Conan Scott d120db533a fix(route): inject Origin header for native app canvas WebSocket auth
Native iOS/macOS apps do not send an Origin header in WebSocket connections.
The gateway checkBrowserOrigin() fails immediately on null origin before any
allowedOrigins check can run. Injecting Origin at the HAProxy ingress level
gives the gateway a valid origin to validate against the existing allowedOrigins
list (https://openclaw.apps.lab.apilab.us).

Related: openclaw/openclaw#24055, #35030, #35109
2026-03-13 07:22:42 +00:00
2026-01-30 10:18:11 +00:00

openclaw (OpenShift)

GitOps repo for deploying OpenClaw into the openclaw namespace.

Layout:

  • bootstrap/ ArgoCD Application (apply manually once)
  • manifests/ Namespace + workload resources (ArgoCD-managed)

Target:

  • Namespace: openclaw
  • Route host: openclaw.apps.lab.apilab.us
  • Image: default-route-openshift-image-registry.apps.lab.apilab.us/openclaw/openclaw:latest
  • Gateway port: 18789

Notes:

  • This repo intentionally does not deploy TEI; it assumes the existing service: http://text-embeddings.tei.svc.cluster.local:8080/v1/
Description
Repo for openclaw configuration
Readme 53 KiB