keycloak client cleanup: harden candidate selection
/ test (push) Successful in 8s

This commit is contained in:
2026-09-04 12:05:23 +00:00
parent 10f27fa3c4
commit 3bf6f22a4a
+4 -2
View File
@@ -677,13 +677,15 @@ extraDeploy:
CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \ CLIENTS=$(curl -sf -H "Authorization: Bearer ${TOKEN}" \
"${KEYCLOAK_URL}/admin/realms/${REALM}/clients") "${KEYCLOAK_URL}/admin/realms/${REALM}/clients")
CANDIDATES=$(echo "$CLIENTS" | jq -c --argjson protected "$PROTECTED_JSON" --argjson now "$NOW_SEC" --argjson min_age "$MIN_AGE_SEC" --arg pattern "$CLIENT_ID_PATTERN" ' CANDIDATES=$(echo "$CLIENTS" | jq -c --argjson protected "$PROTECTED_JSON" \
--argjson now "$NOW_SEC" --argjson min_age "$MIN_AGE_SEC" --arg pattern "$CLIENT_ID_PATTERN" '
[ [
.[] .[]
| select(.clientId as $cid | $protected | index($cid) | not) | select(.clientId as $cid | $protected | index($cid) | not)
| select(.attributes["k8s.secret.sync"] != "true") | select(.attributes["k8s.secret.sync"] != "true")
| select(.clientId | test($pattern; "i")) | select(.clientId | test($pattern; "i"))
| select((.createdTimestamp // 0) / 1000 < ($now - $min_age)) | select(.attributes["client.secret.creation.time"] != null)
| select((.attributes["client.secret.creation.time"] | tonumber) < ($now - $min_age))
] ]
') ')