Skip to content

DRAFT: Add support for multiple IdP providers in Federation #3001

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

jagee
Copy link
Contributor

@jagee jagee commented May 20, 2025

This patch will setup two realms in keycloak. Keystone will be configured to work with these two realms as different IdPs. Each realm will get its own mapping in openstack. It will also enable these two IdP choices to the horizon UI.

Jira: https://issues.redhat.com/browse/OSPRH-14033

@jagee jagee requested a review from a team as a code owner May 20, 2025 22:16
Copy link
Contributor

openshift-ci bot commented May 20, 2025

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Copy link
Contributor

openshift-ci bot commented May 20, 2025

Hi @jagee. Thanks for your PR.

I'm waiting for a openstack-k8s-operators member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/b5fdc40a45b24f309f2d32dd5554958b

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 49m 01s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 15m 19s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 33m 29s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 40s
cifmw-pod-pre-commit FAILURE in 8m 09s
build-push-container-cifmw-client RETRY_LIMIT in 3m 47s

@jagee jagee force-pushed the add-federation-multirealm branch from eda4b8f to e56f951 Compare May 21, 2025 00:45
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/77f3f11bca0d4d7b915ed7fc685df780

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 47m 06s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 06m 17s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 32m 28s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 40s
✔️ cifmw-pod-pre-commit SUCCESS in 8m 10s
build-push-container-cifmw-client RETRY_LIMIT in 3m 45s

@jagee jagee force-pushed the add-federation-multirealm branch 2 times, most recently from 35b405d to b182e70 Compare June 4, 2025 22:14
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/4d4391df6a40434cbb576037a7906a49

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 47m 49s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 20m 35s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 33m 22s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 48s
cifmw-pod-pre-commit FAILURE in 6m 15s
✔️ build-push-container-cifmw-client SUCCESS in 21m 32s
✔️ cifmw-molecule-federation SUCCESS in 2m 22s

@jagee jagee force-pushed the add-federation-multirealm branch 4 times, most recently from 1f9c71a to e48c62e Compare June 6, 2025 03:29
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/b50093b87701455c96fc024bd69d8544

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 47m 12s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 21m 28s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 31m 43s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 32s
cifmw-pod-pre-commit FAILURE in 6m 27s
✔️ build-push-container-cifmw-client SUCCESS in 22m 11s
✔️ cifmw-molecule-federation SUCCESS in 2m 23s

@jagee jagee force-pushed the add-federation-multirealm branch from e48c62e to 7d66c3c Compare June 6, 2025 12:42
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/a285299115154e389d0268b5bd0bdec1

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 44m 21s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 15m 57s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 27m 30s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 9m 09s
cifmw-pod-pre-commit FAILURE in 6m 47s
✔️ build-push-container-cifmw-client SUCCESS in 23m 11s
✔️ cifmw-molecule-federation SUCCESS in 2m 55s

@jagee jagee force-pushed the add-federation-multirealm branch from 7d66c3c to 5490246 Compare June 6, 2025 20:56
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/62cd93d3e4bb4eb48f9aeac05eb60ee0

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 58m 49s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 19m 00s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 44m 03s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 24s
cifmw-pod-pre-commit FAILURE in 5m 59s
✔️ build-push-container-cifmw-client SUCCESS in 17m 58s
✔️ cifmw-molecule-federation SUCCESS in 2m 22s

@jagee jagee force-pushed the add-federation-multirealm branch from 5490246 to d83797d Compare June 7, 2025 01:13
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/f1f5ca0bc96541d4ad5ecb4861933402

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 47m 18s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 21m 49s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 32m 58s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 8m 26s
cifmw-pod-pre-commit FAILURE in 6m 01s
✔️ build-push-container-cifmw-client SUCCESS in 22m 06s
✔️ cifmw-molecule-federation SUCCESS in 2m 14s

@jagee jagee force-pushed the add-federation-multirealm branch from d83797d to 7b18fb8 Compare June 9, 2025 20:49
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/5ef1c975fb97408d907ebcfb2a904a04

✔️ openstack-k8s-operators-content-provider SUCCESS in 1h 44m 45s
✔️ podified-multinode-edpm-deployment-crc SUCCESS in 1h 19m 32s
✔️ cifmw-crc-podified-edpm-baremetal SUCCESS in 1h 30m 47s
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 12m 36s
cifmw-pod-pre-commit FAILURE in 6m 25s
✔️ build-push-container-cifmw-client SUCCESS in 26m 30s
✔️ cifmw-molecule-federation SUCCESS in 2m 19s

@jagee jagee force-pushed the add-federation-multirealm branch from 7b18fb8 to c890ab1 Compare June 10, 2025 04:24
@jagee jagee force-pushed the add-federation-multirealm branch from c890ab1 to 71df0f3 Compare June 10, 2025 21:38
@jagee jagee force-pushed the add-federation-multirealm branch from 71df0f3 to 110c3a1 Compare June 11, 2025 21:46
@jagee jagee force-pushed the add-federation-multirealm branch from 110c3a1 to 6d90dac Compare June 11, 2025 22:43
@jagee jagee force-pushed the add-federation-multirealm branch from 6d90dac to 08faa71 Compare June 17, 2025 20:03
@jagee jagee force-pushed the add-federation-multirealm branch from 08faa71 to 0ca4d25 Compare June 17, 2025 21:00
Copy link

Build failed (check pipeline). Post recheck (without leading slash)
to rerun all jobs. Make sure the failure cause has been resolved before
you rerun jobs.

https://softwarefactory-project.io/zuul/t/rdoproject.org/buildset/5acfac2b14164ee785432d16ca5a81f4

openstack-k8s-operators-content-provider FAILURE in 5m 18s
⚠️ podified-multinode-edpm-deployment-crc SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
⚠️ cifmw-crc-podified-edpm-baremetal SKIPPED Skipped due to failed job openstack-k8s-operators-content-provider
✔️ noop SUCCESS in 0s
✔️ cifmw-pod-ansible-test SUCCESS in 7m 40s
cifmw-pod-pre-commit FAILURE in 7m 33s
✔️ build-push-container-cifmw-client SUCCESS in 18m 47s
✔️ cifmw-molecule-federation SUCCESS in 2m 54s

@jagee jagee force-pushed the add-federation-multirealm branch 2 times, most recently from 4b0991d to d6f985a Compare June 20, 2025 14:04
This patch will setup two realms in keycloak. Keystone will be configured to work
with these two realms as different IdPs. Each realm will get its own mapping in
openstack. It will also enable these two IdP choices to the horizon UI.

Jira: https://issues.redhat.com/browse/OSPRH-14033
@jagee jagee force-pushed the add-federation-multirealm branch from 8c1e46f to 55bcbc8 Compare June 24, 2025 00:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant