Hermes Agent b2cca91b6b hermes: derive the oauth2-proxy callback from the request host
Restoring the legacy chat/triage hosts is not enough on its own: both
proxies pinned --redirect-url to the renamed host, and oauth2-proxy
returns that value verbatim whenever it carries a host
(getOAuthRedirectURI short-circuits on redirectURL.Host != ""). A login
started on a legacy host would therefore send the browser to the
canonical host's callback, while the CSRF cookie stays behind: it is
issued with the __Host- prefix, which forbids a Domain attribute and
pins it to the exact origin. The callback lands without it and fails as
"unable to find a valid CSRF token".

Drop the host from both callback URLs so oauth2-proxy builds them from
the request host instead. For the renamed hosts the derived value is
byte-identical to the pinned one, so their behaviour is unchanged; the
legacy hosts now complete a login on the host the user actually visited.
Derivation reads X-Forwarded-Host only behind a trusted reverse proxy,
which both deployments already declare, and Keycloak still matches the
result against the redirect URIs registered by the ensure script.

The agent proxy keeps its pinned callback: it serves one host.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 09:09:54 +00:00

titan-iac

Flux-managed Kubernetes desired-state config for bstein.dev.

Canonical source URL:

  • ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git

Scope

This repo contains cluster configuration consumed by Flux:

  • platform/infrastructure manifests
  • service manifests and kustomizations
  • operational scripts for render/reconcile workflows

Apply model

I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.

Description
No description provided
Readme 17 MiB
Languages
Python 74%
JavaScript 10.2%
Shell 6.2%
TypeScript 3.9%
Go 2.1%
Other 3.4%