From ed0f4602a68f1378b0cbe06239e14ae6d491f6e7 Mon Sep 17 00:00:00 2001 From: jochen Date: Thu, 24 Sep 2026 17:27:04 +0200 Subject: [PATCH] keycloak: use Hostname v2's actual config shape, not v1's deprecated flags The previous commit on this branch used KC_PROXY=edge and KC_HOSTNAME_STRICT_HTTPS=true, carried over from HAL's config -- but HAL ran an older Keycloak using the v1 hostname provider. This image (26.0.8) defaults to Hostname v2, which warned 'options [proxy, hostname-strict-https] are still in use, please review your configuration' and kept generating http:// URLs regardless -- verified against /realms/Novox/.well-known/openid-configuration directly, not just the login button, after the first fix deployed. v2's actual shape (keycloak.org/server/hostname): KC_HOSTNAME is a full URL, not a bare hostname -- the scheme in the URL is what tells Keycloak to generate https, not a separate strict-https flag. KC_PROXY_HEADERS replaces KC_PROXY: xforwarded to trust traefik's X-Forwarded-* headers, which it sends by default. --- modules/keycloak/module.json | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/modules/keycloak/module.json b/modules/keycloak/module.json index d65681a..44e0d44 100644 --- a/modules/keycloak/module.json +++ b/modules/keycloak/module.json @@ -89,9 +89,8 @@ "KC_DB": "postgres", "KC_HTTP_ENABLED": "true", "KC_HEALTH_ENABLED": "true", - "KC_HOSTNAME": "keycloak.novox.be", - "KC_HOSTNAME_STRICT_HTTPS": "true", - "KC_PROXY": "edge" + "KC_HOSTNAME": "https://keycloak.novox.be", + "KC_PROXY_HEADERS": "xforwarded" }, "env-file": [ "/var/lib/keycloak/admin.env",