Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
d9a4d6b
Add design spec for Gundi Keycloak login theme (KC 11 and 26)
Sep 23, 2026
ffaaf56
Pin Keycloak 11 theme base image to quay.io/keycloak/keycloak:11.0.2
Sep 23, 2026
8e5ecca
Spec: title override is 26-only; add screenshot and css-guard test sc…
Sep 23, 2026
b14e104
Add implementation plan for Gundi Keycloak login theme
Sep 23, 2026
bc3e80b
Add local Keycloak 11/26 theme harness with smoke and screenshot scripts
Sep 23, 2026
f003955
Add gundi Keycloak theme skeleton for KC 11 and 26 with title overrides
Sep 23, 2026
bea6b2c
Add Inter fonts, Gundi logo mark and design tokens to the theme
Sep 23, 2026
f54cfab
Add shared Gundi login stylesheet and cascade guard
Sep 23, 2026
4754cd4
Style Keycloak 11 login pages with PatternFly 3 overrides
Sep 23, 2026
4473b43
Style Keycloak 26 login pages with PatternFly 5 overrides
Sep 23, 2026
489d56b
Add Dockerfiles baking the Gundi theme into Keycloak 11 and 26 images
Sep 23, 2026
e7e40c1
Add CI workflow that builds, smoke-tests and pushes Keycloak theme im…
Sep 23, 2026
d914928
Add Keycloak theme runbook: local dev, prod rollout, rollback, 26 han…
Sep 23, 2026
e5cd287
Address review: fix KC 26 phone-width overflow, runbook health-check …
Sep 23, 2026
b12b7f8
Fix alert icon overlapping the message text on Keycloak 11
Sep 23, 2026
544d9f7
Add the Gundi mark as the login theme favicon
Sep 23, 2026
6cde07d
Move the logo into the card with a Welcome title and subtitle
Sep 23, 2026
43bd4be
Address review: smoke assertion, script hardening, :has() fallback, a…
Sep 23, 2026
cdaf76e
Fix screenshot cleanup trap scope
Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
101 changes: 101 additions & 0 deletions .github/workflows/keycloak-theme.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
name: Keycloak Gundi theme images

on:
push:
branches: [main]
paths:
- 'keycloak/**'
- '.github/workflows/keycloak-theme.yml'
pull_request:
paths:
- 'keycloak/**'
- '.github/workflows/keycloak-theme.yml'

jobs:
test:
# Builds each image locally (no push), boots it with the dev realm, and runs the smoke test.
# The shared build_docker workflow always pushes, so it must not run before this passes.
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- version: kc11
port: 8081
- version: kc26
port: 8082
steps:
- uses: actions/checkout@v4

- name: Cascade guard (shared stylesheet has no framework classes)
run: keycloak/tests/check-css.sh

- name: Realm fixture matches the base realm export
run: keycloak/dev/generate-realm.py --check

- name: Build image
run: docker build -f keycloak/Dockerfile.${{ matrix.version }} -t gundi-keycloak:${{ matrix.version }} .

- name: Start Keycloak 11
if: matrix.version == 'kc11'
run: |
docker run -d --name kc -p 8081:8080 \
-e KEYCLOAK_USER=admin -e KEYCLOAK_PASSWORD=admin -e DB_VENDOR=h2 \
-e KEYCLOAK_IMPORT=/tmp/realm.json \
-v "$PWD/keycloak/dev/realm-with-theme.json:/tmp/realm.json:ro" \
gundi-keycloak:kc11 -b 0.0.0.0

- name: Start Keycloak 26
if: matrix.version == 'kc26'
run: |
docker run -d --name kc -p 8082:8080 \
-e KC_BOOTSTRAP_ADMIN_USERNAME=admin -e KC_BOOTSTRAP_ADMIN_PASSWORD=admin \
-e KC_HTTP_RELATIVE_PATH=/auth \
-v "$PWD/keycloak/dev/realm-with-theme.json:/opt/keycloak/data/import/realm.json:ro" \
gundi-keycloak:kc26 start-dev --import-realm

- name: Wait for Keycloak
run: keycloak/tests/wait-ready.sh http://localhost:${{ matrix.port }}/auth/realms/cdip-dev 300

- name: Smoke test
run: keycloak/tests/smoke.sh http://localhost:${{ matrix.port }} cdip-dev ${{ matrix.version }}

- name: Keycloak logs
if: failure()
run: docker logs kc

vars:
# Only feeds the main-gated push job. The image tag's version prefix comes from each
# Dockerfile's FROM tag, so bumping a base image cannot leave the tag behind.
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
outputs:
sha: ${{ steps.vars.outputs.sha }}
kc11: ${{ steps.vars.outputs.kc11 }}
kc26: ${{ steps.vars.outputs.kc26 }}
steps:
- uses: actions/checkout@v4
with:
sparse-checkout: keycloak
- id: vars
run: |
echo "sha=${GITHUB_SHA::7}" >> "$GITHUB_OUTPUT"
for v in kc11 kc26; do
tag=$(sed -nE 's#^FROM quay.io/keycloak/keycloak:([^[:space:]]+).*#\1#p' "keycloak/Dockerfile.$v")
[[ -n $tag ]] || { echo "no keycloak FROM tag in keycloak/Dockerfile.$v" >&2; exit 1; }
echo "$v=$tag" >> "$GITHUB_OUTPUT"
done

push:
# Only from main, only after both smoke tests pass. Nothing deploys; see keycloak/RUNBOOK.md.
if: github.ref == 'refs/heads/main'
needs: [test, vars]
strategy:
matrix:
version: [kc11, kc26]
uses: PADAS/gundi-workflows/.github/workflows/build_docker.yml@v11
with:
workload_identity_provider: ${{ vars.WORKLOAD_IDENTITY_PROVIDER }}
repository: europe-west3-docker.pkg.dev/serca-artifact-registry/gundi/keycloak
tag: ${{ needs.vars.outputs[matrix.version] }}-gundi-${{ needs.vars.outputs.sha }}
dockerfile: keycloak/Dockerfile.${{ matrix.version }}
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -293,3 +293,6 @@ override.tf.json

# Local task notes — may hold payloads pasted from production
TASK.md

# Keycloak theme screenshots (generated by keycloak/tests/screenshot.sh)
keycloak/tests/shots/
1,556 changes: 1,556 additions & 0 deletions docs/superpowers/plans/2026-09-22-keycloak-gundi-login-theme.md

Large diffs are not rendered by default.

Loading
Loading