Skip to main content

Identity Domain

The Identity domain manages identity and access management for the Control Plane through Keycloak integration. It provisions identity providers, realms, and service-account clients in a declarative, Kubernetes-native way.

Custom Resources

Client

Client is the Schema for the clients API

Group: identity.cp.ei.telekom.de · Version: v1 · Scope: Namespaced

ClientSpec

Appears in: Client

ClientSpec defines the desired state of Client

FieldTypeDefaultValidation
clientIdstringRequired
clientSecretstringRequired
realmObjectRefRequired

ObjectRef

Appears in: ClientSpec, RealmSpec

ObjectRef is a reference to a Kubernetes object It is similar to types.NamespacedName but has the required json tags for serialization

FieldTypeDefaultValidation
namestringRequired
namespacestringRequired
uidstringOptional

ClientStatus

Appears in: Client

ClientStatus defines the observed state of Client

FieldTypeDefaultValidation
conditionsCondition[]Optional
issuerUrlstringRequired

Condition

Appears in: ClientStatus, IdentityProviderStatus, RealmStatus

FieldTypeDefaultValidation
lastTransitionTimestringRequired, Format: date-time
messagestringRequired, maxLength: 32768
observedGenerationintegerOptional, Format: int64, minimum: 0
reasonstringRequired, minLength: 1, maxLength: 1024, pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$
statusstringRequired, Enum: True \| False \| Unknown
typestringRequired, maxLength: 316, pattern: ^([a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*/)?(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])$

IdentityProvider

IdentityProvider is the Schema for the identityproviders API

Group: identity.cp.ei.telekom.de · Version: v1 · Scope: Namespaced

IdentityProviderSpec

Appears in: IdentityProvider

IdentityProviderSpec defines the desired state of IdentityProvider

FieldTypeDefaultValidation
adminClientIdstringRequired
adminPasswordstringRequired
adminUrlstringRequired
adminUserNamestringRequired

IdentityProviderStatus

Appears in: IdentityProvider

IdentityProviderStatus defines the observed state of IdentityProvider

FieldTypeDefaultValidation
adminConsoleUrlstringOptional
adminTokenUrlstringRequired
adminUrlstringRequired
conditionsCondition[]Optional

Realm

Realm is the Schema for the realms API

Group: identity.cp.ei.telekom.de · Version: v1 · Scope: Namespaced

RealmSpec

Appears in: Realm

RealmSpec defines the desired state of Realm

FieldTypeDefaultValidation
identityProviderObjectRefRequired

RealmStatus

Appears in: Realm

RealmStatus defines the observed state of Realm

FieldTypeDefaultValidation
adminClientIdstringRequired
adminPasswordstringRequired
adminTokenUrlstringRequired
adminUrlstringRequired
adminUserNamestringRequired
conditionsCondition[]Optional
issuerUrlstringRequired

Domain Interactions

  • Admin domain — Zones define which identity provider to use.
  • Organization domain — Team creation provisions identity clients.
  • Application domain — Application creation provisions identity clients.
  • Event domain — EventConfig provisioning creates identity clients for OAuth2 token exchange.
  • Secret Manager — Resolves secret references before provisioning clients in Keycloak.