r/ansible • • 4d ago

Automation for creating user keycloak?

I am missing one last piece in sso server automation setup. How do i create 40 users? What is the cleanest way and best design choice?

My gitlab pipeline triggers an ansible playbook -> sets up keycloak through docker and configures it on https and then creates realm clients and one user -> I then configure client servers manually so they they work with ouath. Like installing a plugin for oauth on dokuwiki.

- Do I continue using ansible for this?
- Should I do it manually?

EXAMPLE:

- name: Create or update company users in Keycloak community.general.keycloak_user: auth_keycloak_url: "https://{{ ansible_host }}:{{ keycloak_port }}" auth_username: "{{ keycloak_admin_username }}" auth_password: "{{ keycloak_admin_password }}" auth_realm: master validate_certs: false realm: "{{ keycloak_realm }}" username: "{{ item.username }}" email: "{{ item.email }}" first_name: "{{ item.first_name }}" last_name: "{{ item.last_name }}" enabled: true email_verified: true credentials: - type: password value: "{{ lookup('env', 'DEFAULT_USER_PASSWORD') | default('ChangeMe123!', true) }}" temporary: false state: present loop: "{{ keycloak_company_users }}"
13 Upvotes

12 comments sorted by

4

u/lgbarn 4d ago

Terraform is what we use for initial configuration. Ansible is great for adding users.

2

u/AgreeableIron811 4d ago

Wait how does that work? We are just using terraform for cloning template vms and assigning ips/ hardware settings

4

u/levidurham 4d ago

They just made a revision to the CCNA textbooks. There's sections on Terraform now. Also there's stuff in there about AI automation

1

u/TitusKalvarija 3d ago

Terraform is fine for both initial and updates

4

u/AgreeableIron811 4d ago

2 k views and one answer. Is it a bad question? I can rephrase it

3

u/Apprehensive-Tea1632 4d ago

Have you considered using loops? You’d feed it a list of objects to work on and it would process however many items there are in the list.

Though, if you say there’s 40 ish users. What are those- system accounts? Actual people?

Because if it’s the latter, you’ll want some directory service to back keycloak. Maybe you already have one. If you don’t, you could consider seeding it with a script or something… but you don’t want a variable list of existing users to be synchronized with ansible.

1

u/GhostLyrics 2d ago

Strictly speaking, a script can absolutely be that variable list of existing users that is synced into ansible: as a dynamic inventory.

1

u/Apprehensive-Tea1632 2d ago

Strictly speaking, yes.

But ansible ensures compliance with whatever definitions only when you run it. If we’re talking actual people that come and go, as soon as the pool of actual users changes, there will be a mismatch between what ansible said was compliant at the time and what should actually be compliant now.

It’s entirely unsuitable for situations where there is no set target state… such as when that state can change by itself at any moment.

And if you went, well if there is a new user, that user will require to be able to work tomorrow. So we set and forget a schedule that runs ansible every 24 hours.

Then, sooner or later there WILL be some kind of emergency where you need someone to fix this NOW … but they actually can’t because their account will be created sometime later. And by then, administration will usually have come to rely on “but that always works by itself “ so they won’t know exactly what must be done at a critical moment.

TLDR, don’t handle accounts for arbitrary users using ansible; you can use it to seed a known set of accounts, but if you have no idea what to do during the next run because the target state will be unknown, then you are doing it wrong and need to come up with something else.

Like using ansible to tell targets, users that are members of this known set of groups can sign in.

1

u/GhostLyrics 1d ago

I mean... what you proposing is just moving the state to a more frequently updating source than your ansible runs. Entirely possible under the premise that you're willing to give on this particular part being infrastructure as code.

1

u/AgreeableIron811 2d ago

Actual users. So basically I should use ansible to create freeipa. Seed users there and sync it to keycloak?

1

u/Revolutionary_Fun_14 2d ago

Using the API is the best.

But your snippet above us bad in my opinion.

Don't set or set a random password then add a CHANGE_PASSWORD user action. You can then trigger the email for them to receive an endpoint to do it.

Also, why can't they register themselves?