weave
module · Identity & SSO

Keycloak

Keycloak — self-hosted OIDC realms, users, roles

Namespace: weave keycloak Env: KEYCLOAK_URL
3
Commands
1
State kinds
Identity & SSO
Category
1
API docs

Setup

Configure credentials via environment variables. We recommend sourcing them through 1Password or your secrets manager rather than committing them to the shell rc.

Official API reference

weave commands for this module are checked against the vendor's published API.

Variable Description Status
KEYCLOAK_URLRequired for authentication.required
KEYCLOAK_TOKENRequired for authentication.required

Sanity-check the wiring:

weave secrets check
weave keycloak --help
weave doctor   # reports KEYCLOAK_URL status

Capabilities

What this module can do, by entity and verb. means a working CLI surface; · means not (yet) wired.

Entity findlistshowdosnapshotdiffapply
realm······
user··

Commands

Every registered CLI command, grouped by verb. Each example uses placeholder arguments — substitute real values for your environment.

find (1)

find user

read

Find a user by email, username, or Keycloak user id.

weave keycloak find user <identifier>

list (2)

list realms

read

List all realms (admin root API).

weave keycloak list realms <arg>

list users

read

List users in the configured realm.

weave keycloak list users <arg>
snapshot / diff / apply are generated automatically from the State Kinds declared on this module — see the State kinds section below for per-kind details. Workflow: snapshot → edit YAML → diffapply --yes (or confirm interactively; apply --dry-run previews the same diff).

State kinds

Resources this module can snapshot and diff; apply where the kind supports live writes (see Round-trip per kind). Always run diff before apply; use --yes in automation after review. Files live under .weave-state/keycloak/.

users

snapshot diff apply

keycloak users — field-level apply via REST.

Scope
Round-trip
Full round-trip — snapshot, diff, apply.

State file skeleton

module: keycloak
kind: users
items:
  - # <fields specific to this kind — see snapshot output>

Workflows

End-to-end recipes from operators who already run this module in production. Copy, adapt, and put under change-control.

Users audit

Snapshot, diff, and apply users.

weave keycloak snapshot users
$EDITOR .weave-state/keycloak/users.yaml
weave keycloak diff users
weave keycloak apply users

Terraform parity

For each Terraform resource in the canonical provider, here's the equivalent live-API verb in weave. Use this as a migration cheat-sheet, not a 1:1 contract — weave deliberately stays in the live-state lane, not the desired-state lane.

Terraform resource weave equivalent
keycloak_usersweave keycloak snapshot/diff/apply users
Round-trip via weave state.

Troubleshooting & source

Missing credentials

Run weave doctor — it reports which env vars (including KEYCLOAK_URL) are set and which are blank.

Unexpected behaviour from a state apply

Re-run weave keycloak diff <kind> to confirm the controller's current state, then re-snapshot before the next apply. The driver always re-snapshots before diffing.