134 lines
4.8 KiB
YAML
134 lines
4.8 KiB
YAML
---
|
|
# Настройка Keycloak
|
|
- name: Keycloak prepare clients
|
|
block:
|
|
- name: Create or update Keycloak client - grafana_oidc
|
|
community.general.keycloak_client:
|
|
auth_keycloak_url: "https://{{ iam_fqdn }}"
|
|
auth_realm: master
|
|
auth_username: "{{ iam_admin_username }}"
|
|
auth_password: "{{ iam_admin_pass }}"
|
|
state: present
|
|
validate_certs: false
|
|
realm: "{{ iam_realm }}"
|
|
client_id: grafana_oidc
|
|
name: client_grafana_oidc
|
|
enabled: true
|
|
root_url: "https://{{ mon_fqdn }}"
|
|
admin_url: "https://{{ mon_fqdn }}"
|
|
redirect_uris:
|
|
- "https://{{ mon_fqdn }}/login/generic_oauth"
|
|
web_origins:
|
|
- "https://{{ mon_fqdn }}"
|
|
client_authenticator_type: client-secret
|
|
secret: "{{ grafana_client_secret }}"
|
|
standard_flow_enabled: true
|
|
direct_access_grants_enabled: true
|
|
protocol: openid-connect
|
|
public_client: false
|
|
# delegate_to: localhost
|
|
|
|
- name: Create or update Keycloak client - gem-event-client
|
|
community.general.keycloak_client:
|
|
auth_keycloak_url: "https://{{ iam_fqdn }}"
|
|
auth_realm: master
|
|
auth_username: "{{ iam_admin_username }}"
|
|
auth_password: "{{ iam_admin_pass }}"
|
|
state: present
|
|
validate_certs: false
|
|
realm: "{{ iam_realm }}"
|
|
client_id: "{{ user_app_client_id }}"
|
|
enabled: true
|
|
name: client_user_app
|
|
bearer_only: false
|
|
redirect_uris:
|
|
- /*
|
|
web_origins:
|
|
- /*
|
|
client_authenticator_type: client-secret
|
|
secret: "{{ user_app_client_secret }}"
|
|
standard_flow_enabled: true
|
|
direct_access_grants_enabled: false
|
|
service_accounts_enabled: true
|
|
protocol: openid-connect
|
|
public_client: false
|
|
# delegate_to: localhost
|
|
when: user_event_publisher.enable == "yes"
|
|
|
|
- name: Create or update Keycloak client - gem-auth-client (cowork)
|
|
community.general.keycloak_client:
|
|
auth_keycloak_url: "https://{{ iam_fqdn }}"
|
|
auth_realm: master
|
|
auth_username: "{{ iam_admin_username }}"
|
|
auth_password: "{{ iam_admin_pass }}"
|
|
state: present
|
|
validate_certs: false
|
|
realm: "{{ iam_realm }}"
|
|
client_id: gem-auth-client
|
|
enabled: true
|
|
name: client_gem-auth-client
|
|
bearer_only: false
|
|
redirect_uris:
|
|
- /*
|
|
- https://web.co-work.ru/*
|
|
- cowork://oauth2redirect
|
|
- app://links.cowork.ru/oauth2redirect
|
|
- "{{ admin_app_url }}/*"
|
|
web_origins:
|
|
- +
|
|
client_authenticator_type: client-secret
|
|
secret: "{{ gem_auth_client_secret }}"
|
|
standard_flow_enabled: true
|
|
direct_access_grants_enabled: true
|
|
protocol: openid-connect
|
|
public_client: false
|
|
# delegate_to: localhost
|
|
when: instance_app == "cowork"
|
|
|
|
- name: Create or update Keycloak client - gem-auth-client (gemteam)
|
|
community.general.keycloak_client:
|
|
auth_keycloak_url: "https://{{ iam_fqdn }}"
|
|
auth_realm: master
|
|
auth_username: "{{ iam_admin_username }}"
|
|
auth_password: "{{ iam_admin_pass }}"
|
|
state: present
|
|
validate_certs: false
|
|
realm: "{{ iam_realm }}"
|
|
client_id: gem-auth-client
|
|
enabled: true
|
|
name: client_gem-auth-client
|
|
bearer_only: false
|
|
redirect_uris:
|
|
- /*
|
|
- https://demo-web.gem.team/*
|
|
- gemteam://oauth2redirect
|
|
- app://links.gem.team/oauth2redirect
|
|
- https://web.gem.team/*
|
|
- "{{ admin_app_url }}/*"
|
|
web_origins:
|
|
- +
|
|
client_authenticator_type: client-secret
|
|
secret: "{{ gem_auth_client_secret }}"
|
|
standard_flow_enabled: true
|
|
direct_access_grants_enabled: true
|
|
protocol: openid-connect
|
|
public_client: false
|
|
# delegate_to: localhost
|
|
when: instance_app == "gemteam"
|
|
|
|
- name: Set default and optional client scopes on gem-auth-client
|
|
community.general.keycloak_clientscope_type:
|
|
auth_keycloak_url: "https://{{ iam_fqdn }}"
|
|
auth_realm: master
|
|
auth_username: "{{ iam_admin_username }}"
|
|
auth_password: "{{ iam_admin_pass }}"
|
|
realm: "{{ iam_realm }}"
|
|
validate_certs: false
|
|
client_id: "gem-auth-client"
|
|
default_clientscopes: ['acr', 'basic', 'email', 'profile', 'roles', 'user_id', 'web-origins']
|
|
optional_clientscopes: ['address', 'microprofile-jwt', 'offline_access', 'organization', 'phone']
|
|
# register: iam_scope
|
|
|
|
# - name: Debug iam_scope
|
|
# debug:
|
|
# msg: "{{ iam_scope }}" |