fix(k8s): keep Keycloak's backchannel URLs https behind the labs Caddy (refs #177)
CI / lint (pull_request) Successful in 1m44s
CI / k8s (pull_request) Successful in 9s
CI / build (pull_request) Successful in 1m21s
CI / unit (pull_request) Successful in 1m31s
CI / frontend (pull_request) Successful in 2m31s
CI / mutation (pull_request) Successful in 4m47s
CI / verify-stack (pull_request) Successful in 20m11s
CI / lint (pull_request) Successful in 1m44s
CI / k8s (pull_request) Successful in 9s
CI / build (pull_request) Successful in 1m21s
CI / unit (pull_request) Successful in 1m31s
CI / frontend (pull_request) Successful in 2m31s
CI / mutation (pull_request) Successful in 4m47s
CI / verify-stack (pull_request) Successful in 20m11s
KC_HOSTNAME_BACKCHANNEL_DYNAMIC builds the token/userinfo/certs URLs from the request, which reaches Keycloak as plain http through the proxy, so browsers blocked them as mixed content after login. Trust X-Forwarded-Proto. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -286,6 +286,11 @@ workloads:
|
||||
# Only rendered with demo.otpAutofill (big.env skips empty values); off, Keycloak
|
||||
# keeps its stock theme and the mounted big-demo theme is unused.
|
||||
KC_SPI_THEME_DEFAULT: '{{ if .Values.demo.otpAutofill }}big-demo{{ end }}'
|
||||
# Behind a TLS proxy (keycloakUrl) the dynamic backchannel URLs — token,
|
||||
# userinfo, certs — take their scheme from the request, which reaches Keycloak
|
||||
# as plain http; trusting X-Forwarded-Proto keeps them https so the browser
|
||||
# doesn't block them as mixed content. In-cluster calls send no such header.
|
||||
KC_PROXY_HEADERS: xforwarded
|
||||
ports: [{ name: http, port: 8080 }]
|
||||
# TCP, not /health/ready on the management port: nothing here gates on realm
|
||||
# import, and a wrong health path would leave the Service with no endpoints.
|
||||
|
||||
Reference in New Issue
Block a user