Compare commits

..

24 Commits

Author SHA1 Message Date
Christian Galo 9427619e89 Update Keycloak image version to 26.4 2025-12-05 01:29:56 +00:00
Christian Galo 1dcce43067 xforwarded 2025-02-25 07:54:57 +00:00
Christian Galo fb9acb2ef5 Update Keycloak environment variables for bootstrap configuration 2025-02-21 00:39:03 +00:00
Christian Galo e427203cda 26.1 changes. Replace KC_PROXY env due to deprecation 2025-02-19 08:32:58 +00:00
Christian Galo adba4a6dee Update Keycloak version to 25.0.1 and add providers volume 2024-07-22 02:23:42 +00:00
Christian Galo 743eee88cd keycloak bump version 2023-10-16 23:19:44 +00:00
Christian Galo 8d0149f128 un-abra-ify. 2023-08-14 07:24:41 +00:00
Christian Galo 2bdc8f8d1e delete abra-specific files. Rewrite README 2023-08-14 03:34:39 +00:00
decentral1se 04b584ab4f chore: publish 7.0.0+22.0.1 release
continuous-integration/drone/push Build is passing
2023-07-20 17:04:52 +02:00
3wordchant d2b9fffc46 chore: publish 6.0.0+21.0.2 release
continuous-integration/drone/push Build is passing
2023-04-12 17:34:23 -04:00
3wordchant b682264613 chore: publish 6.0.0+21.0.2 release
continuous-integration/drone/push Build is passing
2023-04-12 17:17:24 -04:00
3wordchant be3980d66f chore: publish 5.1.0+20.0.3 release
continuous-integration/drone/push Build is failing
2023-03-19 19:22:18 -04:00
knoflook 157d3beaab fix: put the admin password in the container, also add restore capabilities
continuous-integration/drone/push Build is passing
2023-03-05 12:07:56 +01:00
knoflook d432a45c21 chore: publish 5.0.2+20.0.3 release
continuous-integration/drone/push Build is passing
2023-03-02 10:44:47 +01:00
knoflook 6a085e0546 fix: change the themes directory
continuous-integration/drone/push Build is passing
2023-03-02 10:43:03 +01:00
decentral1se 836abe0237 chore: publish 5.0.1+20.0.3 release
continuous-integration/drone/push Build is passing
2023-02-13 08:56:00 +01:00
3wordchant 9bd0b2928c Switch to self-hosted stack-ssh-deploy image [mass update]
continuous-integration/drone/push Build is passing
2023-01-21 11:49:56 -08:00
3wordchant f42183601c Fix CI by adding networks: [mass update]
continuous-integration/drone/push Build is passing
2023-01-20 11:58:41 -08:00
3wordchant 04618a142b Automatically generate catalogue on release [mass update]
continuous-integration/drone/push Build is failing
Re: coop-cloud/recipes-catalogue-json#4
2023-01-20 10:27:11 -08:00
3wordchant 5b306db9b7 Update abra syntax in examples (finally) [mass update]
continuous-integration/drone/push Build is failing
2023-01-19 16:02:27 -08:00
3wordchant c0fab3a3a3 fix: improve DB backup
continuous-integration/drone/push Build is failing
2022-12-22 19:20:30 -08:00
decentral1se 2ac47abfcd feat!: new 20.x release
continuous-integration/drone/push Build is failing
2022-11-16 19:37:17 +01:00
decentral1se ef6ffd9985 feat: backup labels for mysql 2022-11-16 18:16:25 +01:00
philippr 38bdef2fd0 adds welcome_theme env
continuous-integration/drone/push Build is failing
2022-05-18 14:54:35 +02:00
8 changed files with 115 additions and 177 deletions
-33
View File
@@ -1,33 +0,0 @@
---
kind: pipeline
name: deploy to swarm-test.autonomic.zone
steps:
- name: deployment
image: decentral1se/stack-ssh-deploy:latest
settings:
host: swarm-test.autonomic.zone
stack: keycloak
generate_secrets: true
purge: true
deploy_key:
from_secret: drone_ssh_swarm_test
environment:
DOMAIN: keycloak.swarm-test.autonomic.zone
STACK_NAME: keycloak
LETS_ENCRYPT_ENV: production
SECRET_ADMIN_PASSWORD_VERSION: v1
SECRET_DB_PASSWORD_VERSION: v1
SECRET_DB_ROOT_PASSWORD_VERSION: v1
trigger:
branch:
- master
---
kind: pipeline
name: recipe release
steps:
- name: release a new version
image: thecoopcloud/drone-abra:latest
settings:
command: recipe keycloak release
deploy_key:
from_secret: abra_bot_deploy_key
-12
View File
@@ -1,12 +0,0 @@
TYPE=keycloak
DOMAIN=keycloak.example.com
## Domain aliases
#EXTRA_DOMAINS=', `www.keycloak.example.com`'
LETS_ENCRYPT_ENV=production
ADMIN_USERNAME=admin
SECRET_DB_ROOT_PASSWORD_VERSION=v1
SECRET_DB_PASSWORD_VERSION=v1
SECRET_ADMIN_PASSWORD_VERSION=v1
+1
View File
@@ -0,0 +1 @@
.env
+24 -34
View File
@@ -1,46 +1,36 @@
# keycloak
# Keycloak
[![Build Status](https://drone.autonomic.zone/api/badges/coop-cloud/keycloak/status.svg)](https://drone.autonomic.zone/coop-cloud/keycloak)
Wiki Cafe's configuration for a Keycloak deployment. Originally slimmed down from an `abra` [recipe](https://git.coopcloud.tech/coop-cloud/keycloak) by [Co-op Cloud](https://coopcloud.tech/).
