KeycloakSAMLClient

The KeycloakSAMLClient Custom Resource declares a SAML 2.0 client in a realm of a running Keycloak™ instance. It is the SAML counterpart of KeycloakOIDCClient: same shape, same reconciliation, a client representation carrying SAML's signing and binding options instead of OIDC's redirect and origin settings.

New in 26.7.

Resource Information

PropertyValue
API Groupk8s.keycloak.org
API Versionv2alpha1
KindKeycloakSAMLClient
Pluralkeycloaksamlclients
ScopeNamespaced
API version

v2alpha1 is the storage version for this resource. Unlike Keycloak and KeycloakRealmImport, which moved to v2beta1, this resource has only ever had v2alpha1.

Example

apiVersion: k8s.keycloak.org/v2alpha1
kind: KeycloakSAMLClient
metadata:
  name: my-saml-app
  namespace: keycloak
spec:
  keycloakCRName: example-kc
  realm: my-realm
  client:
    displayName: My SAML Application
    enabled: true
    appUrl: https://app.example.com
    redirectUris:
      - https://app.example.com/saml/acs
    nameIdFormat: username
    forcePostBinding: true
    signDocuments: true
    clientSignatureRequired: true

Spec

All three top-level fields are required.

FieldTypeDescription
keycloakCRNamestringThe name of the Keycloak resource to act against, in the same namespace.
realmstringThe realm the client belongs to.
clientobjectThe client itself. See below.

spec.client

Shared with the OIDC client: displayName, description, enabled, appUrl, redirectUris, roles, createdTimestamp, updatedTimestamp.

SAML-specific:

FieldTypeDescription
nameIdFormatstringNameID format presented in assertions.
forceNameIdFormatbooleanIgnore the format requested by the service provider and use nameIdFormat.
forcePostBindingbooleanAlways respond with HTTP-POST binding rather than Redirect.
includeAuthnStatementbooleanInclude an AuthnStatement in the assertion.
frontChannelLogoutbooleanPerform logout through the front channel.
allowEcpFlowbooleanPermit the SAML ECP profile.
signDocumentsbooleanSign the SAML response document.
signAssertionsbooleanSign the assertion inside the response.
clientSignatureRequiredbooleanRequire the client to sign its requests.
signingCertificatestringCertificate used to validate the client's signatures.
signatureAlgorithmstringAlgorithm used for signing.
signatureCanonicalizationMethodstringXML canonicalization method used for signing.

Status

Identical in shape to KeycloakOIDCClient: conditions, uuid, hash, observedGeneration.

The full schema, including every nested field, is rendered in the generated API reference from the resource's CRD.


Keycloak™ is a trademark of The Linux Foundation. Alauda is an independent vendor. This product is not affiliated with, endorsed by, or sponsored by The Linux Foundation. All trademarks are the property of their respective owners and are used here for identification purposes only.