PageSourceSearch

https://docs.mia-platform.eu/assets/js/ecdd20d3.911416a0.js

js mia-platform.eu collected 2026-10-02 06:06:42 UTC 23,808 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkmia_platform_docs=self.webpackChunkmia_platform_docs||[]).push([["14539"],{507733(e,n,t){t.r(n),t.d(n,{metadata:()=>s,default:()=>h,frontMatter:()=>l,contentTitle:()=>a,toc:()=>d,assets:()=>c});var s=JSON.parse('{"id":"requirements/installation-guidelines/shared-services/authn/federation-strategies/customer-keycloak-cli","title":"Customer Keycloak via CLI","description":"When to use this guide: the customer already operates a Keycloak instance with full admin access and wants Mia Platform realms provisioned within it. Mia Platform does not deploy a Keycloak instance in this scenario. The keycloak-realm-management chart is used as a CLI tool to import and incrementally update the mia-platform and mia-platform-extensibility realms on the customer\'s Keycloak.","source":"@site/versioned_docs/version-15.1.0/requirements/installation-guidelines/shared-services/authn/federation-strategies/customer-keycloak-cli.md","sourceDirName":"requirements/installation-guidelines/shared-services/authn/federation-strategies","slug":"/requirements/installation-guidelines/shared-services/authn/federation-strategies/customer-keycloak-cli","permalink":"/docs/requirements/installation-guidelines/shared-services/authn/federation-strategies/customer-keycloak-cli","draft":false,"unlisted":false,"tags":[],"version":"15.1.0","sidebarPosition":2,"frontMatter":{"id":"customer-keycloak-cli","title":"Customer Keycloak via CLI","sidebar_label":"Customer Keycloak via CLI","sidebar_position":2},"sidebar":"governance","previous":{"title":"Managed Keycloak","permalink":"/docs/requirements/installation-guidelines/shared-services/authn/federation-strategies/managed-keycloak"},"next":{"title":"Restricted Customer IdP","permalink":"/docs/requirements/installation-guidelines/shared-services/authn/federation-strategies/managed-keycloak-restricted-idp"}}'),i=t(474848),r=t(28453);let l={id:"customer-keycloak-cli",title:"Customer Keycloak via CLI",sidebar_label:"Customer Keycloak via CLI",sidebar_position:2},a="Customer Keycloak via CLI",c={},d=[{value:"Prerequisites",id:"prerequisites",level:2},{value:"Phase 1: Initial setup on the customer&#39;s Keycloak",id:"phase-1-initial-setup-on-the-customers-keycloak",level:2},{value:"Step 1.1: Create the <code>keycloak-config-cli</code> service account",id:"step-11-create-the-keycloak-config-cli-service-account",level:3},{value:"Step 1.2: Verify connectivity",id:"step-12-verify-connectivity",level:3},{value:"Phase 2: Values file configuration",id:"phase-2-values-file-configuration",level:2},{value:"Step 2.1: Install chart dependencies",id:"step-21-install-chart-dependencies",level:3},{value:"Step 2.2: Create a values file for each realm",id:"step-22-create-a-values-file-for-each-realm",level:3},{value:"Phase 3: Initial realm import",id:"phase-3-initial-realm-import",level:2},{value:"Step 3.1: Render templates without applying (dry-run)",id:"step-31-render-templates-without-applying-dry-run",level:3},{value:"Step 3.2: Import the realms (bootstrap with admin credentials)",id:"step-32-import-the-realms-bootstrap-with-admin-credentials",level:3},{value:"Step 3.3: Verify",id:"step-33-verify",level:3},{value:"Phase 4: Incremental realm updates",id:"phase-4-incremental-realm-updates",level:2},{value:"Safe update workflow",id:"safe-update-workflow",level:3},{value:"Step 4.1: Update chart dependencies",id:"step-41-update-chart-dependencies",level:3},{value:"Step 4.2: Render and review (dry-run)",id:"step-42-render-and-review-dry-run",level:3},{value:"Step 4.3: Apply with the service account",id:"step-43-apply-with-the-service-account",level:3},{value:"Safety guarantees",id:"safety-guarantees",level:3},{value:"Environment variables reference",id:"environment-variables-reference",level:2},{value:"Next steps",id:"next-steps",level:2}];function o(e){let n={a:"a",admonition:"admonition",blockquote:"blockquote",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",hr:"hr",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,r.