--- apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: name: keycloak-auth spec: forwardAuth: address: http://oauth2-proxy.oauth2-proxy.svc:80 trustForwardHeader: true authResponseHeaders: - X-Auth-Request-User - X-Auth-Request-Email - X-Auth-Request-Groups --- apiVersion: traefik.io/v1alpha1 kind: IngressRoute metadata: name: secret-reader annotations: cert-manager.io/cluster-issuer: letsencrypt spec: entryPoints: - websecure routes: - match: Host(`secret-reader.hexor.cy`) kind: Rule middlewares: - name: keycloak-auth services: - name: secret-reader port: 80 tls: secretName: secret-reader-tls --- apiVersion: cert-manager.io/v1 kind: Certificate metadata: name: secret-reader-tls spec: secretName: secret-reader-tls issuerRef: name: letsencrypt kind: ClusterIssuer dnsNames: - secret-reader.hexor.cy