[Keycloak](https://www.keycloak.org) + Coöp Cloud.
## Extensions
<!-- metadata -->
* **Category**: Apps
* **Status**: 2, beta
* **Image**: [`jboss/keycloak`](https://hub.docker.com/r/jboss/keycloak), 4, upstream
* **Healthcheck**: Yes
* **Backups**: ?
* **Email**: 1
* **Tests**: 2
* **SSO**: N/A
<!-- endmetadata -->
This stack includes the following extensions:
## Basic usage
- (keycloak-events)[https://github.com/p2-inc/keycloak-events]
- (keycloak-restrict-client-auth)[https://github.com/sventorben/keycloak-restrict-client-auth]
1. Set up Docker Swarm and [`abra`][abra]
2. Deploy [`coop-cloud/traefik`][cc-traefik]
3. `abra app new keycloak --secrets` (optionally with `--pass` if you'd like
to save secrets in `pass`)
4. `abra app YOURAPPDOMAIN config` - be sure to change `$DOMAIN` to something that resolves to
your Docker swarm box
5. `abra app YOURAPPDOMAIN deploy`
### Installing extensions
## How do I setup a custom theme?
To install the extensions, download their JAR files and place them in the `providers` directory. Then, restart the Keycloak container.
Check [this approach](https://git.autonomic.zone/ruangrupa/login.lumbung.space).
You can update an extension by simply replacing the old JAR file with the new one.
## How do I create another admin user?
## Deploying the app with Docker Swarm
- Under the `Master` realm > `Users` > `Add user`
- Create the user and set a temporary password
- Under the `Role Mappings` tab, move `admin` from `Available Roles` into `Assigned Roles`
Set the environment variables from the .env file during the shell session.
## How do I configure Keycloak login for..
```
set -a && source .env && set +a
```
- [Nextcloud][nextcloud]
- [Peertube][peertube]
Set the secrets.
[nextcloud]: https://git.coopcloud.tech/coop-cloud/nextcloud
[peertube]: https://git.coopcloud.tech/coop-cloud/peertube
[abra]: https://git.autonomic.zone/autonomic-cooperative/abra
[cc-traefik]: https://git.autonomic.zone/coop-cloud/traefik
```
printf "SECRET_HERE" | docker secret create SECRET_NAME -
```
Deploy using the `-c` flag to specify one or multiple compose files.
```
docker stack deploy keycloak --detach=true -c compose.yaml
```
+90
View File
@@ -0,0 +1,90 @@
services:
app:
image: "keycloak/keycloak:26.4"
entrypoint: >
bash -c "KC_BOOTSTRAP_ADMIN_PASSWORD=\"$$(cat /run/secrets/admin_password)\" KC_DB_PASSWORD=\"$$(cat /run/secrets/db_password)\" /opt/keycloak/bin/kc.sh start"
networks:
- proxy
- internal
secrets:
- admin_password
- db_password
environment:
- KC_DB=mariadb
- KC_DB_URL_DATABASE=keycloak
- KC_DB_URL_HOST=db
- KC_HOSTNAME=https://${DOMAIN}
- KC_PROXY_HEADERS=xforwarded
- KC_BOOTSTRAP_ADMIN_USERNAME=${ADMIN_USERNAME}
- KEYCLOAK_WELCOME_THEME=${WELCOME_THEME}
- KC_FEATURES
- KC_HTTP_ENABLED=true
# healthcheck:
# https://www.keycloak.org/server/health
# Use external health checks
volumes:
- "themes:/opt/keycloak/themes"
- "providers:/opt/keycloak/providers"
depends_on:
- mariadb
deploy:
update_config:
failure_action: rollback
order: start-first
labels:
- "traefik.enable=true"
- "traefik.http.services.keycloak.loadbalancer.server.port=8080"
- "traefik.http.routers.keycloak.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.keycloak.entrypoints=web-secure"
- "traefik.http.routers.keycloak.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.routers.keycloak.middlewares=keycloak-redirect"
- "traefik.http.middlewares.keycloak-redirect.headers.SSLForceHost=true"
- "traefik.http.middlewares.keycloak-redirect.headers.SSLHost=${DOMAIN}"
- "caddy=${DOMAIN}"
- "caddy.reverse_proxy={{upstreams 8080}}"
- "caddy.tls.on_demand="
db:
image: "mariadb:10.11"
environment:
- MYSQL_DATABASE=keycloak
- MYSQL_USER=keycloak
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password
secrets:
- db_password
- db_root_password
volumes:
- "mariadb:/var/lib/mysql"
networks:
- internal
deploy:
labels:
backupbot.backup: "true"
backupbot.backup.path: "/tmp/dump.sql.gz"
backupbot.backup.post-hook: "rm -f /tmp/dump.sql.gz"
backupbot.backup.pre-hook: "sh -c 'mysqldump -u root -p\"$$(cat /run/secrets/db_root_password)\" keycloak | gzip > /tmp/dump.sql.gz'"
backupbot.restore.pre-hook: "sh -c 'cd /tmp && gzip -d dump.sql.gz'"
backupbot.restore: "true"
backupbot.restore.post-hook: "sh -c 'mysql -u root -p\"$$(cat /run/secrets/db_root_password)\" keycloak < /tmp/dump.sql && rm -f /tmp/dump.sql'"
networks:
internal:
proxy:
external: true
secrets:
admin_password:
name: keycloak_admin_password
external: true
db_password:
name: keycloak_db_password
external: true
db_root_password:
name: keycloak_db_root_password
external: true
volumes:
mariadb:
themes:
providers:
-80
View File
@@ -1,80 +0,0 @@
---
version: "3.8"
services:
app:
image: "jboss/keycloak:16.1.1"
networks:
- proxy
- internal
secrets:
- admin_password
- db_password
environment:
- DB_ADDR=db
- DB_DATABASE=keycloak
- DB_PASSWORD_FILE=/run/secrets/db_password
- DB_USER=keycloak
- DB_VENDOR=mariadb
- KEYCLOAK_PASSWORD_FILE=/run/secrets/admin_password
- KEYCLOAK_USER=${ADMIN_USERNAME}
- PROXY_ADDRESS_FORWARDING=true
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8080"]
interval: 30s
timeout: 10s
retries: 10
start_period: 1m
volumes:
- "themes:/opt/jboss/keycloak/themes"
depends_on:
- mariadb
deploy:
update_config:
failure_action: rollback
order: start-first
labels:
- "traefik.enable=true"
- "traefik.http.services.${STACK_NAME}.loadbalancer.server.port=8080"
- "traefik.http.routers.${STACK_NAME}.rule=Host(`${DOMAIN}`${EXTRA_DOMAINS})"
- "traefik.http.routers.${STACK_NAME}.entrypoints=web-secure"
- "traefik.http.routers.${STACK_NAME}.tls.certresolver=${LETS_ENCRYPT_ENV}"
- "traefik.http.routers.${STACK_NAME}.middlewares=${STACK_NAME}-redirect"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLForceHost=true"
- "traefik.http.middlewares.${STACK_NAME}-redirect.headers.SSLHost=${DOMAIN}"
- "coop-cloud.${STACK_NAME}.version=4.0.1+16.1.1"
db:
image: "mariadb:10.6"
environment:
- MYSQL_DATABASE=keycloak
- MYSQL_USER=keycloak
- MYSQL_PASSWORD_FILE=/run/secrets/db_password
- MYSQL_ROOT_PASSWORD_FILE=/run/secrets/db_root_password
secrets:
- db_password
- db_root_password
volumes:
- "mariadb:/var/lib/mysql"
networks:
- internal
networks:
internal:
proxy:
external: true
secrets:
admin_password:
name: ${STACK_NAME}_admin_password_${SECRET_ADMIN_PASSWORD_VERSION}
external: true
db_password:
name: ${STACK_NAME}_db_password_${SECRET_DB_PASSWORD_VERSION}
external: true
db_root_password:
name: ${STACK_NAME}_db_root_password_${SECRET_DB_ROOT_PASSWORD_VERSION}
external: true
volumes:
mariadb:
themes:
-12
View File
@@ -1,12 +0,0 @@
This major release comes with a blog post about a CVE:
https://www.keycloak.org/2021/12/cve.html
Not all versions are affected but they're suggesting that people upgrade soon.
As per usual, this upgrade didn't go too smoothly and I ended up having to
undeploy and deploy the new versions. The healtcheck kept failing on the new
instance when trying to deploy alongside the existing old version. Idk, some
docker weirdness.
No app data errors discovered after upgrade.
-6
View File
@@ -1,6 +0,0 @@
{
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
"extends": [
"config:base"
]
}