When to use it
Use external-proxy mode when an existing reverse proxy, load balancer, tunnel agent, or ingress service terminates public HTTPS.
--hostname oneview.customer.example \
--tls-mode external-proxy \
--trusted-proxy 127.0.0.1
Proxy target
The installed tooling displays the local HTTP address that the external proxy must use. Do not publish any other OneView service port.
The proxy must preserve the public host, identify the original HTTPS scheme, and prevent untrusted clients from spoofing forwarding headers. The public URL configured in OneView must match the URL users open.
For a proxy on another host, establish an approved private path using the address shown by the installed tooling.