Keycloak
k8s.keycloak.org / v2beta1
apiVersion: k8s.keycloak.org/v2beta1
kind: Keycloak
metadata:
name: example
spec object
additionalOptions []object
Configuration of the Keycloak server.
expressed as a keys (reference: https://www.keycloak.org/server/all-config) and values that can be either direct values or references to secrets.
name
string
secret object
key
string
name
string
optional
boolean
value
string
admin object
In this section you can find all properties related to making admin connections from the operator to the server. These settings are not used by the server.
tlsSecret
string
If mTLS is required, this references a secret containing the client TLS configuration for the admin client. Reference: https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets.
automountServiceAccountToken
boolean
Set this to to false to disable automounting the default ServiceAccount Token and Service CA. This is enabled by default.
bootstrapAdmin object
In this section you can configure Keycloak's bootstrap admin - will be used only for initial cluster creation.
service object
Configures the bootstrap admin service account
secret
string
Name of the Secret that contains the client-id and client-secret keys
user object
Configures the bootstrap admin user
secret
string
Name of the Secret that contains the username and password keys
cache object
In this section you can configure Keycloak's cache
configMapFile object
key
string
name
string
optional
boolean
db object
In this section you can find all properties related to connect to a database.
database
string
Sets the database name of the default JDBC URL of the chosen vendor. If the `url` option is set, this option is ignored.
host
string
Sets the hostname of the default JDBC URL of the chosen vendor. If the `url` option is set, this option is ignored.
passwordSecret object
The reference to a secret holding the password of the database user.
key
string
name
string
optional
boolean
poolInitialSize
integer
The initial size of the connection pool.
poolMaxSize
integer
The maximum size of the connection pool.
poolMinSize
integer
The minimal size of the connection pool.
port
integer
Sets the port of the default JDBC URL of the chosen vendor. If the `url` option is set, this option is ignored.
schema
string
The database schema to be used.
url
string
The full database JDBC URL. If not provided, a default URL is set based on the selected database vendor. For instance, if using 'postgres', the default JDBC URL would be 'jdbc:postgresql://localhost/keycloak'.
usernameSecret object
The reference to a secret holding the username of the database user.
key
string
name
string
optional
boolean
vendor
string
The database vendor.
env []object
Environment variables for the Keycloak server.
Values can be either direct values or references to secrets. Use additionalOptions for first-class options rather than KC_ values here.
name
string
secret object
key
string
name
string
optional
boolean
value
string
features object
In this section you can configure Keycloak features, which should be enabled/disabled.
disabled
[]string
Disabled Keycloak features
enabled
[]string
Enabled Keycloak features
hostname object
In this section you can configure Keycloak hostname and related properties.
admin
string
The hostname for accessing the administration console. Applicable for Hostname v1 and v2.
adminUrl
string
DEPRECATED. Sets the base URL for accessing the administration console, including scheme, host, port and path. Applicable for Hostname v1.
backchannelDynamic
boolean
Enables dynamic resolving of backchannel URLs, including hostname, scheme, port and context path. Set to true if your application accesses Keycloak via a private network. Applicable for Hostname v2.
hostname
string
Hostname for the Keycloak server. Applicable for Hostname v1 and v2.
strict
boolean
Disables dynamically resolving the hostname from request headers. Applicable for Hostname v1 and v2.
strictBackchannel
boolean
DEPRECATED. By default backchannel URLs are dynamically resolved from request headers to allow internal and external applications. Applicable for Hostname v1.
http object
In this section you can configure Keycloak features related to HTTP and HTTPS
annotations
object
Annotations to be appended to the Service object
httpEnabled
boolean
Enables the HTTP listener.
httpPort
integer
The used HTTP port.
httpsPort
integer
The used HTTPS port.
labels
object
Labels to be appended to the Service object
serviceHttpPort
integer
The HTTP port exposed on the Kubernetes Service. When set, the Service will use this port while the pod still listens on httpPort.
serviceHttpsPort
integer
The HTTPS port exposed on the Kubernetes Service. When set, the Service will use this port while the pod still listens on httpsPort.
serviceName
string
The name of the Kubernetes Service. When not set, the name defaults to the Keycloak CR name with a "-service" suffix.
tlsSecret
string
A secret containing the TLS configuration for HTTPS. Reference: https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets.
httpManagement object
In this section you can configure Keycloak's management interface setting.
port
integer
Port of the management interface.
image
string
Custom Keycloak image to be used.
imagePullSecrets []object
Secret(s) that might be used when pulling an image from a private container image registry or repository.
name
string
import object
In this section you can configure import Jobs
scheduling object
In this section you can configure import jobs scheduling
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
priorityClassName
string
tolerations []object
effect
string
key
string
operator
string
tolerationSeconds
integer
value
string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
maxSkew
integer
minDomains
integer
nodeAffinityPolicy
string
nodeTaintsPolicy
string
topologyKey
string
whenUnsatisfiable
string
ingress object
The deployment is, by default, exposed through a basic ingress.
You can change this behaviour by setting the enabled property to false.
annotations
object
Additional annotations to be appended to the Ingress object
className
string
enabled
boolean
labels
object
Additional labels to be appended to the Ingress object
tlsSecret
string
A secret containing the TLS configuration for re-encrypt or TLS termination scenarios. Reference: https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets.
instances
integer
Number of Keycloak instances. Default is 1.
livenessProbe object
Configuration for liveness probe, by default it is 10 for periodSeconds and 3 for failureThreshold
failureThreshold
integer
periodSeconds
integer
networkPolicy object
Controls the ingress traffic flow into Keycloak pods.
enabled
boolean
Enables or disables the ingress traffic control.
http []object
A list of sources which should be able to access this endpoint. Items in this list are combined using a logical OR operation. If this field is empty or missing, this rule matches all sources (traffic not restricted by source). If this field is present and contains at least one item, this rule allows traffic only if the traffic matches at least one item in the from list.
ipBlock object
cidr
string
except
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
podSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
https []object
A list of sources which should be able to access this endpoint. Items in this list are combined using a logical OR operation. If this field is empty or missing, this rule matches all sources (traffic not restricted by source). If this field is present and contains at least one item, this rule allows traffic only if the traffic matches at least one item in the from list.
ipBlock object
cidr
string
except
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
podSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
management []object
A list of sources which should be able to access this endpoint. Items in this list are combined using a logical OR operation. If this field is empty or missing, this rule matches all sources (traffic not restricted by source). If this field is present and contains at least one item, this rule allows traffic only if the traffic matches at least one item in the from list.
ipBlock object
cidr
string
except
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
podSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
proxy object
In this section you can configure Keycloak's reverse proxy setting
headers
string
The proxy headers that should be accepted by the server. Misconfiguration might leave the server exposed to security vulnerabilities.
readinessProbe object
Configuration for readiness probe, by default it is 10 for periodSeconds and 3 for failureThreshold
failureThreshold
integer
periodSeconds
integer
resources object
Compute Resources required by Keycloak container
claims []object
name
string
request
string
limits
object
requests
object
scheduling object
In this section you can configure Keycloak's scheduling
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
priorityClassName
string
tolerations []object
effect
string
key
string
operator
string
tolerationSeconds
integer
value
string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
maxSkew
integer
minDomains
integer
nodeAffinityPolicy
string
nodeTaintsPolicy
string
topologyKey
string
whenUnsatisfiable
string
serviceMonitor object
Configuration related to the generated ServiceMonitor
annotations
object
Annotations to be appended to the Service object
enabled
boolean
Enables or disables the creation of the ServiceMonitor.
interval
string
Interval at which metrics should be scraped
labels
object
Labels to be appended to the Service object
scrapeTimeout
string
Timeout after which the scrape is ended
startOptimized
boolean
Set to force the behavior of the --optimized flag for the start command. If left unspecified the operator will assume custom images have already been augmented.
startupProbe object
Configuration for startup probe, by default it is 1 for periodSeconds and 600 for failureThreshold
failureThreshold
integer
periodSeconds
integer
telemetry object
In this section you can configure general shared OpenTelemetry settings for Keycloak.
endpoint
string
OpenTelemetry endpoint to connect to.
protocol
string
OpenTelemetry protocol used for the telemetry data (default 'grpc'). For more information, check the OpenTelemetry guide.
resourceAttributes
object
OpenTelemetry resource attributes present in the exported telemetry data to characterize the telemetry producer.
serviceName
string
OpenTelemetry service name. Takes precedence over 'service.name' defined in the 'resourceAttributes' map.
tracing object
In this section you can configure OpenTelemetry Tracing for Keycloak.
compression
string
OpenTelemetry compression method used to compress payloads. If unset, compression is disabled. Possible values are: gzip, none.
enabled
boolean
Enables the OpenTelemetry tracing.
endpoint
string
OpenTelemetry endpoint to connect to.
protocol
string
OpenTelemetry protocol used for the telemetry data (default 'grpc'). For more information, check the Tracing guide.
resourceAttributes
object
DEPRECATED - use the 'telemetry.resourceAttributes' instead. OpenTelemetry resource attributes present in the exported trace to characterize the telemetry producer.
samplerRatio
number
OpenTelemetry sampler ratio. Probability that a span will be sampled. Expected double value in interval [0,1].
samplerType
string
OpenTelemetry sampler to use for tracing (default 'traceidratio'). For more information, check the Tracing guide.
serviceName
string
DEPRECATED - use the 'telemetry.serviceName' instead. OpenTelemetry service name. Takes precedence over 'service.name' defined in the 'resourceAttributes' map.
transaction object
In this section you can find all properties related to the settings of transaction behavior.
xaEnabled
boolean
Determine whether Keycloak should use a non-XA datasource in case the database does not support XA transactions.
truststores
object
In this section you can configure Keycloak truststores.
unsupported object
In this section you can configure podTemplate advanced features, not production-ready, and not supported settings.
Use at your own risk and open an issue with your use-case if you don't find an alternative way.
podTemplate object
You can configure that will be merged with the one configured by default by the operator.
Use at your own risk, we reserve the possibility to remove/change the way any field gets merged in future releases without notice.
Reference: https://kubernetes.io/docs/concepts/workloads/pods/#pod-templates
metadata object
annotations
object
creationTimestamp
string
deletionGracePeriodSeconds
integer
deletionTimestamp
string
finalizers
[]string
generateName
string
generation
integer
labels
object
managedFields []object
apiVersion
string
fieldsType
string
fieldsV1
object
manager
string
operation
string
subresource
string
time
string
name
string
namespace
string
ownerReferences []object
apiVersion
string
blockOwnerDeletion
boolean
controller
boolean
kind
string
name
string
uid
string
resourceVersion
string
selfLink
string
uid
string
spec object
activeDeadlineSeconds
integer
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
automountServiceAccountToken
boolean
containers []object
args
[]string
command
[]string
env []object
name
string
value
string
valueFrom object
configMapKeyRef object
key
string
name
string
optional
boolean
fieldRef object
apiVersion
string
fieldPath
string
fileKeyRef object
key
string
optional
boolean
path
string
volumeName
string
resourceFieldRef object
containerName
string
divisor
string | integer
resource
string
secretKeyRef object
key
string
name
string
optional
boolean
envFrom []object
configMapRef object
name
string
optional
boolean
prefix
string
secretRef object
name
string
optional
boolean
image
string
imagePullPolicy
string
lifecycle object
postStart object
exec object
command
[]string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
sleep object
seconds
integer
tcpSocket object
host
string
port
string | integer
preStop object
exec object
command
[]string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
sleep object
seconds
integer
tcpSocket object
host
string
port
string | integer
stopSignal
string
livenessProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
name
string
ports []object
containerPort
integer
hostIP
string
hostPort
integer
name
string
protocol
string
readinessProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
resizePolicy []object
resourceName
string
restartPolicy
string
resources object
claims []object
name
string
request
string
limits
object
requests
object
restartPolicy
string
restartPolicyRules []object
action
string
exitCodes object
operator
string
values
[]integer
securityContext object
allowPrivilegeEscalation
boolean
appArmorProfile object
localhostProfile
string
type
string
capabilities object
add
[]string
drop
[]string
privileged
boolean
procMount
string
readOnlyRootFilesystem
boolean
runAsGroup
integer
runAsNonRoot
boolean
runAsUser
integer
seLinuxOptions object
level
string
role
string
type
string
user
string
seccompProfile object
localhostProfile
string
type
string
windowsOptions object
gmsaCredentialSpec
string
gmsaCredentialSpecName
string
hostProcess
boolean
runAsUserName
string
startupProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
stdin
boolean
stdinOnce
boolean
terminationMessagePath
string
terminationMessagePolicy
string
tty
boolean
volumeDevices []object
devicePath
string
name
string
volumeMounts []object
mountPath
string
mountPropagation
string
name
string
readOnly
boolean
recursiveReadOnly
string
subPath
string
subPathExpr
string
workingDir
string
dnsConfig object
nameservers
[]string
options []object
name
string
value
string
searches
[]string
dnsPolicy
string
enableServiceLinks
boolean
ephemeralContainers []object
args
[]string
command
[]string
env []object
name
string
value
string
valueFrom object
configMapKeyRef object
key
string
name
string
optional
boolean
fieldRef object
apiVersion
string
fieldPath
string
fileKeyRef object
key
string
optional
boolean
path
string
volumeName
string
resourceFieldRef object
containerName
string
divisor
string | integer
resource
string
secretKeyRef object
key
string
name
string
optional
boolean
envFrom []object
configMapRef object
name
string
optional
boolean
prefix
string
secretRef object
name
string
optional
boolean
image
string
imagePullPolicy
string
lifecycle object
postStart object
exec object
command
[]string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
sleep object
seconds
integer
tcpSocket object
host
string
port
string | integer
preStop object
exec object
command
[]string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
sleep object
seconds
integer
tcpSocket object
host
string
port
string | integer
stopSignal
string
livenessProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
name
string
ports []object
containerPort
integer
hostIP
string
hostPort
integer
name
string
protocol
string
readinessProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
resizePolicy []object
resourceName
string
restartPolicy
string
resources object
claims []object
name
string
request
string
limits
object
requests
object
restartPolicy
string
restartPolicyRules []object
action
string
exitCodes object
operator
string
values
[]integer
securityContext object
allowPrivilegeEscalation
boolean
appArmorProfile object
localhostProfile
string
type
string
capabilities object
add
[]string
drop
[]string
privileged
boolean
procMount
string
readOnlyRootFilesystem
boolean
runAsGroup
integer
runAsNonRoot
boolean
runAsUser
integer
seLinuxOptions object
level
string
role
string
type
string
user
string
seccompProfile object
localhostProfile
string
type
string
windowsOptions object
gmsaCredentialSpec
string
gmsaCredentialSpecName
string
hostProcess
boolean
runAsUserName
string
startupProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
stdin
boolean
stdinOnce
boolean
targetContainerName
string
terminationMessagePath
string
terminationMessagePolicy
string
tty
boolean
volumeDevices []object
devicePath
string
name
string
volumeMounts []object
mountPath
string
mountPropagation
string
name
string
readOnly
boolean
recursiveReadOnly
string
subPath
string
subPathExpr
string
workingDir
string
hostAliases []object
hostnames
[]string
ip
string
hostIPC
boolean
hostNetwork
boolean
hostPID
boolean
hostUsers
boolean
hostname
string
hostnameOverride
string
imagePullSecrets []object
name
string
initContainers []object
args
[]string
command
[]string
env []object
name
string
value
string
valueFrom object
configMapKeyRef object
key
string
name
string
optional
boolean
fieldRef object
apiVersion
string
fieldPath
string
fileKeyRef object
key
string
optional
boolean
path
string
volumeName
string
resourceFieldRef object
containerName
string
divisor
string | integer
resource
string
secretKeyRef object
key
string
name
string
optional
boolean
envFrom []object
configMapRef object
name
string
optional
boolean
prefix
string
secretRef object
name
string
optional
boolean
image
string
imagePullPolicy
string
lifecycle object
postStart object
exec object
command
[]string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
sleep object
seconds
integer
tcpSocket object
host
string
port
string | integer
preStop object
exec object
command
[]string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
sleep object
seconds
integer
tcpSocket object
host
string
port
string | integer
stopSignal
string
livenessProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
name
string
ports []object
containerPort
integer
hostIP
string
hostPort
integer
name
string
protocol
string
readinessProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
resizePolicy []object
resourceName
string
restartPolicy
string
resources object
claims []object
name
string
request
string
limits
object
requests
object
restartPolicy
string
restartPolicyRules []object
action
string
exitCodes object
operator
string
values
[]integer
securityContext object
allowPrivilegeEscalation
boolean
appArmorProfile object
localhostProfile
string
type
string
capabilities object
add
[]string
drop
[]string
privileged
boolean
procMount
string
readOnlyRootFilesystem
boolean
runAsGroup
integer
runAsNonRoot
boolean
runAsUser
integer
seLinuxOptions object
level
string
role
string
type
string
user
string
seccompProfile object
localhostProfile
string
type
string
windowsOptions object
gmsaCredentialSpec
string
gmsaCredentialSpecName
string
hostProcess
boolean
runAsUserName
string
startupProbe object
exec object
command
[]string
failureThreshold
integer
grpc object
port
integer
service
string
httpGet object
host
string
httpHeaders []object
name
string
value
string
path
string
port
string | integer
scheme
string
initialDelaySeconds
integer
periodSeconds
integer
successThreshold
integer
tcpSocket object
host
string
port
string | integer
terminationGracePeriodSeconds
integer
timeoutSeconds
integer
stdin
boolean
stdinOnce
boolean
terminationMessagePath
string
terminationMessagePolicy
string
tty
boolean
volumeDevices []object
devicePath
string
name
string
volumeMounts []object
mountPath
string
mountPropagation
string
name
string
readOnly
boolean
recursiveReadOnly
string
subPath
string
subPathExpr
string
workingDir
string
nodeName
string
nodeSelector
object
os object
name
string
overhead
object
preemptionPolicy
string
priority
integer
priorityClassName
string
readinessGates []object
conditionType
string
resourceClaims []object
name
string
resourceClaimName
string
resourceClaimTemplateName
string
resources object
claims []object
name
string
request
string
limits
object
requests
object
restartPolicy
string
runtimeClassName
string
schedulerName
string
schedulingGates []object
name
string
schedulingGroup object
podGroupName
string
securityContext object
appArmorProfile object
localhostProfile
string
type
string
fsGroup
integer
fsGroupChangePolicy
string
runAsGroup
integer
runAsNonRoot
boolean
runAsUser
integer
seLinuxChangePolicy
string
seLinuxOptions object
level
string
role
string
type
string
user
string
seccompProfile object
localhostProfile
string
type
string
supplementalGroups
[]integer
supplementalGroupsPolicy
string
sysctls []object
name
string
value
string
windowsOptions object
gmsaCredentialSpec
string
gmsaCredentialSpecName
string
hostProcess
boolean
runAsUserName
string
serviceAccount
string
serviceAccountName
string
setHostnameAsFQDN
boolean
shareProcessNamespace
boolean
subdomain
string
terminationGracePeriodSeconds
integer
tolerations []object
effect
string
key
string
operator
string
tolerationSeconds
integer
value
string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
maxSkew
integer
minDomains
integer
nodeAffinityPolicy
string
nodeTaintsPolicy
string
topologyKey
string
whenUnsatisfiable
string
volumes []object
awsElasticBlockStore object
fsType
string
partition
integer
readOnly
boolean
volumeID
string
azureDisk object
cachingMode
string
diskName
string
diskURI
string
fsType
string
kind
string
readOnly
boolean
azureFile object
readOnly
boolean
secretName
string
shareName
string
cephfs object
monitors
[]string
path
string
readOnly
boolean
secretFile
string
secretRef object
name
string
user
string
cinder object
fsType
string
readOnly
boolean
secretRef object
name
string
volumeID
string
configMap object
defaultMode
integer
items []object
key
string
mode
integer
path
string
name
string
optional
boolean
csi object
driver
string
fsType
string
nodePublishSecretRef object
name
string
readOnly
boolean
volumeAttributes
object
downwardAPI object
defaultMode
integer
items []object
fieldRef object
apiVersion
string
fieldPath
string
mode
integer
path
string
resourceFieldRef object
containerName
string
divisor
string | integer
resource
string
emptyDir object
medium
string
sizeLimit
string | integer
ephemeral object
volumeClaimTemplate object
metadata object
annotations
object
creationTimestamp
string
deletionGracePeriodSeconds
integer
deletionTimestamp
string
finalizers
[]string
generateName
string
generation
integer
labels
object
managedFields []object
apiVersion
string
fieldsType
string
fieldsV1
object
manager
string
operation
string
subresource
string
time
string
name
string
namespace
string
ownerReferences []object
apiVersion
string
blockOwnerDeletion
boolean
controller
boolean
kind
string
name
string
uid
string
resourceVersion
string
selfLink
string
uid
string
spec object
accessModes
[]string
dataSource object
apiGroup
string
kind
string
name
string
dataSourceRef object
apiGroup
string
kind
string
name
string
namespace
string
resources object
limits
object
requests
object
selector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
storageClassName
string
volumeAttributesClassName
string
volumeMode
string
volumeName
string
fc object
fsType
string
lun
integer
readOnly
boolean
targetWWNs
[]string
wwids
[]string
flexVolume object
driver
string
fsType
string
options
object
readOnly
boolean
secretRef object
name
string
flocker object
datasetName
string
datasetUUID
string
gcePersistentDisk object
fsType
string
partition
integer
pdName
string
readOnly
boolean
gitRepo object
directory
string
repository
string
revision
string
glusterfs object
endpoints
string
path
string
readOnly
boolean
hostPath object
path
string
type
string
image object
pullPolicy
string
reference
string
iscsi object
chapAuthDiscovery
boolean
chapAuthSession
boolean
fsType
string
initiatorName
string
iqn
string
iscsiInterface
string
lun
integer
portals
[]string
readOnly
boolean
secretRef object
name
string
targetPortal
string
name
string
nfs object
path
string
readOnly
boolean
server
string
persistentVolumeClaim object
claimName
string
readOnly
boolean
photonPersistentDisk object
fsType
string
pdID
string
portworxVolume object
fsType
string
readOnly
boolean
volumeID
string
projected object
defaultMode
integer
sources []object
clusterTrustBundle object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
name
string
optional
boolean
path
string
signerName
string
configMap object
items []object
key
string
mode
integer
path
string
name
string
optional
boolean
downwardAPI object
items []object
fieldRef object
apiVersion
string
fieldPath
string
mode
integer
path
string
resourceFieldRef object
containerName
string
divisor
string | integer
resource
string
podCertificate object
certificateChainPath
string
credentialBundlePath
string
keyPath
string
keyType
string
maxExpirationSeconds
integer
signerName
string
userAnnotations
object
secret object
items []object
key
string
mode
integer
path
string
name
string
optional
boolean
serviceAccountToken object
audience
string
expirationSeconds
integer
path
string
quobyte object
group
string
readOnly
boolean
registry
string
tenant
string
user
string
volume
string
rbd object
fsType
string
image
string
keyring
string
monitors
[]string
pool
string
readOnly
boolean
secretRef object
name
string
user
string
scaleIO object
fsType
string
gateway
string
protectionDomain
string
readOnly
boolean
secretRef object
name
string
sslEnabled
boolean
storageMode
string
storagePool
string
system
string
volumeName
string
secret object
defaultMode
integer
items []object
key
string
mode
integer
path
string
optional
boolean
secretName
string
storageos object
fsType
string
readOnly
boolean
secretRef object
name
string
volumeName
string
volumeNamespace
string
vsphereVolume object
fsType
string
storagePolicyID
string
storagePolicyName
string
volumePath
string
update object
Configuration related to Keycloak deployment updates.
labels
object
Optionally set to add additional labels to the Job created for the update.
revision
string
When use the Explicit strategy, the revision signals if a rolling update can be used or not.
scheduling object
In this section you can configure the update job's scheduling
affinity object
nodeAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
preference object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution object
nodeSelectorTerms []object
matchExpressions []object
key
string
operator
string
values
[]string
matchFields []object
key
string
operator
string
values
[]string
podAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
podAntiAffinity object
preferredDuringSchedulingIgnoredDuringExecution []object
podAffinityTerm object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
weight
integer
requiredDuringSchedulingIgnoredDuringExecution []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
mismatchLabelKeys
[]string
namespaceSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
namespaces
[]string
topologyKey
string
priorityClassName
string
tolerations []object
effect
string
key
string
operator
string
tolerationSeconds
integer
value
string
topologySpreadConstraints []object
labelSelector object
matchExpressions []object
key
string
operator
string
values
[]string
matchLabels
object
matchLabelKeys
[]string
maxSkew
integer
minDomains
integer
nodeAffinityPolicy
string
nodeTaintsPolicy
string
topologyKey
string
whenUnsatisfiable
string
strategy
string
Sets the update strategy to use.
enum:
Auto, Explicit, RecreateOnImageChangestatus object
conditions []object
lastTransitionTime
string
message
string
observedGeneration
integer
status
string
type
string
instances
integer
observedGeneration
integer
selector
string
No matches. Try .spec.additionalOptions for an exact path