Files
Homelabv4/infrastructure/vps-standby/nextcloud/manifests/ingress.yaml
T
Scooby HuskyandClaude Sonnet 5 220cdfb00a VPS-standby: force HTTPS redirect on all 5 Traefik ingresses
Root cause of the Vault OIDC 'Missing auth_url' error (and the same
symptom on every other VPS-standby app): the Ingress tls: block makes
HTTPS available but Traefik still serves plain HTTP on the same host too
- nothing was forcing the redirect. A browser landing on
http://vault.vps.huskypup.net gets a Vault UI that computes its OIDC
callback using window.location.origin (http://...), which doesn't match
the https:// entry in allowed_redirect_uris - Vault silently returns an
empty auth_url rather than an obviously-config-looking error. Confirmed
via a HAR capture of the actual failing browser request.

Adds a per-namespace Traefik Middleware (redirectScheme -> https,
permanent) referenced via router.middlewares on each Ingress. Applied
directly via kubectl first to test - ArgoCD's selfHeal immediately
reverted it since it wasn't in git yet, confirming the fix needs to ship
through the normal pipeline rather than live kubectl edits on ArgoCD-
managed VPS resources.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-20 20:58:40 -05:00

41 lines
1.1 KiB
YAML

---
# See infrastructure/vps-standby/vault/manifests/ingress.yaml for the
# vps.huskypup.net subdomain design rationale, and for why this
# https-redirect Middleware is needed (found live 2026-08-21 diagnosing
# the exact same symptom on this app's OIDC login).
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: https-redirect
namespace: nextcloud
spec:
redirectScheme:
scheme: https
permanent: true
---
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: vps-nextcloud
namespace: nextcloud
annotations:
cert-manager.io/cluster-issuer: letsencrypt-production
traefik.ingress.kubernetes.io/router.middlewares: nextcloud-https-redirect@kubernetescrd
spec:
ingressClassName: traefik
tls:
- hosts:
- nextcloud.vps.huskypup.net
secretName: vps-nextcloud-tls
rules:
- host: nextcloud.vps.huskypup.net
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: vps-nextcloud
port:
number: 8080