keycloak-attribute-endpoint.../testing/README.md
stb 93dc7ddc75
Some checks failed
/ Verify (push) Has been cancelled
Add a Docker Compose setup with debugging and testing realm (#27)
Configure Keycloak to allow attaching a debugger (localhost:8081).

Add a testing realm with suitable example entries, and explain how to update and export the realm.

Reviewed-on: #27
2026-07-18 14:16:14 +02:00

56 lines
2.3 KiB
Markdown

# Creating a Testing Keycloak
The Docker Compose setup in this directory sets up Keycloak and imports a realm `testing`.
## Starting Keycloak
Run `docker compose up -d` to start Keycloak. The admin console will be available at http://localhost:8080/.
You can attach a Java debugger at `localhost:8081`.
The realm export is in `import/testing.json`.
It will be imported automatically when Keycloak starts.
## Updating the Realm
If you want to make changes to the testing realm and persist them, you need to export the realm.
The following command runs the Keycloak export for the realm `testing` storing it in the mapped directory `import/testing.json`.
The copying of the database is necessary to avoid locking errors.
`env -i` makes sure the regular environment variables are not set to avoid port conflicts.
```sh
docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env -i -- /opt/keycloak/bin/kc.sh export --db dev-file --db-url 'jdbc:h2:file:/tmp/h2/keycloakdb;NON_KEYWORDS=VALUE' --file /opt/keycloak/data/import/testing.json --realm testing"
```
## Testing Realm Configuration
The realm contains these objects:
* Clients:
* `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and role `export-dooris-ssh-keys`
* `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses`
* Realm Roles:
* `dooris-authorized`
* `mailing-list-chaos-member`
* `mailing-list-intern-member`
* `export-dooris-ssh-keys`
* `export-mailing-list-addresses`
* Groups:
* `chaos` with role `mailing-list-chaos-member`
* `ìntern` with roles `dooris-authorized` and `mailing-list-intern-member`
* Users:
* `tester` (Tony Tester), email `tester@example.com`, member of group `chaos`
* Mailing List Addresses:
* Chaos: `tester+chaos@example.com`
* Intern: `tester+intern@example.com`
* Dooris SSH Keys:
* SSH Key 1: `tester-ssh-key-1`
* SSH Key 2: `tester-ssh-key-2`
* `hacker` (Hans Acker), email `hacker@example.net`, member of groups `chaos`and `intern`
* Mailing List Addresses:
* Chaos: `hacker+chaos@example.net`
* Intern: `hacker+intern@example.net`
* Dooris SSH Keys:
* SSH Key 1: `hacker-ssh-key-1`
* SSH Key 2: `hacker-ssh-key-2`