Skip to content

Commit 128f8b1

Browse files
committed
Update keycloak
Signed-off-by: Renovate Bot <[email protected]>
1 parent 21ad044 commit 128f8b1

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

49 files changed

+267
-105
lines changed

class/defaults.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -61,10 +61,10 @@ parameters:
6161
charts:
6262
keycloakx:
6363
source: https://codecentric.github.io/helm-charts
64-
version: 2.5.1
64+
version: 7.0.1
6565
postgresql:
6666
source: https://charts.bitnami.com/bitnami
67-
version: 12.12.10
67+
version: 16.6.6
6868
# FQDN should be overwritten on the cluster level
6969
fqdn: keycloak.example.com
7070
# Default path since Quarkus is "/" rather than "/auth"

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/ingress.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ metadata:
1111
app.kubernetes.io/managed-by: commodore
1212
app.kubernetes.io/name: keycloak
1313
app.kubernetes.io/version: 25.0.6
14-
helm.sh/chart: keycloakx-2.5.1
14+
helm.sh/chart: keycloakx-7.0.1
1515
name: keycloakx
1616
namespace: syn-builtin
1717
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/networkpolicy.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
app.kubernetes.io/managed-by: Helm
77
app.kubernetes.io/name: keycloakx
88
app.kubernetes.io/version: 25.0.6
9-
helm.sh/chart: keycloakx-2.5.1
9+
helm.sh/chart: keycloakx-7.0.1
1010
name: keycloakx
1111
namespace: syn-builtin
1212
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/prometheusrule.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx
1212
namespace: syn-builtin
1313
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/service-headless.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: keycloakx
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx-headless
1212
namespace: syn-builtin
1313
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/service-http.yaml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,15 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx-http
1212
namespace: syn-builtin
1313
spec:
1414
ports:
15+
- name: http-internal
16+
port: 9000
17+
protocol: TCP
18+
targetPort: http-internal
1519
- name: http
1620
port: 8080
1721
protocol: TCP

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/serviceaccount.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,6 @@ metadata:
99
app.kubernetes.io/managed-by: commodore
1010
app.kubernetes.io/name: keycloak
1111
app.kubernetes.io/version: 25.0.6
12-
helm.sh/chart: keycloakx-2.5.1
12+
helm.sh/chart: keycloakx-7.0.1
1313
name: keycloakx
1414
namespace: syn-builtin

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/servicemonitor.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx-keycloakx
1212
namespace: syn-builtin
1313
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/keycloakx/templates/statefulset.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx
1212
namespace: syn-builtin
1313
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/networkpolicy.yaml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -6,21 +6,21 @@ metadata:
66
app.kubernetes.io/instance: keycloak
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: postgresql
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
11-
name: keycloak-postgresql-ingress
9+
app.kubernetes.io/version: 17.4.0
10+
helm.sh/chart: postgresql-16.6.6
11+
name: keycloak-postgresql
1212
namespace: syn-builtin
1313
spec:
14+
egress:
15+
- {}
1416
ingress:
15-
- from:
16-
- podSelector:
17-
matchLabels:
18-
app.kubernetes.io/instance: keycloakx
19-
app.kubernetes.io/name: keycloakx
20-
ports:
17+
- ports:
2118
- port: 5432
2219
podSelector:
2320
matchLabels:
2421
app.kubernetes.io/component: primary
2522
app.kubernetes.io/instance: keycloak
2623
app.kubernetes.io/name: postgresql
24+
policyTypes:
25+
- Ingress
26+
- Egress
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
apiVersion: policy/v1
2+
kind: PodDisruptionBudget
3+
metadata:
4+
labels:
5+
app.kubernetes.io/component: primary
6+
app.kubernetes.io/instance: builtin
7+
app.kubernetes.io/managed-by: commodore
8+
app.kubernetes.io/name: keycloak
9+
app.kubernetes.io/version: 17.4.0
10+
helm.sh/chart: postgresql-16.6.6
11+
name: keycloak-postgresql
12+
namespace: syn-builtin
13+
spec:
14+
maxUnavailable: 1
15+
selector:
16+
matchLabels:
17+
app.kubernetes.io/component: primary
18+
app.kubernetes.io/instance: keycloak
19+
app.kubernetes.io/name: postgresql

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/statefulset.yaml

Lines changed: 51 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ metadata:
66
app.kubernetes.io/instance: builtin
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
9+
app.kubernetes.io/version: 17.4.0
10+
helm.sh/chart: postgresql-16.6.6
1111
name: keycloak-postgresql
1212
namespace: syn-builtin
1313
spec:
@@ -29,8 +29,8 @@ spec:
2929
app.kubernetes.io/instance: keycloak
3030
app.kubernetes.io/managed-by: Helm
3131
app.kubernetes.io/name: postgresql
32-
app.kubernetes.io/version: 15.4.0
33-
helm.sh/chart: postgresql-12.12.10
32+
app.kubernetes.io/version: 17.4.0
33+
helm.sh/chart: postgresql-16.6.6
3434
name: keycloak-postgresql
3535
spec:
3636
affinity:
@@ -46,6 +46,7 @@ spec:
4646
app.kubernetes.io/name: postgresql
4747
topologyKey: kubernetes.io/hostname
4848
weight: 1
49+
automountServiceAccountToken: false
4950
containers:
5051
- env:
5152
- name: BITNAMI_DEBUG
@@ -58,16 +59,10 @@ spec:
5859
value: /bitnami/postgresql/data
5960
- name: POSTGRES_USER
6061
value: keycloak
61-
- name: POSTGRES_PASSWORD
62-
valueFrom:
63-
secretKeyRef:
64-
key: password
65-
name: keycloak-postgresql
66-
- name: POSTGRES_POSTGRES_PASSWORD
67-
valueFrom:
68-
secretKeyRef:
69-
key: postgres-password
70-
name: keycloak-postgresql
62+
- name: POSTGRES_PASSWORD_FILE
63+
value: /opt/bitnami/postgresql/secrets/password
64+
- name: POSTGRES_POSTGRES_PASSWORD_FILE
65+
value: /opt/bitnami/postgresql/secrets/postgres-password
7166
- name: POSTGRES_DATABASE
7267
value: keycloak
7368
- name: POSTGRESQL_ENABLE_LDAP
@@ -125,20 +120,38 @@ spec:
125120
successThreshold: 1
126121
timeoutSeconds: 5
127122
resources:
128-
limits: {}
123+
limits:
124+
cpu: 150m
125+
ephemeral-storage: 2Gi
126+
memory: 192Mi
129127
requests:
130-
cpu: 250m
131-
memory: 256Mi
128+
cpu: 100m
129+
ephemeral-storage: 50Mi
130+
memory: 128Mi
132131
securityContext:
133132
allowPrivilegeEscalation: false
134133
capabilities:
135134
drop:
136135
- ALL
136+
privileged: false
137+
readOnlyRootFilesystem: true
137138
runAsNonRoot: true
138139
runAsUser: 1001
140+
seLinuxOptions: {}
139141
seccompProfile:
140142
type: RuntimeDefault
141143
volumeMounts:
144+
- mountPath: /tmp
145+
name: empty-dir
146+
subPath: tmp-dir
147+
- mountPath: /opt/bitnami/postgresql/conf
148+
name: empty-dir
149+
subPath: app-conf-dir
150+
- mountPath: /opt/bitnami/postgresql/tmp
151+
name: empty-dir
152+
subPath: app-tmp-dir
153+
- mountPath: /opt/bitnami/postgresql/secrets/
154+
name: postgresql-password
142155
- mountPath: /opt/bitnami/postgresql/certs
143156
name: postgresql-certificates
144157
readOnly: true
@@ -166,15 +179,25 @@ spec:
166179
imagePullPolicy: IfNotPresent
167180
name: init-chmod-data
168181
resources:
169-
limits: {}
170-
requests: {}
182+
limits:
183+
cpu: 150m
184+
ephemeral-storage: 2Gi
185+
memory: 192Mi
186+
requests:
187+
cpu: 100m
188+
ephemeral-storage: 50Mi
189+
memory: 128Mi
171190
securityContext:
172191
runAsGroup: 0
173192
runAsNonRoot: false
174193
runAsUser: 0
194+
seLinuxOptions: {}
175195
seccompProfile:
176196
type: RuntimeDefault
177197
volumeMounts:
198+
- mountPath: /tmp
199+
name: empty-dir
200+
subPath: tmp-dir
178201
- mountPath: /bitnami/postgresql
179202
name: data
180203
- mountPath: /dev/shm
@@ -185,8 +208,16 @@ spec:
185208
name: postgresql-certificates
186209
securityContext:
187210
fsGroup: 1001
188-
serviceAccountName: default
211+
fsGroupChangePolicy: Always
212+
supplementalGroups: []
213+
sysctls: []
214+
serviceAccountName: keycloak-postgresql
189215
volumes:
216+
- emptyDir: {}
217+
name: empty-dir
218+
- name: postgresql-password
219+
secret:
220+
secretName: keycloak-postgresql
190221
- name: raw-certificates
191222
secret:
192223
secretName: keycloak-postgresql-tls

