Skip to content

Land the Keycloak wait fix and configurable ports on main - #27

Merged
slominskir merged 2 commits into
mainfrom
land-integration-fixes
Oct 1, 2026
Merged

slominskir merged 2 commits into
mainfrom
land-integration-fixes

Conversation

@slominskir-coding-agent

Copy link
Copy Markdown
Contributor

Brings two changes to main that were merged into the integration-tests branch instead:

The certificate fix (48e22e2) did make it into #24's squash, so it's not repeated here. With this PR, main matches the integration-tests branch.

Commits

  1. Wait for Keycloak's setup before integration tests: this fixes Implement integration testing in CI workflow #25's failing CI job. There, awaitReady gave up on the first token request ({"error":"Realm does not exist"}, 404) while Keycloak was still creating the test realm. The token failure is an assertion error, which wasn't retried. The check now also waits for the admin's password login, which works only after Keycloak's last setup script has run.
  2. Make the Compose stack's ports configurable: Make the Compose stack's ports configurable #26, unchanged.

Checks

  • ./gradlew spotlessCheck build integrationTest against the running stack: 45 tests pass (33 unit, 12 integration).
  • The wait fix, checked before (on Add integration tests #24's branch): recreating Keycloak and running the tests straight away, they waited about 2.5 minutes, then all 12 passed.
  • From Implement integration testing in CI workflow #25's log: GitHub's runners reach pki.jlab.org, and the images build in about 1.5 minutes. The only failure was this one.

After merging, #25's integration job should pass once its branch is updated with main.

🤖 Generated with Claude Code

slominskir-coding-agent Bot and others added 2 commits October 1, 2026 15:01
awaitReady retried only I/O and runtime exceptions, but a failed token
request is an assertion error, so the tests failed at once while
Keycloak was still creating the test realm. Retry those too, and wait
for the admin's password login, which works only once Keycloak's last
setup script has run: the service account's login works earlier.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Two copies of the stack, or adm and another project, could not run at
once on one machine: every host port was fixed, and so was every
container name.

Each published port now comes from an ADM_*_PORT variable, which
docker compose reads from the environment or from .env, defaulting to
the port it used before. Keycloak's frontend URL and redirect URIs, and
the app's KEYCLOAK_FRONTEND_SERVER_URL and FRONTEND_SERVER_URL, follow
ADM_KEYCLOAK_PORT and ADM_HTTPS_PORT, so logins and token issuers match
the ports in use.

The services no longer set container_name, so Compose names containers,
network, and images after the project directory (adm-oracle-1 and so
on), and a copy in a git worktree gets its own.

The integrationTest task passes the ADM_* variables in .env to the
tests, which build their default URLs from ADM_HTTPS_PORT and
ADM_KEYCLOAK_PORT. The README lists the variables.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@slominskir-coding-agent slominskir-coding-agent Bot added the bug Something isn't working label Oct 1, 2026
@slominskir
slominskir merged commit c88999c into main Oct 1, 2026
5 checks passed
@slominskir
slominskir deleted the land-integration-fixes branch October 1, 2026 19:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant