I am using a dockerized version of Crowd which is sitting behind a Traefik reverse proxy.
Everything works fine except for one thing: I have a third party application that uses Crowd for identity management and I have added it as an application and added the external IP address of the third party application in the Remote Addresses tab.
However, Crowd blocks the authentication requests with this message:
> INFO [crowd.manager.validation.ClientValidationManagerImpl] Client with address '172.25.0.4' is forbidden from making requests to application 'x x x'
172.25.0.4 is the IP address of the reverse proxy in the internal Docker network.
What changes do I have to make so that Crowd is able to know the original IP address? Is there a header that Traefik should set or something similar?