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/svc-headless.yaml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,14 @@
11
apiVersion: v1
22
kind: Service
33
metadata:
4-
annotations:
5-
service.alpha.kubernetes.io/tolerate-unready-endpoints: 'true'
4+
annotations: null
65
labels:
76
app.kubernetes.io/component: primary
87
app.kubernetes.io/instance: keycloak
98
app.kubernetes.io/managed-by: Helm
109
app.kubernetes.io/name: postgresql
11-
app.kubernetes.io/version: 15.4.0
12-
helm.sh/chart: postgresql-12.12.10
10+
app.kubernetes.io/version: 17.4.0
11+
helm.sh/chart: postgresql-16.6.6
1312
name: keycloak-postgresql-hl
1413
namespace: syn-builtin
1514
spec:

tests/golden/builtin/builtin/builtin/01_keycloak_helmchart/postgresql/templates/primary/svc.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -6,8 +6,8 @@ metadata:
66
app.kubernetes.io/instance: keycloak
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: postgresql
9-
app.kubernetes.io/version: 15.4.0
10-
helm.sh/chart: postgresql-12.12.10
9+
app.kubernetes.io/version: 17.4.0
10+
helm.sh/chart: postgresql-16.6.6
1111
name: keycloak-postgresql
1212
namespace: syn-builtin
1313
spec:
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
apiVersion: v1
2+
automountServiceAccountToken: false
3+
kind: ServiceAccount
4+
metadata:
5+
labels:
6+
app.kubernetes.io/instance: keycloak
7+
app.kubernetes.io/managed-by: Helm
8+
app.kubernetes.io/name: postgresql
9+
app.kubernetes.io/version: 17.4.0
10+
helm.sh/chart: postgresql-16.6.6
11+
name: keycloak-postgresql
12+
namespace: syn-builtin

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/ingress.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ metadata:
1010
app.kubernetes.io/managed-by: commodore
1111
app.kubernetes.io/name: keycloak
1212
app.kubernetes.io/version: 25.0.6
13-
helm.sh/chart: keycloakx-2.5.1
13+
helm.sh/chart: keycloakx-7.0.1
1414
name: keycloakx
1515
namespace: syn-external
1616
spec:

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/networkpolicy.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ metadata:
66
app.kubernetes.io/managed-by: Helm
77
app.kubernetes.io/name: keycloakx
88
app.kubernetes.io/version: 25.0.6
9-
helm.sh/chart: keycloakx-2.5.1
9+
helm.sh/chart: keycloakx-7.0.1
1010
name: keycloakx
1111
namespace: syn-external
1212
spec:

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/prometheusrule.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx
1212
namespace: syn-external
1313
spec:

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/service-headless.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: Helm
88
app.kubernetes.io/name: keycloakx
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx-headless
1212
namespace: syn-external
1313
spec:

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/service-http.yaml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,15 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx-http
1212
namespace: syn-external
1313
spec:
1414
ports:
15+
- name: http-internal
16+
port: 9000
17+
protocol: TCP
18+
targetPort: http-internal
1519
- name: http
1620
port: 8080
1721
protocol: TCP

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/serviceaccount.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,6 @@ metadata:
99
app.kubernetes.io/managed-by: commodore
1010
app.kubernetes.io/name: keycloak
1111
app.kubernetes.io/version: 25.0.6
12-
helm.sh/chart: keycloakx-2.5.1
12+
helm.sh/chart: keycloakx-7.0.1
1313
name: keycloakx
1414
namespace: syn-external

tests/golden/external/external/external/01_keycloak_helmchart/keycloakx/templates/servicemonitor.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ metadata:
77
app.kubernetes.io/managed-by: commodore
88
app.kubernetes.io/name: keycloak
99
app.kubernetes.io/version: 25.0.6
10-
helm.sh/chart: keycloakx-2.5.1
10+
helm.sh/chart: keycloakx-7.0.1
1111
name: keycloakx-keycloakx
1212
namespace: syn-external
1313
spec:

0 commit comments

Comments
 (0)