blumeops/docs/changelog.d
Erich Blume 1f0308bbd2 Fix Caddy v2.11 Host header rewrite breaking proxied services
Caddy v2.11 (#7454) auto-rewrites the Host header to match the
upstream address for HTTPS backends. This causes services behind
Tailscale Ingress to see *.tail8d86e.ts.net instead of *.ops.eblu.me,
breaking Authentik OAuth flows, Homepage host validation, and other
services that check the Host header.

Only apply header_up for HTTPS backends (Tailscale Ingress); HTTP
backends (forge, registry, jellyfin, sifaka) are unaffected.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-15 18:28:18 -07:00
..
+caddy-v2.11-host-header.bugfix.md Fix Caddy v2.11 Host header rewrite breaking proxied services 2026-03-15 18:28:18 -07:00
.gitkeep Add towncrier changelog system (#86) 2026-02-03 11:48:13 -08:00
externalize-tailscale-operator-base.infra.md Externalize Tailscale operator to forge mirror (#295) 2026-03-15 17:44:35 -07:00
feature-caddy-upgrade-v2.11.2.infra.md Upgrade Caddy v2.10.2 → v2.11.2, fix forge mirrors (#294) 2026-03-15 10:33:48 -07:00