Reverse-proxying to non-local target

I have not use this against something like okta, just legacy severs. Define the service using a dynamic file provider.

http:
  services:
    oldnbusted:
      loadBalancer:
        servers: 
        - url: http://legacy-server:8080
# your example might look like:
# a router defined in the dynamic file provide can use the service name okta, a docker router would use okta@file
    okta:
      loadBalancer:
        servers:
        - url: https://myorg.okta.com/auth/xyz