1# Optionally override the fully qualified name
3# Optionally override the name
5# Optionally override the namespace for all resources. Useful for umbrella charts that
6# deploy multiple aliased keycloak instances each into their own namespace.
8# The number of replicas to create (has no effect if autoscaling enabled)
10# Additional labels applied to every resource in this chart, and on the StatefulSet's pods
13 # The Keycloak image repository
14 repository: chainreg.biz/chainguard-private/keycloak-fips
15 # Overrides the Keycloak image tag whose default is the chart appVersion
17 # Overrides the Keycloak image tag with a specific digest
18 digest: sha256:18eea66cf4cbaad032ba98f36f49ded8aa3f39ea70b5aea6190a058854350845
19 # The Keycloak image pull policy
20 pullPolicy: IfNotPresent
21# Image pull secrets for the Pod
23# - name: myRegistrKeySecretName
25# Mapping between IPs and hostnames that will be injected as entries in the Pod's hosts files
31# Indicates whether information about services should be injected into Pod's environment variables, matching the syntax of Docker links
32enableServiceLinks: true
33# Pod management policy. One of `Parallel` or `OrderedReady`
34podManagementPolicy: OrderedReady
35# StatefulSet's update strategy
36updateStrategy: RollingUpdate
37# StatefulSet's revision history limit (number of old ReplicaSets to retain). Defaults to 10 if not set
38revisionHistoryLimit: ""
39# Pod restart policy. One of `Always`, `OnFailure`, or `Never`
42 # Specifies whether a ServiceAccount should be created
44 # Specifies whether the ServiceAccount can get and list pods
46 # The name of the service account to use.
47 # If not set and create is true, a name is generated using the fullname template
49 # Additional annotations for the ServiceAccount
51 # Additional labels for the ServiceAccount
53 # Image pull secrets that are attached to the ServiceAccount
55 # Automount API credentials for the Service Account
56 automountServiceAccountToken: true
60 # RBAC rules for KUBE_PING
68# SecurityContext for the entire Pod. Every container running in the Pod will inherit this SecurityContext. This might be relevant when other components of the environment inject additional containers into running Pods (service meshes are the most prominent example for this)
71# SecurityContext for the Keycloak container
75# Additional init containers, e. g. for providing custom themes
76extraInitContainers: ""
77# When using service meshes which rely on a sidecar, it may be necessary to skip init containers altogether,
78# since the sidecar doesn't start until the init containers are done, and the sidecar may be required
80# For example, Istio in strict mTLS mode prevents the dbchecker init container from ever completing
81skipInitContainers: false
82# Additional sidecar containers, e. g. for a database proxy, such as Google's cloudsql-proxy
84# Lifecycle hooks for the Keycloak container
93# Termination grace period in seconds for Keycloak shutdown. Clusters with a large cache might need to extend this to give Infinispan more time to rebalance
94terminationGracePeriodSeconds: 60
95# The internal Kubernetes cluster domain
96clusterDomain: cluster.local
97## Overrides the default entrypoint of the Keycloak container
99## Overrides the default args for the Keycloak container
101# Additional environment variables for Keycloak
103# - name: KC_LOG_LEVEL
106# Additional environment variables for Keycloak mapped from Secret or ConfigMap
108# Pod priority class name
113 requiredDuringSchedulingIgnoredDuringExecution:
116 {{- include "keycloak.selectorLabels" . | nindent 10 }}
118 - key: app.kubernetes.io/component
122 topologyKey: kubernetes.io/hostname
123 preferredDuringSchedulingIgnoredDuringExecution:
128 {{- include "keycloak.selectorLabels" . | nindent 12 }}
130 - key: app.kubernetes.io/component
134 topologyKey: topology.kubernetes.io/zone
135# Topology spread constraints template
136topologySpreadConstraints:
137# Node labels for Pod assignment
139# Node taints to tolerate
141# Additional Pod labels
143# Additional Pod annotations
145# Liveness probe configuration
148 path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/health/live'
149 port: '{{ .Values.http.internalPort }}'
150 scheme: '{{ .Values.http.internalScheme }}'
151 initialDelaySeconds: 0
153# Readiness probe configuration
156 path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/health/ready'
157 port: '{{ .Values.http.internalPort }}'
158 scheme: '{{ .Values.http.internalScheme }}'
159 initialDelaySeconds: 10
161# Startup probe configuration
164 path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/health'
165 port: '{{ .Values.http.internalPort }}'
166 scheme: '{{ .Values.http.internalScheme }}'
167 initialDelaySeconds: 15
171# Pod resource requests and limits
180# Add additional volumes, e. g. for custom themes
182# Add volume claim templates to the StatefulSet, e. g. for dynamic provisioning
183volumeClaimTemplates: ""
187# accessModes: [ "ReadWriteOncePod" ]
188# storageClassName: "my-storage-class"
193# Add additional volumes mounts, e. g. for custom themes
195# Add additional ports, e. g. for admin console or exposing JGroups ports
197# Pod disruption budget
198podDisruptionBudget: {}
202# Annotations for the StatefulSet
203statefulsetAnnotations: {}
204# Additional labels for the StatefulSet
206# Configuration for secrets that should be created
216 # Annotations for HTTP service
218 # Additional labels for HTTP Service
223 # Optional IP for the load balancer. Used for services of type LoadBalancer only
225 # The http Service port
227 # The HTTP Service node port if type is NodePort
229 # The HTTPS Service port
231 # The HTTPS Service node port if type is NodePort
233 # Additional Service ports, e. g. for custom admin console
235 # When using Service type LoadBalancer, you can restrict source ranges allowed
236 # to connect to the LoadBalancer, e. g. will result in Security Groups
237 # (or equivalent) with inbound source ranges allowed to connect
238 loadBalancerSourceRanges: []
239 # When using Service type LoadBalancer or NodePort, you can preserve the source IP seen in the container
240 # by changing the default (Cluster) to be Local.
241 # See https://kubernetes.io/docs/tasks/access-application-cluster/create-external-load-balancer/#preserving-the-client-source-ip
242 externalTrafficPolicy: "Cluster"
243 # Controls how traffic from internal sources is routed. Valid values: Cluster, Local.
244 # See https://kubernetes.io/docs/concepts/services-networking/service-traffic-policy/
245 internalTrafficPolicy: ""
247 # See https://kubernetes.io/docs/concepts/services-networking/service/#proxy-mode-userspace
249 # Session affinity config
250 sessionAffinityConfig: {}
252 # Annotations for headless service
254 # Additional labels for headless service
256 # Add additional ports to the headless service, e. g. for admin console or exposing JGroups ports
258# -- Expose the service via gateway-api HTTPRoute
259# Requires Gateway API resources and suitable controller installed within the cluster
260# (see: https://gateway-api.sigs.k8s.io/guides/)
264 # Additional HTTPRoute labels
266 # HTTPRoute annotations.
268 # The Service port targeted by the HTTPRoute, MUST BE AN NUMBER
270 # Which Gateways this Route is attached to.
275 # Hostnames matching HTTP header.
277 - chart-example.local
278 # List of rules and filters applied.
283 value: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/'
284 # -- Create a ListenerSet resource to attach listeners to an existing Gateway
285 # without requiring write access to the Gateway resource itself. Useful for
286 # namespace-level configuration where app owners do not have Gateway write access.
287 # When enabled, the HTTPRoute parentRefs are auto-derived from the ListenerSet name,
288 # and hostnames are derived from listener hostnames; httpRoute.parentRefs and
289 # httpRoute.hostnames are unused.
291 # If `true`, a ListenerSet resource is created alongside the HTTPRoute
293 # Additional ListenerSet labels
295 # ListenerSet annotations
297 # The Gateway this ListenerSet attaches to
300 # namespace: envoy-gateway-system
301 # Listeners to attach to the Gateway. Passed through as-is.
302 # Listener hostnames are used to populate the HTTPRoute hostnames field.
305 # hostname: keycloak.example.com
311 # HTTPRoute for console only (/auth/admin)
313 # If `true`, an HTTPRoute is created for console path only
315 # Additional HTTPRoute labels
317 # HTTPRoute annotations.
319 # Which Gateways this Route is attached to.
324 # Hostnames matching HTTP header.
326 - chart-example.local
327 # List of rules and filters applied.
332 value: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/admin'
334 # If `true`, an Ingress is created
336 # The name of the Ingress Class associated with this ingress
338 # The Service port targeted by the Ingress
340 # Ingress annotations
342 ## Resolve HTTP 502 error using ingress-nginx:
343 ## See https://www.ibm.com/support/pages/502-error-ingress-keycloak-response
344 # nginx.ingress.kubernetes.io/proxy-buffer-size: 128k
346 # Additional Ingress labels
348 # List of rules for the Ingress
351 host: '{{ .Release.Name }}.keycloak.example.com'
354 - path: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/'
356 # serviceName: "" # Optional: Override backend service name (e.g., for AWS ALB action annotations)
357 # servicePort: "" # Optional: Override backend service port name
361 # - keycloak.example.com
364 # ingress for console only (/auth/admin)
366 # If `true`, an Ingress is created for console path only
368 # The name of Ingress Class associated with the console ingress only
370 # Ingress annotations for console ingress only
371 # Useful to set nginx.ingress.kubernetes.io/whitelist-source-range particularly
373 # Additional Ingress labels for console path only
377 host: '{{ .Release.Name }}.keycloak.example.com'
380 - path: '{{ tpl .Values.http.relativePath $ | trimSuffix "/" }}/admin'
382 # serviceName: "" # Optional: Override backend service name (e.g., for AWS ALB action annotations)
383 # servicePort: "" # Optional: Override backend service port name
384 # Console TLS configuration
387 # - console.keycloak.example.com
389## Network policy configuration
390# https://kubernetes.io/docs/concepts/services-networking/network-policies/
392 # If true, the Network policies are deployed
394 # Additional Network policy labels
396 # Define all other external allowed source
397 # See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#networkpolicypeer-v1-networking-k8s-io
399 # Define egress networkpolicies for the Keycloak pods (external database for example)
400 # See https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.25/#networkpolicyegressrule-v1-networking-k8s-io
404 # cidr: 192.168.1.30/32
410 # If `true`, an OpenShift Route is created
416 # Additional Route labels
418 # Host name for the Route
422 # If `true`, TLS is enabled for the Route
424 # Insecure edge termination policy of the Route. Can be `None`, `Redirect`, or `Allow`
425 insecureEdgeTerminationPolicy: Redirect
426 # TLS termination of the route. Can be `edge`, `passthrough`, or `reencrypt`
431 # Docker image used to check Database readiness at startup
432 repository: chainreg.biz/chainguard-private/netcat
433 # Image tag for the dbchecker image
434 tag: 1.238-r1@sha256:e3cbf859cb046eb2058a6f8b19f3656b11a961154944c98c1de3ad58d4a5cd6a
435 # Image pull policy for the dbchecker image
436 pullPolicy: IfNotPresent
437 # SecurityContext for the dbchecker container
439 allowPrivilegeEscalation: false
443 # Resource requests and limits for the dbchecker container
452 # don't create secret for db password. Instead use existing k8s secret
453 # existingSecret: "my-existent-dbpass-secret"
454 # existingSecretKey: "password"
456 existingSecretKey: ""
457 # E.g. dev-file, dev-mem, mariadb, mssql, mysql, oracle or postgres
465 # Use "custom" to disable automatic cache configuration
477 # For backwards compatibility reasons we set this to the value used by previous Keycloak versions.
478 relativePath: "/auth"
479 # Set the relative path for Keycloak's management interface (KC_HTTP_MANAGEMENT_RELATIVE_PATH).
480 # This controls the path prefix for health and metrics endpoints served on the management port (9000).
481 # When empty, the env var is not set and Keycloak inherits the value from `http.relativePath`.
482 # Set to "/" to serve management endpoints at the root (e.g. /health, /metrics).
483 managementRelativePath: ""
484 internalPort: http-internal
487 # If `true`, a ServiceMonitor resource for the prometheus-operator is created
489 # Optionally sets a target namespace in which to deploy the ServiceMonitor resource
491 # Optionally sets a namespace for the ServiceMonitor
492 namespaceSelector: {}
493 # Annotations for the ServiceMonitor
495 # Additional labels for the ServiceMonitor
497 # Interval at which Prometheus scrapes metrics
499 # Timeout for scraping
501 # Relabelings for the Servicemonitor
503 # metricRelabelings for the Servicemonitor
504 metricRelabelings: []
505 # The path at which metrics are served
506 path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/metrics'
507 # The Service port at which metrics are served
508 port: '{{ .Values.http.internalPort }}'
509 # The scheme to use for scraping metrics ("http" or "https"); if not set, the `http.internalScheme` value is used
512 # If `true`, a ServiceMonitor resource for the prometheus-operator is created
514 # Optionally sets a target namespace in which to deploy the ServiceMonitor resource
516 # Optionally sets a namespace for the ServiceMonitor
517 namespaceSelector: {}
518 # Annotations for the ServiceMonitor
520 # Additional labels for the ServiceMonitor
522 # Interval at which Prometheus scrapes metrics
524 # Timeout for scraping
526 # Relabelings for the Servicemonitor
528 # metricRelabelings for the Servicemonitor
529 metricRelabelings: []
530 # The path at which metrics are served
531 path: '{{ tpl (coalesce .Values.http.managementRelativePath .Values.http.relativePath) $ | trimSuffix "/" }}/metrics'
532 # The Service port at which metrics are served
533 port: '{{ .Values.http.internalPort }}'
534 # The scheme to use for scraping metrics ("http" or "https"); if not set, the `http.internalScheme` value is used
537 # If `true`, a PrometheusRule resource for the prometheus-operator is created
539 # Optionally sets a target namespace in which to deploy the ServiceMonitor resource
541 # Annotations for the PrometheusRule
543 # Additional labels for the PrometheusRule
545 # List of rules for Prometheus
547 # - alert: keycloak-IngressHigh5xxRate
549 # message: The percentage of 5xx errors for keycloak over the last 5 minutes is over 1%.
554 # nginx_ingress_controller_response_duration_seconds_count{exported_namespace="mynamespace",ingress="mynamespace-keycloak",status=~"5[0-9]{2}"}[1m]
560 # nginx_ingress_controller_response_duration_seconds_count{exported_namespace="mynamespace",ingress="mynamespace-keycloak"}[1m]
568 # If `true`, an autoscaling/v2 HorizontalPodAutoscaler resource is created (requires Kubernetes 1.23 or above)
569 # Autoscaling seems to be most reliable when using KUBE_PING service discovery (see README for details)
570 # This disables the `replicas` field in the StatefulSet
572 # Additional HorizontalPodAutoscaler labels
574 # The minimum and maximum number of replicas for the Keycloak StatefulSet
577 # The metrics to use for scaling
584 averageUtilization: 80
585 # The scaling policy to use. This will scale up quickly but only scale down a single Pod per 5 minutes.
586 # This is important because caches are usually only replicated to 2 Pods and if one of those Pods is terminated this will give the cluster time to recover.
589 stabilizationWindowSeconds: 300
595 # If `true`, test resources are created
598 # The image for the test Pod
599 repository: docker.io/selenium/standalone-chromium
600 # The tag for the test Pod image
602 # The image pull policy for the test Pod image
603 pullPolicy: IfNotPresent
604 # SecurityContext for the entire test Pod
606 fsGroup: 1200 # UID of seluser in selenium/standalone-chromium
607 # SecurityContext for the test container
609 runAsUser: 1200 # UID of seluser in selenium/standalone-chromium
611 # See https://helm.sh/docs/topics/charts_hooks/#hook-deletion-policies
612 deletionPolicy: before-hook-creation
613## -- Extra Kubernetes objects to deploy with the helm chart
619# name: {{ include "keycloak.fullname" . }}-tpl
625# name: "{{ include \"keycloak.fullname\" . }}-tpl"