IdentityProvider
saml.keycloak.crossplane.io / v1alpha1
apiVersion: saml.keycloak.crossplane.io/v1alpha1
kind: IdentityProvider
metadata:
name: example
apiVersion
string
APIVersion defines the versioned schema of this representation of an object.
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind
string
Kind is a string value representing the REST resource this object represents.
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata
object
spec object required
IdentityProviderSpec defines the desired state of IdentityProvider
deletionPolicy
string
DeletionPolicy specifies what will happen to the underlying external
when this managed resource is deleted - either "Delete" or "Orphan" the
external resource.
This field is planned to be deprecated in favor of the ManagementPolicies
field in a future release. Currently, both could be set independently and
non-default values would be honored if the feature flag is enabled.
See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223
enum:
Orphan, DeleteforProvider object required
addReadTokenRoleOnCreate
boolean
When true, new users will be able to read stored tokens. This will automatically assign the broker.read-token role. Defaults to false.
Enable/disable if new users can read any stored tokens. This assigns the broker.read-token role.
alias
string
The unique name of identity provider.
The alias uniquely identifies an identity provider and it is also used to build the redirect uri.
authenticateByDefault
boolean
Authenticate users by default. Defaults to false.
Enable/disable authenticate users by default.
authnContextClassRefs
[]string
Ordered list of requested AuthnContext ClassRefs.
AuthnContext ClassRefs
authnContextComparisonType
string
Specifies the comparison method used to evaluate the requested context classes or statements.
AuthnContext Comparison
authnContextDeclRefs
[]string
Ordered list of requested AuthnContext DeclRefs.
AuthnContext DeclRefs
backchannelSupported
boolean
Does the external IDP support backchannel logout?. Defaults to false.
Does the external IDP support backchannel logout?
displayName
string
The display name for the realm that is shown when logging in to the admin console.
Friendly name for Identity Providers.
enabled
boolean
When false, users and clients will not be able to access this realm. Defaults to true.
Enable/disable this identity provider.
entityId
string
The Entity ID that will be used to uniquely identify this SAML Service Provider.
The Entity ID that will be used to uniquely identify this SAML Service Provider.
extraConfig
object
A map of key/value pairs to add extra configuration to this identity provider. Use this attribute at your own risk, as custom attributes may conflict with top-level configuration attributes in future provider updates.
firstBrokerLoginFlowAlias
string
Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account. Defaults to first broker login.
Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account.
forceAuthn
boolean
Indicates whether the identity provider must authenticate the presenter directly rather than rely on a previous security context.
Require Force Authn.
guiOrder
string
A number defining the order of this identity provider in the GUI.
GUI Order
hideOnLoginPage
boolean
If hidden, then login with this provider is possible only if requested explicitly, e.g. using the 'kc_idp_hint' parameter.
Hide On Login Page.
linkOnly
boolean
When true, users cannot log in using this provider, but their existing accounts will be linked when possible. Defaults to false.
If true, users cannot log in through this provider. They can only link to this provider. This is useful if you don't want to allow login from the provider, but want to integrate with a provider
loginHint
string
Login Hint.
nameIdPolicyFormat
string
Specifies the URI reference corresponding to a name identifier format. Defaults to empty.
Name ID Policy Format.
orgDomain
string
The organization domain to associate this identity provider with. It is used to map users to an organization based on their email domain and to authenticate them accordingly in the scope of the organization.
orgRedirectModeEmailMatches
boolean
Indicates whether to automatically redirect users to this identity provider when email domain matches domain.
organizationId
string
The ID of the organization to link this identity provider to.
ID of organization with which this identity is linked.
organizationIdRef object
Reference to a Organization in organization to populate organizationId.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentorganizationIdSelector object
Selector for a Organization in organization to populate organizationId.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
postBindingAuthnRequest
boolean
Indicates whether the AuthnRequest must be sent using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Authn Request.
postBindingLogout
boolean
Indicates whether to respond to requests using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Logout.
postBindingResponse
boolean
Indicates whether to respond to requests using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Response.
postBrokerLoginFlowAlias
string
Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it. Defaults to empty.
Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it.
principalAttribute
string
The principal attribute.
