fix(authentik): resolve Traefik 500 from upstream TLS verification #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/traefik-authentik-upstream"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Fix the HTTP 500 from the SSO service exposure on
shel1svc00. Traefik verifies the Authentik HTTPS certificate against the container IP and rejects it because it has no matching IP SAN. Verification using the public hostname also fails because the certificate has expired.Add a target-specific smoke check and document the routing and validation command.
Evidence
bash scripts/check-traefik.sh shel1svc00.s1q.devfails with HTTP 500. The matching live Traefik log reports the x509 IP SAN error forhttps://10.89.2.2:9443.After:
bash scripts/check-traefik.sh shel1svc00.s1q.devpasses against the deployed target with HTTP 302 at/and HTTP 200 after following the login redirect. Komodo recreated the server with upstream labelsport=9000andscheme=http. A local replay with Traefik 3.7.8 also changed from HTTP 500 to HTTP 302.git diff --checkpass. The smoke check passes against the existing public server.Merge Danger
Door: two-way
Revert the routing labels to roll back. The merge triggers the managed Komodo deployment and may briefly interrupt the target Authentik server while it is recreated.
Blast Radius: SSO
Traefik terminates client TLS; upstream traffic uses HTTP on the trusted project frontend network.