-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcompose.yaml
More file actions
73 lines (68 loc) · 2.23 KB
/
compose.yaml
File metadata and controls
73 lines (68 loc) · 2.23 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
services:
app:
container_name: app
build:
context: .
dockerfile: Dockerfile
environment:
SERVER_PORT: 8083
SPRING_PROFILES_ACTIVE: "OIDC"
AUTH_CLIENT_ID: oidc-client
AUTH_CLIENT_SECRET: pvRQkTKcE2zZw9vxT30oXC1Zynq2b3yw
AUTH_SCOPE: openid, profile, email
AUTH_GRANT_TYPE: authorization_code
AUTH_REDIRECT_URI: "{baseUrl}/login/oauth2/code/{registrationId}"
AUTH_ISSUER_URI: http://localhost:8080/realms/redirect-login-example
ports:
- "8083:8083"
depends_on:
keycloak:
condition: service_healthy
networks:
- spring_keycloak
keycloak:
container_name: keycloak
build:
context: .
dockerfile: Dockerfile.keycloak
ports:
- "8080:8080"
environment:
KC_DB: postgres
KC_DB_URL: jdbc:postgresql://keycloak-database:5432/oidc_auth_db
KC_DB_USERNAME: postgres
KC_DB_PASSWORD: password
KC_HTTP_ENABLED: "true"
KC_HTTP_PORT: "8080"
KC_HOSTNAME: localhost
KC_HEALTH_ENABLED: "true"
KC_METRICS_ENABLED: "true"
KEYCLOAK_ADMIN: admin #⚠️ DO NOT USE IN PRODUCTION
KEYCLOAK_ADMIN_PASSWORD: admin #⚠️ DO NOT USE IN PRODUCTION
KC_HTTPS_CERTIFICATE_FILE: /opt/keycloak/certs/tls.crt
KC_HTTPS_CERTIFICATE_KEY_FILE: /opt/keycloak/certs/tls.key
volumes:
- ./docker/keycloak/certs:/opt/keycloak/certs
depends_on:
- keycloak-database
healthcheck:
test: ["CMD-SHELL", "exec 3<>/dev/tcp/127.0.0.1/9000;echo -e 'GET /health/ready HTTP/1.1\r\nhost: http://localhost\r\nConnection: close\r\n\r\n' >&3;if [ $? -eq 0 ]; then echo 'Healthcheck Successful';exit 0;else echo 'Healthcheck Failed';exit 1;fi;"]
interval: 5s
timeout: 10s
retries: 10
networks:
- spring_keycloak
keycloak-database:
image: postgres:18.2-alpine3.22
container_name: keycloak-database
environment:
POSTGRES_USER: postgres #⚠️ DO NOT USE IN PRODUCTION
POSTGRES_PASSWORD: password #⚠️ DO NOT USE IN PRODUCTION
ports:
- "5432:5432"
volumes:
- ./docker/keycloak/backups/oidc_auth_db_backup.sql:/docker-entrypoint-initdb.d/init.sql
networks:
- spring_keycloak
networks:
spring_keycloak: