cw-deploy/cw_docker_deploy/roles/iam_prep/tasks/clients.yml
2026-04-14 18:45:11 +03:00

134 lines
4.8 KiB
YAML

---
# Настройка Keycloak
- name: Keycloak prepare clients
block:
- name: Create or update Keycloak client - grafana_oidc
community.general.keycloak_client:
auth_keycloak_url: "https://{{ iam_fqdn }}"
auth_realm: master
auth_username: "{{ iam_admin_username }}"
auth_password: "{{ iam_admin_pass }}"
state: present
validate_certs: false
realm: "{{ iam_realm }}"
client_id: grafana_oidc
name: client_grafana_oidc
enabled: true
root_url: "https://{{ mon_fqdn }}"
admin_url: "https://{{ mon_fqdn }}"
redirect_uris:
- "https://{{ mon_fqdn }}/login/generic_oauth"
web_origins:
- "https://{{ mon_fqdn }}"
client_authenticator_type: client-secret
secret: "{{ grafana_client_secret }}"
standard_flow_enabled: true
direct_access_grants_enabled: true
protocol: openid-connect
public_client: false
# delegate_to: localhost
- name: Create or update Keycloak client - gem-event-client
community.general.keycloak_client:
auth_keycloak_url: "https://{{ iam_fqdn }}"
auth_realm: master
auth_username: "{{ iam_admin_username }}"
auth_password: "{{ iam_admin_pass }}"
state: present
validate_certs: false
realm: "{{ iam_realm }}"
client_id: "{{ user_app_client_id }}"
enabled: true
name: client_user_app
bearer_only: false
redirect_uris:
- /*
web_origins:
- /*
client_authenticator_type: client-secret
secret: "{{ user_app_client_secret }}"
standard_flow_enabled: true
direct_access_grants_enabled: false
service_accounts_enabled: true
protocol: openid-connect
public_client: false
# delegate_to: localhost
when: user_event_publisher.enable == "yes"
- name: Create or update Keycloak client - gem-auth-client (cowork)
community.general.keycloak_client:
auth_keycloak_url: "https://{{ iam_fqdn }}"
auth_realm: master
auth_username: "{{ iam_admin_username }}"
auth_password: "{{ iam_admin_pass }}"
state: present
validate_certs: false
realm: "{{ iam_realm }}"
client_id: gem-auth-client
enabled: true
name: client_gem-auth-client
bearer_only: false
redirect_uris:
- /*
- https://web.co-work.ru/*
- cowork://oauth2redirect
- app://links.cowork.ru/oauth2redirect
- "{{ admin_app_url }}/*"
web_origins:
- +
client_authenticator_type: client-secret
secret: "{{ gem_auth_client_secret }}"
standard_flow_enabled: true
direct_access_grants_enabled: true
protocol: openid-connect
public_client: false
# delegate_to: localhost
when: instance_app == "cowork"
- name: Create or update Keycloak client - gem-auth-client (gemteam)
community.general.keycloak_client:
auth_keycloak_url: "https://{{ iam_fqdn }}"
auth_realm: master
auth_username: "{{ iam_admin_username }}"
auth_password: "{{ iam_admin_pass }}"
state: present
validate_certs: false
realm: "{{ iam_realm }}"
client_id: gem-auth-client
enabled: true
name: client_gem-auth-client
bearer_only: false
redirect_uris:
- /*
- https://demo-web.gem.team/*
- gemteam://oauth2redirect
- app://links.gem.team/oauth2redirect
- https://web.gem.team/*
- "{{ admin_app_url }}/*"
web_origins:
- +
client_authenticator_type: client-secret
secret: "{{ gem_auth_client_secret }}"
standard_flow_enabled: true
direct_access_grants_enabled: true
protocol: openid-connect
public_client: false
# delegate_to: localhost
when: instance_app == "gemteam"
- name: Set default and optional client scopes on gem-auth-client
community.general.keycloak_clientscope_type:
auth_keycloak_url: "https://{{ iam_fqdn }}"
auth_realm: master
auth_username: "{{ iam_admin_username }}"
auth_password: "{{ iam_admin_pass }}"
realm: "{{ iam_realm }}"
validate_certs: false
client_id: "gem-auth-client"
default_clientscopes: ['acr', 'basic', 'email', 'profile', 'roles', 'user_id', 'web-origins']
optional_clientscopes: ['address', 'microprofile-jwt', 'offline_access', 'organization', 'phone']
# register: iam_scope
# - name: Debug iam_scope
# debug:
# msg: "{{ iam_scope }}"