Keycloak Chart Values Reference

This reference lists the Keycloak values the Axual Governance Helm chart exposes: the image and pull secrets, the database connection, the admin credentials, and the ingress and OpenShift Route options.

Type

Reference

Goal

Look up a Keycloak chart value while writing the Axual Governance values file.

Audience

Platform Operator deploying the Keycloak that authenticates Self-Service users.

When to use

While configuring Keycloak, alongside the procedure that installs Axual Governance.

Contents

The sections below cover each area in this reference:

About Keycloak

Keycloak is an open-source identity and access management server. It provides user federation, strong authentication, user management, and fine-grained authorisation.

Keycloak Configuration

Axual Governance wraps the codecentric KeycloakX Helm chart, so the KeycloakX public documentation holds the full list of configuration options. Set each value below under the keycloak alias, and replace every <VALUE> placeholder with your own value before installing.

Keycloak Repository Configuration

You can override registry, tag, and pullPolicy for the Keycloak pod. By default these values come from the Axual Governance chart. You can also override imagePullSecrets; if you leave it unset, the Keycloak pod uses global.imagePullSecrets.

values.yaml
keycloak:
  image:
    # The Keycloak image repository
    repository: quay.io/keycloak/keycloak
    # Overrides the Keycloak image tag whose default is the chart appVersion
    tag: "22.0.4"
    # Overrides the Keycloak image tag with a specific digest
    digest: ""
    # The Keycloak image pull policy
    pullPolicy: IfNotPresent
  # Image pull secrets for the Pod
  imagePullSecrets:
    - name: axualdockercred

Keycloak Database Configuration

Point Keycloak at the MySQL database the Axual Governance chart creates for it.

values.yaml
keycloak:
  database:
    vendor: "mysql"
    hostname: "keycloak-mysql"
    database: "keycloak-db"
    port: "3306"
    username: "keycloak"
    password: "<KEYCLOAK_DB_PASSWORD>"

Keycloak Admin Configuration

Set the Keycloak admin credentials through extraEnv variables.

values.yaml
keycloak:
  extraEnv: |
    - name: KEYCLOAK_ADMIN
      value: "admin"
    - name: KEYCLOAK_ADMIN_PASSWORD
      value: "<KEYCLOAK_ADMIN_PASSWORD>"

Ingress Configuration

The Keycloak Helm chart can create an Ingress that exposes the Keycloak admin console outside the Kubernetes cluster. By default Keycloak stays inside the cluster, because Self-Service reaches it through the API Gateway. To expose the admin console anyway, configure the ingress as follows.

values.yaml
keycloak:

  ingress:
    # -- Enable creation of the Ingress resource to expose this service.
    enabled: true
    # -- The name of the IngressClass cluster resource.
    # The associated IngressClass defines which controller will implement the resource.
    className: ""
    # -- Annotations to add to the Ingress resource.
    annotations: {}
    hosts:
      - # -- The fully qualified domain name of a network host.
        host: "<hostDomainName>"
        paths:
          - # -- Matched against the path of an incoming request.
            path: "/auth"
            # -- Determines the interpretation of the Path matching.
            # Can be one of the following values: `Exact`, `Prefix`, `ImplementationSpecific`.
            pathType: "ImplementationSpecific"
    # -- TLS configuration for this Ingress.
    tls: []
    #  - secretName: chart-example-tls
    #    hosts:
    #      - <hostDomainName>

Route Configuration

On OpenShift, the Keycloak Helm chart can create a Route instead of an Ingress. The same default applies: Keycloak stays inside the cluster unless you enable it, because Self-Service reaches it through the API Gateway.

values.yaml
keycloak:

  route:
    # -- Enable creation of an OpenShift Route resource to expose this service.
    enabled: true
    # -- Annotations to add to the Route.
    annotations: {}
    # -- Labels to add to the route.
    labels: {}
    # -- An alias/DNS that points to the service. Optional. If not specified a route name will typically be automatically chosen.
    host: ""
    # -- subdomain is a DNS subdomain that is requested within the ingress controller's domain (as a subdomain). If host is set this field is ignored.
    subdomain: ""
    # -- Path that the router watches for, to route traffic for to the service.
    path: "/auth"
    tls:
      # -- The Certificate Authority certificate contents.
      caCertificate: ""
      # -- Certificate contents. This should be a single serving certificate, not a certificate chain. Do not include a CA certificate.
      certificate: ""
      # -- Key file contents.
      key: ""
      # -- Indicates termination type. One of: `edge`, `passthrough`, or `reencrypt`.
      termination: "passthrough"
      # --The CA certificate of the final destination. When using reencrypt termination this file should be provided
      # in order to have routers use it for health checks on the secure connection.
      destinationCACertificate: ""