Summary
As of today, Keycloak Operator adds Kubernetes CA to the Truststore. This capability is not provided by the server and is a foundation layer for obtaining the Kubernetes JWKS and validating tokens using Signed JWT Client Authenticator.
Keycloak ticket: keycloak/keycloak#42900