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(n.header,{children:(0,i.jsx)(n.h1,{id:"customer-keycloak-via-cli",children:"Customer Keycloak via CLI"})}),"\n",(0,i.jsxs)(n.blockquote,{children:["\n",(0,i.jsxs)(n.p,{children:[(0,i.jsx)(n.strong,{children:"When to use this guide:"})," the customer already operates a Keycloak instance with full admin access and wants Mia Platform realms provisioned within it. Mia Platform ",(0,i.jsx)(n.strong,{children:"does not deploy a Keycloak instance"})," in this scenario. The ",(0,i.jsx)(n.code,{children:"keycloak-realm-management"})," chart is used as a CLI tool to import and incrementally update the ",(0,i.jsx)(n.code,{children:"mia-platform"})," and ",(0,i.jsx)(n.code,{children:"mia-platform-extensibility"})," realms on the customer's Keycloak."]}),"\n"]}),"\n",(0,i.jsxs)(n.p,{children:["For an overview of all available federation models see ",(0,i.jsx)(n.a,{href:"/docs/requirements/installation-guidelines/shared-services/authn/federation-strategies/",children:"Federation Strategies"}),"."]}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"prerequisites",children:"Prerequisites"}),"\n",(0,i.jsxs)(n.table,{children:[(0,i.jsx)(n.thead,{children:(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.th,{children:"Requirement"}),(0,i.jsx)(n.th,{children:"Notes"})]})}),(0,i.jsxs)(n.tbody,{children:[(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:"Customer's Keycloak"}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.strong,{children:"version \u2265 25.0"})})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:"Admin access to the customer's Keycloak"}),(0,i.jsx)(n.td,{children:"Required for the initial setup"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:"Helm v3"}),(0,i.jsx)(n.td,{children:"For rendering templates"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:"Docker"}),(0,i.jsxs)(n.td,{children:["For running ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})]})]})]})]}),"\n",(0,i.jsx)(n.admonition,{title:"Minimum Keycloak version",type:"warning",children:(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"keycloak-realm-management"})," chart uses Keycloak features available from version 25.0 (Organizations, extended OIDC attributes). Earlier versions are not supported. Verify the customer's Keycloak version before proceeding."]})}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"phase-1-initial-setup-on-the-customers-keycloak",children:"Phase 1: Initial setup on the customer's Keycloak"}),"\n",(0,i.jsxs)(n.h3,{id:"step-11-create-the-keycloak-config-cli-service-account",children:["Step 1.1: Create the ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})," service account"]}),"\n",(0,i.jsxs)(n.p,{children:["To allow subsequent imports to run without admin credentials, create a dedicated service client in the ",(0,i.jsx)(n.code,{children:"master"})," realm of the customer's Keycloak."]}),"\n",(0,i.jsx)(n.p,{children:"In the customer's Keycloak admin console:"}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["Navigate to the ",(0,i.jsx)(n.strong,{children:"master"})," realm \u2192 ",(0,i.jsx)(n.strong,{children:"Clients"})," \u2192 ",(0,i.jsx)(n.strong,{children:"Create client"}),"."]}),"\n",(0,i.jsxs)(n.li,{children:["Fill in the fields:","\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Client type"}),": OpenID Connect"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Client ID"}),": ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Client authentication"}),": enabled"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Authorization"}),": disabled"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Standard flow"}),": disabled"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Service accounts roles"}),": enabled"]}),"\n"]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["Save and open the ",(0,i.jsx)(n.strong,{children:"Service account roles"})," tab."]}),"\n",(0,i.jsxs)(n.li,{children:["Assign the ",(0,i.jsx)(n.code,{children:"realm-admin"})," role (client role from the ",(0,i.jsx)(n.code,{children:"realm-management"})," client) for the realms that ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})," will manage."]}),"\n"]}),"\n",(0,i.jsx)(n.admonition,{title:"Least-privilege alternative",type:"note",children:(0,i.jsxs)(n.p,{children:["Instead of ",(0,i.jsx)(n.code,{children:"realm-admin"}),", assign only the specific roles needed: ",(0,i.jsx)(n.code,{children:"manage-realm"}),", ",(0,i.jsx)(n.code,{children:"manage-clients"}),", ",(0,i.jsx)(n.code,{children:"manage-identity-providers"}),", ",(0,i.jsx)(n.code,{children:"manage-authorization"}),", ",(0,i.jsx)(n.code,{children:"manage-users"}),", ",(0,i.jsx)(n.code,{children:"manage-events"}),". This reduces the blast radius if the service account credentials are compromised."]})}),"\n",(0,i.jsxs)(n.ol,{start:"5",children:["\n",(0,i.jsxs)(n.li,{children:["In the ",(0,i.jsx)(n.strong,{children:"Credentials"})," tab, copy the ",(0,i.jsx)(n.strong,{children:"Client secret"}),": it will be used as ",(0,i.jsx)(n.code,{children:"KEYCLOAK_CLIENT_SECRET"}),"."]}),"\n"]}),"\n",(0,i.jsx)(n.h3,{id:"step-12-verify-connectivity",children:"Step 1.2: Verify connectivity"}),"\n",(0,i.jsx)(n.p,{children:"Confirm the service account can authenticate:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:'curl -s -X POST \\\n  https://keycloak.customer.example.com/realms/master/protocol/openid-connect/token \\\n  -d "grant_type=client_credentials" \\\n  -d "client_id=keycloak-config-cli" \\\n  -d "client_secret=<CLIENT_SECRET>" \\\n  | jq .access_token\n'})}),"\n",(0,i.jsx)(n.p,{children:"A JWT in the response confirms that connectivity and credentials are correct."}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"phase-2-values-file-configuration",children:"Phase 2: Values file configuration"}),"\n",(0,i.jsx)(n.h3,{id:"step-21-install-chart-dependencies",children:"Step 2.1: Install chart dependencies"}),"\n",(0,i.jsxs)(n.p,{children:["From the ",(0,i.jsx)(n.code,{children:"keycloak-realm-management"})," repository directory:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"make deps\n"})}),"\n",(0,i.jsx)(n.h3,{id:"step-22-create-a-values-file-for-each-realm",children:"Step 2.2: Create a values file for each realm"}),"\n",(0,i.jsxs)(n.p,{children:["The values file structure for the three realms (master, products, extensibility) follows the same template described 
1in the ",(0,i.jsx)(n.a,{href:"/docs/requirements/installation-guidelines/shared-services/authn/federation-strategies/managed-keycloak#step-22--create-a-values-file-for-each-realm",children:"Managed Keycloak guide"}),"."]}),"\n",(0,i.jsx)(n.p,{children:"The only differences for this scenario:"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:["Set ",(0,i.jsx)(n.code,{children:"urls.keycloak"})," to the customer's Keycloak base URL (e.g. ",(0,i.jsx)(n.code,{children:"https://keycloak.customer.example.com"}),")."]}),"\n",(0,i.jsxs)(n.li,{children:["In the extensibility realm's ",(0,i.jsx)(n.code,{children:"identityProviders"})," block, all endpoint URLs must reference the ",(0,i.jsx)(n.code,{children:"mia-platform"})," realm on the customer's Keycloak (e.g. ",(0,i.jsx)(n.code,{children:"https://keycloak.customer.example.com/realms/mia-platform/..."}),")."]}),"\n",(0,i.jsxs)(n.li,{children:["The ",(0,i.jsx)(n.code,{children:"themes.login"})," field can be left empty to use the customer Keycloak's default theme."]}),"\n"]}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"phase-3-initial-realm-import",children:"Phase 3: Initial realm import"}),"\n",(0,i.jsx)(n.h3,{id:"step-31-render-templates-without-applying-dry-run",children:"Step 3.1: Render templates without applying (dry-run)"}),"\n",(0,i.jsx)(n.p,{children:"Before making any changes to the customer's Keycloak, render the templates and review the YAML that will be imported. This step makes no changes."}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"# Render master realm \u2014 output in rendered/master/master/<values-name>/\nmake template-master VALUES=values/production/master-values.yaml\n\n# Render products realm \u2014 output in rendered/production/products/<values-name>/\nmake template-products ENV=production VALUES=values/production/products-values.yaml\n\n# Render extensibility realm\nmake template-extensibility ENV=production VALUES=values/production/extensibility-values.yaml\n"})}),"\n",(0,i.jsxs)(n.p,{children:["Review the files under ",(0,i.jsx)(n.code,{children:"rendered/"})," to confirm the generated configuration matches expectations before proceeding."]}),"\n",(0,i.jsx)(n.h3,{id:"step-32-import-the-realms-bootstrap-with-admin-credentials",children:"Step 3.2: Import the realms (bootstrap with admin credentials)"}),"\n",(0,i.jsxs)(n.p,{children:["For the first import use the customer's Keycloak admin credentials (",(0,i.jsx)(n.code,{children:"import-admin-*"}),"). Realms must be imported in this order: ",(0,i.jsx)(n.strong,{children:"master \u2192 products \u2192 extensibility"}),"."]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"# Master realm\nmake import-admin-master \\\n  KEYCLOAK_URL=https://keycloak.customer.example.com \\\n  KEYCLOAK_USER=<ADMIN_USER> \\\n  KEYCLOAK_PASSWORD=<ADMIN_PASSWORD> \\\n  VALUES=values/production/master-values.yaml\n\n# mia-platform realm\nmake import-admin-products \\\n  ENV=production \\\n  KEYCLOAK_URL=https://keycloak.customer.example.com \\\n  KEYCLOAK_USER=<ADMIN_USER> \\\n  KEYCLOAK_PASSWORD=<ADMIN_PASSWORD> \\\n  VALUES=values/production/products-values.yaml\n\n# mia-platform-extensibility realm\nmake import-admin-extensibility \\\n  ENV=production \\\n  KEYCLOAK_URL=https://keycloak.customer.example.com \\\n  KEYCLOAK_USER=<ADMIN_USER> \\\n  KEYCLOAK_PASSWORD=<ADMIN_PASSWORD> \\\n  VALUES=values/production/extensibility-values.yaml\n"})}),"\n",(0,i.jsx)(n.h3,{id:"step-33-verify",children:"Step 3.3: Verify"}),"\n",(0,i.jsx)(n.p,{children:"In the customer's Keycloak admin console:"}),"\n",(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["Confirm that the ",(0,i.jsx)(n.code,{children:"mia-platform"})," and ",(0,i.jsx)(n.code,{children:"mia-platform-extensibility"})," realms have been created."]}),"\n",(0,i.jsxs)(n.li,{children:["In the ",(0,i.jsx)(n.code,{children:"mia-platform"})," realm \u2192 ",(0,i.jsx)(n.strong,{children:"Clients"}),": confirm the product clients are present."]}),"\n",(0,i.jsxs)(n.li,{children:["In the ",(0,i.jsx)(n.code,{children:"mia-platform"})," realm \u2192 ",(0,i.jsx)(n.strong,{children:"Identity Providers"}),": confirm the federation entry is present."]}),"\n",(0,i.jsx)(n.li,{children:"Test the login flow by accessing one of the Mia Platform products."}),"\n"]}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"phase-4-incremental-realm-updates",children:"Phase 4: Incremental realm updates"}),"\n",(0,i.jsx)(n.p,{children:"After the initial bootstrap, subsequent updates (new Mia Platform releases, configuration changes) are applied via the service account created in Step 1.1, no admin credentials required."}),"\n",(0,i.jsx)(n.h3,{id:"safe-update-workflow",children:"Safe update workflow"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"1. Update chart dependencies   \u2192  make deps\n2. Ren
