Skip to content

docs: add EDP Keycloak Operator v1.35.0 installation guide - #849

Merged
SuJinpei merged 1 commit into
mainfrom
docs/edp-keycloak-v1.35.0-install-guide
Sep 28, 2026
Merged

SuJinpei merged 1 commit into
mainfrom
docs/edp-keycloak-v1.35.0-install-guide

Conversation

@SuJinpei

Copy link
Copy Markdown
Contributor

Adds the installation guide for EDP Keycloak Operator v1.35.0 (ACP 4.1–4.4), the S2 listing that manages Keycloak configuration as Kubernetes resources.

What the guide covers

  • Install and verify the Operator from OperatorHub.
  • The Keycloak kind-name clash with Alauda Application Services Identity Management E1, and the fully qualified names to use.
  • Using it with Identity Management E1: create an E1 Keycloak instance, connect the Operator through the <name>-initial-admin Secret (spec.auth.passwordGrant), then manage a realm, client, group, role and user as resources, and check that the user can sign in.
  • Switching to a dedicated service-account client (spec.auth.clientCredentials), and sharing one connection across namespaces with ClusterKeycloak.
  • When to use E1's own KeycloakRealmImport / KeycloakOIDCClient, and when to use this Operator.
  • Deletion semantics (the preserve annotation, the delete order), known limitations, uninstall and FAQ.

Validation

Every YAML block and command in the guide was applied verbatim on ACP 4.4.0 (amd64) against Identity Management E1 26.7.4. Each success check was paired with a failing control:

  • Both connection methods connected; the wrong-password and wrong-secret controls stayed false.
  • The user's token carries the developer realm role, granted through the group.
  • A role created after the switch to the service-account client was read back from the Keycloak admin API (200, with a 404 control).
  • The preserve annotation kept its realm; a plain delete removed the realm (404).

Multi-arch and IPv6 support come from the v1.35.0 release testing on ACP 4.1–4.4.

Notes

  • New file, so there is no id: field. The docs workflow assigns it on merge.
  • English only; the zh version is generated by the pipeline.

🤖 Generated with Claude Code

Install guide for the EDP Keycloak Operator (S2, ACP 4.1-4.4), including
how to use it with Alauda Application Services Identity Management E1:
connect to an E1 Keycloak via its initial-admin Secret, manage a realm,
client, group, role and user as resources, switch to a dedicated
service-account client, share a connection with ClusterKeycloak, and
when to use E1's own KeycloakRealmImport / KeycloakOIDCClient instead.

Every YAML block and command was run verbatim on ACP 4.4.0 against
E1 26.7.4 before publishing.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@SuJinpei
SuJinpei merged commit 496efa4 into main Sep 28, 2026
1 check passed
@SuJinpei
SuJinpei deleted the docs/edp-keycloak-v1.35.0-install-guide branch September 28, 2026 02:51

This branch was successfully deployed

1 active deployment
translate — 19a30d82 Deployed Sep 28, 2026 by SuJinpei via build #2717
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant