mirror of
https://github.com/ansible-middleware/keycloak.git
synced 2025-04-05 10:20:27 -07:00
refactor default test for keycloak-quarkus offline
This commit is contained in:
parent
eb66d4a412
commit
fc0ee5a896
3 changed files with 57 additions and 137 deletions
|
@ -2,61 +2,46 @@
|
||||||
- name: Converge
|
- name: Converge
|
||||||
hosts: all
|
hosts: all
|
||||||
vars:
|
vars:
|
||||||
|
keycloak_quarkus_show_deprecation_warnings: false
|
||||||
|
keycloak_quarkus_admin_pass: "remembertochangeme"
|
||||||
keycloak_admin_password: "remembertochangeme"
|
keycloak_admin_password: "remembertochangeme"
|
||||||
keycloak_jvm_package: java-11-openjdk-headless
|
keycloak_quarkus_host: instance
|
||||||
keycloak_modcluster_enabled: True
|
keycloak_quarkus_log: file
|
||||||
keycloak_modcluster_urls:
|
keycloak_quarkus_log_level: debug
|
||||||
- host: myhost1
|
keycloak_quarkus_log_target: /tmp/keycloak
|
||||||
port: 16667
|
keycloak_quarkus_start_dev: True
|
||||||
- host: myhost2
|
keycloak_quarkus_proxy_mode: none
|
||||||
port: 16668
|
keycloak_quarkus_offline_install: true
|
||||||
keycloak_jboss_port_offset: 10
|
keycloak_quarkus_download_path: /tmp/keycloak/
|
||||||
keycloak_log_target: /tmp/keycloak
|
|
||||||
roles:
|
roles:
|
||||||
- role: keycloak
|
- role: keycloak_quarkus
|
||||||
tasks:
|
- role: keycloak_realm
|
||||||
- name: Keycloak Realm Role
|
keycloak_context: ''
|
||||||
ansible.builtin.include_role:
|
keycloak_client_default_roles:
|
||||||
name: keycloak_realm
|
- TestRoleAdmin
|
||||||
vars:
|
- TestRoleUser
|
||||||
keycloak_client_default_roles:
|
keycloak_client_users:
|
||||||
- TestRoleAdmin
|
- username: TestUser
|
||||||
- TestRoleUser
|
password: password
|
||||||
keycloak_client_users:
|
client_roles:
|
||||||
- username: TestUser
|
- client: TestClient
|
||||||
password: password
|
role: TestRoleUser
|
||||||
client_roles:
|
realm: "{{ keycloak_realm }}"
|
||||||
- client: TestClient
|
- username: TestAdmin
|
||||||
role: TestRoleUser
|
password: password
|
||||||
realm: "{{ keycloak_realm }}"
|
client_roles:
|
||||||
- username: TestAdmin
|
- client: TestClient
|
||||||
password: password
|
role: TestRoleUser
|
||||||
client_roles:
|
realm: "{{ keycloak_realm }}"
|
||||||
- client: TestClient
|
- client: TestClient
|
||||||
role: TestRoleUser
|
role: TestRoleAdmin
|
||||||
realm: "{{ keycloak_realm }}"
|
realm: "{{ keycloak_realm }}"
|
||||||
- client: TestClient
|
keycloak_realm: TestRealm
|
||||||
role: TestRoleAdmin
|
keycloak_clients:
|
||||||
realm: "{{ keycloak_realm }}"
|
- name: TestClient
|
||||||
keycloak_realm: TestRealm
|
roles: "{{ keycloak_client_default_roles }}"
|
||||||
keycloak_clients:
|
realm: "{{ keycloak_realm }}"
|
||||||
- name: TestClient
|
public_client: "{{ keycloak_client_public }}"
|
||||||
roles: "{{ keycloak_client_default_roles }}"
|
web_origins: "{{ keycloak_client_web_origins }}"
|
||||||
realm: "{{ keycloak_realm }}"
|
users: "{{ keycloak_client_users }}"
|
||||||
public_client: "{{ keycloak_client_public }}"
|
client_id: TestClient
|
||||||
web_origins: "{{ keycloak_client_web_origins }}"
|
|
||||||
users: "{{ keycloak_client_users }}"
|
|
||||||
client_id: TestClient
|
|
||||||
attributes:
|
|
||||||
post.logout.redirect.uris: '/public/logout'
|
|
||||||
pre_tasks:
|
|
||||||
- name: "Retrieve assets server from env"
|
|
||||||
ansible.builtin.set_fact:
|
|
||||||
assets_server: "{{ lookup('env', 'MIDDLEWARE_DOWNLOAD_RELEASE_SERVER_URL') }}"
|
|
||||||
|
|
||||||
- name: "Set offline when assets server from env is defined"
|
|
||||||
ansible.builtin.set_fact:
|
|
||||||
sso_offline_install: True
|
|
||||||
when:
|
|
||||||
- assets_server is defined
|
|
||||||
- assets_server | length > 0
|
|
||||||
|
|
|
@ -12,18 +12,18 @@
|
||||||
- "{{ assets_server }}/sso/7.6.0/rh-sso-7.6.0-server-dist.zip"
|
- "{{ assets_server }}/sso/7.6.0/rh-sso-7.6.0-server-dist.zip"
|
||||||
- "{{ assets_server }}/sso/7.6.1/rh-sso-7.6.1-patch.zip"
|
- "{{ assets_server }}/sso/7.6.1/rh-sso-7.6.1-patch.zip"
|
||||||
|
|
||||||
- name: Install JDK8
|
- name: Create controller directory for downloads
|
||||||
become: yes
|
ansible.builtin.file: # noqa risky-file-permissions delegated, uses controller host user
|
||||||
ansible.builtin.yum:
|
path: /tmp/keycloak
|
||||||
name:
|
state: directory
|
||||||
- java-1.8.0-openjdk
|
mode: '0750'
|
||||||
state: present
|
delegate_to: localhost
|
||||||
when: ansible_facts['os_family'] == "RedHat"
|
run_once: true
|
||||||
|
|
||||||
- name: Install JDK8
|
- name: Download keycloak archive to controller directory
|
||||||
become: yes
|
ansible.builtin.get_url: # noqa risky-file-permissions delegated, uses controller host user
|
||||||
ansible.builtin.apt:
|
url: https://github.com/keycloak/keycloak/releases/download/24.0.4/keycloak-24.0.4.zip
|
||||||
name:
|
dest: /tmp/keycloak
|
||||||
- openjdk-8-jdk
|
mode: '0640'
|
||||||
state: present
|
delegate_to: localhost
|
||||||
when: ansible_facts['os_family'] == "Debian"
|
run_once: true
|
||||||
|
|
|
@ -3,10 +3,7 @@
|
||||||
hosts: all
|
hosts: all
|
||||||
vars:
|
vars:
|
||||||
keycloak_admin_password: "remembertochangeme"
|
keycloak_admin_password: "remembertochangeme"
|
||||||
keycloak_jvm_package: java-11-openjdk-headless
|
keycloak_uri: "http://localhost:8080"
|
||||||
keycloak_uri: "http://localhost:{{ 8080 + ( keycloak_jboss_port_offset | default(0) ) }}"
|
|
||||||
keycloak_management_port: "http://localhost:{{ 9990 + ( keycloak_jboss_port_offset | default(0) ) }}"
|
|
||||||
keycloak_jboss_port_offset: 10
|
|
||||||
tasks:
|
tasks:
|
||||||
- name: Populate service facts
|
- name: Populate service facts
|
||||||
ansible.builtin.service_facts:
|
ansible.builtin.service_facts:
|
||||||
|
@ -15,16 +12,9 @@
|
||||||
that:
|
that:
|
||||||
- ansible_facts.services["keycloak.service"]["state"] == "running"
|
- ansible_facts.services["keycloak.service"]["state"] == "running"
|
||||||
- ansible_facts.services["keycloak.service"]["status"] == "enabled"
|
- ansible_facts.services["keycloak.service"]["status"] == "enabled"
|
||||||
- name: Verify we are running on requested jvm # noqa blocked_modules command-instead-of-module
|
|
||||||
ansible.builtin.shell: |
|
|
||||||
set -o pipefail
|
|
||||||
ps -ef | grep '/etc/alternatives/jre_11/' | grep -v grep
|
|
||||||
args:
|
|
||||||
executable: /bin/bash
|
|
||||||
changed_when: no
|
|
||||||
- name: Verify token api call
|
- name: Verify token api call
|
||||||
ansible.builtin.uri:
|
ansible.builtin.uri:
|
||||||
url: "{{ keycloak_uri }}/auth/realms/master/protocol/openid-connect/token"
|
url: "{{ keycloak_uri }}/realms/master/protocol/openid-connect/token"
|
||||||
method: POST
|
method: POST
|
||||||
body: "client_id=admin-cli&username=admin&password={{ keycloak_admin_password }}&grant_type=password"
|
body: "client_id=admin-cli&username=admin&password={{ keycloak_admin_password }}&grant_type=password"
|
||||||
validate_certs: no
|
validate_certs: no
|
||||||
|
@ -32,58 +22,3 @@
|
||||||
until: keycloak_auth_response.status == 200
|
until: keycloak_auth_response.status == 200
|
||||||
retries: 2
|
retries: 2
|
||||||
delay: 2
|
delay: 2
|
||||||
- name: Fetch openid-connect config
|
|
||||||
ansible.builtin.uri:
|
|
||||||
url: "{{ keycloak_uri }}/auth/realms/TestRealm/.well-known/openid-configuration"
|
|
||||||
method: GET
|
|
||||||
validate_certs: no
|
|
||||||
status_code: 200
|
|
||||||
register: keycloak_openid_config
|
|
||||||
- name: Verify expected config
|
|
||||||
ansible.builtin.assert:
|
|
||||||
that:
|
|
||||||
- keycloak_openid_config.json.registration_endpoint == 'http://localhost:8080/auth/realms/TestRealm/clients-registrations/openid-connect'
|
|
||||||
- name: Get test realm clients
|
|
||||||
ansible.builtin.uri:
|
|
||||||
url: "{{ keycloak_uri }}/auth/admin/realms/TestRealm/clients"
|
|
||||||
method: GET
|
|
||||||
validate_certs: no
|
|
||||||
status_code: 200
|
|
||||||
headers:
|
|
||||||
Authorization: "Bearer {{ keycloak_auth_response.json.access_token }}"
|
|
||||||
register: keycloak_query_clients
|
|
||||||
- name: Verify expected config
|
|
||||||
ansible.builtin.assert:
|
|
||||||
that:
|
|
||||||
- (keycloak_query_clients.json | selectattr('clientId','equalto','TestClient') | first)["attributes"]["post.logout.redirect.uris"] == '/public/logout'
|
|
||||||
- name: "Privilege escalation as some files/folders may requires it"
|
|
||||||
become: yes
|
|
||||||
block:
|
|
||||||
- name: Check log folder
|
|
||||||
ansible.builtin.stat:
|
|
||||||
path: "/tmp/keycloak"
|
|
||||||
register: keycloak_log_folder
|
|
||||||
- name: Check that keycloak log folder exists and is a link
|
|
||||||
ansible.builtin.assert:
|
|
||||||
that:
|
|
||||||
- keycloak_log_folder.stat.exists
|
|
||||||
- not keycloak_log_folder.stat.isdir
|
|
||||||
- keycloak_log_folder.stat.islnk
|
|
||||||
- name: Check log file
|
|
||||||
ansible.builtin.stat:
|
|
||||||
path: "/tmp/keycloak/server.log"
|
|
||||||
register: keycloak_log_file
|
|
||||||
- name: Check if keycloak file exists
|
|
||||||
ansible.builtin.assert:
|
|
||||||
that:
|
|
||||||
- keycloak_log_file.stat.exists
|
|
||||||
- not keycloak_log_file.stat.isdir
|
|
||||||
- name: Check default log folder
|
|
||||||
ansible.builtin.stat:
|
|
||||||
path: "/var/log/keycloak"
|
|
||||||
register: keycloak_default_log_folder
|
|
||||||
failed_when: false
|
|
||||||
- name: Check that default keycloak log folder doesn't exist
|
|
||||||
ansible.builtin.assert:
|
|
||||||
that:
|
|
||||||
- not keycloak_default_log_folder.stat.exists
|
|
||||||
|
|
Loading…
Add table
Reference in a new issue