- Shipped
- September 28, 2026 at 5:33 PM UTC
- Author
- Kamo
- Commit
- fab3d80
A member signed in on internal.kamouniverse.com (the platform's primary apex since 2026-09-28) opens a document with **************** because DocumentController takes the last two labels of X-Forwarded-Host. coolwsd's alias group listed only *.kamocrm.com and the verified tenant roots, so every such document failed with "unauthorized WOPI host". Add **************** beside the kamocrm.com alternative; nothing is removed and look-alike hosts (api.kamouniverse.com.evil.io, api.notkamouniverse.com) still do not match. docs.kamouniverse.com had DNS and a certificate but no route, so it answered Traefik's 404. The Docs route now matches it next to docs.kamocrm.com, which stays the host DocsService hands out (Docs-host is unchanged). The same aliasgroup1 value goes into klusterservices Docs/deployment.yaml so neither repo's deploy reverts the other.
