How to deploy keycloak on kubernetes with custom configuration?

Viewed 5989

I want to deploy keycloak with below custom configuration, before starting it.

  • new realm
  • role
  • client
  • an admin user under the new realm

I am using below deployment file to create keycloak pod

apiVersion: apps/v1
kind: Deployment
metadata:
  name: keycloak
  namespace: default
  labels:
    app: keycloak
spec:
  replicas: 1
  selector:
    matchLabels:
      app: keycloak
  template:
    metadata:
      labels:
        app: keycloak
    spec:
      containers:
      - name: keycloak
        image: quay.io/keycloak/keycloak:10.0.1
        env:
        - name: KEYCLOAK_USER
          value: "admin"
        - name: KEYCLOAK_PASSWORD
          value: "admin"
        - name: REALM
          value: "ntc"
        - name: PROXY_ADDRESS_FORWARDING
          value: "true"
        volumeMounts:
        - mountPath: /opt/jboss/keycloak/startup/elements
          name: elements
        ports:
        - name: http
          containerPort: 8080
        - name: https
          containerPort: 443
        readinessProbe:
          httpGet:
            path: /auth/realms/master
            port: 8080
        volumes:
      - name: elements
        configMap:
          name: keycloak-elements

and using below cilent.json and realm.json file to generate configmap for keycloak.

client.json

{
  "id": "7ec4ccce-d6ed-461f-8e95-ea98e4912b8c",
  "clientId": "ntc-app",
  "enabled": true,
  "clientAuthenticatorType": "client-secret",
  "secret": "0b360a88-df24-48fa-8e96-bf6577bbee95",
  "directAccessGrantsEnabled": true
}

realm.json

{
 "realm": "ntc",
 "id": "ntc",
 "enabled": "true",
 "revokeRefreshToken" : true,
 "accessTokenLifespan" : 900,
 "passwordPolicy": "length(8) and digits(1) and specialChars(1)",
 "roles" : {
  "realm" : [ {
        "id": "c9253f52-1960-4c9d-af99-5facca0c0846",
        "name": "admin",
        "description" : "admin role",
        "scopeParamRequired": false,
        "composite": false,
        "clientRole": false,
        "containerId": "ntc"
    }, {
      "id" : "1e7ed0c8-9585-44b0-92f8-59e472573461",
      "name" : "user",
      "description" : "user role",
      "scopeParamRequired" : false,
      "composite" : false,
      "clientRole" : false,
      "containerId" : "ntc"
    }
   ]
  }
}

Both the files are saved under the elements folder and used in the below command to generate the config map:

kubectl create configmap keycloak-elements --from-file=elements

Still, I don't see any new realm/role or client created in the KeyCloak console.

2 Answers

When you are setting up Keycloak on kubernetes, you only need to import the new realm (realm.json) and the corresponding clients (client.json) only during the first run. So a Job needs created instead of adding it to the deployment.

Once the Job is run, the json will be imported to the Keycloak database and the job can be suspended. Adding it to the deployment will cause Keycloak to try and import the json files during each restart.

Please follow the steps in this blog post: https://blog.knoldus.com/migrate-keycloak-h2-database-to-postgres-on-kubernetes/

Related