fix(authentik): resolve Traefik 500 from upstream TLS verification #1

Merged
phg merged 1 commit from fix/traefik-authentik-upstream into main 2026-10-07 11:21:13 +00:00
Owner

Summary

Fix the HTTP 500 from the SSO service exposure on shel1svc00. Traefik verifies the Authentik HTTPS certificate against the container IP and rejects it because it has no matching IP SAN. Verification using the public hostname also fails because the certificate has expired.

 Traefik terminates client TLS
-  -> Authentik HTTPS :9443
+  -> Authentik HTTP :9000 on the private frontend network

Add a target-specific smoke check and document the routing and validation command.

Evidence

  • Before: bash scripts/check-traefik.sh shel1svc00.s1q.dev fails with HTTP 500. The matching live Traefik log reports the x509 IP SAN error for https://10.89.2.2:9443.
    After: bash scripts/check-traefik.sh shel1svc00.s1q.dev passes against the deployed target with HTTP 302 at / and HTTP 200 after following the login redirect. Komodo recreated the server with upstream labels port=9000 and scheme=http. A local replay with Traefik 3.7.8 also changed from HTTP 500 to HTTP 302.
  • Compose validation with dummy secret inputs, shell syntax validation, and git diff --check pass. The smoke check passes against the existing public server.
  • Managed Komodo deployment and the original target smoke check completed successfully after merge.

Merge Danger

Door: two-way

Revert the routing labels to roll back. The merge triggers the managed Komodo deployment and may briefly interrupt the target Authentik server while it is recreated.

Blast Radius: SSO

Traefik terminates client TLS; upstream traffic uses HTTP on the trusted project frontend network.

## Summary Fix the HTTP 500 from the SSO service exposure on `shel1svc00`. Traefik verifies the Authentik HTTPS certificate against the container IP and rejects it because it has no matching IP SAN. Verification using the public hostname also fails because the certificate has expired. ```diff Traefik terminates client TLS - -> Authentik HTTPS :9443 + -> Authentik HTTP :9000 on the private frontend network ``` Add a target-specific smoke check and document the routing and validation command. ## Evidence - **Before:** `bash scripts/check-traefik.sh shel1svc00.s1q.dev` fails with HTTP 500. The matching live Traefik log reports the x509 IP SAN error for `https://10.89.2.2:9443`. **After:** `bash scripts/check-traefik.sh shel1svc00.s1q.dev` passes against the deployed target with HTTP 302 at `/` and HTTP 200 after following the login redirect. Komodo recreated the server with upstream labels `port=9000` and `scheme=http`. A local replay with Traefik 3.7.8 also changed from HTTP 500 to HTTP 302. - Compose validation with dummy secret inputs, shell syntax validation, and `git diff --check` pass. The smoke check passes against the existing public server. - Managed Komodo deployment and the original target smoke check completed successfully after merge. ## Merge Danger **Door:** two-way Revert the routing labels to roll back. The merge triggers the managed Komodo deployment and may briefly interrupt the target Authentik server while it is recreated. **Blast Radius:** SSO Traefik terminates client TLS; upstream traffic uses HTTP on the trusted project frontend network.
Traefik fails with HTTP 500 when validating the Authentik HTTPS certificate against the container IP. The certificate also fails verification with the public hostname because it has expired. Route over HTTP port 9000 on the private frontend network after client TLS terminates at Traefik, and add a target-specific smoke check.
phg merged commit 8e7ef04d0a into main 2026-10-07 11:21:13 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
docker-compose/authentik!1
No description provided.