Hi everyone. Quick question for anyone using Keyc...
# rancher-setup
f
Hi everyone. Quick question for anyone using Keycloak for Rancher authentication. I'm on Rancher 2.7.3. Keycloak authentication was all set up and working, or so I thought. I have no problems authenticating and logging in new users etc. But after about 2-3 minutes of configuring the authentication I start getting errors in the Keycloak pod about "type=REFRESH_TOKEN_ERROR, realmId=myrealm, clientId=(removed), userId=null, ipAddress=(removed), error=invalid_token, grant_type=refresh_token". Then after about 30 minutes I suddenly can't see certain LDAP groups associated with clusters, the objects are there but the UI show "Unknown" and something about couldn't query principal something or other. If I go back to the Keycloak configuration the client secret is empty, I put that back in and save the config and everything goes back to working, I can see the LDAP groups again and everything works until the cycle repeats itself. Feel like I've checked the Rancher and Keycloak client configs a million times, but Iust be missing something. Any help or pointers appreciated.