{
  "properties": {
    "spec": {
      "additionalProperties": false,
      "properties": {
        "client": {
          "additionalProperties": false,
          "properties": {
            "allowEcpFlow": {
              "description": "Allow ECP (Enhanced Client or Proxy) flow",
              "type": [
                "boolean",
                "null"
              ]
            },
            "appUrl": {
              "description": "URL to the application's homepage that is represented by this client",
              "type": [
                "string",
                "null"
              ]
            },
            "clientSignatureRequired": {
              "description": "Require client to sign SAML requests",
              "type": [
                "boolean",
                "null"
              ]
            },
            "createdTimestamp": {
              "description": "Timestamp when the client was created",
              "type": [
                "integer",
                "null"
              ]
            },
            "description": {
              "description": "Human readable description of the client",
              "type": [
                "string",
                "null"
              ]
            },
            "displayName": {
              "description": "Human readable name of the client",
              "type": [
                "string",
                "null"
              ]
            },
            "enabled": {
              "description": "Whether this client is enabled",
              "type": [
                "boolean",
                "null"
              ]
            },
            "forceNameIdFormat": {
              "description": "Force the specified Name ID format even if the client requests a different one",
              "type": [
                "boolean",
                "null"
              ]
            },
            "forcePostBinding": {
              "description": "Force POST binding for SAML responses",
              "type": [
                "boolean",
                "null"
              ]
            },
            "frontChannelLogout": {
              "description": "Use front-channel logout (browser redirect)",
              "type": [
                "boolean",
                "null"
              ]
            },
            "includeAuthnStatement": {
              "description": "Include AuthnStatement in the SAML response",
              "type": [
                "boolean",
                "null"
              ]
            },
            "nameIdFormat": {
              "description": "Name ID format to use for the subject",
              "enum": [
                "email",
                "persistent",
                "transient",
                "username"
              ],
              "type": [
                "string",
                "null"
              ]
            },
            "redirectUris": {
              "description": "URIs that the browser can redirect to after login",
              "items": {
                "type": "string"
              },
              "type": [
                "array",
                "null"
              ]
            },
            "roles": {
              "description": "Roles associated with this client",
              "items": {
                "type": "string"
              },
              "type": [
                "array",
                "null"
              ]
            },
            "signAssertions": {
              "description": "Sign SAML assertions",
              "type": [
                "boolean",
                "null"
              ]
            },
            "signDocuments": {
              "description": "Sign SAML documents on the server side",
              "type": [
                "boolean",
                "null"
              ]
            },
            "signatureAlgorithm": {
              "description": "Signature algorithm for signing SAML documents",
              "enum": [
                "DSA_SHA1",
                "RSA_SHA1",
                "RSA_SHA256",
                "RSA_SHA256_MGF1",
                "RSA_SHA512",
                "RSA_SHA512_MGF1"
              ],
              "type": [
                "string",
                "null"
              ]
            },
            "signatureCanonicalizationMethod": {
              "description": "Canonicalization method for XML signatures",
              "type": [
                "string",
                "null"
              ]
            },
            "signingCertificate": {
              "description": "X.509 certificate for signing (PEM format, without headers)",
              "type": [
                "string",
                "null"
              ]
            },
            "updatedTimestamp": {
              "description": "Timestamp when the client was last updated",
              "type": [
                "integer",
                "null"
              ]
            }
          },
          "type": "object"
        },
        "keycloakCRName": {
          "description": "The name of the Keycloak CR to reference, in the same namespace.",
          "type": "string",
          "x-kubernetes-validations": [
            {
              "message": "keycloakCrName is immutable",
              "rule": "self == oldSelf"
            }
          ]
        },
        "realm": {
          "description": "The realm of the Client",
          "type": "string",
          "x-kubernetes-validations": [
            {
              "message": "realm is immutable",
              "rule": "self == oldSelf"
            }
          ]
        }
      },
      "required": [
        "client",
        "keycloakCRName",
        "realm"
      ],
      "type": "object"
    },
    "status": {
      "additionalProperties": false,
      "properties": {
        "conditions": {
          "items": {
            "additionalProperties": false,
            "properties": {
              "lastTransitionTime": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "message": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "observedGeneration": {
                "type": [
                  "integer",
                  "null"
                ]
              },
              "status": {
                "type": [
                  "string",
                  "null"
                ]
              },
              "type": {
                "type": [
                  "string",
                  "null"
                ]
              }
            },
            "type": "object"
          },
          "type": [
            "array",
            "null"
          ]
        },
        "hash": {
          "type": [
            "string",
            "null"
          ]
        },
        "observedGeneration": {
          "type": [
            "integer",
            "null"
          ]
        },
        "uuid": {
          "type": [
            "string",
            "null"
          ]
        }
      },
      "type": [
        "object",
        "null"
      ]
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}