    # forward authentication to outpost
    forward_auth authentik-server-1 {
        uri /

        # capitalization of headers
        copy_headers X-Authentik-Email

        # in this config trust all private ranges only
        trusted_proxies private_ranges
    # always forward outpost path to actual outpost
    reverse_proxy /* authentik-server-1

    # actual site configuration below, for example
    reverse_proxy intranet:80
