keycloak: carry over HAL's hostname/proxy settings, dropped during conversion
Reported: files.novox.be's login button redirects to http://keycloak.novox.be, not https. HAL's original config (/services/keycloak/docker-compose.yml) set three settings the mesh's manifest never carried over: KC_HOSTNAME: keycloak.novox.be KC_HOSTNAME_STRICT_HTTPS: true KC_PROXY: edge Without KC_PROXY: edge, Keycloak has no way to know it sits behind a TLS-terminating reverse proxy (traefik) -- it generates URLs from what it directly sees, which is plain HTTP from traefik's backend connection. Same pattern as the named-volume conversion: the shape was rebuilt from general knowledge of what a keycloak container needs, not from what this installation's own working config actually had.
This commit is contained in:
@@ -88,7 +88,10 @@
|
||||
"env": {
|
||||
"KC_DB": "postgres",
|
||||
"KC_HTTP_ENABLED": "true",
|
||||
"KC_HEALTH_ENABLED": "true"
|
||||
"KC_HEALTH_ENABLED": "true",
|
||||
"KC_HOSTNAME": "keycloak.novox.be",
|
||||
"KC_HOSTNAME_STRICT_HTTPS": "true",
|
||||
"KC_PROXY": "edge"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/keycloak/admin.env",
|
||||
|
||||
Reference in New Issue
Block a user