-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathingress-keycloak-example.yaml
65 lines (65 loc) · 1.79 KB
/
ingress-keycloak-example.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
apiVersion: v1
kind: Service
metadata:
name: external-keycloak
spec:
ports:
- name: https
port: 8443
targetPort: 8443
---
apiVersion: discovery.k8s.io/v1
kind: EndpointSlice
metadata:
name: external-keycloak-1
labels:
kubernetes.io/service-name: external-keycloak
addressType: IPv4
ports:
- name: ''
appProtocol: http
protocol: TCP
port: 8443
endpoints:
- addresses:
- "172.17.0.1"
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: external-keycloak
annotations:
kubernetes.io/ingress.class: "nginx"
nginx.ingress.kubernetes.io/backend-protocol: "HTTPS"
nginx.ingress.kubernetes.io/proxy-buffer-size: "16k"
nginx.ingress.kubernetes.io/proxy-buffers-number: "4"
nginx.ingress.kubernetes.io/proxy-busy-buffers-size: "24k"
nginx.ingress.kubernetes.io/proxy-request-buffering: "off"
nginx.ingress.kubernetes.io/proxy-read-timeout: "180s"
nginx.ingress.kubernetes.io/proxy-send-timeout: "180s"
nginx.ingress.kubernetes.io/proxy-connect-timeout: "180s"
nginx.ingress.kubernetes.io/configuration-snippet: |
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Port $server_port;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Server $host;
proxy_set_header X-Forwarded-Uri $request_uri;
spec:
tls:
- hosts:
- $KEYCLOAK_EXTERNAL_URL
secretName: tls-keycloak-ingress
rules:
- host: $KEYCLOAK_EXTERNAL_URL
http:
paths:
- pathType: Prefix
path: "/"
backend:
service:
name: external-keycloak
port:
number: 8443