diff --git a/infra/helm/big-reference/values.yaml b/infra/helm/big-reference/values.yaml index 20e7361..3effa75 100644 --- a/infra/helm/big-reference/values.yaml +++ b/infra/helm/big-reference/values.yaml @@ -275,6 +275,11 @@ workloads: # this issuer back, which is what browser tokens carry (infra/host-browser.yml). KC_HOSTNAME: '{{ include "big.keycloakUrl" . }}' KC_HOSTNAME_BACKCHANNEL_DYNAMIC: "true" + # Behind a TLS proxy (keycloakUrl) the dynamic backchannel URLs — token, + # userinfo, certs — take their scheme from the request, which reaches Keycloak + # as plain http; trusting X-Forwarded-Proto keeps them https so the browser + # doesn't block them as mixed content. In-cluster calls send no such header. + KC_PROXY_HEADERS: xforwarded ports: [{ name: http, port: 8080 }] # TCP, not /health/ready on the management port: nothing here gates on realm # import, and a wrong health path would leave the Service with no endpoints.