# Zulip — Notes ## TLS-terminating reverse proxy configuration Zulip's internal nginx redirects port 80 → HTTPS by default. When Traefik terminates TLS and forwards plain HTTP internally, this causes an infinite redirect loop. Set these two env vars in the deployment: ```yaml - name: DISABLE_HTTPS value: "true" - name: LOADBALANCER_IPS value: "10.244.0.0/16" # Kubernetes pod CIDR ``` - `DISABLE_HTTPS=true`: configures nginx in `http_only` mode, removing the 80 → HTTPS redirect. - `LOADBALANCER_IPS`: trusts `X-Forwarded-Proto: https` from the pod CIDR so Zulip generates `https://` links instead of `http://`. Set to the cluster's pod network CIDR (typically `10.244.0.0/16` for Flannel). Also update liveness/readiness probes from port 443 HTTPS to port 80 HTTP when `DISABLE_HTTPS=true` is set. ## Root URL returns 404 — this is expected Zulip's root URL (`/`) returns 404 "No organization found" — this is correct behavior. The actual login page is at `/accounts/home/`.