Fix caddy forward_auth settings for authentik
The snippet will now set the correct Host for the next hop and keep the original site in the X-Forward-Auth-Host. The authentik caddy-site will then put the X-Forward-Auth-Host into the X-Forwarded-Host (which would normally be the authentik host/domain). Authentik is able to handle the X-Forwarded-Host header.
This commit is contained in:
		
							parent
							
								
									5d22308f0f
								
							
						
					
					
						commit
						9af19f51fa
					
				
					 5 changed files with 16 additions and 10 deletions
				
			
		|  | @ -2,6 +2,7 @@ | |||
| authentik_svc: | ||||
|   domain: "{{ all_services | service_get_domain(role_name) }}" | ||||
|   port: 9000 | ||||
|   caddy_proxy_extra: "header_up X-Forwarded-Host {http.request.header.X-Forward-Auth-Host}" | ||||
|   image_tag: 2025.2 | ||||
|   db: | ||||
|     host: "{{ postgres.host }}" | ||||
|  |  | |||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue