Skip to search

Client

samlclient.keycloak.crossplane.io / v1alpha1

apiVersion: samlclient.keycloak.crossplane.io/v1alpha1 kind: Client metadata: name: example
View raw schema
apiVersion string
APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
kind string
Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
metadata object
spec object required
ClientSpec defines the desired state of Client
deletionPolicy string
DeletionPolicy specifies what will happen to the underlying external when this managed resource is deleted - either "Delete" or "Orphan" the external resource. This field is planned to be deprecated in favor of the ManagementPolicies field in a future release. Currently, both could be set independently and non-default values would be honored if the feature flag is enabled. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223
enum: Orphan, Delete
forProvider object required
alwaysDisplayInConsole boolean
Always list this client in the Account UI, even if the user does not have an active session.
assertionConsumerPostUrl string
SAML POST Binding URL for the client's assertion consumer service (login responses).
assertionConsumerRedirectUrl string
SAML Redirect Binding URL for the client's assertion consumer service (login responses).
authenticationFlowBindingOverrides []object
Override realm authentication flow bindings
browserId string
Browser flow id, (flow needs to exist)
directGrantId string
Direct grant flow id (flow needs to exist)
baseUrl string
When specified, this URL will be used whenever Keycloak needs to link to this client.
canonicalizationMethod string
The Canonicalization Method for XML signatures. Should be one of "EXCLUSIVE", "EXCLUSIVE_WITH_COMMENTS", "INCLUSIVE", or "INCLUSIVE_WITH_COMMENTS". Defaults to "EXCLUSIVE".
clientId string
The unique ID of this client, referenced in the URI during authentication and in issued tokens.
clientSignatureRequired boolean
When true, Keycloak will expect that documents originating from a client will be signed using the certificate and/or key configured via signing_certificate and signing_private_key. Defaults to true.
consentRequired boolean
When true, users have to consent to client access. Defaults to false.
description string
The description of this client in the GUI.
enabled boolean
When false, this client will not be able to initiate a login or obtain access tokens. Defaults to true.
encryptAssertions boolean
When true, the SAML assertions will be encrypted by Keycloak using the client's public key. Defaults to false.
encryptionAlgorithm string
Algorithm used to encrypt SAML assertions. Allowed values: AES_256_GCM, AES_192_GCM, AES_128_GCM, AES_256_CBC, AES_192_CBC, or AES_128_CBC.
encryptionCertificateSecretRef object
If assertions for the client are encrypted, this certificate will be used for encryption.
key string required
The key to select.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
encryptionDigestMethod string
Digest method used with SAML encryption. Allowed values: SHA-512, SHA-256, or SHA-1. Only valid when encryption_key_algorithm is RSA-OAEP-11 or RSA-OAEP-MGF1P. Default is SHA-256.
encryptionKeyAlgorithm string
Key transport algorithm used by the client to encrypt the secret key for SAML assertion encryption. Allowed values: RSA-OAEP-11, RSA-OAEP-MGF1P, or RSA1_5. Default is RSA-OAEP-11.
encryptionMaskGenerationFunction string
Mask generation function used with SAML encryption. Allowed values: mgf1sha1, mgf1sha224, mgf1sha256, mgf1sha384, or mgf1sha512. Only valid when encryption_key_algorithm is RSA-OAEP-11. Default is mgf1sha256.
extraConfig object
A map of key/value pairs to add extra configuration attributes to this client. Use this attribute at your own risk, as s may conflict with top-level configuration attributes in future provider updates.
forceNameIdFormat boolean
Ignore requested NameID subject format and use the one defined in name_id_format instead. Defaults to false.
forcePostBinding boolean
When true, Keycloak will always respond to an authentication request via the SAML POST Binding. Defaults to true.
frontChannelLogout boolean
When true, this client will require a browser redirect in order to perform a logout. Defaults to true.
fullScopeAllowed boolean
- Allow to include all roles mappings in the access token
idpInitiatedSsoRelayState string
Relay state you want to send with SAML request when you want to do IDP Initiated SSO.
idpInitiatedSsoUrlName string
URL fragment name to reference client when you want to do IDP Initiated SSO.
includeAuthnStatement boolean
When true, an AuthnStatement will be included in the SAML response. Defaults to true.
loginTheme string
The login theme of this client.
logoutServicePostBindingUrl string
SAML POST Binding URL for the client's single logout service.
logoutServiceRedirectBindingUrl string
SAML Redirect Binding URL for the client's single logout service.
masterSamlProcessingUrl string
When specified, this URL will be used for all SAML requests.
name string
The display name of this client in the GUI.
nameIdFormat string
Sets the Name ID format for the subject.
realmId string
The realm this client is attached to.
realmIdRef object
Reference to a Realm in realm to populate realmId.
name string required
Name of the referenced object.
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
realmIdSelector object
Selector for a Realm in realm to populate realmId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
rootUrl string
When specified, this value is prepended to all relative URLs.
signAssertions boolean
When true, the SAML assertions will be signed by Keycloak using the realm's private key, and embedded within the SAML XML Auth response. Defaults to false.
signDocuments boolean
When true, the SAML document will be signed by Keycloak using the realm's private key. Defaults to true.
signatureAlgorithm string
The signature algorithm used to sign documents. Should be one of "RSA_SHA1", "RSA_SHA256", "RSA_SHA256_MGF1, "RSA_SHA512", "RSA_SHA512_MGF1" or "DSA_SHA1".
signatureKeyName string
The value of the KeyName element within the signed SAML document. Should be one of "NONE", "KEY_ID", or "CERT_SUBJECT". Defaults to "KEY_ID".
signingCertificateSecretRef object
If documents or assertions from the client are signed, this certificate will be used to verify the signature.
key string required
The key to select.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
signingPrivateKeySecretRef object
If documents or assertions from the client are signed, this private key will be used to verify the signature.
key string required
The key to select.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
validRedirectUris []string
When specified, Keycloak will use this list to validate given Assertion Consumer URLs specified in the authentication request.
initProvider object
THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.
alwaysDisplayInConsole boolean
Always list this client in the Account UI, even if the user does not have an active session.
assertionConsumerPostUrl string
SAML POST Binding URL for the client's assertion consumer service (login responses).
assertionConsumerRedirectUrl string
SAML Redirect Binding URL for the client's assertion consumer service (login responses).
authenticationFlowBindingOverrides []object
Override realm authentication flow bindings
browserId string
Browser flow id, (flow needs to exist)
directGrantId string
Direct grant flow id (flow needs to exist)
baseUrl string
When specified, this URL will be used whenever Keycloak needs to link to this client.
canonicalizationMethod string
The Canonicalization Method for XML signatures. Should be one of "EXCLUSIVE", "EXCLUSIVE_WITH_COMMENTS", "INCLUSIVE", or "INCLUSIVE_WITH_COMMENTS". Defaults to "EXCLUSIVE".
clientId string
The unique ID of this client, referenced in the URI during authentication and in issued tokens.
clientSignatureRequired boolean
When true, Keycloak will expect that documents originating from a client will be signed using the certificate and/or key configured via signing_certificate and signing_private_key. Defaults to true.
consentRequired boolean
When true, users have to consent to client access. Defaults to false.
description string
The description of this client in the GUI.
enabled boolean
When false, this client will not be able to initiate a login or obtain access tokens. Defaults to true.
encryptAssertions boolean
When true, the SAML assertions will be encrypted by Keycloak using the client's public key. Defaults to false.
encryptionAlgorithm string
Algorithm used to encrypt SAML assertions. Allowed values: AES_256_GCM, AES_192_GCM, AES_128_GCM, AES_256_CBC, AES_192_CBC, or AES_128_CBC.
encryptionCertificateSecretRef object
If assertions for the client are encrypted, this certificate will be used for encryption.
key string required
The key to select.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
encryptionDigestMethod string
Digest method used with SAML encryption. Allowed values: SHA-512, SHA-256, or SHA-1. Only valid when encryption_key_algorithm is RSA-OAEP-11 or RSA-OAEP-MGF1P. Default is SHA-256.
encryptionKeyAlgorithm string
Key transport algorithm used by the client to encrypt the secret key for SAML assertion encryption. Allowed values: RSA-OAEP-11, RSA-OAEP-MGF1P, or RSA1_5. Default is RSA-OAEP-11.
encryptionMaskGenerationFunction string
Mask generation function used with SAML encryption. Allowed values: mgf1sha1, mgf1sha224, mgf1sha256, mgf1sha384, or mgf1sha512. Only valid when encryption_key_algorithm is RSA-OAEP-11. Default is mgf1sha256.
extraConfig object
A map of key/value pairs to add extra configuration attributes to this client. Use this attribute at your own risk, as s may conflict with top-level configuration attributes in future provider updates.
forceNameIdFormat boolean
Ignore requested NameID subject format and use the one defined in name_id_format instead. Defaults to false.
forcePostBinding boolean
When true, Keycloak will always respond to an authentication request via the SAML POST Binding. Defaults to true.
frontChannelLogout boolean
When true, this client will require a browser redirect in order to perform a logout. Defaults to true.
fullScopeAllowed boolean
- Allow to include all roles mappings in the access token
idpInitiatedSsoRelayState string
Relay state you want to send with SAML request when you want to do IDP Initiated SSO.
