Trust external host for Auth.js, provide missing frontend auth env/secrets, and submit a proper CSRF-backed sign-in POST so browser login reaches Keycloak reliably.
14 lines
500 B
YAML
14 lines
500 B
YAML
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: workclub-secrets
|
|
type: Opaque
|
|
stringData:
|
|
database-connection-string: "Host=workclub-postgres;Database=workclub;Username=app;Password=devpassword"
|
|
postgres-password: "devpassword"
|
|
keycloak-db-password: "keycloakpass"
|
|
keycloak-admin-username: "admin"
|
|
keycloak-admin-password: "adminpassword"
|
|
keycloak-client-secret: "dev-secret-workclub-api-change-in-production"
|
|
nextauth-secret: "dev-secret-change-in-production-use-openssl-rand-base64-32"
|