Manage Realms
A Realm is the primary isolation unit in Keycloak. Each Realm has independent users, clients, roles, and authentication configuration. Alauda Application Services Identity Management E1 supports managing Realms both through the Admin Console and declaratively via the KeycloakRealmImport CRD.
TOC
Import a Realm via CRDProcedureUsing Placeholders for SecretsManage Realm Settings via Admin ConsoleAccess Realm SettingsKey Realm SettingsConfigure Token LifespansImport a Realm via CRD
The KeycloakRealmImport CRD enables declarative Realm provisioning. When you create a KeycloakRealmImport resource, the Operator triggers a one-time import Job that loads the Realm configuration into the target Keycloak instance.
The KeycloakRealmImport performs a one-time import at creation, not continuous synchronization. Changes made via the Admin Console after import are not reflected back to the CR. For ongoing Realm configuration changes, use the Admin Console or Admin REST API.
Procedure
Create a KeycloakRealmImport resource:
Apply the manifest:
Check the import status:
When the output is True, the Realm has been imported successfully.
Using Placeholders for Secrets
The spec.placeholders field allows you to inject Secret values into the Realm configuration at import time, avoiding hardcoded credentials in the CR:
Manage Realm Settings via Admin Console
Access Realm Settings
- Log in to the Keycloak Admin Console.
- Select the target Realm from the top-left dropdown.
- Click Realm Settings in the left navigation bar.
Key Realm Settings
Configure Token Lifespans
Token lifespans control how long issued tokens remain valid. Shorter lifespans improve security but require more frequent token refresh operations.