Principal Attribute
principalType
string
The principal type. Can be one of SUBJECT, ATTRIBUTE or FRIENDLY_ATTRIBUTE.
Principal Type
providerId
string
The ID of the identity provider to use. Defaults to saml, which should be used unless you have extended Keycloak and provided your own implementation.
provider id, is always saml, unless you have a custom implementation
realm
string
The name of the realm. This is unique across Keycloak.
Realm Name
realmRef object
Reference to a Realm in realm to populate realm.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentrealmSelector object
Selector for a Realm in realm to populate realm.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
signatureAlgorithm
string
Signing Algorithm. Defaults to empty.
Signing Algorithm.
signingCertificate
string
Signing Certificate.
Signing Certificate.
singleLogoutServiceUrl
string
The Url that must be used to send logout requests.
Logout URL.
singleSignOnServiceUrl
string
The Url that must be used to send authentication requests (SAML AuthnRequest).
SSO Logout URL.
storeToken
boolean
When true, tokens will be stored after authenticating users. Defaults to true.
Enable/disable if tokens must be stored after authenticating users.
syncMode
string
The default sync mode to use for all mappers attached to this identity provider. Can be one of IMPORT, FORCE, or LEGACY.
Sync Mode
trustEmail
boolean
When true, email addresses for users in this provider will automatically be verified regardless of the realm's email verification policy. Defaults to false.
If enabled then email provided by this provider is not verified even if verification is enabled for the realm.
validateSignature
boolean
Enable/disable signature validation of SAML responses.
Enable/disable signature validation of SAML responses.
wantAssertionsEncrypted
boolean
Indicates whether this service provider expects an encrypted Assertion.
Want Assertions Encrypted.
wantAssertionsSigned
boolean
Indicates whether this service provider expects a signed Assertion.
Want Assertions Signed.
wantAuthnRequestsSigned
boolean
Indicates whether this service provider expects authentication requests to be signed (defaults to true if signature_algorithm is set and this isn't).
Want Authn Requests Signed.
xmlSignKeyInfoKeyNameTransformer
string
The SAML signature key name. Can be one of NONE, KEY_ID, or CERT_SUBJECT.
Sign Key Transformer.
initProvider object
THIS IS A BETA FIELD. It will be honored
unless the Management Policies feature flag is disabled.
InitProvider holds the same fields as ForProvider, with the exception
of Identifier and other resource reference fields. The fields that are
in InitProvider are merged into ForProvider when the resource is created.
The same fields are also added to the terraform ignore_changes hook, to
avoid updating them after creation. This is useful for fields that are
required on creation, but we do not desire to update them after creation,
for example because of an external controller is managing them, like an
autoscaler.
addReadTokenRoleOnCreate
boolean
When true, new users will be able to read stored tokens. This will automatically assign the broker.read-token role. Defaults to false.
Enable/disable if new users can read any stored tokens. This assigns the broker.read-token role.
alias
string
The unique name of identity provider.
The alias uniquely identifies an identity provider and it is also used to build the redirect uri.
authenticateByDefault
boolean
Authenticate users by default. Defaults to false.
Enable/disable authenticate users by default.
authnContextClassRefs
[]string
Ordered list of requested AuthnContext ClassRefs.
AuthnContext ClassRefs
authnContextComparisonType
string
Specifies the comparison method used to evaluate the requested context classes or statements.
AuthnContext Comparison
authnContextDeclRefs
[]string
Ordered list of requested AuthnContext DeclRefs.
AuthnContext DeclRefs
backchannelSupported
boolean
Does the external IDP support backchannel logout?. Defaults to false.
Does the external IDP support backchannel logout?
displayName
string
The display name for the realm that is shown when logging in to the admin console.
Friendly name for Identity Providers.
enabled
boolean
When false, users and clients will not be able to access this realm. Defaults to true.
Enable/disable this identity provider.
entityId
string
The Entity ID that will be used to uniquely identify this SAML Service Provider.
