@@ -1384,6 +1384,46 @@ spec:
|
||||
- Adds source tracking annotations (`keycloak.forteapps.net/source-namespace`, `keycloak.forteapps.net/source-name`)
|
||||
- `synchronize: true` — changes to the source Secret are reflected in the clone
|
||||
|
||||
### Keycloak Microsoft/Entra Identity Provider
|
||||
|
||||
**File**: `infra/values/upc-dev/keycloak-values.yaml`
|
||||
**Namespace**: `keycloak`
|
||||
|
||||
**Purpose**: Configures Microsoft Entra (Azure AD) as an external identity provider for the Forte realm, enabling SSO via Microsoft accounts with token storage for downstream API access (e.g., Microsoft Graph).
|
||||
|
||||
**Configuration via keycloakConfigCli**:
|
||||
- IdP alias: `forte-entra`, provider: `microsoft`
|
||||
- Client secret injected from `microsoft-idp-credentials` Secret via `$(env:MS_IDP_CLIENT_SECRET)` syntax
|
||||
- `extraEnvVarsSecret: microsoft-idp-credentials` makes the Secret available as env vars to config-cli
|
||||
|
||||
**Key Configuration Notes**:
|
||||
|
||||
| Field | Location | Notes |
|
||||
|-------|----------|-------|
|
||||
| `tenant` | `config.tenant` | **Must be `tenant`, NOT `tenantId`** — wrong key silently falls back to `common` (multi-tenant) |
|
||||
| `storeToken` | Top-level IdP field | **NOT inside `config`** — enables broker token storage for KC broker API |
|
||||
| `defaultScope` | `config.defaultScope` | Space-separated: `openid email profile User.Read Mail.Send` |
|
||||
| `syncMode` | `config.syncMode` | `IMPORT` — imports user on first login |
|
||||
|
||||
**Token Storage & Broker Access**:
|
||||
- `storeToken: true` persists the Entra access token in Keycloak
|
||||
- Realm role `default-roles-forte` includes composite `broker.read-token` — grants all realm users access to broker token API
|
||||
- Broker token retrievable via: `GET /realms/forte/broker/forte-entra/token`
|
||||
|
||||
**Identity Provider Mappers**:
|
||||
- `forte-entra-email`: Hardcodes `emailVerified=true` for Entra-authenticated users (Entra guarantees email verification)
|
||||
|
||||
**Required Secret** (`microsoft-idp-credentials`):
|
||||
```yaml
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: microsoft-idp-credentials
|
||||
namespace: keycloak
|
||||
stringData:
|
||||
MS_IDP_CLIENT_SECRET: "<entra-app-client-secret>"
|
||||
```
|
||||
|
||||
### Default Namespace Blocker
|
||||
|
||||
**File**: `cluster-resources/policies/default-ns-blocker.yaml`
|
||||
|
||||
Reference in New Issue
Block a user