From 13d036164001a5ed148a4a5ca34ac169f2aa6a85 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 17:25:16 +0200 Subject: [PATCH] keycloak: carry over HAL's hostname/proxy settings, dropped during conversion Reported: files.novox.be's login button redirects to http://keycloak.novox.be, not https. HAL's original config (/services/keycloak/docker-compose.yml) set three settings the mesh's manifest never carried over: KC_HOSTNAME: keycloak.novox.be KC_HOSTNAME_STRICT_HTTPS: true KC_PROXY: edge Without KC_PROXY: edge, Keycloak has no way to know it sits behind a TLS-terminating reverse proxy (traefik) -- it generates URLs from what it directly sees, which is plain HTTP from traefik's backend connection. Same pattern as the named-volume conversion: the shape was rebuilt from general knowledge of what a keycloak container needs, not from what this installation's own working config actually had. --- modules/keycloak/module.json | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index 04e6341..d65681a 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -88,7 +88,10 @@ "env": { "KC_DB": "postgres", "KC_HTTP_ENABLED": "true", - "KC_HEALTH_ENABLED": "true" + "KC_HEALTH_ENABLED": "true", + "KC_HOSTNAME": "keycloak.novox.be", + "KC_HOSTNAME_STRICT_HTTPS": "true", + "KC_PROXY": "edge" }, "env-file": [ "/var/lib/keycloak/admin.env",