fix: proxy.headers xforwarded not forwarded - Traefik sends X-Forwarded-* headers
Validate login GitOps repo / validate (push) Successful in 18s

Keycloak was seeing requests as non-secure (HTTP) because it was expecting
the RFC 7239 Forwarded: header but Traefik sends X-Forwarded-Proto/For/Host.
This caused CSP failures and cookie security warnings.
This commit is contained in:
2026-05-11 00:27:13 +01:00
parent 716ad61115
commit a2036c8381
@@ -42,7 +42,7 @@ spec:
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
proxy:
headers: forwarded
headers: xforwarded
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
bootstrapAdmin: