Validate login GitOps repo / validate (push) Successful in 18s
Keycloak was seeing requests as non-secure (HTTP) because it was expecting the RFC 7239 Forwarded: header but Traefik sends X-Forwarded-Proto/For/Host. This caused CSP failures and cookie security warnings.