Compare commits

...

71 Commits

Author SHA1 Message Date
oxaliq 9555bc7980 add bootstrap password generation to release note
continuous-integration/drone/pr Build is failing
2026-04-10 14:52:22 -04:00
oxaliq 44529dc36a add bootstrap password to secrets
also changes environment variables to reflect KC_BOOTSTRAP values for
temporary bootstrap admin user
2026-04-10 12:11:03 -04:00
oxaliq a6b84ce9b6 prepare kcadm release
continuous-integration/drone/pr Build is failing
2026-04-03 12:07:18 -04:00
oxaliq a85d4f3b8f add documentation for admin cli
continuous-integration/drone/pr Build is failing
also updates initial setup documentation to reflect admin cli usage
in creating permanent admin user.
2026-04-01 11:28:04 -04:00
oxaliq 1fe630211a remove password option from kcadm authentication where possible 2026-04-01 10:54:18 -04:00
oxaliq c6eb27e10c implement kcadm and changes to allow kcadm.sh to authenticate
in order to run kcadm.sh commands the script must authenticate to the REST API.
this commit includes an init_kc command that replaces the bootstrap user with
a permanent admin user (whose password is a docker swarm secret) that can be
used to authenticate before running kcadm commands. this reuses the secret
'admin_password' that was previously used as the password for the bootstrap
admin user.
2026-03-31 12:56:03 -04:00
notplants a5c314f891 Merge pull request '10.6.1+26.5.4: fix backup/restore' (#24) from 10.6.1+26.5.4 into master
continuous-integration/drone/push Build is failing
Reviewed-on: #24
Reviewed-by: ammaratef45 <ammaratef45@proton.me>
2026-02-28 18:56:36 +00:00
notplants 3e6ca4ddc0 Merge pull request 'upgrade to 10.6.0+26.5.4' (#23) from 10.6.0+26.5.4 into master
continuous-integration/drone/push Build is failing
Reviewed-on: #23
Reviewed-by: cyrnel <cyrnel@noreply.git.coopcloud.tech>
Reviewed-by: ammaratef45 <ammaratef45@proton.me>
2026-02-28 18:56:14 +00:00
notplants a69ad2f1d2 bump to 10.6.1+26.5.4
continuous-integration/drone/tag Build is passing
continuous-integration/drone/pr Build is failing
2026-02-26 22:12:39 +00:00
notplants df8d472af4 fix backup/restore hooks: use volume path and correct hook ordering 2026-02-26 22:12:32 +00:00
notplants a8e9862a0e chore: upgrade to 10.6.0+26.5.4
continuous-integration/drone/tag Build is passing
continuous-integration/drone/pr Build is failing
2026-02-26 18:54:39 +00:00
3wordchant f26fcd4c95 chore: publish 10.5.1+26.4.5 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-11-21 11:39:51 -05:00
cyrnel a250244f23 chore: publish 10.5.0+26.4.0 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-10-17 16:18:56 -04:00
cyrnel c225bad91d Merge pull request 'chore: upgrade to v26.4.0' (#22) from 26-4-0 into master
continuous-integration/drone/push Build is passing
Reviewed-on: #22
2025-10-17 19:57:11 +00:00
cyrnel 868a907028 chore: upgrade to v26.4.0
continuous-integration/drone/pr Build is failing
2025-10-13 17:28:37 -04:00
ammaratef45 8864d5f5e8 Merge pull request 'link directly to the integration section of other recipes' (#21) from update_readme into master
continuous-integration/drone/push Build is passing
Reviewed-on: #21
Reviewed-by: decentral1se <decentral1se@noreply.git.coopcloud.tech>
Reviewed-by: 3wordchant <3wordchant@noreply.git.coopcloud.tech>
2025-09-16 18:55:46 +00:00
ammaratef45 a79280b7d6 link directly to the integration section of other recipes
continuous-integration/drone/pr Build is failing
2025-09-16 06:12:45 -07:00
knoflook 4866c6d38e chore: publish 10.4.1+26.3.2 release
continuous-integration/drone/push Build is passing
2025-07-24 14:28:09 +02:00
3wordchant e66e0556c2 chore: publish 10.4.0+26.3.1 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-07-23 18:12:59 +01:00
mac-chaffee eb5ff04e84 Merge pull request 'Add docs for initial admin user setup' (#20) from docs-n-deprecations into master
continuous-integration/drone/push Build is passing
Reviewed-on: #20
2025-06-24 12:28:52 +00:00
Mac Chaffee 35461d2f59 Convert bootstrap-admin command to one-liner
continuous-integration/drone/pr Build is failing
2025-06-22 09:42:20 -04:00
Mac Chaffee abcc59c07c Add docs for initial admin user setup
continuous-integration/drone/pr Build is failing
2025-06-21 21:56:35 -04:00
Mac Chaffee 2e863fb666 Fix deprecated traefik labels for TLS 2025-06-21 21:56:23 -04:00
cas 2c77a8fced chore: publish 10.3.1+26.2.5 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-06-18 10:25:17 -07:00
3wordchant bd2ec2cd9d chore: publish 10.3.0+26.2.1 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-04-23 18:38:24 +02:00
3wordchant 7af65faa5a chore: publish 10.2.1+26.1.2 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-02-26 12:46:39 -05:00
3wordchant 636e81002d Add missing KC_HTTP_ENABLED 2025-02-26 12:46:02 -05:00
3wordchant d3c9fc4784 chore: publish 10.2.0+26.1.2 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-02-26 12:27:10 -05:00
example 41877e765a chore: publish 10.1.1+26.0.1 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2025-01-28 17:43:08 +01:00
example c08753a3ff fix: db backup labels 2025-01-28 17:41:20 +01:00
cas 1af583a429 Update .drone.yml
continuous-integration/drone/push Build is passing
2025-01-08 10:09:13 -08:00
3wordchant ef9fbd5436 Add KC_PROXY_HEADERS to make self-service account URL work
continuous-integration/drone/push Build is passing
2024-11-30 18:50:30 -05:00
3wordchant 1ee9f5e5d7 chore: publish 10.1.0+26.0.1 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2024-10-23 14:23:23 -04:00
3wordchant 88b9c3df1d Add caddy support 2024-10-23 14:22:58 -04:00
trav 9050321e50 chore: publish 10.0.1+26.0.1 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2024-10-23 13:51:04 -04:00
trav d63bb8bc54 fix login http form
continuous-integration/drone/push Build is passing
2024-10-23 13:49:23 -04:00
trav 6053df415e chore: publish 10.0.0+26.0.1 release
continuous-integration/drone/tag Build is passing
continuous-integration/drone/push Build is passing
2024-10-23 13:30:11 -04:00
3wordchant ab009bae84 chore: publish 9.0.0+25.0.6 release
continuous-integration/drone/push Build is passing
2024-10-02 13:30:05 -04:00
3wordchant b02db66093 chore: publish 8.0.1+23.0.6 release
continuous-integration/drone/push Build is passing
2024-02-08 14:37:28 -03:00
3wordchant a4ce30cc5c chore: publish 8.0.0+23.0.0 release
continuous-integration/drone/push Build is passing
2023-11-27 12:11:46 +00:00
3wordchant e7360c2a16 chore: publish 7.2.0+22.0.5 release
continuous-integration/drone/push Build is passing
2023-11-22 15:27:32 +00:00
3wordchant 5b83f487ec Fix compose file version 2023-11-22 15:25:43 +00:00
3wordchant 3d42a26b9e Make persistent theme volume optional 2023-11-22 15:23:27 +00:00
knoflook 6aac16ebd6 chore: publish 7.1.0+22.0.5 release
continuous-integration/drone/push Build is passing
2023-11-22 16:15:42 +01:00
cas a5aae68446 chore: publish 7.0.2+22.0.5 release
continuous-integration/drone/push Build is passing
2023-11-09 09:47:55 -08:00
3wordchant 82f6ad5d52 chore: publish 7.0.1+22.0.4 release
continuous-integration/drone/push Build is passing
2023-10-23 13:56:16 +01:00
decentral1se 04b584ab4f chore: publish 7.0.0+22.0.1 release
continuous-integration/drone/push Build is passing
2023-07-20 17:04:52 +02:00
3wordchant d2b9fffc46 chore: publish 6.0.0+21.0.2 release
continuous-integration/drone/push Build is passing
2023-04-12 17:34:23 -04:00
3wordchant b682264613 chore: publish 6.0.0+21.0.2 release
continuous-integration/drone/push Build is passing
2023-04-12 17:17:24 -04:00
3wordchant be3980d66f chore: publish 5.1.0+20.0.3 release
continuous-integration/drone/push Build is failing
2023-03-19 19:22:18 -04:00
knoflook 157d3beaab fix: put the admin password in the container, also add restore capabilities
continuous-integration/drone/push Build is passing
2023-03-05 12:07:56 +01:00
knoflook d432a45c21 chore: publish 5.0.2+20.0.3 release
continuous-integration/drone/push Build is passing
2023-03-02 10:44:47 +01:00
knoflook 6a085e0546 fix: change the themes directory
continuous-integration/drone/push Build is passing
2023-03-02 10:43:03 +01:00
decentral1se 836abe0237 chore: publish 5.0.1+20.0.3 release
continuous-integration/drone/push Build is passing
2023-02-13 08:56:00 +01:00
3wordchant 9bd0b2928c Switch to self-hosted stack-ssh-deploy image [mass update]
continuous-integration/drone/push Build is passing
2023-01-21 11:49:56 -08:00
3wordchant f42183601c Fix CI by adding networks: [mass update]
continuous-integration/drone/push Build is passing
2023-01-20 11:58:41 -08:00
3wordchant 04618a142b Automatically generate catalogue on release [mass update]
continuous-integration/drone/push Build is failing
Re: coop-cloud/recipes-catalogue-json#4
2023-01-20 10:27:11 -08:00
3wordchant 5b306db9b7 Update abra syntax in examples (finally) [mass update]
continuous-integration/drone/push Build is failing
2023-01-19 16:02:27 -08:00
3wordchant c0fab3a3a3 fix: improve DB backup
continuous-integration/drone/push Build is failing
2022-12-22 19:20:30 -08:00
decentral1se 2ac47abfcd feat!: new 20.x release
continuous-integration/drone/push Build is failing
2022-11-16 19:37:17 +01:00
decentral1se ef6ffd9985 feat: backup labels for mysql 2022-11-16 18:16:25 +01:00
philippr 38bdef2fd0 adds welcome_theme env
continuous-integration/drone/push Build is failing
2022-05-18 14:54:35 +02:00
decentral1se 2de7006106 chore: publish 4.0.1+16.1.1 release
continuous-integration/drone/push Build is failing
2022-02-10 11:02:13 +01:00
decentral1se 0edb882a06 release: expand notes 2022-01-03 16:09:47 +01:00
decentral1se 2c29c75398 release: add notes 2022-01-02 15:57:16 +01:00
decentral1se d32ea20cff chore: publish 4.0.0+16.1.0 release 2022-01-02 15:53:12 +01:00
3wordchant 4e2c0013ce Goodbye, emojis! 😢
[ci skip]
2021-11-23 12:19:05 +02:00
3wordchant 45918d2451 Add app config tips from docs
continuous-integration/drone/push Build is failing
2021-10-30 17:27:31 +02:00
d1admin 1f2ed7932b feat: support storing themes persistently
continuous-integration/drone/push Build is failing
2021-10-21 14:16:23 +02:00
d1admin 6326aff4f0 Revert "feat: custom theme loading"
continuous-integration/drone/push Build is failing
This reverts commit 3b9d0237b2.

