keycloak: carry over HAL's hostname/proxy settings, dropped during conversion

Reported: files.novox.be's login button redirects to http://keycloak.novox.be,
not https. HAL's original config (/services/keycloak/docker-compose.yml) set
three settings the mesh's manifest never carried over:

  KC_HOSTNAME: keycloak.novox.be
  KC_HOSTNAME_STRICT_HTTPS: true
  KC_PROXY: edge

Without KC_PROXY: edge, Keycloak has no way to know it sits behind a
TLS-terminating reverse proxy (traefik) -- it generates URLs from what it
directly sees, which is plain HTTP from traefik's backend connection. Same
pattern as the named-volume conversion: the shape was rebuilt from general
knowledge of what a keycloak container needs, not from what this
installation's own working config actually had.
This commit is contained in:
2026-09-24 17:25:16 +02:00
parent 61eb201f8a
commit 13d0361640
+4 -1
View File
@@ -88,7 +88,10 @@
"env": { "env": {
"KC_DB": "postgres", "KC_DB": "postgres",
"KC_HTTP_ENABLED": "true", "KC_HTTP_ENABLED": "true",
"KC_HEALTH_ENABLED": "true" "KC_HEALTH_ENABLED": "true",
"KC_HOSTNAME": "keycloak.novox.be",
"KC_HOSTNAME_STRICT_HTTPS": "true",
"KC_PROXY": "edge"
}, },
"env-file": [ "env-file": [
"/var/lib/keycloak/admin.env", "/var/lib/keycloak/admin.env",