# Keycloak realm artifact `realms/ca-skeleton-realm.json` is imported by the `keycloak` service in `docker-compose.infra.yml` and is the same realm every GraphQL qualification lane authenticates against. ## The client secret is a reference, never a value The confidential client `ca-skeleton-api` carries `"secret": "${KEYCLOAK_GRAPHQL_SMOKE_CLIENT_SECRET}"`. `entrypoint.sh` reads the value from the Compose secret mounted at `/run/secrets/keycloak-graphql-smoke-client-secret`, exports it, and execs `kc.sh start-dev --import-realm`, so the value never reaches Git, a rendered Compose config, a command line, or an evidence file. A realm file with a working credential in it is a credential in the repository, and "it is only for smoke tests" is not something a scanner or a fork can tell. ## No comment keys in the realm JSON Keycloak deserializes this file into `RealmRepresentation` with unknown fields **rejected**, not ignored. A `"_comment"` key here fails the whole import with `Unrecognized field "_comment"`, the container exits 1, and the lane fails on Keycloak rather than on anything it was testing. That is why this rationale lives in Markdown next to the artifact instead of inside it. ## What the realm grants - realm role `user` — the baseline role the application authorizes ordinary calls on - client role `ca-skeleton-api:graphql-query` — permission to execute a GraphQL query - a service account for the client-credentials grant the qualification lane uses - audience and realm/client role mappers, so the issued token carries what the resource server validates Standard flow and direct access grants are disabled: the lane authenticates as a service, and an enabled password grant is a second way in that nothing tests.