Keycloak Identity Provider
Resumo
- This module creates, removes or update Keycloak identity provider.
Parâmetros
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
alias - required | string | | The alias of the identity provider. |
addReadTokenRoleOnCreate | boolean | Escolhas: - false (default) - true | add Read Token Role On Create. |
authenticateByDefault | boolean | Escolhas: - false (default) - true | authenticate By Default. |
config (Possíveis valores) | dictionary | | Detailed configuration of the identity provider. |
displayName | string | | The display name of the realm. |
enabled | boolean | Escolhas: - false - true (default) | enabled. |
firstBrokerLoginFlowAlias | string | | first Broker Login Flow Alias. |
force | boolean | Escolhas: - false (default) - true | If true, allows to remove realm and recreate it. |
linkOnly | boolean | Escolhas: - false (default) - true | Link only option for identity provider |
mappers (Possíveis valores) | list | | List of mappers for the Identity provider. |
providerId | string | | Type of identity provider. |
postBrokerLoginFlowAlias | string | | post Broker Login Flow Alias. |
realm | string | - master (default) | The name of the realm in which is the identity provider. |
state | string | Escolhas: - present (default) - absent | Control if the realm exists. |
storeToken | boolean | Escolhas: - false - true (default) | store Token. |
trustEmail | boolean | Escolhas: - false (default) - true | trust Email. |
updateProfileFirstLoginMode | string | | update Profile First Login Mode. |
Subcampos da opção config
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
openIdConfigurationUrl | string | | Open ID configuration URL of the IdP to configure. Will be used to configure IdP endpoints. |
clientId | string | | Client ID used to authenticate Keycloak on this IdP |
clientSecret | string | | Client secret to authenticate client on the IdP. |
disableUserInfo | string | Escolhas: - false (default) - true | Do we need to disable user info endpoint query. Default value is False. - Must be set to true when IdP is Microsoft ADFS. |
defaultScope | string | | Default scope supported with this IdP |
guiOrder | integer | | Order to display the IdP button on login screen. Lower's first. |
backchannelSupported: description: - Is back channel logout is supported by the IdP. type: str choices: - 'true' - 'false' default: 'true' | | | |
Subcampos da opção mappers
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
name: description: - Name of the mapper type: str | | | |
identityProviderMapper: description: - Type of identity provider mapper. type: str choices: - oidc-user-attribute-idp-mapper - oidc-role-idp-mapper | | | |
config: description: - Configuration for this mapper. type: dict | | | |
Subcampos da opção config
Parâmetro | Tipo | Escolhas | Valor Padrão | Comentários |
|---|---|---|---|
claim: description: - Name of the claim to map. type: str | | | |
user.attribute: description: - This option is for oidc-user-attribute-idp-mapper - User attribute to copy the claim value to. type: str | | | |
claim.value: description: - This option is for oidc-role-idp-mapper - Role will be granted to the user only if the claim match this value. type: str | | | |
role: description: - This option is for oidc-role-idp-mapper - Role to be granted to the user if the claim match claim.value. type: str | | | |
Exemplos
# Exemplo: Create IdP1 fully configured with idp user attribute mapper and a role mapper
- keycloak_identity_provider:
auth_keycloak_url: http://localhost:8080/auth
auth_username: admin
auth_password: password
auth_realm: master
realm: "master"
alias: "IdP1"
displayName: "My super dooper IdP"
providerId: "oidc"
config:
openIdConfigurationUrl: https://my.idp.com/auth
clientId: ClientIdMyIdpGaveMe
clientSecret: ClientSecretMyIdpGaveMe
disableUserInfo: False
defaultScope: "openid email profile"
guiOrder: 1
backchannelSupported: True
mappers:
- name: ClaimMapper
identityProviderMapper: oidc-user-attribute-idp-mapper
config:
claim: claim1
user.attribute: attr1
state: present
- name: MyRoleMapper
identityProviderMapper: oidc-role-idp-mapper
config:
claim: claimName
claim.value: valueThatGiveRole
role: roleName
state: absent
state: present
# Exemplo: Re-create the Idp1 without mappers. The existing Idp will be deleted.
- keycloak_identity_provider:
auth_keycloak_url: http://localhost:8080/auth
auth_username: admin
auth_password: password
auth_realm: master
realm: "master"
alias: "IdP1"
displayName: "My super dooper IdP"
providerId: "oidc"
config:
openIdConfigurationUrl: https://my.idp.com/auth
clientId: ClientIdMyIdpGaveMe
clientSecret: ClientSecretMyIdpGaveMe
disableUserInfo: False
defaultScope: "openid email profile"
guiOrder: 2
backchannelSupported: True
state: present
force: yes
# Exemplo: Remove a the Idp IdP1.
- keycloak_identity_provider:
auth_keycloak_url: http://localhost:8080/auth
auth_username: admin
auth_password: password
auth_realm: master
realm: "master"
alias: IdP1
state: absent
Valores retornados
Chave | Tipo | Retornado quando | Descrição |
|---|---|---|---|
idp | dictionary | Sucesso | JSON representation for the identity provider. |
mappers | list | Sucesso | List of idp's mappers |
msg | string | Error | Error message if it is the case |
changed | boolean | Sucesso | Return True if the operation changed the identity provider on the keycloak server, false otherwise. |