Files
wild-directory/zulip/notes.md
Paul Payne 4d983819c9 feat(supabase): add services and statefulset for database management
feat(synapse): update ingress to use traefik ingress class and bump version

feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress

feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration

fix(taiga): update liveness and readiness probes to use tcpSocket for health checks

fix(taiga): change PVC access mode to ReadWriteMany for media and static storage

feat(traefik): add icon and ignore rules for traefik service

docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments

feat(ushahidi): implement dedicated Redis deployment for Ushahidi

fix(vllm): update deployment strategy and readiness/liveness probes for improved stability

fix(writefreely): pin writefreely image version to v0.15.1 for consistency

docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
2026-07-02 21:34:27 +00:00

1006 B

Zulip — Notes

TLS-terminating reverse proxy configuration

Zulip's internal nginx redirects port 80 → HTTPS by default. When Traefik terminates TLS and forwards plain HTTP internally, this causes an infinite redirect loop.

Set these two env vars in the deployment:

- name: DISABLE_HTTPS
  value: "true"
- name: LOADBALANCER_IPS
  value: "10.244.0.0/16"  # Kubernetes pod CIDR
  • DISABLE_HTTPS=true: configures nginx in http_only mode, removing the 80 → HTTPS redirect.
  • LOADBALANCER_IPS: trusts X-Forwarded-Proto: https from the pod CIDR so Zulip generates https:// links instead of http://. Set to the cluster's pod network CIDR (typically 10.244.0.0/16 for Flannel).

Also update liveness/readiness probes from port 443 HTTPS to port 80 HTTP when DISABLE_HTTPS=true is set.

Root URL returns 404 — this is expected

Zulip's root URL (/) returns 404 "No organization found" — this is correct behavior. The actual login page is at /accounts/home/.