keycloak: use Hostname v2's actual config shape, not v1's deprecated flags
The previous commit on this branch used KC_PROXY=edge and KC_HOSTNAME_STRICT_HTTPS=true, carried over from HAL's config -- but HAL ran an older Keycloak using the v1 hostname provider. This image (26.0.8) defaults to Hostname v2, which warned 'options [proxy, hostname-strict-https] are still in use, please review your configuration' and kept generating http:// URLs regardless -- verified against /realms/Novox/.well-known/openid-configuration directly, not just the login button, after the first fix deployed. v2's actual shape (keycloak.org/server/hostname): KC_HOSTNAME is a full URL, not a bare hostname -- the scheme in the URL is what tells Keycloak to generate https, not a separate strict-https flag. KC_PROXY_HEADERS replaces KC_PROXY: xforwarded to trust traefik's X-Forwarded-* headers, which it sends by default.
This commit is contained in:
@@ -89,9 +89,8 @@
|
||||
"KC_DB": "postgres",
|
||||
"KC_HTTP_ENABLED": "true",
|
||||
"KC_HEALTH_ENABLED": "true",
|
||||
"KC_HOSTNAME": "keycloak.novox.be",
|
||||
"KC_HOSTNAME_STRICT_HTTPS": "true",
|
||||
"KC_PROXY": "edge"
|
||||
"KC_HOSTNAME": "https://keycloak.novox.be",
|
||||
"KC_PROXY_HEADERS": "xforwarded"
|
||||
},
|
||||
"env-file": [
|
||||
"/var/lib/keycloak/admin.env",
|
||||
|
||||
Reference in New Issue
Block a user