Z
ZITADEL
Z
ZITADEL
Reverse proxy - public gateway with custom domain
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
•
9/27/24, 11:22 AM
I have a hard time grasping how this architecture looks like
But yeah zitadel can be run behing proxies
, we do that all the time
.
There is even a list of config for different ones here
https://zitadel.com/docs/self-hosting/manage/reverseproxy/reverse_proxy
I think the challenge here is that you want to use a different domain to the outside world then your zitadel is configured to
, right
?
F
FFO
•
9/27/24, 11:35 AM
ok but to me that is just you set the externaldomain to my
-app
.com and set all the network appliances to forward that as a host header
F
FFO
•
9/27/24, 11:36 AM
To me it looks like your zitadel should act as my
-app
.com
, right
?
F
FFO
•
9/27/24, 11:37 AM
so like every other proxy
F
FFO
•
9/27/24, 11:37 AM
in that case setting the externaldomain to my
-app is the right thing to do
F
FFO
•
9/27/24, 11:38 AM
Yes
, but I guess you also want to run request internally to zitadel without going through the proxy
, or is that no correct
?
F
FFO
•
9/27/24, 11:39 AM
for that there would be two options
:
1
) your clients just set the host in the api calls to my
-app
2
) you add your internal domain with this api
https://zitadel.com/docs/apis/resources/system/system-service-add-domain
F
FFO
•
9/27/24, 11:41 AM
I mean you have also option 1
)
F
FFO
•
9/27/24, 11:41 AM
But to generate access for the system api you can look into this guide
https://zitadel.com/docs/guides/integrate/zitadel-apis/access-zitadel-system-api
S
spetz
but, if we were to reconfigure zitadel to use the same public domain, it will be...
F
FFO
•
9/27/24, 11:41 AM
only if you do 1 or 2
F
FFO
•
9/27/24, 11:42 AM
I would guess that you also have an internal proxy
, which could set the host to my
-app
F
FFO
•
9/27/24, 2:28 PM
What is the 400 response
?
If you increase the loglevel you should see the log in zitadel stdout as well
.
You can also enable this to log the http calls to stdout
https://github.com/zitadel/zitadel/blob/main/cmd/defaults.yaml#L609
F
FFO
•
10/1/24, 4:06 PM
Hm that is odd
, we have logging enabled in our cloud and it works
.
Can you share your config
?