apiVersion: k8s.keycloak.org/v2alpha1 kind: Keycloak metadata: name: keycloak-server spec: instances: 1 db: vendor: postgres host: postgres-db usernameSecret: name: keycloak-db-secret key: username passwordSecret: name: keycloak-db-secret key: password http: tlsSecret: keycloak-tls-secret hostname: hostname: keycloak.grxe.io proxy: headers: xforwarded # double check your reverse proxy sets and overwrites the X-Forwarded-* headers