2025-11-29 08:37:21 +00:00
|
|
|
http:
|
|
|
|
|
middlewares:
|
|
|
|
|
authentik:
|
|
|
|
|
forwardAuth:
|
2025-11-29 11:52:42 +00:00
|
|
|
# We gebruiken de Service Naam (server) ipv container naam.
|
|
|
|
|
# En we verwijderen de specifieke slug '/traefik' aan het einde.
|
|
|
|
|
# Hierdoor kijkt Authentik naar de domeinnaam van het verzoek om te bepalen welke app het is.
|
|
|
|
|
address: "http://authentik-server-1:9000/outpost.goauthentik.io/auth/layer"
|
|
|
|
|
|
2025-11-29 08:37:21 +00:00
|
|
|
trustForwardHeader: true
|
2025-11-29 12:10:54 +00:00
|
|
|
# STUUR DE X-Forwarded-Proto HEADER MEE. Dit lost de redirect-lus op.
|
|
|
|
|
authRequestHeaders:
|
|
|
|
|
- "X-Forwarded-Proto"
|
|
|
|
|
|
|
|
|
|
# De headers die Authentik terugstuurt na succesvolle authenticatie
|
2025-11-29 08:37:21 +00:00
|
|
|
authResponseHeaders:
|
|
|
|
|
- "X-authentik-username"
|
|
|
|
|
- "X-authentik-groups"
|
|
|
|
|
- "X-authentik-email"
|
|
|
|
|
- "X-authentik-name"
|
|
|
|
|
- "X-authentik-uid"
|
|
|
|
|
- "X-authentik-jwt"
|
|
|
|
|
- "X-authentik-meta-jwks"
|
|
|
|
|
- "X-authentik-meta-outpost"
|
|
|
|
|
- "X-authentik-meta-provider"
|
|
|
|
|
- "X-authentik-meta-app"
|
2025-11-29 11:47:31 +00:00
|
|
|
- "X-authentik-meta-version"
|
2025-11-29 12:10:54 +00:00
|
|
|
- "Set-Cookie"
|
|
|
|
|
|
|
|
|
|
# Optioneel: middleware om HTTP verkeer geforceerd naar HTTPS te sturen
|
|
|
|
|
redirect-to-https:
|
|
|
|
|
redirectScheme:
|
|
|
|
|
scheme: "https"
|
|
|
|
|
permanent: true
|