feat: define trusted reverse proxy header contract

This commit is contained in:
donghyeon-ka
2026-07-25 16:29:32 +09:00
parent 3473875d9a
commit 8539d1bf5b
4 changed files with 53 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
#!/usr/bin/env sh
set -eu
config=deploy/reverse-proxy/nginx-keycloak.conf
env_file=deploy/reverse-proxy/keycloak.env.example
grep -q 'proxy_set_header X-Forwarded-Host' "$config"
grep -q 'proxy_set_header X-Forwarded-Port 443' "$config"
grep -q 'proxy_set_header X-Forwarded-Proto https' "$config"
grep -q '^KC_PROXY_HEADERS=xforwarded$' "$env_file"
grep -q '^KC_HOSTNAME=https://' "$env_file"
docker run --rm \
--add-host keycloak:127.0.0.1 \
-v "$PWD/$config:/etc/nginx/conf.d/default.conf:ro" \
nginx:1.29-alpine nginx -t
echo "Reverse-proxy header and Keycloak hostname contracts verified"