The Entity ID that will be used to uniquely identify this SAML Service Provider.
extraConfig
object
A map of key/value pairs to add extra configuration to this identity provider. Use this attribute at your own risk, as custom attributes may conflict with top-level configuration attributes in future provider updates.
firstBrokerLoginFlowAlias
string
Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account. Defaults to first broker login.
Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account.
forceAuthn
boolean
Indicates whether the identity provider must authenticate the presenter directly rather than rely on a previous security context.
Require Force Authn.
guiOrder
string
A number defining the order of this identity provider in the GUI.
GUI Order
hideOnLoginPage
boolean
If hidden, then login with this provider is possible only if requested explicitly, e.g. using the 'kc_idp_hint' parameter.
Hide On Login Page.
linkOnly
boolean
When true, users cannot log in using this provider, but their existing accounts will be linked when possible. Defaults to false.
If true, users cannot log in through this provider. They can only link to this provider. This is useful if you don't want to allow login from the provider, but want to integrate with a provider
loginHint
string
Login Hint.
nameIdPolicyFormat
string
Specifies the URI reference corresponding to a name identifier format. Defaults to empty.
Name ID Policy Format.
orgDomain
string
The organization domain to associate this identity provider with. It is used to map users to an organization based on their email domain and to authenticate them accordingly in the scope of the organization.
orgRedirectModeEmailMatches
boolean
Indicates whether to automatically redirect users to this identity provider when email domain matches domain.
organizationId
string
The ID of the organization to link this identity provider to.
ID of organization with which this identity is linked.
organizationIdRef object
Reference to a Organization in organization to populate organizationId.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentorganizationIdSelector object
Selector for a Organization in organization to populate organizationId.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
postBindingAuthnRequest
boolean
Indicates whether the AuthnRequest must be sent using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Authn Request.
postBindingLogout
boolean
Indicates whether to respond to requests using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Logout.
postBindingResponse
boolean
Indicates whether to respond to requests using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Response.
postBrokerLoginFlowAlias
string
Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it. Defaults to empty.
Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it.
principalAttribute
string
The principal attribute.
Principal Attribute
principalType
string
The principal type. Can be one of SUBJECT, ATTRIBUTE or FRIENDLY_ATTRIBUTE.
Principal Type
providerId
string
The ID of the identity provider to use. Defaults to saml, which should be used unless you have extended Keycloak and provided your own implementation.
provider id, is always saml, unless you have a custom implementation
realm
string
The name of the realm. This is unique across Keycloak.
Realm Name
realmRef object
Reference to a Realm in realm to populate realm.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentrealmSelector object
Selector for a Realm in realm to populate realm.
matchControllerRef
boolean
MatchControllerRef ensures an object with the same controller reference
as the selecting object is selected.
matchLabels
object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresent
signatureAlgorithm
string
Signing Algorithm. Defaults to empty.
Signing Algorithm.
signingCertificate
string
Signing Certificate.
Signing Certificate.
singleLogoutServiceUrl
string
The Url that must be used to send logout requests.
Logout URL.
singleSignOnServiceUrl
string
The Url that must be used to send authentication requests (SAML AuthnRequest).
SSO Logout URL.
storeToken
boolean
When true, tokens will be stored after authenticating users. Defaults to true.
Enable/disable if tokens must be stored after authenticating users.
syncMode
string
The default sync mode to use for all mappers attached to this identity provider. Can be one of IMPORT, FORCE, or LEGACY.
Sync Mode
trustEmail
boolean
When true, email addresses for users in this provider will automatically be verified regardless of the realm's email verification policy. Defaults to false.
If enabled then email provided by this provider is not verified even if verification is enabled for the realm.
validateSignature
boolean
Enable/disable signature validation of SAML responses.
Enable/disable signature validation of SAML responses.
wantAssertionsEncrypted
boolean
Indicates whether this service provider expects an encrypted Assertion.
Want Assertions Encrypted.
wantAssertionsSigned
boolean
Indicates whether this service provider expects a signed Assertion.
Want Assertions Signed.
wantAuthnRequestsSigned
boolean
Indicates whether this service provider expects authentication requests to be signed (defaults to true if signature_algorithm is set and this isn't).
Want Authn Requests Signed.
xmlSignKeyInfoKeyNameTransformer
string
The SAML signature key name. Can be one of NONE, KEY_ID, or CERT_SUBJECT.
Sign Key Transformer.
managementPolicies
[]string
THIS IS A BETA FIELD. It is on by default but can be opted out
through a Crossplane feature flag.
ManagementPolicies specify the array of actions Crossplane is allowed to
take on the managed and external resources.
This field is planned to replace the DeletionPolicy field in a future
release. Currently, both could be set independently and non-default
values would be honored if the feature flag is enabled. If both are
custom, the DeletionPolicy field will be ignored.
See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223
and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
providerConfigRef object
ProviderConfigReference specifies how the provider that will be used to
create, observe, update, and delete this managed resource should be
configured.
name
string required
Name of the referenced object.
policy object
Policies for referencing.
resolution
string
Resolution specifies whether resolution of this reference is required.
The default is 'Required', which means the reconcile will fail if the
reference cannot be resolved. 'Optional' means this reference will be
a no-op if it cannot be resolved.
enum:
Required, Optional
resolve
string
Resolve specifies when this reference should be resolved. The default
is 'IfNotPresent', which will attempt to resolve the reference only when
the corresponding field is not present. Use 'Always' to resolve the
reference on every reconcile.
enum:
Always, IfNotPresentwriteConnectionSecretToRef object
WriteConnectionSecretToReference specifies the namespace and name of a
Secret to which any connection details for this managed resource should
be written. Connection details frequently include the endpoint, username,
and password required to connect to the managed resource.
name
string required
Name of the secret.
namespace
string required
Namespace of the secret.
status object
IdentityProviderStatus defines the observed state of IdentityProvider.
atProvider object
addReadTokenRoleOnCreate
boolean
When true, new users will be able to read stored tokens. This will automatically assign the broker.read-token role. Defaults to false.
Enable/disable if new users can read any stored tokens. This assigns the broker.read-token role.
alias
string
The unique name of identity provider.
The alias uniquely identifies an identity provider and it is also used to build the redirect uri.
authenticateByDefault
boolean
Authenticate users by default. Defaults to false.
Enable/disable authenticate users by default.
authnContextClassRefs
[]string
Ordered list of requested AuthnContext ClassRefs.
AuthnContext ClassRefs
authnContextComparisonType
string
Specifies the comparison method used to evaluate the requested context classes or statements.
AuthnContext Comparison
authnContextDeclRefs
[]string
Ordered list of requested AuthnContext DeclRefs.
AuthnContext DeclRefs
backchannelSupported
boolean
Does the external IDP support backchannel logout?. Defaults to false.
Does the external IDP support backchannel logout?
displayName
string
The display name for the realm that is shown when logging in to the admin console.
Friendly name for Identity Providers.
enabled
boolean
When false, users and clients will not be able to access this realm. Defaults to true.
Enable/disable this identity provider.
entityId
string
The Entity ID that will be used to uniquely identify this SAML Service Provider.
The Entity ID that will be used to uniquely identify this SAML Service Provider.
extraConfig
object
A map of key/value pairs to add extra configuration to this identity provider. Use this attribute at your own risk, as custom attributes may conflict with top-level configuration attributes in future provider updates.
firstBrokerLoginFlowAlias
string
Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account. Defaults to first broker login.
Alias of authentication flow, which is triggered after first login with this identity provider. Term 'First Login' means that there is not yet existing Keycloak account linked with the authenticated identity provider account.
forceAuthn
boolean
Indicates whether the identity provider must authenticate the presenter directly rather than rely on a previous security context.
Require Force Authn.
guiOrder
string
A number defining the order of this identity provider in the GUI.
GUI Order
hideOnLoginPage
boolean
If hidden, then login with this provider is possible only if requested explicitly, e.g. using the 'kc_idp_hint' parameter.
Hide On Login Page.
id
string
internalId
string
Internal Identity Provider Id
linkOnly
boolean
When true, users cannot log in using this provider, but their existing accounts will be linked when possible. Defaults to false.
If true, users cannot log in through this provider. They can only link to this provider. This is useful if you don't want to allow login from the provider, but want to integrate with a provider
loginHint
string
Login Hint.
nameIdPolicyFormat
string
Specifies the URI reference corresponding to a name identifier format. Defaults to empty.
