Post-Installation Setup
This guide introduces the configuration that turns an installed platform into one people can use: the Keycloak realms that let users sign in, the Vault setup that lets Platform Manager store credentials, and the first Self-Service resources. Installation ends here; using the platform from day to day is the Self-Service Guide.
Type |
Reference |
Goal |
Find the setup step that stands between an installed platform and a usable one. |
Audience |
Platform Operators, working with the first Tenant Admin for the Self-Service steps. |
When to use |
Stage 6 of The installation order. Both installation paths arrive here, whether the platform came from Quick Setup or from the full install. |
The pages in this section are done in the order below, because each depends on the one before it. That order is the reverse of the menu, which lists the end result first:
-
How to Create the Local Realm in Keycloak creates the realm that the first user signs up through.
-
How to Create an SSO Realm in Keycloak gives a tenant a realm that an organisation’s own identity provider connects to. Skip it for a tenant whose users all sign up locally.
-
IAM Group Configuration carries group membership from that identity provider through to Self-Service.
-
How to Set Up Vault for Governance gives Platform Manager the role and policy it needs to read and write cluster, SASL and connector credentials.
-
How to Set Up Vault for Axual Connect adds the second AppRole that Axual Connect uses to read its connectors' credentials. Skip it on an installation that does not run Axual Connect.
-
Create Self-Service Resources registers the first tenant, cluster, instance, environment, topic and application, which is also the first end-to-end proof that the installation works.
Once these are done the platform is in use, and Monitoring should be finished before anyone relies on it. If a sign-up, a realm or the first topic does not behave, Troubleshooting covers it.