1der templates            \u2192  make template-<realm>   (dry-run \u2014 no changes applied)\n3. Review rendered/            \u2192  inspect or diff the generated YAML\n4. Apply                       \u2192  make import-<realm>\n"})}),"\n",(0,i.jsx)(n.h3,{id:"step-41-update-chart-dependencies",children:"Step 4.1: Update chart dependencies"}),"\n",(0,i.jsxs)(n.p,{children:["After receiving a new version of the ",(0,i.jsx)(n.code,{children:"keycloak-realm-management"})," chart:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"make deps\n"})}),"\n",(0,i.jsx)(n.h3,{id:"step-42-render-and-review-dry-run",children:"Step 4.2: Render and review (dry-run)"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"make template-products ENV=production VALUES=values/production/products-values.yaml\n"})}),"\n",(0,i.jsxs)(n.p,{children:["The files generated under ",(0,i.jsx)(n.code,{children:"rendered/production/products/<values-name>/"})," show exactly what will be sent to ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"}),". Compare them with the previous render to identify changes before applying."]}),"\n",(0,i.jsx)(n.h3,{id:"step-43-apply-with-the-service-account",children:"Step 4.3: Apply with the service account"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"# Update master realm\nmake import-master \\\n  KEYCLOAK_URL=https://keycloak.customer.example.com \\\n  LOGIN_REALM=master \\\n  KEYCLOAK_CLIENT_SECRET=<CLIENT_SECRET> \\\n  VALUES=values/production/master-values.yaml\n\n# Update mia-platform realm\nmake import-products \\\n  ENV=production \\\n  KEYCLOAK_URL=https://keycloak.customer.example.com \\\n  LOGIN_REALM=master \\\n  KEYCLOAK_CLIENT_SECRET=<CLIENT_SECRET> \\\n  VALUES=values/production/products-values.yaml\n\n# Update mia-platform-extensibility realm\nmake import-extensibility \\\n  ENV=production \\\n  KEYCLOAK_URL=https://keycloak.customer.example.com \\\n  LOGIN_REALM=master \\\n  KEYCLOAK_CLIENT_SECRET=<CLIENT_SECRET> \\\n  VALUES=values/production/extensibility-values.yaml\n"})}),"\n",(0,i.jsx)(n.h3,{id:"safety-guarantees",children:"Safety guarantees"}),"\n",(0,i.jsxs)(n.p,{children:["Each ",(0,i.jsx)(n.code,{children:"make import-*"})," run is safe to repeat at any time thanks to the following ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})," properties:"]}),"\n",(0,i.jsxs)(n.table,{children:[(0,i.jsx)(n.thead,{children:(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.th,{children:"Property"}),(0,i.jsx)(n.th,{children:"Effect"})]})}),(0,i.jsxs)(n.tbody,{children:[(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"IMPORT_REMOTESTATE_ENABLED=true"})}),(0,i.jsx)(n.td,{children:"Only resources declared in the import file are managed; everything else in the realm is left untouched"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"IMPORT_MANAGED_CLIENT=no-delete"})}),(0,i.jsxs)(n.td,{children:["Removing a client from the values file does ",(0,i.jsx)(n.strong,{children:"not"})," delete the client in Keycloak"]})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"IMPORT_MANAGED_IDENTITYPROVIDER=no-delete"})}),(0,i.jsx)(n.td,{children:"Same for identity providers"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"IMPORT_MANAGED_ROLE=no-delete"})}),(0,i.jsx)(n.td,{children:"Same for roles"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"IMPORT_MANAGED_GROUP=no-delete"})}),(0,i.jsx)(n.td,{children:"Same for groups"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:"Idempotency"}),(0,i.jsx)(n.td,{children:"Applying the same values file multiple times always produces the same result"})]})]})]}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"environment-variables-reference",children:"Environment variables reference"}),"\n",(0,i.jsxs)(n.table,{children:[(0,i.jsx)(n.thead,{children:(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.th,{children:"Variable"}),(0,i.jsx)(n.th,{children:"Default"}),(0,i.jsx)(n.th,{children:"Description"})]})}),(0,i.jsxs)(n.tbody,{children:[(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"KEYCLOAK_URL"})}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"http://localhost:8080"})}),(0,i.jsx)(n.td,{children:"Base URL of the customer's Keycloak"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"KEYCLOAK_USER"})}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"admin"})}),(0,i.jsxs)(n.td,{children:["Admin username (only for ",(0,i.jsx)(n.code,{children:"import-admin-*"}),")"]})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"KEYCLOAK_PASSWORD"})}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"admin"})}),(0,i.jsxs)(n.td,{children:["Admin password (only for ",(0,i.jsx)(n.code,{children:"import-admin-*"}),")"]})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"KEYCLOAK_CLIENT_SECRET"})}),(0,i.jsx)(n.td,{children:"-"}),(0,i.jsxs)(n.td,{children:["Service account client secret (for ",(0,i.jsx)(n.code,{children:"import-*"}),")"]})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"LOGIN_REALM"})}),(0,i.jsx)(n.td,{children:"-"}),(0,i.jsxs)(n.td,{children:["Realm where ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})," authenticates (typically ",(0,i.jsx)(n.code,{children:"master"}),")"]})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"ENV"})}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"dev"})}),(0,i.jsxs)(n.td,{children:["Environment name: used to organise rendered files under ",(0,i.jsx)(n.code,{children:"rendered/<ENV>/"})]})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"VALUES"})}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"values/<ENV>/<realm>-values.yaml"})}),(0,i.jsx)(n.td,{children:"Path to the values file"})]}),(0,i.jsxs)(n.tr,{children:[(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"KEYCLOAK_CONFIG_
1CLI_IMAGE"})}),(0,i.jsx)(n.td,{children:(0,i.jsx)(n.code,{children:"adorsys/keycloak-config-cli:latest-<version>"})}),(0,i.jsxs)(n.td,{children:[(0,i.jsx)(n.code,{children:"keycloak-config-cli"})," Docker image: update to match the customer's Keycloak version"]})]})]})]}),"\n",(0,i.jsx)(n.admonition,{title:"keycloak-config-cli version alignment",type:"note",children:(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"KEYCLOAK_CONFIG_CLI_IMAGE"})," variable in the ",(0,i.jsx)(n.code,{children:"Makefile"})," must match the customer's Keycloak version. A significantly mismatched ",(0,i.jsx)(n.code,{children:"keycloak-config-cli"})," version may silently drop or reject unsupported fields."]})}),"\n",(0,i.jsx)(n.hr,{}),"\n",(0,i.jsx)(n.h2,{id:"next-steps",children:"Next steps"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Configure Mia Platform products"})," to use the customer's Keycloak as the Authentication Provider \u2192 ",(0,i.jsx)(n.a,{href:"/docs/requirements/installation-guidelines/console/self-hosted/helm-values/authentication-provider",children:"Authentication Provider"})]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.strong,{children:"Future realm updates"})," \u2192 ",(0,i.jsx)(n.a,{href:"/docs/requirements/installation-guidelines/shared-services/authn/keycloak-realm-management/how-to-upgrade",children:"How To Upgrade: Keycloak Realm Management"})]}),"\n"]})]})}function h(e={}){let{wrapper:n}={...(0,r.R)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(o,{...e})}):o(e)}},28453(e,n,t){t.d(n,{R:()=>l,x:()=>a});var s=t(296540);let i={},r=s.createContext(i);function l(e){let n=s.useContext(r);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:l(e.components),s.createElement(r.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.