# TomEE App + Keycloak in K8's cluster

**URL:** <https://forum.keycloak.org/t/tomee-app-keycloak-in-k8s-cluster/5239>\
**Category:** Securing applications\
**Created:** [October 8, 2020, 7:21am UTC](https://forum.keycloak.org/t/tomee-app-keycloak-in-k8s-cluster/5239 "2020-10-08T07:21:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zeppelinux](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zeppelinux/32/1876_2.png) [@zeppelinux](https://forum.keycloak.org/u/zeppelinux)\
**Post date:** [October 8, 2020, 7:21am UTC](https://forum.keycloak.org/t/tomee-app-keycloak-in-k8s-cluster/5239/1 "2020-10-08T07:21:08Z")

</div>

Hi All,

I’m trying to secure TomEE(Tomcat) web app originally running on port 80 (no SSL) and load balanced by Nginx Ingress Controller which provides SSL (integrated with Lets Encrypt) and serves requests on port 443 (SSL termination by Ingress Controller). The ingress configures [https://my.web-app.com](https://my.web-app.com) url.

When I’m setting “ssl-required”: “all” in the adapter keycloak.json - I’m getting 403 error page and can see the error in the app log:

`ERROR [http-nio-8080-exec-9] org.keycloak.adapters.OAuthRequestAuthenticator.resolveCode Adapter requires SSL. Request: http://my.web-app.com/?state=50292394-981e-4c17-a9dc-e19c92256d66&session_state=1af28e7c-7c99-442e-906f-4fe9b04b25e5&code=e9756952-addb-4ee1-8edd-e039339f49a5.1af28e7c-7c99-442e-906f-4fe9b04b25e5.c0e25ffa-7230-4714-a15a-5849431b4622`

Note the https:// changed to http:// in the request (probably because Tomee serves requests using http not https, but I’m not sure)

Setting “ssl-required”: “external” makes it work - the secured page is loaded, despite that I still see the http:// in redirect\_uri sent to keycloak by adapter.  
Also, I had to change the ‘Valid Redirect URIs’ in the keycloak admin UI to http://, otherwise (when it was https://) it failed with ‘Invalid parameter: redirect\_uri’ message.

Is it normal or I’m doing something wrong?

Thanks!

---

<div class="post-metadata">

**Author:** ![jsplate](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@jsplate](https://forum.keycloak.org/u/jsplate)\
**Post date:** [January 4, 2023, 4:17pm UTC](https://forum.keycloak.org/t/tomee-app-keycloak-in-k8s-cluster/5239/2 "2023-01-04T16:17:09Z")

</div>

Did you solve this as you got no answer here?  
I have the same problem?  
After having logged in to my tomcat app I see the URL of my app with https://… but then I get an error 403 and the logs show `Adapter requires SSL`

I also tried the same as you but I think using an http-redirect URI is not the correct way.

---

<div class="post-metadata">

**Author:** ![zeppelinux](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zeppelinux/32/1876_2.png) [@zeppelinux](https://forum.keycloak.org/u/zeppelinux)\
**Post date:** [January 4, 2023, 5:36pm UTC](https://forum.keycloak.org/t/tomee-app-keycloak-in-k8s-cluster/5239/3 "2023-01-04T17:36:00Z")

</div>

I ended up porting the app to Quarkus.
