Skip to content

Prod Keycloak manifests, graceful-swap checklist, and runbook image swap via apply - #485

Open
chrisdoehring wants to merge 2 commits into
mainfrom
docs/keycloak-prod-lb-health-check
Open

chrisdoehring wants to merge 2 commits into
mainfrom
docs/keycloak-prod-lb-health-check

Conversation

@chrisdoehring

Copy link
Copy Markdown
Contributor

Summary

  • keycloak/prod/: the live prod Keycloak 11 Deployment, Service and BackendConfig for cdip-prod01/cdip-auth, exported with kubectl neat and stripped of cluster-owned fields. Credentials are secretKeyRef entries against the keycloak-credentials Secret, which stays out of git. The README covers the diff-then-apply workflow with server-side apply, when to force conflicts, and why each value is set.
  • keycloak/RUNBOOK.md: the image-swap step now edits keycloak/prod/deployment.yaml and applies it instead of kubectl set image, so the files cannot drift from prod. Step 1 checks for an empty diff first. The post-swap health check expects 200 or 400 depending on the client's redirect list (the cdip-dev admin-portal client accepts any redirect, so it returns the login page).
  • docs/superpowers/plans/2026-09-28-keycloak-prod-lb-health-check.md: checklist for the changes that keep the load balancer pointed at a serving pod during a swap (5 s health check, 30 s draining, 5 s readiness probe, preStop sleep, 60 s grace period), the credential move into a Secret, and a one-hour theme cache lifetime (-Dkeycloak.theme.staticMaxAge=3600) so theme changes reach browsers without a hard reload.

Status

Everything in the checklist is applied to prod except step 5b (readiness probe period and the theme cache flag). Those two edits are already in keycloak/prod/deployment.yaml and wait for the next restart window, so until then kubectl diff --server-side -f keycloak/prod/ shows exactly those two lines.

Notes for review

  • DB_ADDR in the Deployment is the Cloud SQL private IP. It is internal-only; flag it if we would rather keep it out of the repo.
  • Nothing in this PR deploys anything. Merging only records state and changes documentation.

🤖 Generated with Claude Code

Chris Doehring and others added 2 commits September 30, 2026 08:19
…ul swap

Records the fix for the outage seen on the 2026-09-28 image swap: a
BackendConfig with a 5 s health check and 30 s draining, a 5 s readiness
probe, a preStop sleep and a 60 s grace period. Also covers moving the
Deployment's credentials into a Secret, exporting the live objects with
kubectl neat as the manifest of record, and a one-hour theme cache lifetime
so theme changes reach browsers without a hard reload.

Status as of 2026-09-30: everything is applied except step 5b (probe period
and cache lifetime), which is prepared in the manifest and waits for the
next restart window.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
keycloak/prod/ holds the live Deployment, Service and BackendConfig for
cdip-prod01/cdip-auth, exported with kubectl neat and stripped of
cluster-owned fields. Credentials are secretKeyRef entries against the
keycloak-credentials Secret, which stays out of git. The README covers the
diff-then-apply workflow with server-side apply and when to force conflicts.

The runbook's image swap now edits deployment.yaml and applies it instead
of kubectl set image, so the files cannot drift from prod, and its health
check expects 200 or 400 depending on the client's redirect list.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant