From 221c575a44cd73b7f77da30dc0f07dd5223bc200 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Sun, 30 Aug 2026 14:23:44 +1000 Subject: [PATCH] arrproxy: bump images to v0.5.0 (per-token method scoping) (#443) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Why arrproxy v0.5.0 ships per-token HTTP method scoping for machine tokens, so a minted token can be limited to e.g. `GET` only. Zero-downtime: the mint-API field is additive and existing tokens get an empty methods list, which means unrestricted — they behave exactly as before. ## How - Bump `arrproxy-api` and `arrproxy-ui` pins from v0.4.0 to v0.5.0. - Mirror repo migrations `0002_tier_tokens.sql` and `0003_token_methods.sql` into the migrations ConfigMap. It had drifted at 0001 while v0.4.0 already queried `tier`/`read_only`, and every v0.5.0 token query selects `methods` — without this the new API errors on every token read. - Have the wave-1 migrate Job apply all three files in order. Every statement is `IF NOT EXISTS`, so a resync over an already-migrated database is a no-op. Rendered `kustomize build --enable-helm apps/overlays/au-syd1/arrstack` diff vs main is exactly the two image tags, the two added ConfigMap keys, and the two added `-f` args. Reviewed-on: https://git.unkin.net/unkin/argocd-apps/pulls/443 Co-authored-by: unkin-agent Co-committed-by: unkin-agent --- .../arrstack/arrproxy/api-deployment.yaml | 2 +- apps/base/arrstack/arrproxy/migrate-job.yaml | 4 ++++ .../arrproxy/migrations-configmap.yaml | 19 ++++++++++++++++--- .../base/arrstack/arrproxy/ui-deployment.yaml | 2 +- 4 files changed, 22 insertions(+), 5 deletions(-) diff --git a/apps/base/arrstack/arrproxy/api-deployment.yaml b/apps/base/arrstack/arrproxy/api-deployment.yaml index 3125c94..3ccfba3 100644 --- a/apps/base/arrstack/arrproxy/api-deployment.yaml +++ b/apps/base/arrstack/arrproxy/api-deployment.yaml @@ -34,7 +34,7 @@ spec: type: RuntimeDefault containers: - name: api - image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.4.0 + image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.5.0 imagePullPolicy: IfNotPresent ports: - containerPort: 8080 diff --git a/apps/base/arrstack/arrproxy/migrate-job.yaml b/apps/base/arrstack/arrproxy/migrate-job.yaml index 6cc9fe5..69dbcb8 100644 --- a/apps/base/arrstack/arrproxy/migrate-job.yaml +++ b/apps/base/arrstack/arrproxy/migrate-job.yaml @@ -64,6 +64,10 @@ spec: - ON_ERROR_STOP=1 - -f - /migrations/0001_init.sql + - -f + - /migrations/0002_tier_tokens.sql + - -f + - /migrations/0003_token_methods.sql volumeMounts: - name: migrations mountPath: /migrations diff --git a/apps/base/arrstack/arrproxy/migrations-configmap.yaml b/apps/base/arrstack/arrproxy/migrations-configmap.yaml index ed92d2a..bb26dfc 100644 --- a/apps/base/arrstack/arrproxy/migrations-configmap.yaml +++ b/apps/base/arrstack/arrproxy/migrations-configmap.yaml @@ -1,7 +1,9 @@ --- -# arrproxy schema, mirrored from the arrproxy repo migrations/0001_init.sql -# (v0.1.0). arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies -# this once per sync as the app user. Keep in sync with the repo on schema bumps. +# arrproxy schema, mirrored from the arrproxy repo migrations/ (v0.5.0). +# arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies these in +# order once per sync as the app user. Every statement is idempotent, so a resync +# over an already-migrated database is a no-op. Keep in sync with the repo on +# schema bumps. apiVersion: v1 kind: ConfigMap metadata: @@ -27,3 +29,14 @@ data: CREATE INDEX IF NOT EXISTS tokens_subject_idx ON tokens (subject); CREATE INDEX IF NOT EXISTS tokens_token_hash_idx ON tokens (token_hash); + 0002_tier_tokens.sql: | + -- Tier-scoped virtual API keys. Existing rows (tier '') remain legacy per-app + -- tokens validated on the unprefixed routes; tier keys carry a tier name and, + -- for read-only tiers (kids), read_only=true so writes are rejected. + ALTER TABLE tokens ADD COLUMN IF NOT EXISTS tier TEXT NOT NULL DEFAULT ''; + ALTER TABLE tokens ADD COLUMN IF NOT EXISTS read_only BOOLEAN NOT NULL DEFAULT false; + 0003_token_methods.sql: | + -- Per-token HTTP method scoping. An empty list (the default every existing row + -- gets) means unrestricted, so tokens minted before this column behave exactly + -- as before; a non-empty list limits the token to those methods. + ALTER TABLE tokens ADD COLUMN IF NOT EXISTS methods TEXT[] NOT NULL DEFAULT '{}'; diff --git a/apps/base/arrstack/arrproxy/ui-deployment.yaml b/apps/base/arrstack/arrproxy/ui-deployment.yaml index 04d32cb..5a2ff91 100644 --- a/apps/base/arrstack/arrproxy/ui-deployment.yaml +++ b/apps/base/arrstack/arrproxy/ui-deployment.yaml @@ -31,7 +31,7 @@ spec: type: RuntimeDefault containers: - name: ui - image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.4.0 + image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.5.0 imagePullPolicy: IfNotPresent ports: - containerPort: 8080