Skip to content

Commit 2146629

Browse files
committed
feat: fold ocis-keycloak-setup into ocis-setup (keycloak=true starts Postgres+Keycloak stack)
1 parent 9115380 commit 2146629

1 file changed

Lines changed: 65 additions & 0 deletions

File tree

‎ocis-setup/action.yml‎

Lines changed: 65 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -107,6 +107,10 @@ inputs:
107107
description: "Deprecated: use collaboration-apps: cs3-wopi instead"
108108
required: false
109109
default: "false"
110+
keycloak-realm-file:
111+
description: Path (relative to repo root) to the Keycloak realm dist JSON; only used when keycloak=true
112+
required: false
113+
default: tests/config/ci/ocis-ci-realm.dist.json
110114

111115
outputs:
112116
ocis-url:
@@ -115,6 +119,9 @@ outputs:
115119
wopi-url:
116120
description: WOPI source base URL (http://localhost:PORT); only set when collaboration-apps is non-empty
117121
value: ${{ steps.wopi-url.outputs.wopi-url }}
122+
keycloak-domain:
123+
description: Keycloak domain (host:port); only set when keycloak=true
124+
value: localhost:8443
118125

119126
runs:
120127
using: composite
@@ -193,6 +200,64 @@ runs:
193200
# -------------------------------------------------------------------------
194201
# 3. Optional services
195202
# -------------------------------------------------------------------------
203+
- name: Start Keycloak stack
204+
if: inputs.keycloak == 'true'
205+
shell: bash
206+
working-directory: ${{ github.workspace }}
207+
env:
208+
OCIS_URL: ${{ inputs.ocis-url }}
209+
REALM_DIST: ${{ inputs.keycloak-realm-file }}
210+
run: |
211+
# Generate TLS cert with SAN so Chromium hostname-validates it
212+
mkdir -p keycloak-certs
213+
openssl req -x509 -newkey rsa:2048 \
214+
-keyout keycloak-certs/keycloakkey.pem \
215+
-out keycloak-certs/keycloakcrt.pem \
216+
-nodes -days 365 \
217+
-subj '/CN=localhost' \
218+
-addext 'subjectAltName=DNS:localhost,IP:127.0.0.1'
219+
chmod -R 777 keycloak-certs
220+
221+
# Patch realm file: replace placeholder domain with actual oCIS URL
222+
sed "s|https://ocis-server:9200|${OCIS_URL}|g" "${REALM_DIST}" > /tmp/ocis-realm.json
223+
224+
# Start Postgres (Keycloak backend)
225+
docker run -d --name postgres --network host \
226+
-e POSTGRES_DB=keycloak \
227+
-e POSTGRES_USER=keycloak \
228+
-e POSTGRES_PASSWORD=keycloak \
229+
postgres:alpine3.18
230+
timeout 30 bash -c 'until docker exec postgres pg_isready -U keycloak; do sleep 1; done'
231+
232+
# Start Keycloak
233+
docker run -d --name keycloak --network host \
234+
-e "OCIS_DOMAIN=${OCIS_URL}" \
235+
-e KC_HOSTNAME=localhost \
236+
-e KC_PORT=8443 \
237+
-e KC_DB=postgres \
238+
-e "KC_DB_URL=jdbc:postgresql://localhost:5432/keycloak" \
239+
-e KC_DB_USERNAME=keycloak \
240+
-e KC_DB_PASSWORD=keycloak \
241+
-e KC_FEATURES=impersonation \
242+
-e KC_BOOTSTRAP_ADMIN_USERNAME=admin \
243+
-e KC_BOOTSTRAP_ADMIN_PASSWORD=admin \
244+
-e KC_HTTPS_CERTIFICATE_FILE=/keycloak-certs/keycloakcrt.pem \
245+
-e KC_HTTPS_CERTIFICATE_KEY_FILE=/keycloak-certs/keycloakkey.pem \
246+
-v "$(pwd)/keycloak-certs:/keycloak-certs:ro" \
247+
-v "/tmp/ocis-realm.json:/opt/keycloak/data/import/oCIS-realm.json:ro" \
248+
quay.io/keycloak/keycloak:26.2.5 \
249+
start-dev --proxy-headers xforwarded \
250+
--spi-connections-http-client-default-disable-trust-manager=true \
251+
--import-realm --health-enabled=true
252+
timeout 300 bash -c 'until curl -skf https://localhost:9000/health/ready; do sleep 3; done' \
253+
|| (echo "=== keycloak logs ===" && docker logs keycloak --tail 80 && exit 1)
254+
echo "keycloak ready."
255+
256+
# Trust the cert system-wide (curl + Playwright)
257+
sudo cp keycloak-certs/keycloakcrt.pem /usr/local/share/ca-certificates/keycloak.crt
258+
sudo update-ca-certificates
259+
echo "KEYCLOAK_CERT=$(pwd)/keycloak-certs/keycloakcrt.pem" >> "$GITHUB_ENV"
260+
196261
- name: Start Mailpit (email)
197262
if: inputs.email == 'true'
198263
shell: bash

0 commit comments

Comments
 (0)