diff --git a/etc/bento_post_config.bash b/etc/bento_post_config.bash index fc746a03..3002ba4b 100644 --- a/etc/bento_post_config.bash +++ b/etc/bento_post_config.bash @@ -5,11 +5,9 @@ if [[ "$BENTO_GATEWAY_USE_TLS" == 'true' || "$BENTO_GATEWAY_USE_TLS" == '1' ]]; KC_HTTP_ENABLED='false' KC_HTTPS_CERTIFICATE_FILE=/run/secrets/keycloak-cert-file KC_HTTPS_CERTIFICATE_KEY_FILE=/run/secrets/keycloak-cert-key-file - KC_PROXY='passthrough' else # Disable TLS in keycloak KC_HOSTNAME=https://${BENTOV2_AUTH_DOMAIN} # full URL with HTTPS when KC_HTTP_ENABLED=true KC_HTTP_ENABLED='true' # Required for TLS termination at the proxy - KC_PROXY='edge' KC_PROXY_HEADERS=xforwarded # xforwarded (non-standard) instead of forwarded (RFC7239) for NGINX compatibility fi diff --git a/lib/auth/docker-compose.auth.yaml b/lib/auth/docker-compose.auth.yaml index 6c6dc3bf..f3769276 100644 --- a/lib/auth/docker-compose.auth.yaml +++ b/lib/auth/docker-compose.auth.yaml @@ -28,7 +28,6 @@ services: - KC_HTTP_ENABLED - KC_HTTPS_CERTIFICATE_FILE - KC_HTTPS_CERTIFICATE_KEY_FILE - - KC_PROXY - KC_PROXY_HEADERS mem_limit: ${BENTOV2_AUTH_MEM_LIM} # for mem_limit to work, make sure docker-compose is v2.4 cpus: ${BENTOV2_AUTH_CPUS}