diff --git a/nixos/modules/services/web-apps/keycloak.nix b/nixos/modules/services/web-apps/keycloak.nix
index b0cd1de0d41a..32c6f35e81c5 100644
--- a/nixos/modules/services/web-apps/keycloak.nix
+++ b/nixos/modules/services/web-apps/keycloak.nix
@@ -54,7 +54,11 @@ in
frontendUrl = lib.mkOption {
type = lib.types.str;
- apply = x: if lib.hasSuffix "/" x then x else x + "/";
+ apply = x:
+ if x == "" || lib.hasSuffix "/" x then
+ x
+ else
+ x + "/";
example = "keycloak.example.com/auth";
description = ''
The public URL used as base for all frontend requests. Should
diff --git a/nixos/modules/services/web-apps/keycloak.xml b/nixos/modules/services/web-apps/keycloak.xml
index 8c3e35a051bc..cb706932f48f 100644
--- a/nixos/modules/services/web-apps/keycloak.xml
+++ b/nixos/modules/services/web-apps/keycloak.xml
@@ -85,7 +85,12 @@
The frontend URL is used as base for all frontend requests and
must be configured through .
It should normally include a trailing /auth
- (the default web context).
+ (the default web context). If you use a reverse proxy, you need
+ to set this option to "", so that frontend URL
+ is derived from HTTP headers. X-Forwarded-* headers
+ support also should be enabled, using
+ respective guidelines.