Browse Source

Added keycloak helm chart

pull/222/head
Galip Tolga Erdem 3 years ago
parent
commit
a22dc565b4
  1. 6
      etc/k8s/eshoponabp/README.md
  2. 6
      etc/k8s/eshoponabp/charts/keycloak/Chart.yaml
  3. 44
      etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-deployment.yaml
  4. 32
      etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-ingress.yaml
  5. 16
      etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-service.yaml
  6. 29
      etc/k8s/eshoponabp/charts/keycloak/values.yaml
  7. 60
      etc/k8s/eshoponabp/values.yaml

6
etc/k8s/eshoponabp/README.md

@ -44,18 +44,18 @@ mkcert -install
Create certificate for the eshopOnAbp domains using the mkcert command below:
```powershell
mkcert "eshop-st-web" "eshop-st-public-web" "eshop-st-authserver" "eshop-st-identity" "eshop-st-administration" "eshop-st-basket" "eshop-st-catalog" "eshop-st-ordering" "eshop-st-cmskit" "eshop-st-payment" "eshop-st-gateway-web" "eshop-st-gateway-web-public"
mkcert "eshoponabp.dev" "*.eshoponabp.dev"
```
At the end of the output you will see something like
The certificate is at "./eshop-st-web+10.pem" and the key at "./eshop-st-web+10-key.pem"
The certificate is at "./eshoponabp.dev+1.pem" and the key at "./eshoponabp.dev+1-key.pem"
Copy the cert name and key name below to create tls secret
```powershell
kubectl create namespace eshop
kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshop-st-web+10.pem --key=./eshop-st-web+10-key.pem
kubectl create secret tls -n eshop eshop-wildcard-tls --cert=./eshoponabp.dev+1.pem --key=./eshoponabp.dev+1-key.pem
```
## How to run?

6
etc/k8s/eshoponabp/charts/keycloak/Chart.yaml

@ -0,0 +1,6 @@
apiVersion: v2
name: keycloak
appVersion: "1.0"
description: Keycloak openid-provider instance
version: 1.0.0
type: application

44
etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-deployment.yaml

@ -0,0 +1,44 @@
apiVersion: apps/v1
kind: Deployment
metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
selector:
matchLabels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
template:
metadata:
labels:
app: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
containers:
- image: {{ .Values.image.repository }}:{{ .Values.image.tag }}
imagePullPolicy: {{ .Values.image.pullPolicy }}
command: ["/opt/keycloak/bin/kc.sh", "start", "--optimized", "--http-enabled=true", "--http-port=8080", "--hostname-strict=false", "--hostname-strict-https=false"]
name: {{ .Release.Name }}-{{ .Chart.Name }}
ports:
- name: http
containerPort: 80
- name: https
containerPort: 443
env:
- name: DB_VENDOR
value: "{{ .Values.config.dbVendor }}"
- name: DB_ADDR
value: "{{ .Values.config.dbAddr }}"
- name: DB_DATABASE
value: "{{ .Values.config.dbDatabase }}"
- name: "DB_USER"
value: "{{ .Values.config.dbUser }}"
- name: "DB_PASSWORD"
value: "{{ .Values.config.dbPassword }}"
- name: "KEYCLOAK_ADMIN"
value: "{{ .Values.config.keycloakAdmin }}"
- name: "KEYCLOAK_ADMIN_PASSWORD"
value: "{{ .Values.config.keycloakAdminPassword }}"
- name: "KC_HEALTH_ENABLED"
value: "{{ .Values.config.kcHealthEnabled }}"
{{- if .Values.env }}
{{ toYaml .Values.env | indent 8 }}
{{- end }}

32
etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-ingress.yaml

@ -0,0 +1,32 @@
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: {{ .Release.Name }}-{{ .Chart.Name }}-ingress
annotations:
nginx.ingress.kubernetes.io/rewrite-target: /
nginx.ingress.kubernetes.io/force-ssl-redirect: "true"
nginx.ingress.kubernetes.io/proxy-buffer-size: 32k
nginx.ingress.kubernetes.io/proxy-buffers-number: "8"
cert-manager.io/cluster-issuer: letsencrypt
spec:
ingressClassName: nginx
tls:
- hosts:
- {{ .Values.ingress.host }}
{{- if eq .Release.Name "eshop-az" }}
secretName: {{ .Release.Name }}-{{ .Chart.Name }}-tls
{{- else }}
secretName: {{ .Values.ingress.tlsSecret }}
{{- end }}
rules:
- host: "{{ .Values.ingress.host }}"
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: {{ .Release.Name }}-{{ .Chart.Name }}
port:
number: 80

16
etc/k8s/eshoponabp/charts/keycloak/templates/keycloak-service.yaml

@ -0,0 +1,16 @@
apiVersion: v1
kind: Service
metadata:
labels:
name: {{ .Release.Name }}-{{ .Chart.Name }}
name: {{ .Release.Name }}-{{ .Chart.Name }}
spec:
type: ClusterIP
ports:
- name: "80"
port: 8080
- name: "443"
port: 443
selector:
app: {{ .Release.Name }}-{{ .Chart.Name }}

29
etc/k8s/eshoponabp/charts/keycloak/values.yaml

@ -0,0 +1,29 @@
config:
dbVendor: postgres
dbAddr: eshop-st-postgresdb
dbDatabase: keycloak
dbUser: postgres
dbPassword: myPassw0rd
keycloakAdmin: admin
keycloakAdminPassword: 1q2w3E*
kcHealthEnabled: true
ingress:
host: account.eshoponabp.dev
tlsSecret: eshop-wildcard-tls
image:
repository: quay.io/keycloak/keycloak
tag: 19.0.2
pullPolicy: IfNotPresent
# command:
# - "/opt/keycloak/bin/kc.sh"
# - "start"
# - "--auto-build"
# - "--http-enabled=true"
# - "--http-port=8080"
# - "--hostname-strict=false"
# - "--hostname-strict-https=false"
env: {}

60
etc/k8s/eshoponabp/values.yaml

@ -1,27 +1,21 @@
# auth-server sub-chart override
authserver:
keycloak:
config:
selfUrl: https://eshop-st-authserver
corsOrigins: https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-identity,https://eshop-st-administration,https://eshop-st-basket,https://eshop-st-catalog,https://eshop-st-ordering,https://eshop-st-cmskit,https://eshop-st-payment,https://eshop-st-web,https://eshop-st-public-web
allowedRedirectUrls: https://eshop-st-web
authServer:
authority: http://eshop-st-authserver
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
identityService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
elasticsearchHost: eshop-st-elasticsearch
dbVendor: postgres
dbAddr: eshop-st-postgresdb
dbDatabase: keycloak
dbUser: postgres
dbPassword: myPassw0rd
keycloakAdmin: admin
keycloakAdminPassword: 1q2w3E*
kcHealthEnabled: true
ingress:
host: eshop-st-authserver
host: eshop-st-keycloak
tlsSecret: eshop-wildcard-tls
image:
repository: "ghcr.io/volosoft/eshoponabp/app-authserver"
tag: latest
repository: quay.io/keycloak/keycloak
tag: 19.0.2
pullPolicy: IfNotPresent
# web sub-chart override
web:
@ -29,7 +23,7 @@ web:
selfUrl: https://eshop-st-web
gatewayUrl: https://eshop-st-gateway-web
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: false
responseType: "code"
strictDiscoveryDocumentValidation: false
@ -47,10 +41,10 @@ public-web:
selfUrl: https://eshop-st-public-web
gatewayUrl: http://eshop-st-gateway-web-public/
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
isOnProd: "false"
metaAddress: http://eshop-st-authserver
metaAddress: http://eshop-st-keycloak
dotnetEnv: Staging
redisHost: eshop-st-redis
rabbitmqHost: eshop-st-rabbitmq
@ -71,7 +65,7 @@ identity:
identityService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Identity;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -107,7 +101,7 @@ administration:
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -134,7 +128,7 @@ gateway-web:
corsOrigins: https://eshop-st-web
globalConfigurationBaseUrl: http://eshop-st-gateway-public
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -150,7 +144,7 @@ gateway-web:
tag: 1.0.0
reRoutes:
accountService:
url: http://eshop-st-authserver
url: http://eshop-st-keycloak
identityService:
url: http://eshop-st-identity
administrationService:
@ -167,7 +161,7 @@ gateway-web-public:
config:
selfUrl: https://eshop-st-gateway-web-public
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -183,7 +177,7 @@ gateway-web-public:
tag: 1.0.0
reRoutes:
accountService:
url: http://eshop-st-authserver
url: http://eshop-st-keycloak
identityService:
url: http://eshop-st-identity
administrationService:
@ -207,7 +201,7 @@ basket:
connectionStrings:
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -234,7 +228,7 @@ catalog:
catalogService: "mongodb://eshop-st-mongodb/EShopOnAbp_Catalog"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -263,7 +257,7 @@ ordering:
orderingService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Ordering;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -287,7 +281,7 @@ cmskit:
cmskitService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Cmskit;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"
@ -315,7 +309,7 @@ payment:
paymentService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Payment;User ID=postgres;password=myPassw0rd;Pooling=false"
administrationService: "Host=eshop-st-postgresdb;Port=5432;Database=EShopOnAbp_Administration;User ID=postgres;password=myPassw0rd;Pooling=false"
authServer:
authority: http://eshop-st-authserver
authority: http://eshop-st-keycloak
requireHttpsMetadata: "false"
swaggerClientId: WebGateway_Swagger
swaggerClientSecret: "1q2w3e*"

Loading…
Cancel
Save