arrstack: wire arrproxy v0.4.0 tier routing (fafflix/cheeztv) (#416)
## Why
The old bare `sonarr`/`radarr` Services are gone, but arrproxy still ran the v0.3.x built-in default topology pointing at non-existent `sonarr`/`radarr` upstreams and mounted dead `sonarr-apikey`/`radarr-apikey` Secrets. This cuts the front door over to arrproxy v0.4.0 tier routing so the adult (fafflix, `/3aa168`) and kids (cheeztv, `/3df803`) *arr instances are reachable again, with per-tier group authorization.
## Changes
- Bump `arrproxy-api` and `arrproxy-ui` images to `v0.4.0`.
- Add `arrproxy-tiers` ConfigMap (`ARRPROXY_TIERS_FILE`): `fafflix` + `cheeztv` tiers, each with sonarr/radarr upstreams, route hash, key subdir and group grants. Adults (`akP-media-fafflix`) reach both tiers all methods; kids (`akP-media-cheeztv`) reach only cheeztv, GET/HEAD. `legacyRoutes:false` retires the unprefixed routes.
- Because arrproxy strips `/<hash>` and proxies `/<app>/...`, each upstream URL carries the `/<hash>` path segment so the joined upstream path (`/3aa168/sonarr/...`) matches the *arr's own UrlBase.
- Mount the tiers file and rework the projected keys volume to the real per-instance `{sonarr,radarr}-{adult,kids}-apikey` Secrets under `<keyDir>/<app>` (`adult/*`, `kids/*`); refresh reloader annotations.
- oauth2-proxy: route `/3aa168` and `/3df803` to arrproxy-api (drop dead `/sonarr` `/radarr` `/prowlarr`; prowlarr is served directly), and widen `SKIP_AUTH_REGEX` to `^/[^/]+/[^/]+/api` for the hash-prefixed tier api paths.
Group headers keep flowing via the existing Authentik `ak_groups` claim -> oauth2-proxy `X-Forwarded-Groups` mechanism. Validated with `kustomize build` + repo kubeconform (88/88 valid). No new Vault seeds required — the per-instance apikey Secrets already exist.
Reviewed-on: #416
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #416.
This commit is contained in:
@@ -21,9 +21,11 @@ data:
|
||||
# application (terraform-authentik PR #18).
|
||||
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/arrstack/"
|
||||
OAUTH2_PROXY_REDIRECT_URL: "https://arrstack.unkin.net/oauth2/callback"
|
||||
# Longest-prefix wins: /api and /<app> go to arrproxy-api, everything else
|
||||
# (the SPA + static assets) to arrproxy-ui.
|
||||
OAUTH2_PROXY_UPSTREAMS: "http://arrproxy-ui.arrstack.svc.cluster.local:8080/,http://arrproxy-api.arrstack.svc.cluster.local:8080/api/,http://arrproxy-api.arrstack.svc.cluster.local:8080/sonarr/,http://arrproxy-api.arrstack.svc.cluster.local:8080/radarr/,http://arrproxy-api.arrstack.svc.cluster.local:8080/prowlarr/"
|
||||
# Longest-prefix wins: /api and the per-tier hash routes (/3aa168, /3df803) go
|
||||
# to arrproxy-api, everything else (the SPA + static assets) to arrproxy-ui.
|
||||
# Tier routes carry /<hash>/<app>/...; the bare /sonarr /radarr /prowlarr
|
||||
# upstreams are retired (legacy routes off; prowlarr is served directly).
|
||||
OAUTH2_PROXY_UPSTREAMS: "http://arrproxy-ui.arrstack.svc.cluster.local:8080/,http://arrproxy-api.arrstack.svc.cluster.local:8080/api/,http://arrproxy-api.arrstack.svc.cluster.local:8080/3aa168/,http://arrproxy-api.arrstack.svc.cluster.local:8080/3df803/"
|
||||
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
||||
# Populate session.Groups from the Authentik ak_groups claim; pass-user-headers
|
||||
# then emits it as a single comma-joined X-Forwarded-Groups header.
|
||||
@@ -33,14 +35,16 @@ data:
|
||||
# set-xauthrequest is intentionally NOT set -- it only populates auth_request
|
||||
# *response* headers, which never reach an --upstreams-proxied backend.
|
||||
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
||||
# Bypass auth for the *arr proxy API (/<app>/api...) and the machine-mint
|
||||
# admin route (/api/admin/...). The first matches /sonarr/api; the second
|
||||
# matches /api/admin/ only -- both routed to the arrproxy-api upstream by the
|
||||
# catch-all /api/ prefix above. /api/admin/ is protected by arrproxy's OWN
|
||||
# ARRPROXY_ADMIN_TOKEN bearer (OpenBao on the VMs reaches it via the ingress),
|
||||
# so it is intentionally oauth-skipped. /api/tokens and /api/me are NOT
|
||||
# matched and stay oauth-authenticated.
|
||||
OAUTH2_PROXY_SKIP_AUTH_REGEX: "^/[^/]+/api,^/api/admin/"
|
||||
# Bypass auth for the tier *arr proxy API (/<hash>/<app>/api...) and the
|
||||
# machine-mint admin route (/api/admin/...). The first matches
|
||||
# /3aa168/sonarr/api (two path segments before /api, since tier routes are
|
||||
# hash-prefixed); the second matches /api/admin/ only -- both routed to the
|
||||
# arrproxy-api upstream by the tier and catch-all /api/ prefixes above.
|
||||
# /api/admin/ is protected by arrproxy's OWN ARRPROXY_ADMIN_TOKEN bearer
|
||||
# (OpenBao on the VMs reaches it via the ingress), so it is intentionally
|
||||
# oauth-skipped. /api/tokens and /api/me are NOT matched and stay
|
||||
# oauth-authenticated.
|
||||
OAUTH2_PROXY_SKIP_AUTH_REGEX: "^/[^/]+/[^/]+/api,^/api/admin/"
|
||||
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||
# Authentik hardcodes email_verified=false in the id_token; without this
|
||||
# oauth2-proxy rejects the session ("email ... isn't verified") -> 500 on
|
||||
|
||||
Reference in New Issue
Block a user