reference: https://kubernetes.io/docs/concepts/workloads/pods/#pod-templates
metadata object
annotations object
creationTimestamp string
deletionGracePeriodSeconds integer
deletionTimestamp string
finalizers []string
generateName string
generation integer
labels object
managedFields []object
apiVersion string
fieldsType string
fieldsV1 object
manager string
operation string
subresource string
time string
name string
namespace string
ownerReferences []object
apiVersion string
blockOwnerDeletion boolean
controller boolean
kind string
name string
uid string
resourceVersion string
selfLink string
uid string
spec object
activeDeadlineSeconds integer
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
weight integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
automountServiceAccountToken boolean
containers []object
args []string
command []string
env []object
name string
value string
valueFrom object
configMapKeyRef object
key string
name string
optional boolean
fieldRef object
apiVersion string
fieldPath string
fileKeyRef object
key string
optional boolean
path string
volumeName string
resourceFieldRef object
containerName string
divisor string | integer
resource string
secretKeyRef object
key string
name string
optional boolean
envFrom []object
configMapRef object
name string
optional boolean
prefix string
secretRef object
name string
optional boolean
image string
imagePullPolicy string
lifecycle object
postStart object
exec object
command []string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
sleep object
seconds integer
tcpSocket object
host string
port string | integer
preStop object
exec object
command []string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
sleep object
seconds integer
tcpSocket object
host string
port string | integer
stopSignal string
livenessProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
name string
ports []object
containerPort integer
hostIP string
hostPort integer
name string
protocol string
readinessProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
resizePolicy []object
resourceName string
restartPolicy string
resources object
claims []object
name string
request string
limits object
requests object
restartPolicy string
restartPolicyRules []object
action string
exitCodes object
operator string
values []integer
securityContext object
allowPrivilegeEscalation boolean
appArmorProfile object
localhostProfile string
type string
capabilities object
add []string
drop []string
privileged boolean
procMount string
readOnlyRootFilesystem boolean
runAsGroup integer
runAsNonRoot boolean
runAsUser integer
seLinuxOptions object
level string
role string
type string
user string
seccompProfile object
localhostProfile string
type string
windowsOptions object
gmsaCredentialSpec string
gmsaCredentialSpecName string
hostProcess boolean
runAsUserName string
startupProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
stdin boolean
stdinOnce boolean
terminationMessagePath string
terminationMessagePolicy string
tty boolean
volumeDevices []object
devicePath string
name string
volumeMounts []object
mountPath string
mountPropagation string
name string
readOnly boolean
recursiveReadOnly string
subPath string
subPathExpr string
workingDir string
dnsConfig object
nameservers []string
options []object
name string
value string
searches []string
dnsPolicy string
enableServiceLinks boolean
ephemeralContainers []object
args []string
command []string
env []object
name string
value string
valueFrom object
configMapKeyRef object
key string
name string
optional boolean
fieldRef object
apiVersion string
fieldPath string
fileKeyRef object
key string
optional boolean
path string
volumeName string
resourceFieldRef object
containerName string
divisor string | integer
resource string
secretKeyRef object
key string
name string
optional boolean
envFrom []object
configMapRef object
name string
optional boolean
prefix string
secretRef object
name string
optional boolean
image string
imagePullPolicy string
lifecycle object
postStart object
exec object
command []string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
sleep object
seconds integer
tcpSocket object
host string
port string | integer
preStop object
exec object
command []string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
sleep object
seconds integer
tcpSocket object
host string
port string | integer
stopSignal string
livenessProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
name string
ports []object
containerPort integer
hostIP string
hostPort integer
name string
protocol string
readinessProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
resizePolicy []object
resourceName string
restartPolicy string
resources object
claims []object
name string
request string
limits object
requests object
restartPolicy string
restartPolicyRules []object
action string
exitCodes object
operator string
values []integer
securityContext object
allowPrivilegeEscalation boolean
appArmorProfile object
localhostProfile string
type string
capabilities object
add []string
drop []string
privileged boolean
procMount string
readOnlyRootFilesystem boolean
runAsGroup integer
runAsNonRoot boolean
runAsUser integer
seLinuxOptions object
level string
role string
type string
user string
seccompProfile object
localhostProfile string
type string
windowsOptions object
gmsaCredentialSpec string
gmsaCredentialSpecName string
hostProcess boolean
runAsUserName string
startupProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
stdin boolean
stdinOnce boolean
targetContainerName string
terminationMessagePath string
terminationMessagePolicy string
tty boolean
volumeDevices []object
devicePath string
name string
volumeMounts []object
mountPath string
mountPropagation string
name string
readOnly boolean
recursiveReadOnly string
subPath string
subPathExpr string
workingDir string
hostAliases []object
hostnames []string
ip string
hostIPC boolean
hostNetwork boolean
hostPID boolean
hostUsers boolean
hostname string
hostnameOverride string
imagePullSecrets []object
name string
initContainers []object
args []string
command []string
env []object
name string
value string
valueFrom object
configMapKeyRef object
key string
name string
optional boolean
fieldRef object
apiVersion string
fieldPath string
fileKeyRef object
key string
optional boolean
path string
volumeName string
resourceFieldRef object
containerName string
divisor string | integer
resource string
secretKeyRef object
key string
name string
optional boolean
envFrom []object
configMapRef object
name string
optional boolean
prefix string
secretRef object
name string
optional boolean
image string
imagePullPolicy string
lifecycle object
postStart object
exec object
command []string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
sleep object
seconds integer
tcpSocket object
host string
port string | integer
preStop object
exec object
command []string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
sleep object
seconds integer
tcpSocket object
host string
port string | integer
stopSignal string
livenessProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
name string
ports []object
containerPort integer
hostIP string
hostPort integer
name string
protocol string
readinessProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
resizePolicy []object
resourceName string
restartPolicy string
resources object
claims []object
name string
request string
limits object
requests object
restartPolicy string
restartPolicyRules []object
action string
exitCodes object
operator string
values []integer
securityContext object
allowPrivilegeEscalation boolean
appArmorProfile object
localhostProfile string
type string
capabilities object
add []string
drop []string
privileged boolean
procMount string
readOnlyRootFilesystem boolean
runAsGroup integer
runAsNonRoot boolean
runAsUser integer
seLinuxOptions object
level string
role string
type string
user string
seccompProfile object
localhostProfile string
type string
windowsOptions object
gmsaCredentialSpec string
gmsaCredentialSpecName string
hostProcess boolean
runAsUserName string
startupProbe object
exec object
command []string
failureThreshold integer
grpc object
port integer
service string
httpGet object
host string
httpHeaders []object
name string
value string
path string
port string | integer
scheme string
initialDelaySeconds integer
periodSeconds integer
successThreshold integer
tcpSocket object
host string
port string | integer
terminationGracePeriodSeconds integer
timeoutSeconds integer
stdin boolean
stdinOnce boolean
terminationMessagePath string
terminationMessagePolicy string
tty boolean
volumeDevices []object
devicePath string
name string
volumeMounts []object
mountPath string
mountPropagation string
name string
readOnly boolean
recursiveReadOnly string
subPath string
subPathExpr string
workingDir string
nodeName string
nodeSelector object
os object
name string
overhead object
preemptionPolicy string
priority integer
priorityClassName string
readinessGates []object
conditionType string
resourceClaims []object
name string
resourceClaimName string
resourceClaimTemplateName string
resources object
claims []object
name string
request string
limits object
requests object
restartPolicy string
runtimeClassName string
schedulerName string
schedulingGates []object
name string
schedulingGroup object
podGroupName string
securityContext object
appArmorProfile object
localhostProfile string
type string
fsGroup integer
fsGroupChangePolicy string
runAsGroup integer
runAsNonRoot boolean
runAsUser integer
seLinuxChangePolicy string
seLinuxOptions object
level string
role string
type string
user string
seccompProfile object
localhostProfile string
type string
supplementalGroups []integer
supplementalGroupsPolicy string
sysctls []object
name string
value string
windowsOptions object
gmsaCredentialSpec string
gmsaCredentialSpecName string
hostProcess boolean
runAsUserName string
serviceAccount string
serviceAccountName string
setHostnameAsFQDN boolean
shareProcessNamespace boolean
subdomain string
terminationGracePeriodSeconds integer
tolerations []object
effect string
key string
operator string
tolerationSeconds integer
value string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
maxSkew integer
minDomains integer
nodeAffinityPolicy string
nodeTaintsPolicy string
topologyKey string
whenUnsatisfiable string
volumes []object
awsElasticBlockStore object
fsType string
partition integer
readOnly boolean
volumeID string
azureDisk object
cachingMode string
diskName string
diskURI string
fsType string
kind string
readOnly boolean
azureFile object
readOnly boolean
secretName string
shareName string
cephfs object
monitors []string
path string
readOnly boolean
secretFile string
secretRef object
name string
user string
cinder object
fsType string
readOnly boolean
secretRef object
name string
volumeID string
configMap object
defaultMode integer
items []object
key string
mode integer
path string
name string
optional boolean
csi object
driver string
fsType string
nodePublishSecretRef object
name string
readOnly boolean
volumeAttributes object
downwardAPI object
defaultMode integer
items []object
fieldRef object
apiVersion string
fieldPath string
mode integer
path string
resourceFieldRef object
containerName string
divisor string | integer
resource string
emptyDir object
medium string
sizeLimit string | integer
ephemeral object
volumeClaimTemplate object
metadata object
annotations object
creationTimestamp string
deletionGracePeriodSeconds integer
deletionTimestamp string
finalizers []string
generateName string
generation integer
labels object
managedFields []object
apiVersion string
fieldsType string
fieldsV1 object
manager string
operation string
subresource string
time string
name string
namespace string
ownerReferences []object
apiVersion string
blockOwnerDeletion boolean
controller boolean
kind string
name string
uid string
resourceVersion string
selfLink string
uid string
spec object
accessModes []string
dataSource object
apiGroup string
kind string
name string
dataSourceRef object
apiGroup string
kind string
name string
namespace string
resources object
limits object
requests object
selector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
storageClassName string
volumeAttributesClassName string
volumeMode string
volumeName string
fc object
fsType string
lun integer
readOnly boolean
targetWWNs []string
wwids []string
flexVolume object
driver string
fsType string
options object
readOnly boolean
secretRef object
name string
flocker object
datasetName string
datasetUUID string
gcePersistentDisk object
fsType string
partition integer
pdName string
readOnly boolean
gitRepo object
directory string
repository string
revision string
glusterfs object
endpoints string
path string
readOnly boolean
hostPath object
path string
type string
image object
pullPolicy string
reference string
iscsi object
chapAuthDiscovery boolean
chapAuthSession boolean
fsType string
initiatorName string
iqn string
iscsiInterface string
lun integer
portals []string
readOnly boolean
secretRef object
name string
targetPortal string
name string
nfs object
path string
readOnly boolean
server string
persistentVolumeClaim object
claimName string
readOnly boolean
photonPersistentDisk object
fsType string
pdID string
portworxVolume object
fsType string
readOnly boolean
volumeID string
projected object
defaultMode integer
sources []object
clusterTrustBundle object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
name string
optional boolean
path string
signerName string
configMap object
items []object
key string
mode integer
path string
name string
optional boolean
downwardAPI object
items []object
fieldRef object
apiVersion string
fieldPath string
mode integer
path string
resourceFieldRef object
containerName string
divisor string | integer
resource string
podCertificate object
certificateChainPath string
credentialBundlePath string
keyPath string
keyType string
maxExpirationSeconds integer
signerName string
userAnnotations object
secret object
items []object
key string
mode integer
path string
name string
optional boolean
serviceAccountToken object
audience string
expirationSeconds integer
path string
quobyte object
group string
readOnly boolean
registry string
tenant string
user string
volume string
rbd object
fsType string
image string
keyring string
monitors []string
pool string
readOnly boolean
secretRef object
name string
user string
scaleIO object
fsType string
gateway string
protectionDomain string
readOnly boolean
secretRef object
name string
sslEnabled boolean
storageMode string
storagePool string
system string
volumeName string
secret object
defaultMode integer
items []object
key string
mode integer
path string
optional boolean
secretName string
storageos object
fsType string
readOnly boolean
secretRef object
name string
volumeName string
volumeNamespace string
vsphereVolume object
fsType string
storagePolicyID string
storagePolicyName string
volumePath string
update object
Configuration related to Keycloak deployment updates.
labels object
Optionally set to add additional labels to the Job created for the update.
revision string
When use the Explicit strategy, the revision signals if a rolling update can be used or not.
scheduling object
In this section you can configure the update job's scheduling
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
weight integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key string
operator string
values []string
matchFields []object
key string
operator string
values []string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
weight integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
mismatchLabelKeys []string
namespaceSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
namespaces []string
topologyKey string
priorityClassName string
tolerations []object
effect string
key string
operator string
tolerationSeconds integer
value string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key string
operator string
values []string
matchLabels object
matchLabelKeys []string
maxSkew integer
minDomains integer
nodeAffinityPolicy string
nodeTaintsPolicy string
topologyKey string
whenUnsatisfiable string
strategy string
Sets the update strategy to use.
enum: Auto, Explicit, RecreateOnImageChange
status object
conditions []object
lastTransitionTime string
message string
observedGeneration integer
status string
type string
instances integer
observedGeneration integer
selector string

No matches. Try .spec.additionalOptions for an exact path