-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsetup-keycloak.sh
More file actions
executable file
·88 lines (72 loc) · 2.71 KB
/
Copy pathsetup-keycloak.sh
File metadata and controls
executable file
·88 lines (72 loc) · 2.71 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
#!/bin/bash
echo "=== Financial Ledger Keycloak Setup ==="
echo ""
# Check if jq is installed
if ! command -v jq &> /dev/null; then
echo "Error: jq is required but not installed."
echo "Please install jq first:"
echo " macOS: brew install jq"
echo " Ubuntu: sudo apt-get install jq"
echo " Windows: Download from https://stedolan.github.io/jq/"
exit 1
fi
# Start services
echo "1. Starting Docker services..."
docker-compose up -d postgres keycloak
echo "2. Waiting for Keycloak to be ready..."
until curl -s http://localhost:8080/health > /dev/null; do
echo " Waiting for Keycloak..."
sleep 5
done
echo "3. Keycloak is ready! Getting admin token..."
# Get admin token
ADMIN_TOKEN=$(curl -X POST http://localhost:8080/realms/master/protocol/openid-connect/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "username=admin" \
-d "password=admin" \
-d "grant_type=password" \
-d "client_id=admin-cli" | jq -r '.access_token')
if [ "$ADMIN_TOKEN" = "null" ] || [ -z "$ADMIN_TOKEN" ]; then
echo "Error: Failed to get admin token"
exit 1
fi
echo "4. Admin token obtained. Creating realm..."
# Create realm
RESPONSE=$(curl -X POST http://localhost:8080/admin/realms \
-H "Authorization: Bearer $ADMIN_TOKEN" \
-H "Content-Type: application/json" \
-d @keycloak-init/financial-ledger-realm.json)
if [ $? -eq 0 ]; then
echo "5. Realm created successfully!"
else
echo "Error: Failed to create realm: $RESPONSE"
exit 1
fi
# Get client secrets
echo "6. Getting client secrets..."
TRANSACTION_SERVICE_SECRET=$(curl -X GET http://localhost:8080/admin/realms/financial-ledger/clients \
-H "Authorization: Bearer $ADMIN_TOKEN" | jq -r '.[] | select(.clientId=="transaction-service") | .secret')
API_GATEWAY_SECRET=$(curl -X GET http://localhost:8080/admin/realms/financial-ledger/clients \
-H "Authorization: Bearer $ADMIN_TOKEN" | jq -r '.[] | select(.clientId=="api-gateway") | .secret')
echo ""
echo "=== Client Secrets ==="
echo "Transaction Service Secret: $TRANSACTION_SERVICE_SECRET"
echo "API Gateway Secret: $API_GATEWAY_SECRET"
echo ""
echo "7. Creating .env file with secrets..."
cat > .env << EOF
# Keycloak Client Secrets
TRANSACTION_SERVICE_SECRET=$TRANSACTION_SERVICE_SECRET
API_GATEWAY_SECRET=$API_GATEWAY_SECRET
EOF
echo "8. Keycloak setup completed!"
echo ""
echo "=== Test Users ==="
echo "Username: compliance_officer, Password: password123"
echo "Username: transaction_operator, Password: password123"
echo "Username: auditor, Password: password123"
echo ""
echo "=== Next Steps ==="
echo "1. Update your application.properties files with the secrets above"
echo "2. Start your Spring Boot applications"
echo "3. Test the endpoints with the provided users"