KeycloakOIDCClient

The KeycloakOIDCClient Custom Resource declares an OpenID Connect client in a realm of a running Keycloak™ instance. The Operator reconciles it against that instance's Admin API, so a client can be managed declaratively alongside the workload that uses it instead of being created by hand in the Admin Console.

New in 26.7.

Resource Information

PropertyValue
API Groupk8s.keycloak.org
API Versionv2alpha1
KindKeycloakOIDCClient
Pluralkeycloakoidcclients
ScopeNamespaced
API version

v2alpha1 is the storage version for this resource. Unlike Keycloak and KeycloakRealmImport, which moved to v2beta1, this resource has only ever had v2alpha1.

Example

apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakOIDCClient
metadata:
  name: my-app
  namespace: keycloak
spec:
  keycloakCRName: example-kc
  realm: my-realm
  client:
    displayName: My Application
    description: OIDC client for my application
    enabled: true
    appUrl: https://app.example.com
    redirectUris:
      - https://app.example.com/callback
    webOrigins:
      - https://app.example.com

Spec

All three top-level fields are required.

FieldTypeDescription
keycloakCRNamestringThe name of the Keycloak resource to act against, in the same namespace.
realmstringThe realm the client belongs to.
clientobjectThe client itself. See below.

spec.client

FieldTypeDescription
displayNamestringHuman-readable name shown in the Admin Console.
descriptionstringFree-text description.
enabledbooleanWhether the client may be used.
appUrlstringBase URL of the application.
redirectUrisarrayPermitted redirect URIs after authentication.
webOriginsarrayPermitted CORS origins.
authobjectClient authentication settings.
loginFlowsobjectAuthentication flow bindings for this client.
rolesarrayClient roles to create.
serviceAccountRolesarrayRoles granted to the client's service account.
createdTimestamp / updatedTimestampstringSet by the Operator; not for you to write.

Status

FieldTypeDescription
conditionsarrayStandard Kubernetes conditions describing reconciliation.
uuidstringThe client's id in Keycloak™, assigned on creation.
hashstringHash of the last applied spec, used to detect drift.
observedGenerationintegerThe metadata.generation this status refers to.

The full schema, including every nested field, is rendered in the generated API reference from the resource's CRD.


Keycloak™ is a trademark of The Linux Foundation. Alauda is an independent vendor. This product is not affiliated with, endorsed by, or sponsored by The Linux Foundation. All trademarks are the property of their respective owners and are used here for identification purposes only.