Skip to main content

Keycloak Role

Deploy Keycloak identity and access management as a Podman quadlet.


Variables​

VariableTypeOptionsDefaultDescription
podman_userstring---{{ ansible_user }}system user for rootless podman operations
keycloak_proxy_enabledbooltrue, falsefalseenable HTTP proxy for image pulls
keycloak_proxy_httpstring---""HTTP proxy URL
keycloak_proxy_httpsstring---""HTTPS proxy URL
keycloak_proxy_no_proxystring---""comma-separated list of proxy exclusions
keycloak_proxy_envlist of string---[]generated proxy environment entries
keycloak_network_enabledbooltrue, falsetruecreate and manage the podman network
keycloak_network_driverstring---bridgepodman network driver
keycloak_network_namestring---keycloak-internalpodman network name
keycloak_bind_ipstring---127.0.0.1host IP to bind exposed ports to
keycloak_port_map_enabledbooltrue, falsetrueexpose container ports on the host
keycloak_port_maplist of string---["8080:8080"]host:container port mappings
keycloak_versionstring---26.7.2container image version
keycloak_autoupdatebooltrue, falsetrueenable podman auto-update for this container
keycloak_domainstring---login.nixpi.deexternal domain for the Keycloak instance
keycloak_db_namestring---keycloakdatabase name
keycloak_db_hoststring---postgresql-podPostgreSQL container hostname
keycloak_db_userstring---keycloakdatabase user
keycloak_db_passwordstring---""database user password
keycloak_admin_passwordstring---""admin bootstrap password
keycloak_environment_varsdict---{}extra environment variables injected into the container
keycloak_extra_fileslist of dict---[]arbitrary file entries with src (controller path) or source (target path), dest, optional mount, mode, and template
keycloak_extra_dirslist of dict---[]arbitrary directory entries with src (controller directory) or source (target path), dest, optional mount and mode
keycloak_entrypointstring---""optional container entrypoint override