fix: proxy.headers xforwarded not forwarded - Traefik sends X-Forwarded-* headers
Validate login GitOps repo / validate (push) Successful in 18s
Validate login GitOps repo / validate (push) Successful in 18s
Keycloak was seeing requests as non-secure (HTTP) because it was expecting the RFC 7239 Forwarded: header but Traefik sends X-Forwarded-Proto/For/Host. This caused CSP failures and cookie security warnings.
This commit is contained in:
@@ -42,7 +42,7 @@ spec:
|
|||||||
|
|
||||||
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
|
# ── Proxy: trust forwarded headers from Traefik ──────────────────────────
|
||||||
proxy:
|
proxy:
|
||||||
headers: forwarded
|
headers: xforwarded
|
||||||
|
|
||||||
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
|
# ── Bootstrap admin credentials (sealed secret — see admin.sealed.secret.yaml)
|
||||||
bootstrapAdmin:
|
bootstrapAdmin:
|
||||||
|
|||||||
Reference in New Issue
Block a user