KeycloakSAMLClient
k8s.keycloak.org / v2alpha1
apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakSAMLClient
metadata:
name: example
spec object required
client object required
allowEcpFlow
boolean
Allow ECP (Enhanced Client or Proxy) flow
appUrl
string
URL to the application's homepage that is represented by this client
clientSignatureRequired
boolean
Require client to sign SAML requests
createdTimestamp
integer
Timestamp when the client was created
description
string
Human readable description of the client
displayName
string
Human readable name of the client
enabled
boolean
Whether this client is enabled
forceNameIdFormat
boolean
Force the specified Name ID format even if the client requests a different one
forcePostBinding
boolean
Force POST binding for SAML responses
frontChannelLogout
boolean
Use front-channel logout (browser redirect)
includeAuthnStatement
boolean
Include AuthnStatement in the SAML response
nameIdFormat
string
Name ID format to use for the subject
enum:
email, persistent, transient, username
redirectUris
[]string
URIs that the browser can redirect to after login
roles
[]string
Roles associated with this client
signAssertions
boolean
Sign SAML assertions
signDocuments
boolean
Sign SAML documents on the server side
signatureAlgorithm
string
Signature algorithm for signing SAML documents
enum:
DSA_SHA1, RSA_SHA1, RSA_SHA256, RSA_SHA256_MGF1, RSA_SHA512, RSA_SHA512_MGF1
signatureCanonicalizationMethod
string
Canonicalization method for XML signatures
signingCertificate
string
X.509 certificate for signing (PEM format, without headers)
updatedTimestamp
integer
Timestamp when the client was last updated
keycloakCRName
string required
The name of the Keycloak CR to reference, in the same namespace.
realm
string required
The realm of the Client
status object
conditions []object
lastTransitionTime
string
message
string
observedGeneration
integer
status
string
type
string
hash
string
observedGeneration
integer
uuid
string
No matches. Try .spec.client for an exact path