This doesn't work because we can't get into the root account in the
entrypoint and we need that to use microdnf. Another approach is needed.
2021-10-21 14:14:16 +02:00
decentral1se f4220652a7 Merge pull request 'Custom theme loading' (#10) from custom-theme-loading into master
continuous-integration/drone/push Build is failing
Reviewed-on: #10
2021-10-21 11:48:21 +00:00
13 changed files with 208 additions and 63 deletions
+14 -6
View File
@@ -3,10 +3,12 @@ kind: pipeline
name: deploy to swarm-test.autonomic.zone
steps:
- name: deployment
image: decentral1se/stack-ssh-deploy:latest
image: git.coopcloud.tech/coop-cloud/stack-ssh-deploy:latest
settings:
host: swarm-test.autonomic.zone
stack: keycloak
networks:
- proxy
generate_secrets: true
purge: true
deploy_key:
@@ -23,11 +25,17 @@ trigger:
- master
---
kind: pipeline
name: recipe release
name: generate recipe catalogue
steps:
- name: release a new version
image: thecoopcloud/drone-abra:latest
image: plugins/downstream
settings:
command: recipe keycloak release
deploy_key:
from_secret: abra_bot_deploy_key
server: https://build.coopcloud.tech
token:
from_secret: drone_abra-bot_token
fork: true
repositories:
- toolshed/auto-recipes-catalogue-json
trigger:
event: tag
+8 -2
View File
@@ -5,11 +5,17 @@ DOMAIN=keycloak.example.com
#EXTRA_DOMAINS=', `www.keycloak.example.com`'
LETS_ENCRYPT_ENV=production
# ADMIN_USERNAME and _EMAIL are for permanent admin user
ADMIN_USERNAME=admin
ADMIN_EMAIL=
WELCOME_THEME=keycloak
# CUSTOM_THEME_ENABLED=1
# CUSTOM_THEME_URL=
COMPOSE_FILE="compose.yml"
SECRET_DB_ROOT_PASSWORD_VERSION=v1
SECRET_DB_PASSWORD_VERSION=v1
SECRET_ADMIN_PASSWORD_VERSION=v1
SECRET_BOOTSTRAP_PASSWORD_VERSION=v1
# Enable persistent theme volume, if you want to apply a custom theme
#COMPOSE_FILE="$COMPOSE_FILE:compose.theme.yml"
+53 -7
View File
@@ -6,12 +6,12 @@
<!-- metadata -->
* **Category**: Apps
* **Status**: ❷💛
* **Image**: [`jboss/keycloak`](https://hub.docker.com/r/jboss/keycloak), ❶💚, upstream
* **Status**: 2, beta
* **Image**: [`jboss/keycloak`](https://hub.docker.com/r/jboss/keycloak), 4, upstream
* **Healthcheck**: Yes
* **Backups**: ?
* **Email**: ❸🍎
* **Tests**: ❷💛
* **Email**: 1
* **Tests**: 2
* **SSO**: N/A
<!-- endmetadata -->
@@ -20,10 +20,56 @@
1. Set up Docker Swarm and [`abra`][abra]
2. Deploy [`coop-cloud/traefik`][cc-traefik]
3. `abra app new keycloak --secrets` (optionally with `--pass` if you'd like
to save secrets in `pass`)
4. `abra app YOURAPPDOMAIN config` - be sure to change `$DOMAIN` to something that resolves to
to save secrets in `pass`). Make sure to note the `admin_password`
4. `abra app config YOURAPPDOMAIN` - be sure to change `$DOMAIN` to something that resolves to
your Docker swarm box
5. `abra app YOURAPPDOMAIN deploy`
5. `abra app deploy YOURAPPDOMAIN`
6. Proceed with replacing the temporary admin user
## Replacing the temporary admin user
The inital user created by Keycloak, is a bootstrap user whose password is stored in plain text on the server. This recipe assigns that user the name "admin_bootstrap" and the password $BOOTSTRAP_PASSWORD set by `abra app config YOURAPDOMAIN`
Running `abra app command YOURAPPDOMAIN app init_kc` replaces this bootstrap admin with a permanent admin user whose username is $ADMIN_USERNAME and whose password is the secret generated in step 3 above. This will also delete the temporary admin user.