idpInitiatedSsoUrlName string
URL fragment name to reference client when you want to do IDP Initiated SSO.
includeAuthnStatement boolean
When true, an AuthnStatement will be included in the SAML response. Defaults to true.
loginTheme string
The login theme of this client.
logoutServicePostBindingUrl string
SAML POST Binding URL for the client's single logout service.
logoutServiceRedirectBindingUrl string
SAML Redirect Binding URL for the client's single logout service.
masterSamlProcessingUrl string
When specified, this URL will be used for all SAML requests.
name string
The display name of this client in the GUI.
nameIdFormat string
Sets the Name ID format for the subject.
realmId string
The realm this client is attached to.
realmIdRef object
Reference to a Realm in realm to populate realmId.
name string required
Name of the referenced object.
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
realmIdSelector object
Selector for a Realm in realm to populate realmId.
matchControllerRef boolean
MatchControllerRef ensures an object with the same controller reference as the selecting object is selected.
matchLabels object
MatchLabels ensures an object with matching labels is selected.
policy object
Policies for selection.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
rootUrl string
When specified, this value is prepended to all relative URLs.
signAssertions boolean
When true, the SAML assertions will be signed by Keycloak using the realm's private key, and embedded within the SAML XML Auth response. Defaults to false.
signDocuments boolean
When true, the SAML document will be signed by Keycloak using the realm's private key. Defaults to true.
signatureAlgorithm string
The signature algorithm used to sign documents. Should be one of "RSA_SHA1", "RSA_SHA256", "RSA_SHA256_MGF1, "RSA_SHA512", "RSA_SHA512_MGF1" or "DSA_SHA1".
signatureKeyName string
The value of the KeyName element within the signed SAML document. Should be one of "NONE", "KEY_ID", or "CERT_SUBJECT". Defaults to "KEY_ID".
signingCertificateSecretRef object
If documents or assertions from the client are signed, this certificate will be used to verify the signature.
key string required
The key to select.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
signingPrivateKeySecretRef object
If documents or assertions from the client are signed, this private key will be used to verify the signature.
key string required
The key to select.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
validRedirectUris []string
When specified, Keycloak will use this list to validate given Assertion Consumer URLs specified in the authentication request.
managementPolicies []string
THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. This field is planned to replace the DeletionPolicy field in a future release. Currently, both could be set independently and non-default values would be honored if the feature flag is enabled. If both are custom, the DeletionPolicy field will be ignored. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
providerConfigRef object
ProviderConfigReference specifies how the provider that will be used to create, observe, update, and delete this managed resource should be configured.
name string required
Name of the referenced object.
policy object
Policies for referencing.
resolution string
Resolution specifies whether resolution of this reference is required. The default is 'Required', which means the reconcile will fail if the reference cannot be resolved. 'Optional' means this reference will be a no-op if it cannot be resolved.
enum: Required, Optional
resolve string
Resolve specifies when this reference should be resolved. The default is 'IfNotPresent', which will attempt to resolve the reference only when the corresponding field is not present. Use 'Always' to resolve the reference on every reconcile.
enum: Always, IfNotPresent
writeConnectionSecretToRef object
WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.
name string required
Name of the secret.
namespace string required
Namespace of the secret.
status object
ClientStatus defines the observed state of Client.
atProvider object
alwaysDisplayInConsole boolean
Always list this client in the Account UI, even if the user does not have an active session.
assertionConsumerPostUrl string
SAML POST Binding URL for the client's assertion consumer service (login responses).
assertionConsumerRedirectUrl string
SAML Redirect Binding URL for the client's assertion consumer service (login responses).
authenticationFlowBindingOverrides []object
Override realm authentication flow bindings
browserId string
Browser flow id, (flow needs to exist)
directGrantId string
Direct grant flow id (flow needs to exist)
baseUrl string
When specified, this URL will be used whenever Keycloak needs to link to this client.
canonicalizationMethod string
The Canonicalization Method for XML signatures. Should be one of "EXCLUSIVE", "EXCLUSIVE_WITH_COMMENTS", "INCLUSIVE", or "INCLUSIVE_WITH_COMMENTS". Defaults to "EXCLUSIVE".
clientId string
The unique ID of this client, referenced in the URI during authentication and in issued tokens.
clientSignatureRequired boolean
When true, Keycloak will expect that documents originating from a client will be signed using the certificate and/or key configured via signing_certificate and signing_private_key. Defaults to true.
consentRequired boolean
When true, users have to consent to client access. Defaults to false.
description string
The description of this client in the GUI.
enabled boolean
When false, this client will not be able to initiate a login or obtain access tokens. Defaults to true.
encryptAssertions boolean
When true, the SAML assertions will be encrypted by Keycloak using the client's public key. Defaults to false.
encryptionAlgorithm string
Algorithm used to encrypt SAML assertions. Allowed values: AES_256_GCM, AES_192_GCM, AES_128_GCM, AES_256_CBC, AES_192_CBC, or AES_128_CBC.
encryptionCertificateSha1 string
(Computed) The sha1sum fingerprint of the encryption certificate. If the encryption certificate is not in correct base64 format, this will be left empty.
encryptionDigestMethod string
Digest method used with SAML encryption. Allowed values: SHA-512, SHA-256, or SHA-1. Only valid when encryption_key_algorithm is RSA-OAEP-11 or RSA-OAEP-MGF1P. Default is SHA-256.
encryptionKeyAlgorithm string
Key transport algorithm used by the client to encrypt the secret key for SAML assertion encryption. Allowed values: RSA-OAEP-11, RSA-OAEP-MGF1P, or RSA1_5. Default is RSA-OAEP-11.
encryptionMaskGenerationFunction string
Mask generation function used with SAML encryption. Allowed values: mgf1sha1, mgf1sha224, mgf1sha256, mgf1sha384, or mgf1sha512. Only valid when encryption_key_algorithm is RSA-OAEP-11. Default is mgf1sha256.
extraConfig object
A map of key/value pairs to add extra configuration attributes to this client. Use this attribute at your own risk, as s may conflict with top-level configuration attributes in future provider updates.
forceNameIdFormat boolean
Ignore requested NameID subject format and use the one defined in name_id_format instead. Defaults to false.
forcePostBinding boolean
When true, Keycloak will always respond to an authentication request via the SAML POST Binding. Defaults to true.
frontChannelLogout boolean
When true, this client will require a browser redirect in order to perform a logout. Defaults to true.
fullScopeAllowed boolean
- Allow to include all roles mappings in the access token
id string
idpInitiatedSsoRelayState string
Relay state you want to send with SAML request when you want to do IDP Initiated SSO.
idpInitiatedSsoUrlName string
URL fragment name to reference client when you want to do IDP Initiated SSO.
includeAuthnStatement boolean
When true, an AuthnStatement will be included in the SAML response. Defaults to true.
loginTheme string
The login theme of this client.
logoutServicePostBindingUrl string
SAML POST Binding URL for the client's single logout service.
logoutServiceRedirectBindingUrl string
SAML Redirect Binding URL for the client's single logout service.
masterSamlProcessingUrl string
When specified, this URL will be used for all SAML requests.
name string
The display name of this client in the GUI.
nameIdFormat string
Sets the Name ID format for the subject.
realmId string
The realm this client is attached to.
rootUrl string
When specified, this value is prepended to all relative URLs.
signAssertions boolean
When true, the SAML assertions will be signed by Keycloak using the realm's private key, and embedded within the SAML XML Auth response. Defaults to false.
signDocuments boolean
When true, the SAML document will be signed by Keycloak using the realm's private key. Defaults to true.
signatureAlgorithm string
The signature algorithm used to sign documents. Should be one of "RSA_SHA1", "RSA_SHA256", "RSA_SHA256_MGF1, "RSA_SHA512", "RSA_SHA512_MGF1" or "DSA_SHA1".
signatureKeyName string
The value of the KeyName element within the signed SAML document. Should be one of "NONE", "KEY_ID", or "CERT_SUBJECT". Defaults to "KEY_ID".
signingCertificateSha1 string
(Computed) The sha1sum fingerprint of the signing certificate. If the signing certificate is not in correct base64 format, this will be left empty.
signingPrivateKeySha1 string
(Computed) The sha1sum fingerprint of the signing private key. If the signing private key is not in correct base64 format, this will be left empty.
validRedirectUris []string
When specified, Keycloak will use this list to validate given Assertion Consumer URLs specified in the authentication request.
conditions []object
Conditions of the resource.
lastTransitionTime string required
LastTransitionTime is the last time this condition transitioned from one status to another.
format: date-time
message string
A Message containing details about this condition's last transition from one status to another, if any.
observedGeneration integer
ObservedGeneration represents the .metadata.generation that the condition was set based upon. For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date with respect to the current state of the instance.
format: int64
reason string required
A Reason for this condition's last transition from one status to another.
status string required
Status of this condition; is it currently True, False, or Unknown?
type string required
Type of this condition. At most one of each condition type may apply to a resource at any point in time.
observedGeneration integer
ObservedGeneration is the latest metadata.generation which resulted in either a ready state, or stalled due to error it can not recover from without human intervention.
format: int64

No matches. Try .spec.deletionPolicy for an exact path