Name ID Policy Format.
orgDomain
string
The organization domain to associate this identity provider with. It is used to map users to an organization based on their email domain and to authenticate them accordingly in the scope of the organization.
orgRedirectModeEmailMatches
boolean
Indicates whether to automatically redirect users to this identity provider when email domain matches domain.
organizationId
string
The ID of the organization to link this identity provider to.
ID of organization with which this identity is linked.
postBindingAuthnRequest
boolean
Indicates whether the AuthnRequest must be sent using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Authn Request.
postBindingLogout
boolean
Indicates whether to respond to requests using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Logout.
postBindingResponse
boolean
Indicates whether to respond to requests using HTTP-POST binding. If false, HTTP-REDIRECT binding will be used.
Post Binding Response.
postBrokerLoginFlowAlias
string
Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it. Defaults to empty.
Alias of authentication flow, which is triggered after each login with this identity provider. Useful if you want additional verification of each user authenticated with this identity provider (for example OTP). Leave this empty if you don't want any additional authenticators to be triggered after login with this identity provider. Also note, that authenticator implementations must assume that user is already set in ClientSession as identity provider already set it.
principalAttribute
string
The principal attribute.
Principal Attribute
principalType
string
The principal type. Can be one of SUBJECT, ATTRIBUTE or FRIENDLY_ATTRIBUTE.
Principal Type
providerId
string
The ID of the identity provider to use. Defaults to saml, which should be used unless you have extended Keycloak and provided your own implementation.
provider id, is always saml, unless you have a custom implementation
realm
string
The name of the realm. This is unique across Keycloak.
Realm Name
signatureAlgorithm
string
Signing Algorithm. Defaults to empty.
Signing Algorithm.
signingCertificate
string
Signing Certificate.
Signing Certificate.
singleLogoutServiceUrl
string
The Url that must be used to send logout requests.
Logout URL.
singleSignOnServiceUrl
string
The Url that must be used to send authentication requests (SAML AuthnRequest).
SSO Logout URL.
storeToken
boolean
When true, tokens will be stored after authenticating users. Defaults to true.
Enable/disable if tokens must be stored after authenticating users.
syncMode
string
The default sync mode to use for all mappers attached to this identity provider. Can be one of IMPORT, FORCE, or LEGACY.
Sync Mode
trustEmail
boolean
When true, email addresses for users in this provider will automatically be verified regardless of the realm's email verification policy. Defaults to false.
If enabled then email provided by this provider is not verified even if verification is enabled for the realm.
validateSignature
boolean
Enable/disable signature validation of SAML responses.
Enable/disable signature validation of SAML responses.
wantAssertionsEncrypted
boolean
Indicates whether this service provider expects an encrypted Assertion.
Want Assertions Encrypted.
wantAssertionsSigned
boolean
Indicates whether this service provider expects a signed Assertion.
Want Assertions Signed.
wantAuthnRequestsSigned
boolean
Indicates whether this service provider expects authentication requests to be signed (defaults to true if signature_algorithm is set and this isn't).
Want Authn Requests Signed.
xmlSignKeyInfoKeyNameTransformer
string
The SAML signature key name. Can be one of NONE, KEY_ID, or CERT_SUBJECT.
Sign Key Transformer.
conditions []object
Conditions of the resource.
lastTransitionTime
string required
LastTransitionTime is the last time this condition transitioned from one
status to another.
format:
date-time
message
string
A Message containing details about this condition's last transition from
one status to another, if any.
observedGeneration
integer
ObservedGeneration represents the .metadata.generation that the condition was set based upon.
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
format:
int64
reason
string required
A Reason for this condition's last transition from one status to another.
status
string required
Status of this condition; is it currently True, False, or Unknown?
type
string required
Type of this condition. At most one of each condition type may apply to
a resource at any point in time.
observedGeneration
integer
ObservedGeneration is the latest metadata.generation
which resulted in either a ready state, or stalled due to error
it can not recover from without human intervention.
format:
int64No matches. Try .spec.deletionPolicy for an exact path