Commit graph

1699 commits

Author SHA1 Message Date
andymunro
63edca0a39
Update health check instructions
Closes #47393

Signed-off-by: AndyMunro <amunro@redhat.com>
2026-04-07 18:04:37 +02:00
Marek Posolda
f29249f3d7
Improve performance of scope processing in TokenManager. Limit for maximum length of OIDC parameters in Token endpoint (#478) (#47799)
closes #47716
Closes CVE-2026-4634


(cherry picked from commit b455ee4f28)

Signed-off-by: mposolda <mposolda@gmail.com>
2026-04-07 11:17:17 +02:00
Rahul Ramkumar
799699a808
Add KCRAW_ prefix for environment variables to preserve literal values (#47197)
Closes #46657

Signed-off-by: Rahul Ramkumar <rahulram226@gmail.com>
2026-04-07 10:12:18 +02:00
Alexander Schwartz
dee672728a
Fixing link as it has changed and is redirecting (#47793)
Closes #47792

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-04-07 09:52:45 +02:00
Alexander Schwartz
97fce120ac
Finalizing release notes and migration guide for 26.6 (#47791)
Closes #47790

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-04-07 09:44:13 +02:00
Alexander Schwartz
a9a403b12f
Adding OAuth Client ID Metadata Document to the specifications list (#47706)
Closes #47705

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-04-07 09:40:58 +02:00
Steven Hawkins
51b6f9b291
fix: promotes keycloak and realm import to v2beta1 (#45840)
closes: #45795

Signed-off-by: Steve Hawkins <shawkins@redhat.com>
2026-04-04 16:46:28 +02:00
Václav Muzikář
3560286f0d
Update docs to better reflect FIPS support with Java 25. (#47699)
Signed-off-by: Václav Muzikář <vmuzikar@ibm.com>
2026-04-02 15:04:15 +02:00
Tomáš Kyjovský
e513374669
Add an operational procedure doc for CNPG switchover
Closes #47678

Signed-off-by: Tomas Kyjovsky <tkyjovsk@ibm.com>
Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Co-authored-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-04-02 11:48:14 +00:00
Benjamin DeWeese
a9f571d940
Implementing locale based theme-description translation
Closes #47038

Signed-off-by: Benjamin DeWeese <bdeweesevans@gmail.com>
Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Co-authored-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-04-02 11:40:45 +02:00
Pedro Ruivo
09eef36e90
CNPG - Backup And Restore followup
Closes #47531

Signed-off-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
Signed-off-by: Ryan Emerson <remerson@ibm.com>
Co-authored-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
Co-authored-by: Ryan Emerson <remerson@ibm.com>
2026-04-02 00:25:02 +02:00
Stefan Guilhen
7e8eb64a52
Add troubleshooting section to workflows documentation
- also add workflows as supported in release notes

Closes #47692

Signed-off-by: Stefan Guilhen <sguilhen@redhat.com>
2026-04-02 00:05:04 +02:00
Václav Muzikář
d7238a77ba
Clarify Java 25 support scope in docs (#47539)
Closes #47537

Signed-off-by: Václav Muzikář <vmuzikar@ibm.com>
2026-04-01 15:20:37 +02:00
Stefan Guilhen
031b6604a2 Ensure all workflow steps are described in the documentation.
- also change name of add/remove required action providers to better align with other step providers.

Closes #47655

Signed-off-by: Stefan Guilhen <sguilhen@redhat.com>
2026-04-01 09:10:59 -03:00
Pedro Ruivo
be17c5e747
CNPG - Backup And Restore procedures documentation
Closes #47531

Signed-off-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
Co-authored-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
2026-04-01 12:45:42 +02:00
Takashi Norimatsu
a504df1a1c Update release-notes for CIMD
closes #47667

Signed-off-by: Takashi Norimatsu <takashi.norimatsu.ws@hitachi.com>
2026-04-01 12:42:53 +02:00
Giuseppe Graziano
46d1c4fa5a Sender constrained tokens for token exchange
Closes #46092

Signed-off-by: Giuseppe Graziano <g.graziano94@gmail.com>
2026-04-01 10:23:51 +02:00
Marek Posolda
48b1d0fed9
Clarify in FIPS docs that it is still recommended to use Java 21 (#47623)
closes #47621

Signed-off-by: mposolda <mposolda@gmail.com>
2026-04-01 09:58:09 +02:00
Rick Pastoor
d9bd2ae5ff
Update realm creation steps in documentation (#47633)
Signed-off-by: Rick Pastoor <rickpastoor@gmail.com>
Signed-off-by: Alexander Schwartz <alexander.schwartz@gmx.net>
Co-authored-by: Alexander Schwartz <alexander.schwartz@gmx.net>
2026-03-31 18:02:18 +00:00
mposolda
30fcb2ca40 Clarify at the beginning of legacy-token-exchange section that it needs fgap:v1
closes #47162

Signed-off-by: mposolda <mposolda@gmail.com>
2026-03-31 12:17:56 +02:00
Martin Bartoš
c0458c0801 Provide documentation for customizable log service properties
Closes #47586

Co-authored-by: Daniele Mams <mammarella.daniele@gmail.com>
Signed-off-by: Martin Bartoš <mabartos@redhat.com>
2026-03-31 11:16:29 +02:00
Stefan Guilhen
d24d2697aa Add SPI option to setup the start time of the workflows step runner task
Closes #47540

Signed-off-by: Stefan Guilhen <sguilhen@redhat.com>
2026-03-27 16:30:15 -03:00
Tomáš Kyjovský
85d30369bd
Polishing CNPG installation docs
Some checks are pending
Weblate Sync / Trigger Weblate to pull the latest changes (push) Waiting to run
Closes #47535

Signed-off-by: Tomas Kyjovsky <tkyjovsk@ibm.com>
2026-03-27 17:45:10 +01:00
Ruchika Jha
d721235190
Documention about the default db-schema being ambiguous
Closes #28970

Signed-off-by: Ruchika <ruchika.jha1@ibm.com>
2026-03-27 17:26:31 +01:00
mposolda
5b82688883 Moving identity-broker-api to 'security and standards' section of release notes for 26.6.0
Some checks are pending
Weblate Sync / Trigger Weblate to pull the latest changes (push) Waiting to run
closes #45839

Signed-off-by: mposolda <mposolda@gmail.com>
2026-03-26 17:46:32 +01:00
Simon Levermann
f4225b4f9b
Introduce traceId to freemarker attributes
Closes #44090
Closes #34435

Signed-off-by: Simon Levermann <github@simon.slevermann.de>
2026-03-26 17:42:32 +01:00
Alexander Schwartz
ec07458cd5
Disable async startup when health probe is not enabled
Closes #47416

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-03-26 10:11:07 -03:00
rmartinc
b6fe6c2db8 Documentation for brokering API V2 and make it preview
Closes #46590
Closes #47259

Signed-off-by: rmartinc <rmartinc@redhat.com>
2026-03-26 11:13:58 +01:00
mposolda
02be20e9fa Inaccuracies in client federation documentation and tooltips
closes #47444

Signed-off-by: mposolda <mposolda@gmail.com>
2026-03-26 10:01:29 +01:00
Arman Taheri
9dbdde84d6
fix typo in documents (#47420)
Closes #47412
2026-03-25 08:01:25 +00:00
Stian Thorgersen
763bade3bf
Fix link to Facebook docs (#47422)
Signed-off-by: stianst <stianst@gmail.com>
2026-03-25 08:57:44 +01:00
Hager Khamis
13897b9b32
Adding getResourcesCommonUrl() to UrlBean (#47113)
I added getResourcesCommonUrl() following the same URL/Path pattern already used by getResourcesUrl() and getResourcesPath(). Email clients can't resolve relative paths so the existing getResourcesCommonPath() wasn't enough for email templates.

I also pulled out the common-path lookup into a private getCommonPath() helper to avoid duplicating it between getResourcesCommonPath() and the new method. Updated the theme docs with a usage example and a note about absolute URLs in emails.

Closes #33198

Signed-off-by: Hager Khamis <hagerm98@hotmail.com>
2026-03-25 07:45:52 +00:00
mposolda
3f1567c7af Update authentication section in the Server Admin Guide Features section
Some checks are pending
Weblate Sync / Trigger Weblate to pull the latest changes (push) Waiting to run
closes #47393

Signed-off-by: mposolda <mposolda@gmail.com>
2026-03-24 19:26:50 +01:00
Pedro Ruivo
636e7252af
Update docs to use new TLS options (#47288)
Closes #47104

Signed-off-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
Co-authored-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
2026-03-24 10:06:32 +01:00
Gilvan Filho
ed66ac6b0c
add labels and annotations to service monitor (serviceMonitorSpec) (#47298)
* add labels and annotations to service monitor (serviceMonitorSpec)

closes #42626

Signed-off-by: Gilvan Filho <gilvan.sfilho@gmail.com>

* add labels and annotations to service monitor (serviceMonitorSpec)

Co-authored-by: Václav Muzikář <vaclav@muzikari.cz>
Signed-off-by: Gilvan Filho <gilvan.sfilho@gmail.com>

---------

Signed-off-by: Gilvan Filho <gilvan.sfilho@gmail.com>
Co-authored-by: Václav Muzikář <vaclav@muzikari.cz>
2026-03-23 17:35:44 +00:00
Alexander Schwartz
86a44bd378
Review release notes about missing items (#47359)
* Review release notes about missing items

Closes #47358

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>

* Apply suggestion from @stianst

Signed-off-by: Stian Thorgersen <stianst@gmail.com>

* Apply suggestion from @stianst

Signed-off-by: Stian Thorgersen <stianst@gmail.com>

---------

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Signed-off-by: Stian Thorgersen <stianst@gmail.com>
Co-authored-by: Stian Thorgersen <stianst@gmail.com>
2026-03-23 07:58:34 +01:00
Martin Bartoš
6db7608697
Missing release notes entry for OpenTelemetry span attributes location change (#47333)
Closes #47332

Signed-off-by: Martin Bartoš <mabartos@redhat.com>
Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Co-authored-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-03-21 20:44:03 +01:00
Tero Saarni
50517cf933
Reload password blacklist file on change without restart
Fixes #47163

Signed-off-by: Tero Saarni <tero.saarni@est.tech>
2026-03-21 20:07:00 +01:00
Ricardo Martin
b93695eb90
Add versioning to identity brokering api feature (#47281)
Closes #47254

Signed-off-by: rmartinc <rmartinc@redhat.com>
2026-03-20 16:55:56 +01:00
Takashi Norimatsu
08f47dde7c MCP Documentation for 26.6
closes #46617

Signed-off-by: Takashi Norimatsu <takashi.norimatsu.ws@hitachi.com>
2026-03-20 15:16:33 +01:00
Steven Hawkins
29d00b07f3
fix: use to values ahead of keycloak defaults (#46871)
* fix: use `to` values ahead of keycloak defaults

closes: #46728

Signed-off-by: Steve Hawkins <shawkins@redhat.com>

* Update docs/documentation/upgrading/topics/changes/changes-26_6_0.adoc

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Steven Hawkins <shawkins@redhat.com>

* Apply suggestion from @shawkins

Signed-off-by: Steven Hawkins <shawkins@redhat.com>

---------

Signed-off-by: Steve Hawkins <shawkins@redhat.com>
Signed-off-by: Steven Hawkins <shawkins@redhat.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-03-20 14:42:49 +01:00
Pedro Ruivo
c93b6a7e6c
Asynchronous server initialization
Closes #47187

Signed-off-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Signed-off-by: Pedro Ruivo <pruivo@users.noreply.github.com>
Co-authored-by: Pedro Ruivo <1492066+pruivo@users.noreply.github.com>
Co-authored-by: Alexander Schwartz <alexander.schwartz@ibm.com>
Co-authored-by: Steven Hawkins <shawkins@redhat.com>
2026-03-19 21:23:46 +01:00
Ruchika Jha
37c9fd4de0
Added implementation for CLI option for database connection timeout and provide it into quarkus.datasource.jdbc.login-timeout
Closes #47140

Signed-off-by: Ruchika <ruchika.jha1@ibm.com>
2026-03-19 21:04:35 +01:00
Alexander Schwartz
b9cd14f931
Regroup the release notes by category
Closes #47239

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-03-18 14:29:17 +01:00
Peter Skopek
d11136f671 Separate password and OTP brute force protection to prevent OTP bypass attacks by default
Closes #46164

Signed-off-by: Peter Skopek <peter.skopek@ibm.com>

Update model/infinispan/src/main/java/org/keycloak/models/sessions/infinispan/changes/remote/updater/loginfailures/LoginFailuresUpdater.java

Co-authored-by: Pedro Ruivo <pruivo@users.noreply.github.com>
Signed-off-by: Peter Skopek <peter.skopek@ibm.com>

Add recovery codes to the list of brute force checked authenticators.

Closes #46164
Signed-off-by: Peter Skopek <peter.skopek@ibm.com>
2026-03-17 18:57:37 +01:00
Alexander Schwartz
16341be6ac
Update translation check prompt
Closes #47215

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-03-17 14:38:25 -03:00
Ricardo Martin
3c7582f318
Broker token API for saml (#47087)
Closes #46589


Signed-off-by: rmartinc <rmartinc@redhat.com>
2026-03-17 18:29:48 +01:00
Alexander Schwartz
ac89a8c5e5
Move migration changes to already published release
Closes #47217

Signed-off-by: Alexander Schwartz <alexander.schwartz@ibm.com>
2026-03-17 15:01:13 +01:00
Ryan Emerson
eea43029e2
Increase HA architecture tested load in downstream documentation
Closes #47195

Signed-off-by: Ryan Emerson <remerson@ibm.com>
2026-03-17 05:16:45 +01:00
Stian Thorgersen
607096fd4e
Promote federated client authentication, including OIDC and Kube to fully supported
Closes #42634, closes #42635, closes #42826, closes #44412

Signed-off-by: stianst <stianst@gmail.com>
2026-03-17 05:15:13 +01:00