ข้ามไปยังเนื้อหา

This is the Experimental version (Latest). It is under active development and may change. For the most reliable documentation, use the version selector in the top-right to switch to Stable, or click here to go to the Stable version's homepage.

Procuring Keycloak Credentials

อัพเดทล่าสุด:

เนื้อหานี้ยังไม่มีในภาษาของคุณ

After configuring the Opstella realm and its clients, you need to procure the Client Secrets and the Realm Public Key. These will be used in subsequent steps to configure the DevSecOps tools (ArgoCD, GitLab, SonarQube, etc.).

  1. Export Required Shell Variables

    Ensure KEYCLOAK_DOMAIN and KEYCLOAK_REALM are defined as per the Shell Variables guide. Ensure you have KEYCLOAK_ADMIN_USERNAME and KEYCLOAK_ADMIN_PASSWORD exported in your current shell from your variables.

  2. Procure Credentials

    Option A — Procure with Ansible (requires Docker)

    Section titled “Option A — Procure with Ansible (requires Docker)”

    Use the following commands to run the procurement tool. This uses a Docker-based Ansible image to securely fetch and save the credentials to a local file using the pre-provided playbook.

    Terminal window
    # 1. Create the local file so ownership is yours
    touch $BASE_WORKING_DIR/creds.txt
    # 2. Run using the lightweight Ansible-based image
    docker run --rm \
    -v $BASE_WORKING_DIR/assets/files/kc-get-creds.yml:/data/playbook.yml \
    -v $BASE_WORKING_DIR/creds.txt:/data/creds.txt \
    cytopia/ansible:latest-tools \
    ansible-playbook playbook.yml \
    -e "keycloak_url=https://${KEYCLOAK_DOMAIN}" \
    -e "admin_user=${KEYCLOAK_ADMIN_USERNAME}" \
    -e "admin_pass=${KEYCLOAK_ADMIN_PASSWORD}" \
    -e "realm_name=${KEYCLOAK_REALM}" \
    -e "output_file=creds.txt"

    Once finished, the client secrets and public key will be available in the creds.txt file.

    Option B — Procure with curl and jq (no Docker required)

    Section titled “Option B — Procure with curl and jq (no Docker required)”

    Same result, without a container runtime. Values are written straight into a 0600 file and never echoed to the terminal.

    If https://${KEYCLOAK_DOMAIN} is not reachable yet, port-forward the Service first and use http://127.0.0.1:18080 as KC_URL:

    Terminal window
    kubectl port-forward --namespace opstella-identity-system svc/keycloak 18080:8080 &
    Terminal window
    KC_URL="https://${KEYCLOAK_DOMAIN}"
    OUT="$BASE_WORKING_DIR/shell-values/tools/keycloak-clients.vars.sh"
    TOKEN=$(curl -s "$KC_URL/realms/master/protocol/openid-connect/token" \
    -d "client_id=admin-cli" -d "grant_type=password" \
    -d "username=${KEYCLOAK_ADMIN_USERNAME}" \
    -d "password=${KEYCLOAK_ADMIN_PASSWORD}" | jq -r .access_token)
    umask 077
    : > "$OUT"
    for c in argocd-nonprod argocd-prod defectdojo gitlab grafana harbor kubernetes sonarqube vault; do
    ID=$(curl -s -H "Authorization: Bearer $TOKEN" \
    "$KC_URL/admin/realms/${KEYCLOAK_REALM}/clients?clientId=$c" | jq -r '.[0].id')
    SECRET=$(curl -s -H "Authorization: Bearer $TOKEN" \
    "$KC_URL/admin/realms/${KEYCLOAK_REALM}/clients/$ID/client-secret" | jq -r .value)
    VAR=$(echo "$c" | tr 'a-z-' 'A-Z_')
    printf 'export %s_CLIENT_ID="%s"\nexport %s_CLIENT_SECRET="%s"\n' \
    "$VAR" "$c" "$VAR" "$SECRET" >> "$OUT"
    done
    # Realm public key (used by DefectDojo as the signing key)
    curl -s "$KC_URL/realms/${KEYCLOAK_REALM}" | jq -r .public_key \
    | sed 's/^/export KEYCLOAK_SIGNING_PUBKEY="/;s/$/"/' >> "$OUT"
    chmod 600 "$OUT"

    Verify without printing any secret:

    Terminal window
    grep -c 'SECRET=""' $BASE_WORKING_DIR/shell-values/tools/keycloak-clients.vars.sh

    💡 Must print 0. A non-zero count means that client does not exist in the Realm — check the client id against kc-realm.yaml before continuing.

Finished?

Use the below navigation to proceed