diff --git a/infra/helm/big-reference/values.yaml b/infra/helm/big-reference/values.yaml index 1fb687f..2ef6cda 100644 --- a/infra/helm/big-reference/values.yaml +++ b/infra/helm/big-reference/values.yaml @@ -286,6 +286,11 @@ workloads: # Only rendered with demo.otpAutofill (big.env skips empty values); off, Keycloak # keeps its stock theme and the mounted big-demo theme is unused. KC_SPI_THEME_DEFAULT: '{{ if .Values.demo.otpAutofill }}big-demo{{ end }}' + # Behind a TLS proxy (keycloakUrl) the dynamic backchannel URLs — token, + # userinfo, certs — take their scheme from the request, which reaches Keycloak + # as plain http; trusting X-Forwarded-Proto keeps them https so the browser + # doesn't block them as mixed content. In-cluster calls send no such header. + KC_PROXY_HEADERS: xforwarded ports: [{ name: http, port: 8080 }] # TCP, not /health/ready on the management port: nothing here gates on realm # import, and a wrong health path would leave the Service with no endpoints.