Use keycloak-config-cli env var substitution $(env:VAR_NAME) to inject user passwords from K8s Secret instead of hardcoding them in ConfigMap. - realm-configmap.yaml: passwords replaced with $(env:KC_INFRA_ADMIN_PASSWORD) and $(env:KC_INFRA_CLAUDE_PASSWORD) - keycloak ArgoCD app: added keycloakConfigCli.extraEnvVarsSecret - Secrets sourced from OpenBao via create-keycloak-secrets.sh Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
k8s-apps
ArgoCD application manifests (Phase 6 PoC)
Description
Languages
Smarty
100%