It is recommended to also set up MFA for this account from the web admin panel. Log in to the account, select manage account, select account security/signing in, and enable two factor authentication.
## Running Commands in Keycloak's Admin CLI
To authenticate a session to Keycloak's admin API run:
`abra app command YOURAPPDOMAIN app login_kcadm`
After this you can run any Admin CLI command via the run_kcadm command. An example, which creates a "sandbox" realm:
`abra app command YOURAPPDOMAIN app run_kcadm "'create realms -s realm=sandbox -s displayName=sandbox -s enabled=true'"`
[Keycloak Admin CLI documentation](https://www.keycloak.org/docs/latest/server_admin/index.html#admin-cli) has more info on running kcadm commands
## How do I setup a custom theme?
Check [this approach](https://git.autonomic.zone/ruangrupa/login.lumbung.space).
## How do I create another admin user?
- Under the `Master` realm > `Users` > `Add user`
- Create the user and set a temporary password
- Under the `Role Mappings` tab, move `admin` from `Available Roles` into `Assigned Roles`
## What do I do if I lost my admin account credentials?
You can create a new admin account like this:
```
abra app run <domain> app -- bash -c '/opt/keycloak/bin/kc.sh bootstrap-admin user --db-password $(cat /run/secrets/db_password)'
```
Make sure to delete the temp-admin user after you finish recovering.
## How do I configure Keycloak login for..
- [Nextcloud][nextcloud]
- [Peertube][peertube]
[nextcloud]: https://git.coopcloud.tech/coop-cloud/nextcloud#how-do-i-integrate-with-keycloak-sso
[peertube]: https://git.coopcloud.tech/coop-cloud/peertube#plugins
[abra]: https://git.autonomic.zone/autonomic-cooperative/abra
[cc-traefik]: https://git.autonomic.zone/coop-cloud/traefik
+29 -1
View File
@@ -1 +1,29 @@
export ENTRYPOINT_CONF_VERSION=v1
#!/bin/bash
run_kcadm() {
bin/sh -c "/opt/keycloak/bin/kcadm.sh $@"
}
login_kcadm() {
export KC_CLI_PASSWORD=$(cat /run/secrets/admin_password)
run_kcadm "config credentials --server http://localhost:8080 --realm master --user ${ADMIN_USERNAME}"
}
init_kc() {
BOOTSTRAP_PW=$(cat /run/secrets/bootstrap_password)
run_kcadm "config credentials --server http://localhost:8080 --realm master --user admin_bootstrap --password ${BOOTSTRAP_PW}"
# CREATE NEW ADMIN USER
ADMIN_PW=$(cat /run/secrets/admin_password)
run_kcadm "create users -r master -s username=${ADMIN_USERNAME} -s email='${ADMIN_EMAIL}' -s emailVerified=true -s enabled=true"
run_kcadm "set-password -r master --username ${ADMIN_USERNAME} --new-password ${ADMIN_PW}"
run_kcadm "add-roles --uusername ${ADMIN_USERNAME} --rolename admin --rolename default-roles-master"
export KC_CLI_PASSWORD="$ADMIN_PW"
# AUTHENTICATE WITH NEW ADMIN USER
run_kcadm "config credentials --server http://localhost:8080 --realm master --user ${ADMIN_USERNAME}"
# DEMOTE BOOTSTRAP ADMIN IN CASE WE CAN'T DELETE
run_kcadm "remove-roles -r master --uusername admin_bootstrap --rolename admin --rolename default-roles-master"
# JSON MUNGING
BOOTSTRAP_ID=$(run_kcadm "get users -q username=admin_bootstrap --limit 1 --fields id | grep id | cut -d : -f2 | tr -d [:space:]")
run_kcadm "delete -r master users/${BOOTSTRAP_ID}"
}
+7
View File
@@ -0,0 +1,7 @@
services:
app:
volumes:
- "themes:/opt/keycloak/themes"
volumes:
themes:
+43 -35
View File
@@ -1,37 +1,37 @@
---
version: "3.8"
services:
app:
image: "jboss/keycloak:15.0.2"
image: "keycloak/keycloak:26.5.4"
entrypoint: >
bash -c "KC_BOOTSTRAP_ADMIN_PASSWORD=\"$$(cat run/secrets/bootstrap_password)\" KC_DB_PASSWORD=\"$$(cat /run/secrets/db_password)\" /opt/keycloak/bin/kc.sh start"
networks:
- proxy
- internal
secrets:
- admin_password
- bootstrap_password
- db_password
environment:
- CUSTOM_THEME_ENABLED
- CUSTOM_THEME_URL
- DB_ADDR=db
- DB_DATABASE=keycloak
- DB_PASSWORD_FILE=/run/secrets/db_password
- DB_USER=keycloak
- DB_VENDOR=mariadb
- KEYCLOAK_PASSWORD_FILE=/run/secrets/admin_password
- KEYCLOAK_USER=${ADMIN_USERNAME}
- PROXY_ADDRESS_FORWARDING=true
configs:
- source: entrypoint_conf
target: /docker-entrypoint.sh
mode: 0555
entrypoint: /docker-entrypoint.sh
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8080"]
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
- KC_DB=mariadb
- KC_DB_URL_DATABASE=keycloak
- KC_DB_URL_HOST=db
- KC_HOSTNAME=https://${DOMAIN}
- KC_PROXY=edge
- KC_SPI_CONNECTIONS_JPA_LEGACY_MIGRATION_STRATEGY=update
# admin_bootstrap will be superceded by $ADMIN_USERNAME on init_kc
- KC_BOOTSTRAP_ADMIN_USERNAME=admin_bootstrap
- KEYCLOAK_WELCOME_THEME=${WELCOME_THEME}
- KC_PROXY_HEADERS=xforwarded
- KC_HTTP_ENABLED=true
# NOTE(3wc): disabled due to missing curl binary, see
# https://git.coopcloud.tech/coop-cloud/keycloak/issues/15
# healthcheck:
# test: ["CMD", "curl", "-f", "http://localhost:8080"]
# interval: 30s
# timeout: 10s
# retries: 10
# start_period: 1m
volumes:
- "providers:/opt/keycloak/providers"
depends_on:
- mariadb
deploy:
@@ -45,12 +45,15 @@ services:
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "coop-cloud.${STACK_NAME}.version=3.0.0+15.0.2"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectscheme.scheme=https"
- "traefik.http.middlewares.${STACK_NAME}-redirect.redirectscheme.permanent=true"
- "caddy=${DOMAIN}"
- "caddy.reverse_proxy={{upstreams 8080}}"
- "caddy.tls.on_demand="
- "coop-cloud.${STACK_NAME}.version=10.6.1+26.5.4"
db:
image: "mariadb:10.6"
image: "mariadb:12.2"
environment:
- MYSQL_DATABASE=keycloak
- MYSQL_USER=keycloak
@@ -63,6 +66,13 @@ services:
- "mariadb:/var/lib/mysql"
networks:
- internal
deploy:
labels:
backupbot.backup: "true"
backupbot.backup.volumes.mariadb.path: "dump.sql.gz"
backupbot.backup.pre-hook: "sh -c 'mariadb-dump -u root -p\"$$(cat /run/secrets/db_root_password)\" keycloak | gzip > /var/lib/mysql/dump.sql.gz'"
backupbot.backup.post-hook: "rm -f /var/lib/mysql/dump.sql.gz"
backupbot.restore.post-hook: "sh -c 'gzip -d /var/lib/mysql/dump.sql.gz && mariadb -u root -p\"$$(cat /run/secrets/db_root_password)\" keycloak < /var/lib/mysql/dump.sql && rm -f /var/lib/mysql/dump.sql'"
networks:
internal:
@@ -73,6 +83,9 @@ secrets:
admin_password:
name: ${STACK_NAME}_admin_password_${SECRET_ADMIN_PASSWORD_VERSION}
external: true
bootstrap_password:
name: ${STACK_NAME}_bootstrap_password_${SECRET_BOOTSTRAP_PASSWORD_VERSION}
external: true
db_password:
name: ${STACK_NAME}_db_password_${SECRET_DB_PASSWORD_VERSION}
external: true
@@ -82,9 +95,4 @@ secrets:
volumes:
mariadb:
configs:
entrypoint_conf:
name: ${STACK_NAME}_entrypoint_conf_${ENTRYPOINT_CONF_VERSION}
file: entrypoint.sh.tmpl
template_driver: golang
providers:
-12
View File
@@ -1,12 +0,0 @@
#!/bin/bash
set -e
{{ if eq (env "CUSTOM_THEME_ENABLED") "1" }}
microdnf update && microdnf install git
git clone "$CUSTOM_THEME_URL" "/opt/jboss/keycloak/themes/$CUSTOM_THEME_NAME"
{{ end }}
# upstream entrypoint
# https://github.com/keycloak/keycloak-containers/blob/aa2e5515ccb05116e49ab38839d8fcfdd17c45aa/server/Dockerfile#L30
/usr/local/bin/entrypoint.sh "$@"
+1
View File
@@ -0,0 +1 @@
See here for possible breaking changes: https://www.keycloak.org/docs/latest/upgrading/#migrating-to-26-4-0
+12
View File
@@ -0,0 +1,12 @@
This major release comes with a blog post about a CVE:
https://www.keycloak.org/2021/12/cve.html
Not all versions are affected but they're suggesting that people upgrade soon.
As per usual, this upgrade didn't go too smoothly and I ended up having to
undeploy and deploy the new versions. The healtcheck kept failing on the new
instance when trying to deploy alongside the existing old version. Idk, some
docker weirdness.
No app data errors discovered after upgrade.
+9
View File
@@ -0,0 +1,9 @@
You'll need to remove `/auth/` from your app SSO URLs, e.g.
https://foo.example.com/auth/realms/foo/protocol/openid-connect/auth
Would become:
https://foo.example.com/realms/foo/protocol/openid-connect/auth
-- decentral1se @ Autonomic
+2
View File
@@ -0,0 +1,2 @@
Healthchecks are disabled, see
https://git.coopcloud.tech/coop-cloud/keycloak/issues/15
+5
View File
@@ -0,0 +1,5 @@
A persistent volume for themes is now optional, and not enabled by default.
If you are using a custom theme, consult the recipe `.env.sample` to see the new
variables you need to add. You can use `abra app check ...` to verify that
they've been added correctly.
+25
View File
@@ -0,0 +1,25 @@
This release introduces admin cli commands to "abra app command"
If you are updating from a previous release, please note that the meaning
of the "admin_password" secret is changed to reflect the permanent admin
user's password. To enable "login_kcadm" and "run_kcadm" commands, you
will need to add your permanent admin password to the secret store.
To increment the secret version:
"abra app config $APP"
change this line in the config file:
SECRET_ADMIN_PASSWORD_VERSION=NEW_VERSION
To insert your permanent admin password:
"abra app secret insert $APP SECRET_ADMIN_PASSWORD_VERSION \
$NEW_VERSION $ADMIN_PASSWORD"
You will also need to generate a bootstrap password (this will not be used)
"abra app secret generate $APP bootstrap_password v1
See here for more on rotating secrets:
https://docs.coopcloud.tech/operators/handbook/#rotating-a-secret
After redeploying, ensure that you are able to authenticate the admin
CLI by running:
"abra app command $APP app login_kcadm"