feat(synapse): update ingress to use traefik ingress class and bump version feat(syncthing-discovery): introduce syncthing discovery service with deployment and ingress feat(syncthing-relay): add syncthing relay server with deployment and ingress configuration fix(taiga): update liveness and readiness probes to use tcpSocket for health checks fix(taiga): change PVC access mode to ReadWriteMany for media and static storage feat(traefik): add icon and ignore rules for traefik service docs(ushahidi): add notes for Redis configuration and Laravel startup probe adjustments feat(ushahidi): implement dedicated Redis deployment for Ushahidi fix(vllm): update deployment strategy and readiness/liveness probes for improved stability fix(writefreely): pin writefreely image version to v0.15.1 for consistency docs(zulip): add notes for TLS-terminating reverse proxy configuration and expected behavior
1006 B
1006 B
Zulip — Notes
TLS-terminating reverse proxy configuration
Zulip's internal nginx redirects port 80 → HTTPS by default. When Traefik terminates TLS and forwards plain HTTP internally, this causes an infinite redirect loop.
Set these two env vars in the deployment:
- name: DISABLE_HTTPS
value: "true"
- name: LOADBALANCER_IPS
value: "10.244.0.0/16" # Kubernetes pod CIDR
DISABLE_HTTPS=true: configures nginx inhttp_onlymode, removing the 80 → HTTPS redirect.LOADBALANCER_IPS: trustsX-Forwarded-Proto: httpsfrom the pod CIDR so Zulip generateshttps://links instead ofhttp://. Set to the cluster's pod network CIDR (typically10.244.0.0/16for Flannel).
Also update liveness/readiness probes from port 443 HTTPS to port 80 HTTP when
DISABLE_HTTPS=true is set.
Root URL returns 404 — this is expected
Zulip's root URL (/) returns 404 "No organization found" — this is correct behavior.
The actual login page is at /accounts/home/.