arrstack: set *arr UrlBase=/<app> for path-based proxy hosting
This commit is contained in:
@@ -21,10 +21,12 @@ spec:
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
initContainers:
|
||||
# Enforce the Vault-sourced API key in /config/config.xml before the app
|
||||
# starts. Vault is source of truth (override bootstrap): the key is minted
|
||||
# in Vault, synced by VSO into the prowlarr-apikey Secret, and written here.
|
||||
# Runs as root to fix ownership; touches only the <ApiKey> element.
|
||||
# Enforce the Vault-sourced API key and the reverse-proxy URL base in
|
||||
# /config/config.xml before the app starts. Vault is source of truth
|
||||
# (override bootstrap): the key is minted in Vault, synced by VSO into the
|
||||
# prowlarr-apikey Secret, and written here. UrlBase=/prowlarr lets arrproxy
|
||||
# forward arrstack.unkin.net/prowlarr/... with the prefix preserved (no 307).
|
||||
# Runs as root to fix ownership; touches only <ApiKey> and <UrlBase>.
|
||||
- name: apikey-init
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/busybox:1.37.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
@@ -43,21 +45,29 @@ spec:
|
||||
set -eu
|
||||
case "$API_KEY" in
|
||||
"" | *[!0-9a-fA-F]*)
|
||||
echo "apikey-init: API_KEY missing or not hex; refusing" >&2
|
||||
echo "config-init: API_KEY missing or not hex; refusing" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
URL_BASE=/prowlarr
|
||||
CFG=/config/config.xml
|
||||
if [ ! -f "$CFG" ]; then
|
||||
printf '<Config>\n <ApiKey>%s</ApiKey>\n</Config>\n' "$API_KEY" > "$CFG"
|
||||
elif grep -q '<ApiKey>' "$CFG"; then
|
||||
sed -i "s|<ApiKey>[^<]*</ApiKey>|<ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
printf '<Config>\n <ApiKey>%s</ApiKey>\n <UrlBase>%s</UrlBase>\n</Config>\n' "$API_KEY" "$URL_BASE" > "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
if grep -q '<ApiKey>' "$CFG"; then
|
||||
sed -i "s|<ApiKey>[^<]*</ApiKey>|<ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
fi
|
||||
if grep -q '<UrlBase>' "$CFG"; then
|
||||
sed -i "s|<UrlBase>[^<]*</UrlBase>|<UrlBase>${URL_BASE}</UrlBase>|" "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <UrlBase>${URL_BASE}</UrlBase>|" "$CFG"
|
||||
fi
|
||||
fi
|
||||
chown 1000:1000 "$CFG"
|
||||
chmod 600 "$CFG"
|
||||
echo "apikey-init: <ApiKey> enforced from Vault"
|
||||
echo "config-init: <ApiKey> and <UrlBase>=${URL_BASE} enforced from Vault"
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
@@ -85,7 +95,7 @@ spec:
|
||||
value: Australia/Sydney
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
path: /prowlarr/ping
|
||||
port: http
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 30
|
||||
@@ -93,7 +103,7 @@ spec:
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
path: /prowlarr/ping
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
|
||||
@@ -21,10 +21,12 @@ spec:
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
initContainers:
|
||||
# Enforce the Vault-sourced API key in /config/config.xml before the app
|
||||
# starts. Vault is source of truth (override bootstrap): the key is minted
|
||||
# in Vault, synced by VSO into the radarr-apikey Secret, and written here.
|
||||
# Runs as root to fix ownership; touches only the <ApiKey> element.
|
||||
# Enforce the Vault-sourced API key and the reverse-proxy URL base in
|
||||
# /config/config.xml before the app starts. Vault is source of truth
|
||||
# (override bootstrap): the key is minted in Vault, synced by VSO into the
|
||||
# radarr-apikey Secret, and written here. UrlBase=/radarr lets arrproxy
|
||||
# forward arrstack.unkin.net/radarr/... with the prefix preserved (no 307).
|
||||
# Runs as root to fix ownership; touches only <ApiKey> and <UrlBase>.
|
||||
- name: apikey-init
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/busybox:1.37.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
@@ -43,21 +45,29 @@ spec:
|
||||
set -eu
|
||||
case "$API_KEY" in
|
||||
"" | *[!0-9a-fA-F]*)
|
||||
echo "apikey-init: API_KEY missing or not hex; refusing" >&2
|
||||
echo "config-init: API_KEY missing or not hex; refusing" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
URL_BASE=/radarr
|
||||
CFG=/config/config.xml
|
||||
if [ ! -f "$CFG" ]; then
|
||||
printf '<Config>\n <ApiKey>%s</ApiKey>\n</Config>\n' "$API_KEY" > "$CFG"
|
||||
elif grep -q '<ApiKey>' "$CFG"; then
|
||||
sed -i "s|<ApiKey>[^<]*</ApiKey>|<ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
printf '<Config>\n <ApiKey>%s</ApiKey>\n <UrlBase>%s</UrlBase>\n</Config>\n' "$API_KEY" "$URL_BASE" > "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
if grep -q '<ApiKey>' "$CFG"; then
|
||||
sed -i "s|<ApiKey>[^<]*</ApiKey>|<ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
fi
|
||||
if grep -q '<UrlBase>' "$CFG"; then
|
||||
sed -i "s|<UrlBase>[^<]*</UrlBase>|<UrlBase>${URL_BASE}</UrlBase>|" "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <UrlBase>${URL_BASE}</UrlBase>|" "$CFG"
|
||||
fi
|
||||
fi
|
||||
chown 1000:1000 "$CFG"
|
||||
chmod 600 "$CFG"
|
||||
echo "apikey-init: <ApiKey> enforced from Vault"
|
||||
echo "config-init: <ApiKey> and <UrlBase>=${URL_BASE} enforced from Vault"
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
@@ -85,7 +95,7 @@ spec:
|
||||
value: Australia/Sydney
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
path: /radarr/ping
|
||||
port: http
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 30
|
||||
@@ -93,7 +103,7 @@ spec:
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
path: /radarr/ping
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
|
||||
@@ -24,10 +24,12 @@ spec:
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
initContainers:
|
||||
# Enforce the Vault-sourced API key in /config/config.xml before the app
|
||||
# starts. Vault is source of truth (override bootstrap): the key is minted
|
||||
# in Vault, synced by VSO into the sonarr-apikey Secret, and written here.
|
||||
# Runs as root to fix ownership; touches only the <ApiKey> element.
|
||||
# Enforce the Vault-sourced API key and the reverse-proxy URL base in
|
||||
# /config/config.xml before the app starts. Vault is source of truth
|
||||
# (override bootstrap): the key is minted in Vault, synced by VSO into the
|
||||
# sonarr-apikey Secret, and written here. UrlBase=/sonarr lets arrproxy
|
||||
# forward arrstack.unkin.net/sonarr/... with the prefix preserved (no 307).
|
||||
# Runs as root to fix ownership; touches only <ApiKey> and <UrlBase>.
|
||||
- name: apikey-init
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/busybox:1.37.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
@@ -46,21 +48,29 @@ spec:
|
||||
set -eu
|
||||
case "$API_KEY" in
|
||||
"" | *[!0-9a-fA-F]*)
|
||||
echo "apikey-init: API_KEY missing or not hex; refusing" >&2
|
||||
echo "config-init: API_KEY missing or not hex; refusing" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
URL_BASE=/sonarr
|
||||
CFG=/config/config.xml
|
||||
if [ ! -f "$CFG" ]; then
|
||||
printf '<Config>\n <ApiKey>%s</ApiKey>\n</Config>\n' "$API_KEY" > "$CFG"
|
||||
elif grep -q '<ApiKey>' "$CFG"; then
|
||||
sed -i "s|<ApiKey>[^<]*</ApiKey>|<ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
printf '<Config>\n <ApiKey>%s</ApiKey>\n <UrlBase>%s</UrlBase>\n</Config>\n' "$API_KEY" "$URL_BASE" > "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
if grep -q '<ApiKey>' "$CFG"; then
|
||||
sed -i "s|<ApiKey>[^<]*</ApiKey>|<ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <ApiKey>${API_KEY}</ApiKey>|" "$CFG"
|
||||
fi
|
||||
if grep -q '<UrlBase>' "$CFG"; then
|
||||
sed -i "s|<UrlBase>[^<]*</UrlBase>|<UrlBase>${URL_BASE}</UrlBase>|" "$CFG"
|
||||
else
|
||||
sed -i "s|<Config>|<Config>\n <UrlBase>${URL_BASE}</UrlBase>|" "$CFG"
|
||||
fi
|
||||
fi
|
||||
chown 1000:1000 "$CFG"
|
||||
chmod 600 "$CFG"
|
||||
echo "apikey-init: <ApiKey> enforced from Vault"
|
||||
echo "config-init: <ApiKey> and <UrlBase>=${URL_BASE} enforced from Vault"
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
@@ -88,7 +98,7 @@ spec:
|
||||
value: Australia/Sydney
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
path: /sonarr/ping
|
||||
port: http
|
||||
initialDelaySeconds: 30
|
||||
periodSeconds: 30
|
||||
@@ -96,7 +106,7 @@ spec:
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
path: /sonarr/ping
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 10
|
||||
|
||||
Reference in New Issue
Block a user