Skip to search

IdentityProvider

oidc.keycloak.m.crossplane.io / v1alpha2

apiVersion: oidc.keycloak.m.crossplane.io/v1alpha2 kind: IdentityProvider metadata: name: example
View raw schema
apiVersion string
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string
Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata object
spec object required
IdentityProviderSpec defines the desired state of IdentityProvider
forProvider object required
acceptsPromptNoneForwardFromClient boolean
When true, the IDP will accept forwarded authentication requests that contain the prompt=none query parameter. Defaults to false. This is just used together with Identity Provider Authenticator or when kc_idp_hint points to this identity provider. In case that client sends a request with prompt=none and user is not yet authenticated, the error will not be directly returned to client, but the request with prompt=none will be forwarded to this identity provider.
addReadTokenRoleOnCreate boolean
When true, new users will be able to read stored tokens. This will automatically assign the broker.read-token role. Defaults to false. Enable/disable if new users can read any stored tokens. This assigns the broker.read-token role.
alias string
The alias uniquely identifies an identity provider, and it is also used to build the redirect uri. The alias uniquely identifies an identity provider and it is also used to build the redirect uri.
authenticateByDefault boolean
Enable/disable authenticate users by default.
authorizationUrl string
The Authorization Url. OIDC authorization URL.
backchannelSupported boolean
Does the external IDP support backchannel logout? Defaults to true. Does the external IDP support backchannel logout?
clientIdSecretRef object
The client or client identifier registered within the identity provider. Client ID.
key string required
name string required
Name of the secret.
clientSecretSecretRef object
The client or client secret registered within the identity provider. This field is able to obtain its value from vault, use $${vault.ID} format. Required without client_secret_wo and client_secret_wo_version. Client Secret.
key string required
name string required
Name of the secret.
clientSecretWoSecretRef object
The secret for clients with an access_type of CONFIDENTIAL or BEARER-ONLY. If omitted, this will fallback to use client_secret. Client Secret as write-only argument
key string required
name string required
Name of the secret.
clientSecretWoVersion string
The value of this argument is stored in the state and plan files. Required when using client_secret_wo. Version of the Client secret write-only argument
defaultScopes string
The scopes to be sent when asking for authorization. It can be a space-separated list of scopes. Defaults to openid. The scopes to be sent when asking for authorization. It can be a space-separated list of scopes. Defaults to 'openid'.
disableTypeClaimCheck boolean
When true, disables the check for the typ claim of tokens received from the identity provider. Defaults to false. Disables the validation of the `typ` claim of tokens received from the Identity Provider. If this is `off` the type claim is validated (default).
disableUserInfo boolean
When true, disables the usage of the user info service to obtain additional user information. Defaults to false. Disable usage of User Info service to obtain additional user information? Default is to use this OIDC service.
displayName string
Display name for the identity provider in the GUI. The human-friendly name of the identity provider, used in the log in form.
enabled boolean
When true, users will be able to log in to this realm using this identity provider. Defaults to true. Enable/disable this identity provider.
extraConfig object
A map of key/value pairs to add extra configuration to this identity provider. Use this attribute at your own risk, as custom attributes may conflict with top-level configuration attributes in future provider updates.
firstBrokerLoginFlowAlias string
The authentication flow to use when users log in for the first time through this identity provider. Defaults to first broker login. Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account.
firstBrokerLoginFlowAliasRef object
Reference to a Flow in authenticationflow to populate firstBrokerLoginFlowAlias.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
firstBrokerLoginFlowAliasSelector object
Selector for a Flow in authenticationflow to populate firstBrokerLoginFlowAlias.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
guiOrder string
A number defining the order of this identity provider in the GUI. GUI Order
hideOnLoginPage boolean
When true, this provider will be hidden on the login page, and is only accessible when requested explicitly. Defaults to false. Hide On Login Page.
issuer string
The issuer identifier for the issuer of the response. If not provided, no validation will be performed. The issuer identifier for the issuer of the response. If not provided, no validation will be performed.
jwksUrl string
JSON Web Key Set URL. JSON Web Key Set URL
linkOnly boolean
When true, users cannot sign-in using this provider, but their existing accounts will be linked when possible. Defaults to false. If true, users cannot log in through this provider. They can only link to this provider. This is useful if you don't want to allow login from the provider, but want to integrate with a provider
loginHint string
Pass login hint to identity provider. Login Hint.
logoutUrl string
The Logout URL is the end session endpoint to use to sign-out the user from external identity provider. Logout URL
orgDomain string
The organization domain to associate this identity provider with. it is used to map users to an organization based on their email domain and to authenticate them accordingly in the scope of the organization.
orgRedirectModeEmailMatches boolean
Indicates whether to automatically redirect user to this identity provider when email domain matches domain.
organizationId string
The ID of the organization to link this identity provider to. ID of organization with which this identity is linked.
organizationIdRef object
Reference to a Organization in organization to populate organizationId.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
organizationIdSelector object
Selector for a Organization in organization to populate organizationId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
postBrokerLoginFlowAlias string
The authentication flow to use after users have successfully logged in, which can be used to perform additional user verification (such as OTP checking). Defaults to an empty string, which means no post login flow will be used. Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it.
providerId string
The ID of the identity provider to use. Defaults to oidc, which should be used unless you have extended Keycloak and provided your own implementation. provider id, is always oidc, unless you have a custom implementation
realm string
The name of the realm. This is unique across Keycloak. Realm Name
realmRef object
Reference to a Realm in realm to populate realm.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
realmSelector object
Selector for a Realm in realm to populate realm.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
storeToken boolean
When true, tokens will be stored after authenticating users. Defaults to true. Enable/disable if tokens must be stored after authenticating users.
syncMode string
The default sync mode to use for all mappers attached to this identity provider. Can be once of IMPORT, FORCE, or LEGACY. Sync Mode
tokenUrl string
The Token URL. Token URL.
trustEmail boolean
When true, email addresses for users in this provider will automatically be verified regardless of the realm's email verification policy. Defaults to false. If enabled then email provided by this provider is not verified even if verification is enabled for the realm.
uiLocales boolean
Pass current locale to identity provider. Defaults to false. Pass current locale to identity provider
userInfoUrl string
User Info URL. User Info URL
validateSignature boolean
Enable/disable signature validation of external IDP signatures. Defaults to false. Enable/disable signature validation of external IDP signatures.
initProvider object
THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.
acceptsPromptNoneForwardFromClient boolean
When true, the IDP will accept forwarded authentication requests that contain the prompt=none query parameter. Defaults to false. This is just used together with Identity Provider Authenticator or when kc_idp_hint points to this identity provider. In case that client sends a request with prompt=none and user is not yet authenticated, the error will not be directly returned to client, but the request with prompt=none will be forwarded to this identity provider.
addReadTokenRoleOnCreate boolean
When true, new users will be able to read stored tokens. This will automatically assign the broker.read-token role. Defaults to false. Enable/disable if new users can read any stored tokens. This assigns the broker.read-token role.
alias string
The alias uniquely identifies an identity provider, and it is also used to build the redirect uri. The alias uniquely identifies an identity provider and it is also used to build the redirect uri.
authenticateByDefault boolean
Enable/disable authenticate users by default.
authorizationUrl string
The Authorization Url. OIDC authorization URL.
backchannelSupported boolean
Does the external IDP support backchannel logout? Defaults to true. Does the external IDP support backchannel logout?
clientIdSecretRef object required
The client or client identifier registered within the identity provider. Client ID.
key string required
name string required
Name of the secret.
clientSecretSecretRef object
The client or client secret registered within the identity provider. This field is able to obtain its value from vault, use $${vault.ID} format. Required without client_secret_wo and client_secret_wo_version. Client Secret.
key string required
name string required
Name of the secret.
clientSecretWoSecretRef object
The secret for clients with an access_type of CONFIDENTIAL or BEARER-ONLY. If omitted, this will fallback to use client_secret. Client Secret as write-only argument
key string required
name string required
Name of the secret.
clientSecretWoVersion string
The value of this argument is stored in the state and plan files. Required when using client_secret_wo. Version of the Client secret write-only argument
defaultScopes string
The scopes to be sent when asking for authorization. It can be a space-separated list of scopes. Defaults to openid. The scopes to be sent when asking for authorization. It can be a space-separated list of scopes. Defaults to 'openid'.
disableTypeClaimCheck boolean
When true, disables the check for the typ claim of tokens received from the identity provider. Defaults to false. Disables the validation of the `typ` claim of tokens received from the Identity Provider. If this is `off` the type claim is validated (default).
disableUserInfo boolean
When true, disables the usage of the user info service to obtain additional user information. Defaults to false. Disable usage of User Info service to obtain additional user information? Default is to use this OIDC service.
displayName string
Display name for the identity provider in the GUI. The human-friendly name of the identity provider, used in the log in form.
enabled boolean
When true, users will be able to log in to this realm using this identity provider. Defaults to true. Enable/disable this identity provider.
extraConfig object
A map of key/value pairs to add extra configuration to this identity provider. Use this attribute at your own risk, as custom attributes may conflict with top-level configuration attributes in future provider updates.
firstBrokerLoginFlowAlias string
The authentication flow to use when users log in for the first time through this identity provider. Defaults to first broker login. Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account.
firstBrokerLoginFlowAliasRef object
Reference to a Flow in authenticationflow to populate firstBrokerLoginFlowAlias.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
firstBrokerLoginFlowAliasSelector object
Selector for a Flow in authenticationflow to populate firstBrokerLoginFlowAlias.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
guiOrder string
A number defining the order of this identity provider in the GUI. GUI Order
hideOnLoginPage boolean
When true, this provider will be hidden on the login page, and is only accessible when requested explicitly. Defaults to false. Hide On Login Page.
issuer string
The issuer identifier for the issuer of the response. If not provided, no validation will be performed. The issuer identifier for the issuer of the response. If not provided, no validation will be performed.
jwksUrl string
JSON Web Key Set URL. JSON Web Key Set URL
linkOnly boolean
When true, users cannot sign-in using this provider, but their existing accounts will be linked when possible. Defaults to false. If true, users cannot log in through this provider. They can only link to this provider. This is useful if you don't want to allow login from the provider, but want to integrate with a provider
loginHint string
Pass login hint to identity provider. Login Hint.
logoutUrl string
The Logout URL is the end session endpoint to use to sign-out the user from external identity provider. Logout URL
orgDomain string
The organization domain to associate this identity provider with. it is used to map users to an organization based on their email domain and to authenticate them accordingly in the scope of the organization.
orgRedirectModeEmailMatches boolean
Indicates whether to automatically redirect user to this identity provider when email domain matches domain.
organizationId string
The ID of the organization to link this identity provider to. ID of organization with which this identity is linked.
organizationIdRef object
Reference to a Organization in organization to populate organizationId.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
organizationIdSelector object
Selector for a Organization in organization to populate organizationId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
postBrokerLoginFlowAlias string
The authentication flow to use after users have successfully logged in, which can be used to perform additional user verification (such as OTP checking). Defaults to an empty string, which means no post login flow will be used. Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it.
providerId string
The ID of the identity provider to use. Defaults to oidc, which should be used unless you have extended Keycloak and provided your own implementation. provider id, is always oidc, unless you have a custom implementation
realm string
The name of the realm. This is unique across Keycloak. Realm Name
realmRef object
Reference to a Realm in realm to populate realm.
name string required
Name of the referenced object.
namespace string
Namespace of the referenced object
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
realmSelector object
Selector for a Realm in realm to populate realm.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
namespace string
Namespace for the selector
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
storeToken boolean
When true, tokens will be stored after authenticating users. Defaults to true. Enable/disable if tokens must be stored after authenticating users.
syncMode string
The default sync mode to use for all mappers attached to this identity provider. Can be once of IMPORT, FORCE, or LEGACY. Sync Mode
tokenUrl string
The Token URL. Token URL.
trustEmail boolean
When true, email addresses for users in this provider will automatically be verified regardless of the realm's email verification policy. Defaults to false. If enabled then email provided by this provider is not verified even if verification is enabled for the realm.
uiLocales boolean
Pass current locale to identity provider. Defaults to false. Pass current locale to identity provider
userInfoUrl string
User Info URL. User Info URL
validateSignature boolean
Enable/disable signature validation of external IDP signatures. Defaults to false. Enable/disable signature validation of external IDP signatures.
managementPolicies []string
THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
providerConfigRef object
ProviderConfigReference specifies how the provider that will be used to create, observe, update, and delete this managed resource should be configured.
kind string required
Kind of the referenced object.
name string required
Name of the referenced object.
writeConnectionSecretToRef object
WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.
name string required
Name of the secret.
status object
IdentityProviderStatus defines the observed state of IdentityProvider.
atProvider object
acceptsPromptNoneForwardFromClient boolean
When true, the IDP will accept forwarded authentication requests that contain the prompt=none query parameter. Defaults to false. This is just used together with Identity Provider Authenticator or when kc_idp_hint points to this identity provider. In case that client sends a request with prompt=none and user is not yet authenticated, the error will not be directly returned to client, but the request with prompt=none will be forwarded to this identity provider.
addReadTokenRoleOnCreate boolean
When true, new users will be able to read stored tokens. This will automatically assign the broker.read-token role. Defaults to false. Enable/disable if new users can read any stored tokens. This assigns the broker.read-token role.
alias string
The alias uniquely identifies an identity provider, and it is also used to build the redirect uri. The alias uniquely identifies an identity provider and it is also used to build the redirect uri.
authenticateByDefault boolean
Enable/disable authenticate users by default.
authorizationUrl string
The Authorization Url. OIDC authorization URL.
backchannelSupported boolean
Does the external IDP support backchannel logout? Defaults to true. Does the external IDP support backchannel logout?
clientSecretWoVersion string
The value of this argument is stored in the state and plan files. Required when using client_secret_wo. Version of the Client secret write-only argument
defaultScopes string
The scopes to be sent when asking for authorization. It can be a space-separated list of scopes. Defaults to openid. The scopes to be sent when asking for authorization. It can be a space-separated list of scopes. Defaults to 'openid'.
disableTypeClaimCheck boolean
When true, disables the check for the typ claim of tokens received from the identity provider. Defaults to false. Disables the validation of the `typ` claim of tokens received from the Identity Provider. If this is `off` the type claim is validated (default).
disableUserInfo boolean
When true, disables the usage of the user info service to obtain additional user information. Defaults to false. Disable usage of User Info service to obtain additional user information? Default is to use this OIDC service.
displayName string
Display name for the identity provider in the GUI. The human-friendly name of the identity provider, used in the log in form.
enabled boolean
When true, users will be able to log in to this realm using this identity provider. Defaults to true. Enable/disable this identity provider.
extraConfig object
A map of key/value pairs to add extra configuration to this identity provider. Use this attribute at your own risk, as custom attributes may conflict with top-level configuration attributes in future provider updates.
firstBrokerLoginFlowAlias string
The authentication flow to use when users log in for the first time through this identity provider. Defaults to first broker login. Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account.
guiOrder string
A number defining the order of this identity provider in the GUI. GUI Order
hideOnLoginPage boolean
When true, this provider will be hidden on the login page, and is only accessible when requested explicitly. Defaults to false. Hide On Login Page.
id string
internalId string
(Computed) The unique ID that Keycloak assigns to the identity provider upon creation. Internal Identity Provider Id
issuer string
The issuer identifier for the issuer of the response. If not provided, no validation will be performed. The issuer identifier for the issuer of the response. If not provided, no validation will be performed.
jwksUrl string
JSON Web Key Set URL. JSON Web Key Set URL
linkOnly boolean
When true, users cannot sign-in using this provider, but their existing accounts will be linked when possible. Defaults to false. If true, users cannot log in through this provider. They can only link to this provider. This is useful if you don't want to allow login from the provider, but want to integrate with a provider
loginHint string
Pass login hint to identity provider. Login Hint.
logoutUrl string
The Logout URL is the end session endpoint to use to sign-out the user from external identity provider. Logout URL
orgDomain string
The organization domain to associate this identity provider with. it is used to map users to an organization based on their email domain and to authenticate them accordingly in the scope of the organization.
orgRedirectModeEmailMatches boolean
Indicates whether to automatically redirect user to this identity provider when email domain matches domain.
organizationId string
The ID of the organization to link this identity provider to. ID of organization with which this identity is linked.
postBrokerLoginFlowAlias string
The authentication flow to use after users have successfully logged in, which can be used to perform additional user verification (such as OTP checking). Defaults to an empty string, which means no post login flow will be used. Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it.
providerId string
The ID of the identity provider to use. Defaults to oidc, which should be used unless you have extended Keycloak and provided your own implementation. provider id, is always oidc, unless you have a custom implementation
realm string
The name of the realm. This is unique across Keycloak. Realm Name
storeToken boolean
When true, tokens will be stored after authenticating users. Defaults to true. Enable/disable if tokens must be stored after authenticating users.
syncMode string
The default sync mode to use for all mappers attached to this identity provider. Can be once of IMPORT, FORCE, or LEGACY. Sync Mode
tokenUrl string
The Token URL. Token URL.
trustEmail boolean
When true, email addresses for users in this provider will automatically be verified regardless of the realm's email verification policy. Defaults to false. If enabled then email provided by this provider is not verified even if verification is enabled for the realm.
uiLocales boolean
Pass current locale to identity provider. Defaults to false. Pass current locale to identity provider
userInfoUrl string
User Info URL. User Info URL
validateSignature boolean
Enable/disable signature validation of external IDP signatures. Defaults to false. Enable/disable signature validation of external IDP signatures.
conditions []object
Conditions of the resource.
lastTransitionTime string required
LastTransitionTime is the last time this condition transitioned from one status to another.
format: date-time
message string
A Message containing details about this condition's last transition from one status to another, if any.
observedGeneration integer
ObservedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
reason string required
A Reason for this condition's last transition from one status to another.
status string required
Status of this condition; is it currently True, False, or Unknown?
type string required
Type of this condition. At most one of each condition type may apply to a resource at any point in time.
observedGeneration integer
ObservedGeneration is the latest metadata.generation which resulted in either a ready state, or stalled due to error it can not recover from without human intervention.
format: int64

No matches. Try .spec.forProvider for an exact path