Skip to content

[ISSUE] Bring Managment Identity up to Standard for 8.8 #4588

@hamza-m-masood

Description

@hamza-m-masood

Describe the issue:

Overall, the 8.8 management Identity configuration needs to be reviewed on the Helm chart.

Below are areas that might need review, though this list is not exhaustive:

  • Defining clients through env vars when the clients should be defined through the configmap.
    Currently there are 3 clients defined through env vars:
    1 connectors
    2 orchestration
    3 migration (optional)
    Why aren't web-modeler, console, and optimize also defined in this env var section with the other clients?
  • Are the keycloak.presets still needed in the management identity configmap?
  • Why does the management identity deployment require CAMUNDA_IDENTITY_AUDIENCE when optimize is disabled in an OIDC scenario? (create a POC for this to show when optimize is disabled the identity pod won't start)
  • It is required to set IDENTITY_CLIENTID in order to get external keycloak working. Reference: https://camunda.slack.com/archives/C03UR0V2R2M/p1761661562981479
  • It is required to set KEYCLOAK_REALM in order to get a custom real for external keycloak. Reference: https://camunda.slack.com/archives/C03UR0V2R2M/p1761662078802799

support: https://jira.camunda.com/browse/SUPPORT-29705
Environment:

Please note: Without the following info, it's hard to resolve the issue and probably it will be closed.

  • Platform:
  • Helm CLI version:
  • Chart version: 8.8
  • Values file:

Sub-issues

Metadata

Metadata

Labels

kind/issueUnidentified issue, it could be a bug, misconfig, or anything in betweenplatform/awsIssues related to AWSplatform/gcpIssues related to GCPsupportMarks an issue as related to a customer support request (don't edit the lable)

Type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions