Dear all,
Keycloak Operator uses a one-way sync for Realms, Clients and Users. The one way sync has been implemented on purpose. Without this approach, any change made manually in the Admin UI would be overridden.
We recently received an interesting Pull Request [1] that introduced a new field into the Keycloak CR called `unmanaged`. If the field was changed to `managed` with a type of string, this could open the door for implementing other syncing mechanisms, such as `create-only` or `always-update`. Leaving this set to `create-only` for Realms, Clients and Users would make it behavioral backwards compatible.
More information might be found here [2].
What do you think about this?
Thanks,
Sebastian