# Lab entry point. Deployed on the lab host as # /etc/nginx/sites-available/keycloak-lab # and symlinked from sites-enabled/. # # Arch does not ship the Debian sites-available convention, so nginx.conf needs # include /etc/nginx/sites-enabled/*; # inside its http { } block before this file has any effect. # # This is the outer of two L7 hops. It terminates TLS and hands plain HTTP to # the Traefik instance running on each k3s node. upstream k3s_traefik { # Sticky-session switch. Keycloak recommends affinity on AUTH_SESSION_ID; # ip_hash is the cheap stand-in for a single-browser lab. Leaving it off is # the interesting case: Infinispan still routes correctly, only slower. # ip_hash; server 192.168.122.11:80; server 192.168.122.12:80; } server { listen 80 default_server; server_name _; return 301 https://$host$request_uri; } server { listen 443 ssl default_server; http2 on; server_name _; # fullchain.pem, never cert.pem: omitting the intermediates passes on # desktop browsers and fails on mobile and curl. ssl_certificate /etc/letsencrypt/live/auth.hyeonworks.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/auth.hyeonworks.com/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; location / { proxy_pass http://k3s_traefik; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Proto https; proxy_set_header X-Forwarded-Port 443; # $remote_addr, not $proxy_add_x_forwarded_for. This is the trust # boundary: a client-supplied X-Forwarded-For must be discarded, not # extended, or nothing downstream can rely on the value. proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Real-IP $remote_addr; proxy_read_timeout 3600s; proxy_send_timeout 3600s; } }