users.keycloak

Users configuration

This file allows to define the static users.

Removing an user here will not remove it on Keycloak. This is a limitation because some user might be imported by an user federation or identity provider.

The validation of the user can not be done entirely during the aggregation. The module might detect errors due to conflict between email, username, … If this is the case, it will start with the state RUNNING_WITH_ERROR.

It is possible to use substitution ↗️ to hide the value on the configuration.

type

object

properties

  • isTemplateGeneratedByOspComposer

Name of the playbook that generated this file. If present, the file is managed by the Composer and may be overwritten on regeneration. Used for selective clean. Do not edit or set manually.

type

string

  • templateId

The id of the template to use for this file

type

string

  • templateVariables

The variables and their values to be replaced from the template

type

object

additionalProperties

  • users

The configuration for Keycloak users

type

array

items

User

  • variablesFiles

The variables files to use to replace the variables. The first file of the list will take precedence over the following one. Template variables take precedence over the contents of the files.

type

array

items

type

string

additionalProperties

False

User

type

object

properties

  • attributes

The attribute of the user

Default value is [{“authorizedKeys”:[]}]

default

authorizedKeys

Attributes

  • credentials

The credential for the user.

type

array

items

Credential

  • email

The email of the user.

type

string

pattern

^.+@.+$

  • enabled

Flag to activate the user.

type

boolean

  • firstName

The first name of the user.

type

string

  • groups

The group membership of the user. This must be the full path of the groups

type

array

items

type

string

  • lastName

The last name of the user.

type

string

  • username

The username of the user.

type

string

additionalProperties

False

Attributes

type

object

properties

  • apiKey

The api-key associated to the user.

type

string

  • authorizedKeys

The list of the authorized public key.

type

array

items

type

string

  • defaultDashboard

The id of the default dashboard for the user.

type

string

  • defaultViewport

The default viewport (none, fullscreen) for the user.

type

string

enum

none, fullscreen

  • phoneNumber

The phone number for the user.

type

string

additionalProperties

False

Credential

type

object

properties

  • initial

Indicate that the credential must only be set if none already exist. If set to ‘false’ every Keycloak restart or configuration update will reset the password to this value.

Default value is [true]

type

boolean

default

True

  • temporary

Flag to indicate if the credential must be changed at first login.

type

boolean

  • type

The type of the credential.

type

string

enum

password

  • value

The value for the credential.

type

string

additionalProperties

False