Skip to search

UserAttributeMapper

ldap.keycloak.m.crossplane.io / v1alpha1

apiVersion: ldap.keycloak.m.crossplane.io/v1alpha1 kind: UserAttributeMapper metadata: name: example
View raw schema
apiVersion string
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string
Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata object
spec object required
UserAttributeMapperSpec defines the desired state of UserAttributeMapper
forProvider object required
alwaysReadValueFromLdap boolean
When true, the value fetched from LDAP will override the value stored in Keycloak. Defaults to false. When true, the value fetched from LDAP will override the value stored in Keycloak.
attributeDefaultValue string
Default value to set in LDAP if is_mandatory_in_ldap is true and the value is empty. Default value to set in LDAP if is_mandatory_in_ldap and the value is empty
attributeForceDefault boolean
When true, an empty default value is forced for mandatory attributes even when a default value is not specified. Defaults to true. When true, an empty default value is forced for mandatory attributes even when a default value is not specified.
isBinaryAttribute boolean
Should be true for binary LDAP attributes. Should be true for binary LDAP attributes
isMandatoryInLdap boolean
When true, this attribute must exist in LDAP. Defaults to false. When true, this attribute must exist in LDAP.
ldapAttribute string
Name of the mapped attribute on the LDAP object. Name of the mapped attribute on LDAP object.
ldapUserFederationId string
The ID of the LDAP user federation provider to attach this mapper to. The ldap user federation provider to attach this mapper to.
ldapUserFederationIdRef object
Reference to a UserFederation in ldap to populate ldapUserFederationId.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
ldapUserFederationIdSelector object
Selector for a UserFederation in ldap to populate ldapUserFederationId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
name string
Display name of this mapper when displayed in the console. Display name of the mapper when displayed in the console.
readOnly boolean
When true, this attribute is not saved back to LDAP when the user attribute is updated in Keycloak. Defaults to false. When true, this attribute is not saved back to LDAP when the user attribute is updated in Keycloak.
realmId string
The realm that this LDAP mapper will exist in. The realm in which the ldap user federation provider exists.
realmIdRef object
Reference to a Realm in realm to populate realmId.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
realmIdSelector object
Selector for a Realm in realm to populate realmId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
userModelAttribute string
Name of the user property or attribute you want to map the LDAP attribute into. Name of the UserModel property or attribute you want to map the LDAP attribute into.
initProvider object
THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.
alwaysReadValueFromLdap boolean
When true, the value fetched from LDAP will override the value stored in Keycloak. Defaults to false. When true, the value fetched from LDAP will override the value stored in Keycloak.
attributeDefaultValue string
Default value to set in LDAP if is_mandatory_in_ldap is true and the value is empty. Default value to set in LDAP if is_mandatory_in_ldap and the value is empty
attributeForceDefault boolean
When true, an empty default value is forced for mandatory attributes even when a default value is not specified. Defaults to true. When true, an empty default value is forced for mandatory attributes even when a default value is not specified.
isBinaryAttribute boolean
Should be true for binary LDAP attributes. Should be true for binary LDAP attributes
isMandatoryInLdap boolean
When true, this attribute must exist in LDAP. Defaults to false. When true, this attribute must exist in LDAP.
ldapAttribute string
Name of the mapped attribute on the LDAP object. Name of the mapped attribute on LDAP object.
ldapUserFederationId string
The ID of the LDAP user federation provider to attach this mapper to. The ldap user federation provider to attach this mapper to.
ldapUserFederationIdRef object
Reference to a UserFederation in ldap to populate ldapUserFederationId.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
ldapUserFederationIdSelector object
Selector for a UserFederation in ldap to populate ldapUserFederationId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
name string
Display name of this mapper when displayed in the console. Display name of the mapper when displayed in the console.
readOnly boolean
When true, this attribute is not saved back to LDAP when the user attribute is updated in Keycloak. Defaults to false. When true, this attribute is not saved back to LDAP when the user attribute is updated in Keycloak.
realmId string
The realm that this LDAP mapper will exist in. The realm in which the ldap user federation provider exists.
realmIdRef object
Reference to a Realm in realm to populate realmId.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
realmIdSelector object
Selector for a Realm in realm to populate realmId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
userModelAttribute string
Name of the user property or attribute you want to map the LDAP attribute into. Name of the UserModel property or attribute you want to map the LDAP attribute into.
managementPolicies []string
THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
providerConfigRef object
ProviderConfigReference specifies how the provider that will be used to create, observe, update, and delete this managed resource should be configured.
kind string required
Kind of the referenced object.
name string required
Name of the referenced object.
writeConnectionSecretToRef object
WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.
name string required
Name of the secret.
status object
UserAttributeMapperStatus defines the observed state of UserAttributeMapper.
atProvider object
alwaysReadValueFromLdap boolean
When true, the value fetched from LDAP will override the value stored in Keycloak. Defaults to false. When true, the value fetched from LDAP will override the value stored in Keycloak.
attributeDefaultValue string
Default value to set in LDAP if is_mandatory_in_ldap is true and the value is empty. Default value to set in LDAP if is_mandatory_in_ldap and the value is empty
attributeForceDefault boolean
When true, an empty default value is forced for mandatory attributes even when a default value is not specified. Defaults to true. When true, an empty default value is forced for mandatory attributes even when a default value is not specified.
id string
isBinaryAttribute boolean
Should be true for binary LDAP attributes. Should be true for binary LDAP attributes
isMandatoryInLdap boolean
When true, this attribute must exist in LDAP. Defaults to false. When true, this attribute must exist in LDAP.
ldapAttribute string
Name of the mapped attribute on the LDAP object. Name of the mapped attribute on LDAP object.
ldapUserFederationId string
The ID of the LDAP user federation provider to attach this mapper to. The ldap user federation provider to attach this mapper to.
name string
Display name of this mapper when displayed in the console. Display name of the mapper when displayed in the console.
readOnly boolean
When true, this attribute is not saved back to LDAP when the user attribute is updated in Keycloak. Defaults to false. When true, this attribute is not saved back to LDAP when the user attribute is updated in Keycloak.
realmId string
The realm that this LDAP mapper will exist in. The realm in which the ldap user federation provider exists.
userModelAttribute string
Name of the user property or attribute you want to map the LDAP attribute into. Name of the UserModel property or attribute you want to map the LDAP attribute into.
conditions []object
Conditions of the resource.
lastTransitionTime string required
LastTransitionTime is the last time this condition transitioned from one status to another.
format: date-time
message string
A Message containing details about this condition's last transition from one status to another, if any.
observedGeneration integer
ObservedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
reason string required
A Reason for this condition's last transition from one status to another.
status string required
Status of this condition; is it currently True, False, or Unknown?
type string required
Type of this condition. At most one of each condition type may apply to a resource at any point in time.
observedGeneration integer
ObservedGeneration is the latest metadata.generation which resulted in either a ready state, or stalled due to error it can not recover from without human intervention.
format: int64

No matches. Try .spec.forProvider for an exact path