Keycloak realm artifact
realms/ca-skeleton-realm.json is imported by the keycloak service in docker-compose.infra.yml
and is the same realm every GraphQL qualification lane authenticates against.
The client secret is a reference, never a value
The confidential client ca-skeleton-api carries "secret": "${KEYCLOAK_GRAPHQL_SMOKE_CLIENT_SECRET}".
entrypoint.sh reads the value from the Compose secret mounted at
/run/secrets/keycloak-graphql-smoke-client-secret, exports it, and execs kc.sh start-dev --import-realm, so the value never reaches Git, a rendered Compose config, a command line, or an
evidence file. A realm file with a working credential in it is a credential in the repository, and
"it is only for smoke tests" is not something a scanner or a fork can tell.
No comment keys in the realm JSON
Keycloak deserializes this file into RealmRepresentation with unknown fields rejected, not
ignored. A "_comment" key here fails the whole import with Unrecognized field "_comment", the
container exits 1, and the lane fails on Keycloak rather than on anything it was testing. That is
why this rationale lives in Markdown next to the artifact instead of inside it.
What the realm grants
- realm role
user— the baseline role the application authorizes ordinary calls on - client role
ca-skeleton-api:graphql-query— permission to execute a GraphQL query - a service account for the client-credentials grant the qualification lane uses
- audience and realm/client role mappers, so the issued token carries what the resource server validates
Standard flow and direct access grants are disabled: the lane authenticates as a service, and an enabled password grant is a second way in that nothing tests.