arrproxy: bump images to v0.5.0 (per-token method scoping) (#443)

## Why

arrproxy v0.5.0 ships per-token HTTP method scoping for machine tokens, so a minted token can be limited to e.g. `GET` only. Zero-downtime: the mint-API field is additive and existing tokens get an empty methods list, which means unrestricted — they behave exactly as before.

## How

- Bump `arrproxy-api` and `arrproxy-ui` pins from v0.4.0 to v0.5.0.
- Mirror repo migrations `0002_tier_tokens.sql` and `0003_token_methods.sql` into the migrations ConfigMap. It had drifted at 0001 while v0.4.0 already queried `tier`/`read_only`, and every v0.5.0 token query selects `methods` — without this the new API errors on every token read.
- Have the wave-1 migrate Job apply all three files in order. Every statement is `IF NOT EXISTS`, so a resync over an already-migrated database is a no-op.

Rendered `kustomize build --enable-helm apps/overlays/au-syd1/arrstack` diff vs main is exactly the two image tags, the two added ConfigMap keys, and the two added `-f` args.

Reviewed-on: #443
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
This commit was merged in pull request #443.
This commit is contained in:
2026-08-30 14:23:44 +10:00
committed by BenVincent
parent 1ba6180e96
commit 221c575a44
4 changed files with 22 additions and 5 deletions
@@ -34,7 +34,7 @@ spec:
type: RuntimeDefault
containers:
- name: api
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.4.0
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.5.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080
@@ -64,6 +64,10 @@ spec:
- ON_ERROR_STOP=1
- -f
- /migrations/0001_init.sql
- -f
- /migrations/0002_tier_tokens.sql
- -f
- /migrations/0003_token_methods.sql
volumeMounts:
- name: migrations
mountPath: /migrations
@@ -1,7 +1,9 @@
---
# arrproxy schema, mirrored from the arrproxy repo migrations/0001_init.sql
# (v0.1.0). arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies
# this once per sync as the app user. Keep in sync with the repo on schema bumps.
# arrproxy schema, mirrored from the arrproxy repo migrations/ (v0.5.0).
# arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies these in
# order once per sync as the app user. Every statement is idempotent, so a resync
# over an already-migrated database is a no-op. Keep in sync with the repo on
# schema bumps.
apiVersion: v1
kind: ConfigMap
metadata:
@@ -27,3 +29,14 @@ data:
CREATE INDEX IF NOT EXISTS tokens_subject_idx ON tokens (subject);
CREATE INDEX IF NOT EXISTS tokens_token_hash_idx ON tokens (token_hash);
0002_tier_tokens.sql: |
-- Tier-scoped virtual API keys. Existing rows (tier '') remain legacy per-app
-- tokens validated on the unprefixed routes; tier keys carry a tier name and,
-- for read-only tiers (kids), read_only=true so writes are rejected.
ALTER TABLE tokens ADD COLUMN IF NOT EXISTS tier TEXT NOT NULL DEFAULT '';
ALTER TABLE tokens ADD COLUMN IF NOT EXISTS read_only BOOLEAN NOT NULL DEFAULT false;
0003_token_methods.sql: |
-- Per-token HTTP method scoping. An empty list (the default every existing row
-- gets) means unrestricted, so tokens minted before this column behave exactly
-- as before; a non-empty list limits the token to those methods.
ALTER TABLE tokens ADD COLUMN IF NOT EXISTS methods TEXT[] NOT NULL DEFAULT '{}';
@@ -31,7 +31,7 @@ spec:
type: RuntimeDefault
containers:
- name: ui
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.4.0
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.5.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080