From a2036c838179c113821673b469e30fbe2cbe427f Mon Sep 17 00:00:00 2001 From: Nick Gorse Date: Mon, 11 May 2026 00:27:13 +0100 Subject: [PATCH] fix: proxy.headers xforwarded not forwarded - Traefik sends X-Forwarded-* headers Keycloak was seeing requests as non-secure (HTTP) because it was expecting the RFC 7239 Forwarded: header but Traefik sends X-Forwarded-Proto/For/Host. This caused CSP failures and cookie security warnings. --- manifest/overlays/production/keycloak-instance.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/manifest/overlays/production/keycloak-instance.yaml b/manifest/overlays/production/keycloak-instance.yaml index 7bacba1..13fe015 100644 --- a/manifest/overlays/production/keycloak-instance.yaml +++ b/manifest/overlays/production/keycloak-instance.yaml @@ -42,7 +42,7 @@ spec: # ── Proxy: trust forwarded headers from Traefik ────────────────────────── proxy: - headers: forwarded + headers: xforwarded # ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml) bootstrapAdmin: