Compare commits

..

1 Commits

Author SHA1 Message Date
unkin-agent 47f7cd9c51 watchstate: expose externally at watchstate.unkin.net
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
Add a public front door for the WatchState admin UI on watchstate.unkin.net
via the external (DMZ) Traefik, alongside the existing internal
watchstate.k8s.syd1.au.unkin.net gateway. oauth2-proxy fronts both hostnames.

- DNSRecord watchstate-dns-internal (bind-internal/authoritative, unkin.net
  zone) -> A 198.18.199.0, the traefik-external VIP (arrstack precedent).
- watchstate-external Gateway (traefik-external) + HTTPRoutes: http->https
  redirect and https -> watchstate-oauth2:80. TLS terminated with the
  Let's Encrypt *.unkin.net wildcard (wildcard-unkin-net-tls), so no
  cert-manager/external-dns annotations.
- oauth2-proxy: relative redirect-url (/oauth2/callback) so reverse-proxy mode
  derives scheme+host per request, making the callback work on BOTH hosts;
  cookie + whitelist domains cover both hostnames.
- Drop the no-op sync-wave: "0" annotation on the vaultauth default VaultAuth.

Dependencies:
- wildcard-unkin-net-tls reflection into the watchstate namespace (reflector
  allow-list, argocd-apps PR #418).
- Both callback URIs registered on the Authentik watchstate provider
  (terraform-authentik, separate PR).
2026-08-26 21:44:29 +10:00
111 changed files with 225 additions and 2915 deletions
@@ -5,9 +5,7 @@ metadata:
name: arrproxy-api
namespace: arrstack
annotations:
# Wave 2: start only after the wave-0 CNPG Cluster and VSO-synced Secrets
# exist. The api self-migrates at startup under a Postgres advisory lock and
# holds /readyz until the schema is current, so no migration ordering is needed.
# Wave 2: serve only after the wave-1 migrate Job completes.
argocd.argoproj.io/sync-wave: "2"
secret.reloader.stakater.com/reload: "arrproxy-pepper,arrproxy-admin-token,arrproxy-db-app,sonarr-adult-apikey,radarr-adult-apikey,sonarr-kids-apikey,radarr-kids-apikey"
configmap.reloader.stakater.com/reload: "arrproxy-tiers"
@@ -36,7 +34,7 @@ spec:
type: RuntimeDefault
containers:
- name: api
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.6.1
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.4.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080
@@ -5,6 +5,8 @@ kind: Kustomization
resources:
- cnpg_cluster.yaml
- cnpg_backup.yaml
- migrations-configmap.yaml
- migrate-job.yaml
- vaultstaticsecret.yaml
- tiers-configmap.yaml
- oauth2-proxy-configmap.yaml
@@ -0,0 +1,92 @@
---
# Applies the arrproxy schema once per sync, before the api rolls, so the serve
# replicas never race migrations (arrproxy-api does not self-migrate). Runs as the
# CNPG-minted app user so the tokens table is owned by that role.
#
# Sync-phase hook at wave 1 (NOT PreSync): the CNPG Cluster + generated
# arrproxy-db-app Secret apply at wave 0 and ArgoCD waits for the Cluster to be
# Healthy before starting wave 1, so Postgres exists before migrate connects.
apiVersion: batch/v1
kind: Job
metadata:
name: arrproxy-migrate
namespace: arrstack
annotations:
argocd.argoproj.io/hook: Sync
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
argocd.argoproj.io/sync-wave: "1"
spec:
backoffLimit: 6
ttlSecondsAfterFinished: 600
template:
metadata:
labels:
app: arrproxy-migrate
spec:
serviceAccountName: default
automountServiceAccountToken: false
restartPolicy: Never
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
containers:
- name: migrate
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:18-alpine
imagePullPolicy: IfNotPresent
env:
- name: HOME
value: /tmp
- name: PGUSER
valueFrom:
secretKeyRef:
name: arrproxy-db-app
key: username
- name: PGPASSWORD
valueFrom:
secretKeyRef:
name: arrproxy-db-app
key: password
- name: PGHOST
value: arrproxy-db-rw.arrstack.svc.cluster.local
- name: PGPORT
value: "5432"
- name: PGDATABASE
value: arrproxy
- name: PGSSLMODE
value: require
command:
- psql
- -v
- ON_ERROR_STOP=1
- -f
- /migrations/0001_init.sql
volumeMounts:
- name: migrations
mountPath: /migrations
readOnly: true
- name: tmp
mountPath: /tmp
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: migrations
configMap:
name: arrproxy-migrations
- name: tmp
emptyDir:
sizeLimit: 64Mi
@@ -0,0 +1,29 @@
---
# arrproxy schema, mirrored from the arrproxy repo migrations/0001_init.sql
# (v0.1.0). arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies
# this once per sync as the app user. Keep in sync with the repo on schema bumps.
apiVersion: v1
kind: ConfigMap
metadata:
name: arrproxy-migrations
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "0"
data:
0001_init.sql: |
-- arrproxy token store. Only token hashes are persisted; plaintext is shown
-- once at mint time and never recoverable.
CREATE TABLE IF NOT EXISTS tokens (
id TEXT PRIMARY KEY,
subject TEXT NOT NULL,
label TEXT NOT NULL DEFAULT '',
token_hash TEXT NOT NULL UNIQUE,
apps TEXT[] NOT NULL DEFAULT '{}',
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
expires_at TIMESTAMPTZ,
disabled BOOLEAN NOT NULL DEFAULT false,
last_used_at TIMESTAMPTZ
);
CREATE INDEX IF NOT EXISTS tokens_subject_idx ON tokens (subject);
CREATE INDEX IF NOT EXISTS tokens_token_hash_idx ON tokens (token_hash);
@@ -35,7 +35,7 @@ spec:
# identity.unkin.net serves a Vault-PKI cert; combine the system roots
# with the internal CA so oauth2-proxy's OIDC HTTP client trusts it.
- name: combine-certs
image: docker.io/library/alpine:3
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
@@ -31,7 +31,7 @@ spec:
type: RuntimeDefault
containers:
- name: ui
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.6.1
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.4.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080
-3
View File
@@ -8,12 +8,9 @@ resources:
- pv-media-tv.yaml
- pv-media-movies.yaml
- pv-mediafs.yaml
- pv-mediastore.yaml
- pvc-media-tv.yaml
- pvc-media-movies.yaml
- pvc-mediafs.yaml
- pvc-mediastore.yaml
- mediastore-bootstrap-job.yaml
- media-bucket.yaml
- backups-bucket.yaml
- postgres
@@ -1,74 +0,0 @@
---
# Seeds the directory skeleton on the freshly created mediastore subvolume so
# the arrs, nzbget and both jellyfins mount subPaths that already exist and are
# owned by uid/gid 1000 (the uid every arrstack media pod runs as). mkdir -p is
# idempotent, so re-running it on every sync is harmless and self-heals a tree
# someone deleted by hand.
#
# Sync hook with BeforeHookCreation delete: ArgoCD replaces the completed Job
# each sync instead of failing on the immutable pod template. No sync-wave is
# needed -- the PVC applies in the same wave and the pod simply stays Pending
# until it binds.
apiVersion: batch/v1
kind: Job
metadata:
name: mediastore-bootstrap
namespace: arrstack
annotations:
argocd.argoproj.io/hook: Sync
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
spec:
backoffLimit: 6
ttlSecondsAfterFinished: 600
template:
metadata:
labels:
app: mediastore-bootstrap
spec:
serviceAccountName: default
automountServiceAccountToken: false
restartPolicy: Never
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
fsGroupChangePolicy: OnRootMismatch
seccompProfile:
type: RuntimeDefault
containers:
- name: mkdir
image: docker.io/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
- -c
- |
set -eu
mkdir -p \
/media/fafflix/tvseries \
/media/fafflix/movies \
/media/cheeztv/tvseries \
/media/cheeztv/movies \
/media/nzbget/downloads/complete
ls -la /media
volumeMounts:
- name: mediastore
mountPath: /media
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 200m
memory: 128Mi
volumes:
- name: mediastore
persistentVolumeClaim:
claimName: mediastore
-32
View File
@@ -1,32 +0,0 @@
---
# Static PV for the shared MEDIASTORE CephFS subvolume: one 10Ti filesystem
# holding every library plus the nzbget download tree, so arr imports are
# same-filesystem hardlink moves across tv AND movies. Same rootPath as the
# fafflix/cheeztv mediastore PVs; each namespace gets its own PV (unique name +
# volumeHandle) pinned by claimRef.
apiVersion: v1
kind: PersistentVolume
metadata:
name: arrstack-mediastore
spec:
capacity:
storage: 10Ti
accessModes:
- ReadWriteMany
persistentVolumeReclaimPolicy: Retain
storageClassName: ""
volumeMode: Filesystem
claimRef:
namespace: arrstack
name: mediastore
csi:
driver: cephfs.csi.ceph.com
volumeHandle: arrstack-mediastore-static
nodeStageSecretRef:
name: csi-cephfs-secret
namespace: csi-cephfs
volumeAttributes:
staticVolume: "true"
clusterID: cephfs_csi_ssd_ec_4_1
fsName: cephfs
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
-22
View File
@@ -1,22 +0,0 @@
---
# Whole media tree (/fafflix, /cheeztv, /nzbget) on one RWX filesystem, shared
# across the sonarr/radarr/nzbget pods. Statically bound to the
# arrstack-mediastore PV (the same CephFS subvolume fafflix and cheeztv mount).
# storageClassName "" + volumeName disables dynamic provisioning and binds the
# pre-created static PV.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: mediastore
namespace: arrstack
annotations:
k8up.io/backup: "false"
spec:
accessModes:
- ReadWriteMany
resources:
requests:
storage: 10Ti
storageClassName: ""
volumeName: arrstack-mediastore
volumeMode: Filesystem
+1 -1
View File
@@ -28,7 +28,7 @@ metadata:
spec:
shards: 1
replicas: 2
image: docker.io/valkey/valkey:9.0.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/valkey/valkey:9.0.0
exporter:
enabled: false
scheduling:
+1 -1
View File
@@ -36,7 +36,7 @@ spec:
mountPath: /combined-certs
containers:
- name: api
image: git.unkin.net/unkin/artifactapi:v3.11.2
image: git.unkin.net/unkin/artifactapi:v3.11.1
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8000
+1 -28
View File
@@ -1,21 +1,4 @@
---
# Path split between the authenticated UI and the unauthenticated machine API.
# Longest matching prefix wins, so the two UI rules take precedence over "/".
#
# AUTHENTICATED (oauth2 Service -> oauth2-proxy -> ui Service):
# /oauth2 oauth2-proxy sign_in / start / callback / sign_out
# /ui the human-facing SPA
#
# NOT AUTHENTICATED (artifactapi Service, unchanged):
# /api/v1/{remote,local,virtual}/* package proxy reads (yum/dnf, pip, ...)
# /api/v2/remotes|virtuals|locals/* management API + the UI's own XHR calls
# /api/v2/remotes/{name}/files/* CI publish uploads (PUT) and downloads
# /v2/* Docker Registry V2 (containerd, buildah)
# /terraform/v1/providers/* Terraform provider registry
# /.well-known/terraform.json Terraform service discovery
# /health, /version, / probes and the redirect to /ui/
# Those clients cannot complete a browser OIDC flow, so they must never be
# routed through oauth2-proxy.
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
@@ -39,17 +22,7 @@ spec:
- backendRefs:
- group: ""
kind: Service
name: oauth2
port: 80
weight: 1
matches:
- path:
type: PathPrefix
value: /oauth2
- backendRefs:
- group: ""
kind: Service
name: oauth2
name: ui
port: 80
weight: 1
matches:
-2
View File
@@ -12,8 +12,6 @@ resources:
- gateway.yaml
- httproute.yaml
- namespace.yaml
- oauth2-proxy-configmap.yaml
- oauth2-proxy-deployment.yaml
- redis-deployment.yaml
- services.yaml
- ui-deployment.yaml
@@ -1,46 +0,0 @@
---
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
# from the oauth-credentials Secret).
#
# SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just
# /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker
# registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes
# straight to the api Service and is NOT authenticated. yum/dnf, containerd
# registry mirrors, docker/buildah, terraform init and Woodpecker publish steps
# cannot complete a browser OIDC flow, so they must never reach this container.
# Its only upstream is the ui Service -- there is deliberately no api upstream.
apiVersion: v1
kind: ConfigMap
metadata:
name: artifactapi-oauth2-env
namespace: artifactapi
data:
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180"
OAUTH2_PROXY_PROVIDER: "oidc"
# Publicly-trusted Authentik host: the authorize step is a browser redirect,
# so the issuer must present a cert every user's browser already trusts (the
# k8s host serves an internal-CA cert). Slug from terraform-authentik.
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/"
OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback"
OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/"
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
# Populate session.Groups from the Authentik hierarchical ak_groups claim.
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin"
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
# Authentik hardcodes email_verified=false in the id_token; authorization is
# enforced via ak_groups, so accepting the unverified email is safe.
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
OAUTH2_PROXY_COOKIE_SECURE: "true"
OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
OAUTH2_PROXY_REVERSE_PROXY: "true"
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
# Back-channel discovery/token calls resolve the issuer inside the cluster,
# where it is served under the internal unkin.net CA rather than the publicly
# trusted cert the browser sees. Trust the bundle the combine-certs init
# container assembles, as every other oauth2-proxy in the estate does.
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
@@ -1,136 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: oauth2
namespace: artifactapi
annotations:
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
spec:
replicas: 2
selector:
matchLabels:
app: oauth2
strategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app: oauth2
spec:
serviceAccountName: default
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
initContainers:
# The Authentik issuer is served behind the internal unkin.net CA;
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
# trusts the discovery endpoint.
- name: combine-certs
image: docker.io/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
- -c
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
volumeMounts:
- name: vault-ca-cert
mountPath: /custom-ca
readOnly: true
- name: combined-certs
mountPath: /combined-certs
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 32Mi
limits:
cpu: 200m
memory: 64Mi
containers:
- name: oauth2-proxy
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
imagePullPolicy: IfNotPresent
ports:
- containerPort: 4180
name: http
protocol: TCP
- containerPort: 44180
name: metrics
protocol: TCP
envFrom:
- configMapRef:
name: artifactapi-oauth2-env
optional: false
env:
- name: OAUTH2_PROXY_CLIENT_ID
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_id
- name: OAUTH2_PROXY_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_secret
- name: OAUTH2_PROXY_COOKIE_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: cookie_secret
livenessProbe:
httpGet:
path: /ping
port: http
initialDelaySeconds: 10
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /ready
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
volumeMounts:
- name: combined-certs
mountPath: /etc/ssl/combined
readOnly: true
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
- name: combined-certs
emptyDir: {}
restartPolicy: Always
+1 -1
View File
@@ -54,7 +54,7 @@ spec:
successThreshold: 1
timeoutSeconds: 5
- name: metrics-exporter
image: docker.io/oliver006/redis_exporter:v1.89.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 9121
-20
View File
@@ -16,26 +16,6 @@ spec:
sessionAffinity: None
type: ClusterIP
---
# Authenticated front door for the web UI only: api-route sends /ui and /oauth2
# here, oauth2-proxy authenticates and forwards to the ui Service. Every other
# path reaches the api Service above directly and stays unauthenticated.
apiVersion: v1
kind: Service
metadata:
name: oauth2
namespace: artifactapi
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 80
protocol: TCP
targetPort: http
selector:
app: oauth2
sessionAffinity: None
type: ClusterIP
---
apiVersion: v1
kind: Service
metadata:
+1 -1
View File
@@ -22,7 +22,7 @@ spec:
automountServiceAccountToken: true
containers:
- name: ui
image: git.unkin.net/unkin/artifactapi-ui:v3.11.2
image: git.unkin.net/unkin/artifactapi-ui:v3.11.1
imagePullPolicy: IfNotPresent
ports:
- containerPort: 80
@@ -32,26 +32,3 @@ spec:
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
---
# Authentik OIDC client for the artifactapi UI front door (client_id,
# client_secret, cookie_secret). Seeded out of band at
# kv/kubernetes/namespace/artifactapi/default/oauth-credentials; the default
# k8s auth role already grants the artifactapi/default ServiceAccount read on
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so no
# terraform-vault change is needed. Consumed by the oauth2 Deployment.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: oauth-credentials
namespace: artifactapi
spec:
destination:
create: true
name: oauth-credentials
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/artifactapi/default/oauth-credentials
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
-14
View File
@@ -14,17 +14,3 @@ spec:
podMetricsEndpoints:
- port: metrics
path: /metrics
---
# Scrape the UI oauth2-proxy (:44180), which exposes sign-in/authz counters.
apiVersion: operator.victoriametrics.com/v1beta1
kind: VMPodScrape
metadata:
name: oauth2
namespace: artifactapi
spec:
selector:
matchLabels:
app: oauth2
podMetricsEndpoints:
- port: metrics
path: /metrics
-3
View File
@@ -10,9 +10,6 @@ resources:
- httproute.yaml
- ldap-gateway.yaml
- ldap-httproute.yaml
- ldap-outpost-deployment.yaml
- ldap-outpost-vaultstaticsecret.yaml
- ldap-outpost-vmpodscrape.yaml
- ldap-service.yaml
- ldap-tlsroute.yaml
- namespace.yaml
@@ -1,104 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: authentik-ldap-outpost
namespace: authentik
labels:
app.kubernetes.io/name: authentik
app.kubernetes.io/component: ldap
spec:
# Outposts are stateless; run two replicas for availability.
replicas: 2
selector:
matchLabels:
app.kubernetes.io/name: authentik
app.kubernetes.io/component: ldap
template:
metadata:
annotations:
secret.reloader.stakater.com/reload: "authentik-ldap-outpost-token,vault-ca-cert"
labels:
app.kubernetes.io/name: authentik
app.kubernetes.io/component: ldap
spec:
# The outpost validates the authentik core cert (identity.k8s.syd1.au.unkin.net,
# signed by the internal unkin.net CA). Combine the base image's public roots
# with the reflected vault-ca-cert into one bundle that SSL_CERT_FILE points at,
# so AUTHENTIK_INSECURE stays false.
initContainers:
- name: combine-certs
image: alpine:3
command:
- sh
- -c
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
volumeMounts:
- name: vault-ca-cert
mountPath: /custom-ca
readOnly: true
- name: combined-certs
mountPath: /combined-certs
resources:
limits:
cpu: 100m
memory: 64Mi
requests:
cpu: 25m
memory: 32Mi
containers:
- name: ldap
image: ghcr.io/goauthentik/ldap:2026.5.3
imagePullPolicy: IfNotPresent
env:
- name: AUTHENTIK_HOST
value: https://identity.k8s.syd1.au.unkin.net
- name: AUTHENTIK_INSECURE
value: "false"
- name: SSL_CERT_FILE
value: /etc/ssl/combined/ca-certificates.crt
- name: AUTHENTIK_TOKEN
valueFrom:
secretKeyRef:
name: authentik-ldap-outpost-token
key: token
ports:
- containerPort: 3389
name: ldap
protocol: TCP
- containerPort: 6636
name: ldaps
protocol: TCP
- containerPort: 9300
name: metrics
protocol: TCP
livenessProbe:
tcpSocket:
port: ldap
initialDelaySeconds: 10
periodSeconds: 15
readinessProbe:
tcpSocket:
port: ldap
initialDelaySeconds: 5
periodSeconds: 10
resources:
limits:
cpu: "1"
memory: 512Mi
requests:
cpu: 50m
memory: 128Mi
volumeMounts:
- name: combined-certs
mountPath: /etc/ssl/combined
readOnly: true
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
- name: combined-certs
emptyDir: {}
@@ -1,20 +0,0 @@
---
# Outpost API token, issued by authentik for the LDAP outpost and seeded into
# Vault by the terraform-authentik apply. The KV value must exist at this path
# with a `token` key before the outpost can connect.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: authentik-ldap-outpost-token
namespace: authentik
spec:
destination:
create: true
name: authentik-ldap-outpost-token
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/authentik/default/outpost-token
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
@@ -1,16 +0,0 @@
---
# Scrape the LDAP outpost's Prometheus endpoint (:9300). Picked up by the
# observability VMAgent (selectAllByDefault).
apiVersion: operator.victoriametrics.com/v1beta1
kind: VMPodScrape
metadata:
name: authentik-ldap-outpost
namespace: authentik
spec:
selector:
matchLabels:
app.kubernetes.io/name: authentik
app.kubernetes.io/component: ldap
podMetricsEndpoints:
- port: metrics
path: /metrics
-4
View File
@@ -7,10 +7,6 @@ metadata:
spec:
internalTrafficPolicy: Cluster
ports:
- name: ldap
port: 3389
protocol: TCP
targetPort: 3389
- name: ldaps
port: 6636
protocol: TCP
+1 -1
View File
@@ -53,7 +53,7 @@ spec:
- mountPath: /data
name: redis-data
- name: metrics-exporter
image: docker.io/oliver006/redis_exporter:v1.89.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 9121
@@ -14,9 +14,9 @@ spec:
secretTemplate:
annotations:
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate"
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate"
privateKey:
size: 4096
dnsNames:
-3
View File
@@ -15,12 +15,9 @@ resources:
- pvc-transcode.yaml
- pv-media-tv.yaml
- pv-media-movies.yaml
- pv-mediastore.yaml
- pvc-media-tv.yaml
- pvc-media-movies.yaml
- pvc-mediastore.yaml
- statefulset.yaml
- plugin-configmap.yaml
- pdb.yaml
- service.yaml
- valkey.yaml
-97
View File
@@ -1,97 +0,0 @@
---
# Declarative config for the browser-auth plugins bundled in the jellyfin-ha
# image (jellyfin-plugin-sso, jellyfin-plugin-ldapauth). Rendered into
# /config/plugins/configurations/ by the inject-plugin-config initContainer,
# which substitutes the OidSecret / LdapBindPassword placeholders from the
# VSO-synced oauth-credentials Secret so no secret is committed here. The SSO
# provider key "authentik" must match the redirect path segment registered on
# the shared Authentik "jellyfin" OAuth2 client. Roles/AdminRoles are matched
# against the hierarchical Authentik groups claim (akP-jellyfin-user grants
# login, akP-jellyfin-admin grants Jellyfin admin; global admins inherit the
# latter via akR-global-admin).
apiVersion: v1
kind: ConfigMap
metadata:
name: cheeztv-plugin-config
namespace: cheeztv
data:
SSO-Auth.xml: |
<?xml version="1.0" encoding="utf-8"?>
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<SamlConfigs />
<OidConfigs>
<item>
<key>
<string>authentik</string>
</key>
<value>
<PluginConfiguration>
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint>
<OidClientId>jellyfin</OidClientId>
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
<Enabled>true</Enabled>
<EnableAuthorization>true</EnableAuthorization>
<EnableAllFolders>true</EnableAllFolders>
<EnabledFolders />
<AdminRoles>
<string>akP-jellyfin-admin</string>
</AdminRoles>
<Roles>
<string>akP-jellyfin-user</string>
<string>akP-jellyfin-admin</string>
</Roles>
<EnableFolderRoles>false</EnableFolderRoles>
<EnableLiveTvRoles>false</EnableLiveTvRoles>
<EnableLiveTv>false</EnableLiveTv>
<EnableLiveTvManagement>false</EnableLiveTvManagement>
<LiveTvRoles />
<LiveTvManagementRoles />
<FolderRoleMappings />
<RoleClaim>ak_groups</RoleClaim>
<OidScopes>
<string>openid</string>
<string>profile</string>
<string>email</string>
<string>ak_groups</string>
</OidScopes>
<CanonicalLinks></CanonicalLinks>
<DisableHttps>false</DisableHttps>
<DoNotValidateEndpoints>false</DoNotValidateEndpoints>
<DoNotValidateIssuerName>false</DoNotValidateIssuerName>
<SchemeOverride>https</SchemeOverride>
</PluginConfiguration>
</value>
</item>
</OidConfigs>
</PluginConfiguration>
LDAP-Auth.xml: |
<?xml version="1.0" encoding="utf-8"?>
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<LdapServer>authentik-ldap.authentik.svc.cluster.local</LdapServer>
<LdapPort>6636</LdapPort>
<UseSsl>true</UseSsl>
<UseStartTls>false</UseStartTls>
<SkipSslVerify>true</SkipSslVerify>
<LdapBindUser>cn=jellyfin-ldap,ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBindUser>
<LdapBindPassword>@@LDAP_BIND_PASSWORD@@</LdapBindPassword>
<LdapBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBaseDn>
<LdapSearchFilter>(objectClass=user)</LdapSearchFilter>
<LdapAdminBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapAdminBaseDn>
<LdapAdminFilter>(memberOf=cn=akP-jellyfin-admin,ou=groups,DC=ldap,DC=goauthentik,DC=io)</LdapAdminFilter>
<EnableLdapAdminFilterMemberUid>false</EnableLdapAdminFilterMemberUid>
<LdapSearchAttributes>uid, cn, mail, displayName</LdapSearchAttributes>
<CreateUsersFromLdap>true</CreateUsersFromLdap>
<AllowPassChange>false</AllowPassChange>
<LdapUidAttribute>cn</LdapUidAttribute>
<LdapUsernameAttribute>cn</LdapUsernameAttribute>
<LdapPasswordAttribute>userPassword</LdapPasswordAttribute>
<EnableAllFolders>true</EnableAllFolders>
<EnabledFolders />
</PluginConfiguration>
branding.xml: |
<?xml version="1.0" encoding="utf-8"?>
<BrandingOptions xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<LoginDisclaimer>&lt;p style="text-align:center"&gt;&lt;a href="/sso/OID/start/authentik"&gt;Sign in with SSO&lt;/a&gt;&lt;/p&gt;</LoginDisclaimer>
<CustomCss></CustomCss>
<SplashscreenEnabled>false</SplashscreenEnabled>
</BrandingOptions>
-31
View File
@@ -1,31 +0,0 @@
---
# Static PV for the shared MEDIASTORE CephFS subvolume. Same rootPath as
# arrstack's mediastore PV so the arrs write and cheeztv reads the identical
# library tree (cheeztv scans /cheeztv/{tvseries,movies}); each namespace gets
# its own PV (unique name + volumeHandle) pinned by claimRef.
apiVersion: v1
kind: PersistentVolume
metadata:
name: cheeztv-mediastore
spec:
capacity:
storage: 10Ti
accessModes:
- ReadWriteMany
persistentVolumeReclaimPolicy: Retain
storageClassName: ""
volumeMode: Filesystem
claimRef:
namespace: cheeztv
name: cheeztv-mediastore
csi:
driver: cephfs.csi.ceph.com
volumeHandle: cheeztv-mediastore-static
nodeStageSecretRef:
name: csi-cephfs-secret
namespace: csi-cephfs
volumeAttributes:
staticVolume: "true"
clusterID: cephfs_csi_ssd_ec_4_1
fsName: cephfs
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
-24
View File
@@ -1,24 +0,0 @@
---
# Shared media tree, read-many across replicas. Statically bound to the
# cheeztv-mediastore PV (the CephFS subvolume also used by arrstack and
# fafflix). storageClassName "" + volumeName disables dynamic provisioning and
# binds the pre-created static PV.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: cheeztv-mediastore
namespace: cheeztv
annotations:
# Exclude from the cheeztv-config k8up Schedule (skipWithoutAnnotation is
# false cluster-wide, so unannotated PVCs are swept in). Only cheeztv-config
# is backed up; the media library is not restic-backup material.
k8up.io/backup: "false"
spec:
accessModes:
- ReadWriteMany
resources:
requests:
storage: 10Ti
storageClassName: ""
volumeName: cheeztv-mediastore
volumeMode: Filesystem
+1 -55
View File
@@ -109,60 +109,9 @@ spec:
volumeMounts:
- name: config
mountPath: /config
# Render the SSO/LDAP plugin configs into the shared config volume,
# substituting the client secret and LDAP bind password from the
# VSO-synced oauth-credentials Secret (never committed). Plugin configs
# are fully managed here so they are overwritten every start; the login
# button branding is written only when absent so admin edits survive.
- name: inject-plugin-config
image: busybox:1.37.0
command:
- sh
- -c
- |
mkdir -p /config/plugins/configurations /config/config
chown 1000:1000 /config/plugins /config/plugins/configurations /config/config
esc() { printf '%s' "$1" | sed -e 's/[&|\\]/\\&/g'; }
cs=$(esc "${CLIENT_SECRET}")
lp=$(esc "${LDAP_BIND_PASSWORD}")
sed "s|@@CLIENT_SECRET@@|${cs}|" /templates/SSO-Auth.xml > /config/plugins/configurations/SSO-Auth.xml
sed "s|@@LDAP_BIND_PASSWORD@@|${lp}|" /templates/LDAP-Auth.xml > /config/plugins/configurations/LDAP-Auth.xml
chown 1000:1000 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
chmod 600 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
if [ ! -e /config/config/branding.xml ]; then
cp /templates/branding.xml /config/config/branding.xml
chown 1000:1000 /config/config/branding.xml
chmod 664 /config/config/branding.xml
fi
env:
- name: CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_secret
optional: true
- name: LDAP_BIND_PASSWORD
valueFrom:
secretKeyRef:
name: oauth-credentials
key: ldap_bind_password
optional: true
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 64Mi
volumeMounts:
- name: config
mountPath: /config
- name: plugin-config
mountPath: /templates
readOnly: true
containers:
- name: cheeztv
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.1.3
imagePullPolicy: IfNotPresent
ports:
- name: http
@@ -273,9 +222,6 @@ spec:
subPath: kids
readOnly: true
volumes:
- name: plugin-config
configMap:
name: cheeztv-plugin-config
- name: config
persistentVolumeClaim:
claimName: cheeztv-config
-24
View File
@@ -22,27 +22,3 @@ spec:
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
---
# Shared Authentik "jellyfin" OAuth2 client secret (key: client_secret) plus the
# LDAP outpost bind password (key: ldap_bind_password) for the auth plugins.
# The default k8s role's templated policy is namespace-scoped
# (kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*), so each instance
# reads its own namespace path; the SAME shared values must be seeded at both
# fafflix and cheeztv paths. VSO syncs into the oauth-credentials Secret, whose
# keys the inject-plugin-config initContainer substitutes into the plugin XML.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: oauth-credentials
namespace: cheeztv
spec:
destination:
create: true
name: oauth-credentials
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/cheeztv/default/oauth-credentials
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
+1 -1
View File
@@ -21,7 +21,7 @@ spec:
runAsNonRoot: true
containers:
- name: operator
image: git.unkin.net/unkin/kea-operator:v0.1.5
image: git.unkin.net/unkin/kea-operator:v0.1.3
args:
- --metrics-bind-address=:8080
- --health-probe-bind-address=:8081
+1 -1
View File
@@ -23,7 +23,7 @@ spec:
automountServiceAccountToken: true
containers:
- name: encapi
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi:v0.1.2
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi:v0.1.1
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8000
-3
View File
@@ -15,12 +15,9 @@ resources:
- pvc-transcode.yaml
- pv-media-tv.yaml
- pv-media-movies.yaml
- pv-mediastore.yaml
- pvc-media-tv.yaml
- pvc-media-movies.yaml
- pvc-mediastore.yaml
- statefulset.yaml
- plugin-configmap.yaml
- pdb.yaml
- service.yaml
- valkey.yaml
-97
View File
@@ -1,97 +0,0 @@
---
# Declarative config for the browser-auth plugins bundled in the jellyfin-ha
# image (jellyfin-plugin-sso, jellyfin-plugin-ldapauth). Rendered into
# /config/plugins/configurations/ by the inject-plugin-config initContainer,
# which substitutes the OidSecret / LdapBindPassword placeholders from the
# VSO-synced oauth-credentials Secret so no secret is committed here. The SSO
# provider key "authentik" must match the redirect path segment registered on
# the shared Authentik "jellyfin" OAuth2 client. Roles/AdminRoles are matched
# against the hierarchical Authentik groups claim (akP-jellyfin-user grants
# login, akP-jellyfin-admin grants Jellyfin admin; global admins inherit the
# latter via akR-global-admin).
apiVersion: v1
kind: ConfigMap
metadata:
name: fafflix-plugin-config
namespace: fafflix
data:
SSO-Auth.xml: |
<?xml version="1.0" encoding="utf-8"?>
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<SamlConfigs />
<OidConfigs>
<item>
<key>
<string>authentik</string>
</key>
<value>
<PluginConfiguration>
<OidEndpoint>https://identity.k8s.syd1.au.unkin.net/application/o/jellyfin/</OidEndpoint>
<OidClientId>jellyfin</OidClientId>
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
<Enabled>true</Enabled>
<EnableAuthorization>true</EnableAuthorization>
<EnableAllFolders>true</EnableAllFolders>
<EnabledFolders />
<AdminRoles>
<string>akP-jellyfin-admin</string>
</AdminRoles>
<Roles>
<string>akP-jellyfin-user</string>
<string>akP-jellyfin-admin</string>
</Roles>
<EnableFolderRoles>false</EnableFolderRoles>
<EnableLiveTvRoles>false</EnableLiveTvRoles>
<EnableLiveTv>false</EnableLiveTv>
<EnableLiveTvManagement>false</EnableLiveTvManagement>
<LiveTvRoles />
<LiveTvManagementRoles />
<FolderRoleMappings />
<RoleClaim>ak_groups</RoleClaim>
<OidScopes>
<string>openid</string>
<string>profile</string>
<string>email</string>
<string>ak_groups</string>
</OidScopes>
<CanonicalLinks></CanonicalLinks>
<DisableHttps>false</DisableHttps>
<DoNotValidateEndpoints>false</DoNotValidateEndpoints>
<DoNotValidateIssuerName>false</DoNotValidateIssuerName>
<SchemeOverride>https</SchemeOverride>
</PluginConfiguration>
</value>
</item>
</OidConfigs>
</PluginConfiguration>
LDAP-Auth.xml: |
<?xml version="1.0" encoding="utf-8"?>
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<LdapServer>authentik-ldap.authentik.svc.cluster.local</LdapServer>
<LdapPort>6636</LdapPort>
<UseSsl>true</UseSsl>
<UseStartTls>false</UseStartTls>
<SkipSslVerify>true</SkipSslVerify>
<LdapBindUser>cn=jellyfin-ldap,ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBindUser>
<LdapBindPassword>@@LDAP_BIND_PASSWORD@@</LdapBindPassword>
<LdapBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBaseDn>
<LdapSearchFilter>(objectClass=user)</LdapSearchFilter>
<LdapAdminBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapAdminBaseDn>
<LdapAdminFilter>(memberOf=cn=akP-jellyfin-admin,ou=groups,DC=ldap,DC=goauthentik,DC=io)</LdapAdminFilter>
<EnableLdapAdminFilterMemberUid>false</EnableLdapAdminFilterMemberUid>
<LdapSearchAttributes>uid, cn, mail, displayName</LdapSearchAttributes>
<CreateUsersFromLdap>true</CreateUsersFromLdap>
<AllowPassChange>false</AllowPassChange>
<LdapUidAttribute>cn</LdapUidAttribute>
<LdapUsernameAttribute>cn</LdapUsernameAttribute>
<LdapPasswordAttribute>userPassword</LdapPasswordAttribute>
<EnableAllFolders>true</EnableAllFolders>
<EnabledFolders />
</PluginConfiguration>
branding.xml: |
<?xml version="1.0" encoding="utf-8"?>
<BrandingOptions xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<LoginDisclaimer>&lt;p style="text-align:center"&gt;&lt;a href="/sso/OID/start/authentik"&gt;Sign in with SSO&lt;/a&gt;&lt;/p&gt;</LoginDisclaimer>
<CustomCss></CustomCss>
<SplashscreenEnabled>false</SplashscreenEnabled>
</BrandingOptions>
-31
View File
@@ -1,31 +0,0 @@
---
# Static PV for the shared MEDIASTORE CephFS subvolume. Same rootPath as
# arrstack's mediastore PV so the arrs write and fafflix reads the identical
# library tree (fafflix scans /fafflix/{tvseries,movies}); each namespace gets
# its own PV (unique name + volumeHandle) pinned by claimRef.
apiVersion: v1
kind: PersistentVolume
metadata:
name: fafflix-mediastore
spec:
capacity:
storage: 10Ti
accessModes:
- ReadWriteMany
persistentVolumeReclaimPolicy: Retain
storageClassName: ""
volumeMode: Filesystem
claimRef:
namespace: fafflix
name: fafflix-mediastore
csi:
driver: cephfs.csi.ceph.com
volumeHandle: fafflix-mediastore-static
nodeStageSecretRef:
name: csi-cephfs-secret
namespace: csi-cephfs
volumeAttributes:
staticVolume: "true"
clusterID: cephfs_csi_ssd_ec_4_1
fsName: cephfs
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
-24
View File
@@ -1,24 +0,0 @@
---
# Shared media tree, read-many across replicas. Statically bound to the
# fafflix-mediastore PV (the CephFS subvolume also used by arrstack and
# cheeztv). storageClassName "" + volumeName disables dynamic provisioning and
# binds the pre-created static PV.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: fafflix-mediastore
namespace: fafflix
annotations:
# Exclude from the fafflix-config k8up Schedule (skipWithoutAnnotation is
# false cluster-wide, so unannotated PVCs are swept in). Only fafflix-config
# is backed up; the media library is not restic-backup material.
k8up.io/backup: "false"
spec:
accessModes:
- ReadWriteMany
resources:
requests:
storage: 10Ti
storageClassName: ""
volumeName: fafflix-mediastore
volumeMode: Filesystem
+1 -55
View File
@@ -109,60 +109,9 @@ spec:
volumeMounts:
- name: config
mountPath: /config
# Render the SSO/LDAP plugin configs into the shared config volume,
# substituting the client secret and LDAP bind password from the
# VSO-synced oauth-credentials Secret (never committed). Plugin configs
# are fully managed here so they are overwritten every start; the login
# button branding is written only when absent so admin edits survive.
- name: inject-plugin-config
image: busybox:1.37.0
command:
- sh
- -c
- |
mkdir -p /config/plugins/configurations /config/config
chown 1000:1000 /config/plugins /config/plugins/configurations /config/config
esc() { printf '%s' "$1" | sed -e 's/[&|\\]/\\&/g'; }
cs=$(esc "${CLIENT_SECRET}")
lp=$(esc "${LDAP_BIND_PASSWORD}")
sed "s|@@CLIENT_SECRET@@|${cs}|" /templates/SSO-Auth.xml > /config/plugins/configurations/SSO-Auth.xml
sed "s|@@LDAP_BIND_PASSWORD@@|${lp}|" /templates/LDAP-Auth.xml > /config/plugins/configurations/LDAP-Auth.xml
chown 1000:1000 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
chmod 600 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
if [ ! -e /config/config/branding.xml ]; then
cp /templates/branding.xml /config/config/branding.xml
chown 1000:1000 /config/config/branding.xml
chmod 664 /config/config/branding.xml
fi
env:
- name: CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_secret
optional: true
- name: LDAP_BIND_PASSWORD
valueFrom:
secretKeyRef:
name: oauth-credentials
key: ldap_bind_password
optional: true
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 64Mi
volumeMounts:
- name: config
mountPath: /config
- name: plugin-config
mountPath: /templates
readOnly: true
containers:
- name: fafflix
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.2.0
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.1.3
imagePullPolicy: IfNotPresent
ports:
- name: http
@@ -287,9 +236,6 @@ spec:
subPath: kids
readOnly: true
volumes:
- name: plugin-config
configMap:
name: fafflix-plugin-config
- name: config
persistentVolumeClaim:
claimName: fafflix-config
-24
View File
@@ -22,27 +22,3 @@ spec:
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
---
# Shared Authentik "jellyfin" OAuth2 client secret (key: client_secret) plus the
# LDAP outpost bind password (key: ldap_bind_password) for the auth plugins.
# The default k8s role's templated policy is namespace-scoped
# (kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*), so each instance
# reads its own namespace path; the SAME shared values must be seeded at both
# fafflix and cheeztv paths. VSO syncs into the oauth-credentials Secret, whose
# keys the inject-plugin-config initContainer substitutes into the plugin XML.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: oauth-credentials
namespace: fafflix
spec:
destination:
create: true
name: oauth-credentials
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/fafflix/default/oauth-credentials
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
+1 -1
View File
@@ -83,7 +83,7 @@ spec:
- mountPath: /data
name: data
- name: metrics-exporter
image: docker.io/oliver006/redis_exporter:v1.89.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 9121
+17
View File
@@ -26,6 +26,13 @@ spec:
secretKeyRef:
name: oauth-credentials
key: client_secret
# identity.unkin.net is served by the internal unkin.net CA, which
# the stock Grafana image doesn't trust. Mount the reflected
# vault-ca-cert and point generic_oauth's tls_client_ca at it.
volumeMounts:
- name: vault-ca-cert
mountPath: /etc/grafana/vault-ca
readOnly: true
resources:
requests:
cpu: 100m
@@ -33,6 +40,13 @@ spec:
limits:
cpu: "1"
memory: 1Gi
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
config:
server:
root_url: "https://grafana.k8s.syd1.au.unkin.net"
@@ -57,6 +71,9 @@ spec:
auth_url: "https://identity.unkin.net/application/o/authorize/"
token_url: "https://identity.unkin.net/application/o/token/"
api_url: "https://identity.unkin.net/application/o/userinfo/"
# Trust the internal unkin.net CA that signs identity.unkin.net's cert
# (mounted from the reflected vault-ca-cert Secret).
tls_client_ca: "/etc/grafana/vault-ca/ca.crt"
# Authentik permission groups -> Grafana roles. akP-grafana-admin is granted
# to akR-global-admin members (and direct members) via terraform-authentik.
role_attribute_path: "contains(ak_groups[*], 'akP-grafana-admin') && 'Admin' || 'Viewer'"
+1 -1
View File
@@ -61,7 +61,7 @@ spec:
mountPropagation: None
name: data
- name: metrics-exporter
image: docker.io/oliver006/redis_exporter:v1.89.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 9121
@@ -87,7 +87,7 @@ spec:
runAsGroup: 101
containers:
- name: clickhouse
image: docker.io/clickhouse/clickhouse-server:24.8
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/clickhouse/clickhouse-server:24.8
resources:
requests:
cpu: 500m
+1 -1
View File
@@ -32,7 +32,7 @@ spec:
runAsGroup: 101
containers:
- name: clickhouse-schema
image: docker.io/clickhouse/clickhouse-server:24.8
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/clickhouse/clickhouse-server:24.8
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
@@ -34,7 +34,7 @@ spec:
# identity.unkin.net serves a Vault-PKI cert; combine the system roots
# with the internal CA so oauth2-proxy's OIDC HTTP client trusts it.
- name: combine-certs
image: docker.io/library/alpine:3
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
+1 -1
View File
@@ -58,7 +58,7 @@ spec:
runAsGroup: 1000
containers:
- name: nats-bootstrap
image: docker.io/natsio/nats-box:0.18.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/natsio/nats-box:0.18.0
# nats CLI stats the working directory when loading its response
# schemas; under readOnlyRootFilesystem + runAsUser 1000 the image's
# default WORKDIR is not accessible ("stat .: permission denied"), so
-114
View File
@@ -1,114 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: mediamark
namespace: mediamark
annotations:
secret.reloader.stakater.com/reload: "arrstack-virtual-key"
spec:
replicas: 2
selector:
matchLabels:
app: mediamark
strategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app: mediamark
spec:
serviceAccountName: default
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
# 1000:1000 matches the media tree ownership on the shared mediastore
# subvolume; mediamark hardlinks/renames files the *arr apps own, so it
# deliberately does NOT run as the usual 65532.
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
seccompProfile:
type: RuntimeDefault
containers:
- name: mediamark
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/mediamark:v0.1.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080
name: http
protocol: TCP
env:
- name: MEDIAMARK_MEDIA_ROOT
value: /media
- name: MEDIAMARK_KEYS_DIR
value: /etc/mediamark/keys
# Virtual keys are only honoured by arrproxy, which validates the
# machine token and injects the real per-app key upstream; the
# sonarr/radarr Services would reject them.
- name: MEDIAMARK_SONARR_URL
value: http://arrproxy-api.arrstack.svc.cluster.local:8080/3aa168/sonarr
- name: MEDIAMARK_RADARR_URL
value: http://arrproxy-api.arrstack.svc.cluster.local:8080/3aa168/radarr
# oauth2-proxy --pass-user-headers forwards the Authentik groups as a
# comma-joined X-Forwarded-Groups; X-Auth-Request-Groups is
# auth_request-response-only and never reaches a proxied upstream.
- name: MEDIAMARK_GROUPS_HEADER
value: X-Forwarded-Groups
- name: MEDIAMARK_ALLOWED_GROUPS
value: akP-mediamark-user
volumeMounts:
- name: mediastore
mountPath: /media
- name: arr-keys
mountPath: /etc/mediamark/keys
readOnly: true
livenessProbe:
httpGet:
path: /livez
port: http
initialDelaySeconds: 10
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /readyz
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: mediastore
persistentVolumeClaim:
claimName: mediamark-mediastore
# One ephemeral virtual key covers both apps, so the same token lands on
# both per-app files under MEDIAMARK_KEYS_DIR; mediamark re-reads the
# file per request, so lease renewal rotates in place.
- name: arr-keys
projected:
sources:
- secret:
name: arrstack-virtual-key
items:
- key: token
path: sonarr
- key: token
path: radarr
restartPolicy: Always
-39
View File
@@ -1,39 +0,0 @@
---
# External (DMZ) front for mediamark on mediamark.unkin.net via the external
# Traefik (LB VIP 198.18.199.0). TLS terminates with the real Let's Encrypt
# *.unkin.net wildcard (Certificate wildcard-unkin-net in cert-manager,
# reflected into this namespace as wildcard-unkin-net-tls by the emberstack
# reflector), so there is no cert-manager annotation here. The apex
# mediamark.unkin.net A record lives in the bind-operator unkin.net zone, NOT
# external-dns, so no external-dns annotation either. oauth2-proxy fronts both
# hostnames.
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
labels:
traefik.io/instance: external
name: mediamark-external
namespace: mediamark
spec:
gatewayClassName: traefik-external
listeners:
- name: http
port: 80
protocol: HTTP
hostname: mediamark.unkin.net
allowedRoutes:
namespaces:
from: Same
- name: https
port: 443
protocol: HTTPS
hostname: mediamark.unkin.net
allowedRoutes:
namespaces:
from: Same
tls:
mode: Terminate
certificateRefs:
- group: ""
kind: Secret
name: wildcard-unkin-net-tls
-38
View File
@@ -1,38 +0,0 @@
---
# Internal front for mediamark (cf. watchstate).
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
labels:
traefik.io/instance: internal
annotations:
cert-manager.io/cluster-issuer: vault-issuer
cert-manager.io/common-name: mediamark.k8s.syd1.au.unkin.net
cert-manager.io/private-key-size: "4096"
external-dns.alpha.kubernetes.io/hostname: mediamark.k8s.syd1.au.unkin.net
external-dns.alpha.kubernetes.io/target: 198.18.200.4
name: mediamark
namespace: mediamark
spec:
gatewayClassName: traefik-internal
listeners:
- allowedRoutes:
namespaces:
from: Same
hostname: mediamark.k8s.syd1.au.unkin.net
name: http
port: 80
protocol: HTTP
- allowedRoutes:
namespaces:
from: Same
hostname: mediamark.k8s.syd1.au.unkin.net
name: https
port: 443
protocol: HTTPS
tls:
certificateRefs:
- group: ""
kind: Secret
name: mediamark-tls
mode: Terminate
@@ -1,49 +0,0 @@
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: mediamark-external-http-redirect
namespace: mediamark
spec:
hostnames:
- mediamark.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: mediamark-external
sectionName: http
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: mediamark-external
namespace: mediamark
spec:
hostnames:
- mediamark.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: mediamark-external
sectionName: https
rules:
- backendRefs:
- group: ""
kind: Service
name: mediamark-oauth2
port: 4180
weight: 1
matches:
- path:
type: PathPrefix
value: /
-49
View File
@@ -1,49 +0,0 @@
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: mediamark-http-redirect
namespace: mediamark
spec:
hostnames:
- mediamark.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: mediamark
sectionName: http
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: mediamark
namespace: mediamark
spec:
hostnames:
- mediamark.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: mediamark
sectionName: https
rules:
- backendRefs:
- group: ""
kind: Service
name: mediamark-oauth2
port: 4180
weight: 1
matches:
- path:
type: PathPrefix
value: /
-19
View File
@@ -1,19 +0,0 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- vaultauth.yaml
- vaultstaticsecret.yaml
- vaultdynamicsecret.yaml
- pv-mediastore.yaml
- pvc-mediastore.yaml
- deployment.yaml
- oauth2-proxy-configmap.yaml
- oauth2-proxy-deployment.yaml
- service.yaml
- gateway.yaml
- httproute.yaml
- gateway-external.yaml
- httproute-external.yaml
-7
View File
@@ -1,7 +0,0 @@
---
apiVersion: v1
kind: Namespace
metadata:
labels:
app.kubernetes.io/name: mediamark
name: mediamark
@@ -1,45 +0,0 @@
---
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
# from the oauth-credentials Secret). Single auth front for mediamark on both
# host names; access is gated here on the akP-mediamark-user Authentik group and
# re-checked by the app from X-Forwarded-Groups.
apiVersion: v1
kind: ConfigMap
metadata:
name: mediamark-oauth2-env
namespace: mediamark
data:
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
OAUTH2_PROXY_PROVIDER: "oidc"
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/mediamark/"
# Relative (host-less) redirect URL: with reverse-proxy mode on, oauth2-proxy
# derives scheme+host per request from X-Forwarded-Proto/Host, so the same
# deployment serves BOTH the external mediamark.unkin.net and internal
# mediamark.k8s.syd1.au.unkin.net callbacks. Both absolute callback URIs are
# registered on the Authentik provider (terraform-authentik, separate PR).
OAUTH2_PROXY_REDIRECT_URL: "/oauth2/callback"
OAUTH2_PROXY_UPSTREAMS: "http://mediamark.mediamark.svc.cluster.local:8080/"
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
# Populate session.Groups from the Authentik ak_groups claim; pass-user-headers
# then emits it as a single comma-joined X-Forwarded-Groups header.
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-mediamark-user"
# Forward identity + groups to mediamark as X-Forwarded-{User,Email,Groups}.
# NOTE: set-xauthrequest is intentionally NOT set -- it only populates
# auth_request *response* headers, which never reach a proxied upstream.
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
# Authentik hardcodes email_verified=false in the id_token; authorization is
# enforced via ak_groups, so accepting the unverified email is safe.
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
OAUTH2_PROXY_COOKIE_SECURE: "true"
# One cookie domain per host (a single parent-domain cookie can't span
# unkin.net and k8s.syd1.au.unkin.net cleanly); oauth2-proxy picks the domain
# matching the request host. Whitelist both so post-auth `rd` redirects to
# either front door are honoured.
OAUTH2_PROXY_COOKIE_DOMAINS: "mediamark.unkin.net,mediamark.k8s.syd1.au.unkin.net"
OAUTH2_PROXY_WHITELIST_DOMAINS: "mediamark.unkin.net,mediamark.k8s.syd1.au.unkin.net"
OAUTH2_PROXY_REVERSE_PROXY: "true"
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
@@ -1,133 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: mediamark-oauth2
namespace: mediamark
annotations:
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
spec:
replicas: 2
selector:
matchLabels:
app: mediamark-oauth2
strategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app: mediamark-oauth2
spec:
serviceAccountName: default
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
initContainers:
# The Authentik issuer is served behind the internal unkin.net CA;
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
# trusts the discovery endpoint.
- name: combine-certs
image: docker.io/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
- -c
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
volumeMounts:
- name: vault-ca-cert
mountPath: /custom-ca
readOnly: true
- name: combined-certs
mountPath: /combined-certs
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 32Mi
limits:
cpu: 200m
memory: 64Mi
containers:
- name: oauth2-proxy
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
imagePullPolicy: IfNotPresent
ports:
- containerPort: 4180
name: http
protocol: TCP
envFrom:
- configMapRef:
name: mediamark-oauth2-env
optional: false
env:
- name: OAUTH2_PROXY_CLIENT_ID
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_id
- name: OAUTH2_PROXY_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_secret
- name: OAUTH2_PROXY_COOKIE_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: cookie_secret
volumeMounts:
- name: combined-certs
mountPath: /etc/ssl/combined
readOnly: true
livenessProbe:
httpGet:
path: /ping
port: http
initialDelaySeconds: 10
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /ready
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
- name: combined-certs
emptyDir: {}
restartPolicy: Always
-32
View File
@@ -1,32 +0,0 @@
---
# Static PV for the shared MEDIASTORE CephFS subvolume, same rootPath as the
# arrstack/fafflix/cheeztv mediastore PVs. Each namespace gets its own PV
# (unique name + volumeHandle) pinned by claimRef; mediamark reads and rewrites
# the same library tree the *arr apps import into, so it must be the same
# filesystem (hardlink-safe).
apiVersion: v1
kind: PersistentVolume
metadata:
name: mediamark-mediastore
spec:
capacity:
storage: 10Ti
accessModes:
- ReadWriteMany
persistentVolumeReclaimPolicy: Retain
storageClassName: ""
volumeMode: Filesystem
claimRef:
namespace: mediamark
name: mediamark-mediastore
csi:
driver: cephfs.csi.ceph.com
volumeHandle: mediamark-mediastore-static
nodeStageSecretRef:
name: csi-cephfs-secret
namespace: csi-cephfs
volumeAttributes:
staticVolume: "true"
clusterID: cephfs_csi_ssd_ec_4_1
fsName: cephfs
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
-20
View File
@@ -1,20 +0,0 @@
---
# Statically bound to the mediamark-mediastore PV; storageClassName "" +
# volumeName disables dynamic provisioning. Not backed up here -- the media tree
# is backed up once from arrstack.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: mediamark-mediastore
namespace: mediamark
annotations:
k8up.io/backup: "false"
spec:
accessModes:
- ReadWriteMany
resources:
requests:
storage: 10Ti
storageClassName: ""
volumeName: mediamark-mediastore
volumeMode: Filesystem
-36
View File
@@ -1,36 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: mediamark
namespace: mediamark
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 8080
protocol: TCP
targetPort: http
selector:
app: mediamark
sessionAffinity: None
type: ClusterIP
---
# Front-door entry Service: both HTTPRoutes target this; all traffic enters via
# oauth2-proxy.
apiVersion: v1
kind: Service
metadata:
name: mediamark-oauth2
namespace: mediamark
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 4180
protocol: TCP
targetPort: http
selector:
app: mediamark-oauth2
sessionAffinity: None
type: ClusterIP
-38
View File
@@ -1,38 +0,0 @@
---
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultAuth
metadata:
name: default
namespace: mediamark
spec:
allowedNamespaces:
- mediamark
kubernetes:
audiences:
- vault
role: default
serviceAccount: default
tokenExpirationSeconds: 600
method: kubernetes
mount: k8s/au/syd1
vaultConnectionRef: vso-system/default
---
# Separate auth for the arrstack secrets engine: the `mediamark` k8s role is the
# only one whose policy grants arrstack/creds/mediamark.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultAuth
metadata:
name: arrstack-creds
namespace: mediamark
spec:
allowedNamespaces:
- mediamark
kubernetes:
audiences:
- vault
role: mediamark
serviceAccount: default
tokenExpirationSeconds: 600
method: kubernetes
mount: k8s/au/syd1
vaultConnectionRef: vso-system/default
@@ -1,21 +0,0 @@
---
# Ephemeral arrstack virtual key. The engine mints one machine token covering
# both radarr and sonarr; it is only honoured by arrproxy, which validates it and
# swaps in the real per-app key upstream. Role ttl is 60s, so VSO renews the
# lease continuously (renewalPercent default 67) and rewrites the secret; the
# reloader annotation restarts pods when the token actually changes.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultDynamicSecret
metadata:
name: arrstack-virtual-key
namespace: mediamark
spec:
allowStaticCreds: false
destination:
create: true
name: arrstack-virtual-key
overwrite: true
mount: arrstack
path: creds/mediamark
revoke: true
vaultAuthRef: arrstack-creds
@@ -1,22 +0,0 @@
---
# Authentik OIDC client for the mediamark front door (client_id, client_secret,
# cookie_secret) at kv/kubernetes/namespace/mediamark/default/oauth-credentials.
# The default k8s role's templated policy already grants read on
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so no
# terraform-vault change is needed.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: oauth-credentials
namespace: mediamark
spec:
destination:
create: true
name: oauth-credentials
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/mediamark/default/oauth-credentials
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
+1 -1
View File
@@ -83,7 +83,7 @@ spec:
- mountPath: /data
name: data
- name: metrics-exporter
image: docker.io/oliver006/redis_exporter:v1.89.0
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 9121
+8 -5
View File
@@ -6,11 +6,14 @@ metadata:
namespace: pdbmux
data:
PDBMUX_LISTEN: ":8080"
# Two PuppetDB backends merged during the VM -> k8s migration, in precedence
# order (first wins ties / pass-through):
# new = the in-cluster k8s PuppetDB (plain HTTP on 8080; in-cluster address
# is preferred over the external gateway to avoid a hairpin)
# Two PuppetDB backends merged during the VM -> k8s migration:
# old = legacy Consul-registered puppetdbapi (reachable from pods via the
# Consul DNS the puppet workloads already use)
PDBMUX_BACKENDS: "new=http://puppetdb.puppet.svc.cluster.local:8080,old=http://puppetdbapi.service.consul:8080"
# new = the in-cluster k8s PuppetDB (plain HTTP on 8080; in-cluster address
# is preferred over the external gateway to avoid a hairpin).
PDBMUX_BACKENDS: "old=http://puppetdbapi.service.consul:8080,new=http://puppetdb.puppet.svc.cluster.local:8080"
# "new" (the k8s PuppetDB) is the primary for non-merged pass-through and the
# preferred backend for ties / static-merge fallback.
PDBMUX_PRIMARY: "new"
PDBMUX_PREFER: "new"
PDBMUX_MERGE: "freshness"
+3 -2
View File
@@ -25,14 +25,15 @@ spec:
- name: pdbmux
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on
# a v* tag. It only exists after that tag is cut (see PR merge gates).
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.4.0
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.1.0
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080
name: http
protocol: TCP
envFrom:
# PDBMUX_LISTEN / PDBMUX_BACKENDS / PDBMUX_MERGE
# PDBMUX_LISTEN / PDBMUX_BACKENDS / PDBMUX_PRIMARY / PDBMUX_PREFER /
# PDBMUX_MERGE
- configMapRef:
name: pdbmux-env
optional: false
@@ -11,10 +11,9 @@ metadata:
namespace: puppet
data:
OPENVOXSERVER_PORT: "8140"
OPENVOXSERVER_ENVIRONMENT_TIMEOUT: "0"
DNS_ALT_NAMES: "puppetserver-compiler,puppet,puppet.k8s.syd1.au.unkin.net"
OPENVOXDB_SERVER_URLS: "https://puppetdb:8081"
CA_ENABLED: "false"
CA_HOSTNAME: "puppetca"
CA_PORT: "8140"
OPENVOXSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
PUPPETSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
@@ -12,4 +12,4 @@ metadata:
data:
PUPPET_DATA_DIR: "/etc/puppetlabs/code/environments"
PUPPET_SSL_DIR: "/etc/puppetlabs/puppet/ssl/certs"
OPENVOXSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
PUPPETSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
@@ -12,8 +12,7 @@ metadata:
data:
OPENVOXSERVER_HOSTNAME: "puppet"
OPENVOXSERVER_PORT: "8140"
OPENVOXSERVER_ENVIRONMENT_TIMEOUT: "0"
DNS_ALT_NAMES: "puppet,puppetserver-agents-to-puppet,puppetca,puppet-headless,puppetca.k8s.syd1.au.unkin.net,puppet.k8s.syd1.au.unkin.net"
OPENVOXDB_SERVER_URLS: "https://puppetdb:8081"
CA_ALLOW_SUBJECT_ALT_NAMES: "true"
OPENVOXSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
PUPPETSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
@@ -99,24 +99,6 @@ spec:
- mountPath: /docker-custom-entrypoint.d/post-startup/additional-ruby-gems.sh
name: additional-ruby-gems
subPath: additional-ruby-gems.sh
- mountPath: /usr/local/bin/certmanager
name: cert-helpers
subPath: vault-helper
- mountPath: /usr/local/bin/sshsignhost
name: cert-helpers
subPath: vault-helper
- mountPath: /opt/certmanager/config.yaml
name: cert-helpers
subPath: certmanager-config.yaml
- mountPath: /opt/sshsignhost/config.yaml
name: cert-helpers
subPath: sshsignhost-config.yaml
- mountPath: /configmaps/auth.conf
name: compiler-auth-conf
subPath: auth.conf
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
name: compiler-auth-conf-seed
subPath: 10-auth-conf.sh
initContainers:
- name: copy-configmaps
image: busybox:1.35
@@ -161,7 +143,7 @@ spec:
touch /opt/puppetlabs/server/data/puppetserver/dropsonde/bin/dropsonde
chown puppet:puppet -R /opt/puppetlabs/server/data/puppetserver/
env:
- name: OPENVOXSERVER_JAVA_ARGS
- name: PUPPETSERVER_JAVA_ARGS
value: -Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false
resources:
limits:
@@ -218,63 +200,6 @@ spec:
volumeMounts:
- mountPath: /opt/bin/
name: puppet-shared-bins
- name: setup-cert-helpers
image: git.unkin.net/unkin/almalinux9-base:20260606
command:
- sh
- -c
args:
- |
set -e
CH=/opt/bin/certhelpers
PYROOT=$CH/py-el9-1
TPL=/etc/puppetlabs/code/environments/develop/site/profiles/templates/helpers
mkdir -p "$CH"
# The helpers are python3 (requests, pyyaml) and openvoxserver ships
# no python, so stage a self-contained EL9 tree once per volume.
if [ ! -f "$PYROOT/.ready" ]; then
echo "Staging python runtime for the cert helpers..."
TMP=$CH/.py-el9-1.$$
rm -rf "$TMP"
dnf -y --installroot="$TMP" --releasever=9 --nodocs \
--setopt=install_weak_deps=0 --disablerepo=unkin install \
python3 python3-requests python3-pyyaml python3-six
rm -rf "$TMP/var/cache" "$TMP/var/lib/dnf" "$TMP/var/lib/rpm" \
"$TMP/usr/share/locale"
# Both hardcode EL absolute paths that only exist inside the tree.
SP=$TMP/usr/lib/python3.9/site-packages
ln -sfn ../../six.py "$SP/urllib3/packages/six.py"
sed -i "s|'/etc/pki/tls/certs/ca-bundle.crt'|'$PYROOT/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem'|" \
"$SP/requests/certs.py"
touch "$TMP/.ready"
mv -T "$TMP" "$PYROOT" || rm -rf "$TMP"
fi
# Render from the puppet-prod ERB templates on the code volume so this
# repo never carries a second copy of the scripts.
for n in certmanager sshsignhost; do
sed -e "s|<%= @venv_path %>|$PYROOT/usr|g" \
-e "s|<%= @config_path %>|/opt/$n/config.yaml|g" \
"$TPL/$n.erb" > "$CH/.$n.$$"
chmod 0755 "$CH/.$n.$$"
mv "$CH/.$n.$$" "$CH/$n"
done
echo "Cert helpers setup completed"
resources:
limits:
cpu: 1
memory: 1Gi
requests:
cpu: 200m
memory: 256Mi
volumeMounts:
- mountPath: /opt/bin/
name: puppet-shared-bins
- mountPath: /etc/puppetlabs/code/
name: puppet-code-volume
readOnly: true
securityContext:
fsGroup: 999
seccompProfile:
@@ -309,25 +234,5 @@ spec:
configMap:
name: additional-ruby-gems
defaultMode: 0755
- name: cert-helpers
configMap:
name: cert-helpers
items:
- key: vault-helper
path: vault-helper
mode: 0755
- key: certmanager-config.yaml
path: certmanager-config.yaml
mode: 0444
- key: sshsignhost-config.yaml
path: sshsignhost-config.yaml
mode: 0444
- name: compiler-auth-conf
configMap:
name: compiler-auth.conf
- name: compiler-auth-conf-seed
configMap:
name: compiler-auth-conf-seed
defaultMode: 0755
strategy:
type: RollingUpdate
-17
View File
@@ -54,25 +54,8 @@ configMapGenerator:
- resources/compiler/puppetdb.conf
options:
disableNameSuffixHash: true
- name: compiler-auth.conf
files:
- resources/compiler/auth.conf
options:
disableNameSuffixHash: true
- name: compiler-auth-conf-seed
files:
- resources/compiler/10-auth-conf.sh
options:
disableNameSuffixHash: true
- name: additional-ruby-gems
files:
- resources/additional-ruby-gems.sh
options:
disableNameSuffixHash: true
- name: cert-helpers
files:
- resources/cert-helpers/vault-helper
- resources/cert-helpers/certmanager-config.yaml
- resources/cert-helpers/sshsignhost-config.yaml
options:
disableNameSuffixHash: true
@@ -1,12 +0,0 @@
---
# profiles::helpers::certmanager::vault_config, with kubernetes auth: the
# certmanager approle is CIDR-bound to the legacy VM masters.
vault:
addr: 'https://vault.service.consul:8200'
auth_method: 'kubernetes'
k8s_mount: 'k8s/au/syd1'
k8s_role: 'puppet_certmanager'
jwt_path: '/var/run/secrets/kubernetes.io/serviceaccount/token'
mount_point: 'pki_int'
role_name: 'servers_default'
output_path: '/tmp/certmanager'
@@ -1,11 +0,0 @@
---
# profiles::helpers::sshsignhost::vault_config, with kubernetes auth.
vault:
addr: 'https://vault.service.consul:8200'
auth_method: 'kubernetes'
k8s_mount: 'k8s/au/syd1'
k8s_role: 'puppet_sshsigner'
jwt_path: '/var/run/secrets/kubernetes.io/serviceaccount/token'
mount_point: 'ssh-host-signer'
role_name: 'hostrole'
output_path: '/tmp/sshsignhost'
@@ -1,11 +0,0 @@
#!/bin/sh
# Runs the certmanager/sshsignhost helper matching the name it is invoked as.
# The openvoxserver image has no python, so the EL9 tree staged on the shared
# bins volume is started through its own dynamic loader.
set -eu
PYROOT=/opt/bin/certhelpers/py-el9-1
exec "${PYROOT}/lib64/ld-linux-x86-64.so.2" \
--library-path "${PYROOT}/lib64:${PYROOT}/usr/lib64" \
"${PYROOT}/usr/bin/python3.9" "/opt/bin/certhelpers/${0##*/}" "$@"
@@ -1,14 +0,0 @@
#!/bin/bash
set -euo pipefail
SRC=/configmaps/auth.conf
DST=/etc/puppetlabs/puppetserver/conf.d/auth.conf
# Copied rather than mounted: the entrypoint chowns conf.d and rewrites auth.conf,
# both of which fail on a read-only configmap mount and abort container startup.
if [ ! -s "$SRC" ]; then
echo "FATAL: $SRC missing or empty; refusing to start on the image default auth.conf" >&2
exit 1
fi
cp "$SRC" "$DST"
@@ -1,320 +0,0 @@
# Copied into conf.d at startup by 10-auth-conf.sh; the entrypoint then appends the
# admin API cache rule and re-renders the result, so the running file is not byte-identical.
authorization: {
version: 1
rules: [
{
# Allow nodes to retrieve their own catalog
match-request: {
path: "^/puppet/v3/catalog/([^/]+)$"
type: regex
method: [get, post]
}
allow: "$1"
sort-order: 500
name: "puppetlabs v3 catalog from agents"
},
{
# Allow catalog-diff to retrieve catalogs on behalf of others.
# sort-order 400 must stay lower than the puppetlabs deny that follows: rules
# sort by [sort-order, name] and the first match wins.
match-request: {
path: "^/puppet/v4/catalog/?$"
type: regex
method: post
}
allow: "catalog-diff.main.unkin.net"
sort-order: 400
name: "unkin v4 catalog for catalog-diff"
},
{
# Allow services to retrieve catalogs on behalf of others
match-request: {
path: "^/puppet/v4/catalog/?$"
type: regex
method: post
}
deny: "*"
sort-order: 500
name: "puppetlabs v4 catalog for services"
},
{
# Allow nodes to retrieve the certificate they requested earlier
match-request: {
path: "/puppet-ca/v1/certificate/"
type: path
method: get
}
allow-unauthenticated: true
sort-order: 500
name: "puppetlabs certificate"
},
{
# Allow all nodes to access the certificate revocation list
match-request: {
path: "/puppet-ca/v1/certificate_revocation_list/ca"
type: path
method: get
}
allow-unauthenticated: true
sort-order: 500
name: "puppetlabs crl"
},
{
# Allow nodes to request a new certificate
match-request: {
path: "/puppet-ca/v1/certificate_request"
type: path
method: [get, put]
}
allow-unauthenticated: true
sort-order: 500
name: "puppetlabs csr"
},
{
# Allow nodes to renew their certificate
match-request: {
path: "/puppet-ca/v1/certificate_renewal"
type: path
method: post
}
# this endpoint should never be unauthenticated, as it requires the cert to be provided.
allow: "*"
sort-order: 500
name: "puppetlabs certificate renewal"
},
{
# Allow the CA CLI to access the certificate_status endpoint
match-request: {
path: "/puppet-ca/v1/certificate_status"
type: path
method: [get, put, delete]
}
allow: {
extensions: {
pp_cli_auth: "true"
}
}
sort-order: 500
name: "puppetlabs cert status"
},
{
match-request: {
path: "^/puppet-ca/v1/certificate_revocation_list$"
type: regex
method: put
}
allow: {
extensions: {
pp_cli_auth: "true"
}
}
sort-order: 500
name: "puppetlabs CRL update"
},
{
# Allow the CA CLI to access the certificate_statuses endpoint
match-request: {
path: "/puppet-ca/v1/certificate_statuses"
type: path
method: get
}
allow: {
extensions: {
pp_cli_auth: "true"
}
}
sort-order: 500
name: "puppetlabs cert statuses"
},
{
# Allow authenticated access to the CA expirations endpoint
match-request: {
path: "/puppet-ca/v1/expirations"
type: path
method: get
}
allow: "*"
sort-order: 500
name: "puppetlabs CA cert and CRL expirations"
},
{
# Allow the CA CLI to access the certificate clean endpoint
match-request: {
path: "/puppet-ca/v1/clean"
type: path
method: put
}
allow: {
extensions: {
pp_cli_auth: "true"
}
}
sort-order: 500
name: "puppetlabs cert clean"
},
{
# Allow the CA CLI to access the certificate sign endpoint
match-request: {
path: "/puppet-ca/v1/sign"
type: path
method: post
}
allow: {
extensions: {
pp_cli_auth: "true"
}
}
sort-order: 500
name: "puppetlabs cert sign"
},
{
# Allow the CA CLI to access the certificate sign all endpoint
match-request: {
path: "/puppet-ca/v1/sign/all"
type: path
method: post
}
allow: {
extensions: {
pp_cli_auth: "true"
}
}
sort-order: 500
name: "puppetlabs cert sign all"
},
{
# Allow unauthenticated access to the status service endpoint
match-request: {
path: "/status/v1/services"
type: path
method: get
}
allow-unauthenticated: true
sort-order: 500
name: "puppetlabs status service - full"
},
{
match-request: {
path: "/status/v1/simple"
type: path
method: get
}
allow-unauthenticated: true
sort-order: 500
name: "puppetlabs status service - simple"
},
{
match-request: {
path: "/puppet/v3/environments"
type: path
method: get
}
allow: "*"
sort-order: 500
name: "puppetlabs environments"
},
{
# Allow nodes to access all file_bucket_files. Note that access for
# the 'delete' method is forbidden by Puppet regardless of the
# configuration of this rule.
match-request: {
path: "/puppet/v3/file_bucket_file"
type: path
method: [get, head, post, put]
}
allow: "*"
sort-order: 500
name: "puppetlabs file bucket file"
},
{
# Allow nodes to access all file_content. Note that access for the
# 'delete' method is forbidden by Puppet regardless of the
# configuration of this rule.
match-request: {
path: "/puppet/v3/file_content"
type: path
method: [get, post]
}
allow: "*"
sort-order: 500
name: "puppetlabs file content"
},
{
# Allow nodes to access all file_metadata. Note that access for the
# 'delete' method is forbidden by Puppet regardless of the
# configuration of this rule.
match-request: {
path: "/puppet/v3/file_metadata"
type: path
method: [get, post]
}
allow: "*"
sort-order: 500
name: "puppetlabs file metadata"
},
{
# Allow nodes to retrieve only their own node definition
match-request: {
path: "^/puppet/v3/node/([^/]+)$"
type: regex
method: get
}
allow: "$1"
sort-order: 500
name: "puppetlabs node"
},
{
# Allow nodes to store only their own reports
match-request: {
path: "^/puppet/v3/report/([^/]+)$"
type: regex
method: put
}
allow: "$1"
sort-order: 500
name: "puppetlabs report"
},
{
# Allow nodes to update their own facts
match-request: {
path: "^/puppet/v3/facts/([^/]+)$"
type: regex
method: put
}
allow: "$1"
sort-order: 500
name: "puppetlabs facts"
},
{
match-request: {
path: "/puppet/v3/static_file_content"
type: path
method: get
}
allow: "*"
sort-order: 500
name: "puppetlabs static file content"
},
{
match-request: {
path: "/puppet/v3/tasks"
type: path
}
allow: "*"
sort-order: 500
name: "puppet tasks information"
},
{
# Deny everything else. This ACL is not strictly
# necessary, but illustrates the default policy
match-request: {
path: "/"
type: path
}
deny: "*"
sort-order: 999
name: "puppetlabs deny all"
}
]
}
-123
View File
@@ -1,123 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: repospawner
namespace: repospawner
annotations:
secret.reloader.stakater.com/reload: "repospawner-woodpecker"
spec:
# Request state lives in memory and is rebuilt from Job labels on startup, so
# exactly one replica may exist at a time.
replicas: 1
selector:
matchLabels:
app: repospawner
strategy:
type: Recreate
template:
metadata:
labels:
app: repospawner
spec:
serviceAccountName: repospawner
automountServiceAccountToken: true
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
containers:
- name: repospawner
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/repospawner:v0.1.1
imagePullPolicy: IfNotPresent
ports:
- containerPort: 8080
name: http
protocol: TCP
env:
- name: REPOSPAWNER_NAMESPACE
value: repospawner
# The server passes its own image down to the Jobs, so this must
# match the image above exactly.
- name: REPOSPAWNER_IMAGE
value: artifactapi.k8s.syd1.au.unkin.net/docker-internal/repospawner:v0.1.1
- name: REPOSPAWNER_JOB_SERVICE_ACCOUNT
value: repospawner
- name: GITEA_URL
value: https://git.unkin.net
- name: REPOSPAWNER_TFGIT_REPO
value: unkin/terraform-git
- name: VAULT_ADDR
value: https://vault.service.consul:8200
- name: WOODPECKER_SERVER
value: https://ci.k8s.syd1.au.unkin.net
# Name only: the enablement Job mounts this Secret itself.
- name: REPOSPAWNER_WOODPECKER_SECRET
value: repospawner-woodpecker
- name: REPOSPAWNER_WOODPECKER_TOKEN_FILE
value: /etc/repospawner/woodpecker/token
# oauth2-proxy --pass-user-headers forwards the Authentik groups as a
# comma-joined X-Forwarded-Groups; X-Auth-Request-Groups is
# auth_request-response-only and never reaches a proxied upstream.
- name: REPOSPAWNER_GROUPS_HEADER
value: X-Forwarded-Groups
- name: REPOSPAWNER_ALLOWED_GROUPS
value: akP-repospawner-admin
volumeMounts:
- name: vault-token
mountPath: /var/run/secrets/vault
readOnly: true
- name: woodpecker-token
mountPath: /etc/repospawner/woodpecker
readOnly: true
livenessProbe:
httpGet:
path: /livez
port: http
initialDelaySeconds: 10
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /readyz
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 300m
memory: 256Mi
volumes:
# Native Vault kubernetes login: the default kubernetes.io token has the
# wrong audience, so the app reads this audience-vault projection.
- name: vault-token
projected:
sources:
- serviceAccountToken:
path: token
audience: vault
expirationSeconds: 600
# Optional: absent, the server starts and refuses woodpecker requests.
- name: woodpecker-token
secret:
secretName: repospawner-woodpecker
optional: true
items:
- key: token
path: token
restartPolicy: Always
@@ -1,39 +0,0 @@
---
# External (DMZ) front for repospawner on repospawner.unkin.net via the external
# Traefik (LB VIP 198.18.199.0). TLS terminates with the real Let's Encrypt
# *.unkin.net wildcard (Certificate wildcard-unkin-net in cert-manager,
# reflected into this namespace as wildcard-unkin-net-tls by the emberstack
# reflector), so there is no cert-manager annotation here. The apex
# repospawner.unkin.net A record lives in the bind-operator unkin.net zone, NOT
# external-dns, so no external-dns annotation either. oauth2-proxy fronts both
# hostnames.
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
labels:
traefik.io/instance: external
name: repospawner-external
namespace: repospawner
spec:
gatewayClassName: traefik-external
listeners:
- name: http
port: 80
protocol: HTTP
hostname: repospawner.unkin.net
allowedRoutes:
namespaces:
from: Same
- name: https
port: 443
protocol: HTTPS
hostname: repospawner.unkin.net
allowedRoutes:
namespaces:
from: Same
tls:
mode: Terminate
certificateRefs:
- group: ""
kind: Secret
name: wildcard-unkin-net-tls
-38
View File
@@ -1,38 +0,0 @@
---
# Internal front for repospawner (cf. mediamark).
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
labels:
traefik.io/instance: internal
annotations:
cert-manager.io/cluster-issuer: vault-issuer
cert-manager.io/common-name: repospawner.k8s.syd1.au.unkin.net
cert-manager.io/private-key-size: "4096"
external-dns.alpha.kubernetes.io/hostname: repospawner.k8s.syd1.au.unkin.net
external-dns.alpha.kubernetes.io/target: 198.18.200.4
name: repospawner
namespace: repospawner
spec:
gatewayClassName: traefik-internal
listeners:
- allowedRoutes:
namespaces:
from: Same
hostname: repospawner.k8s.syd1.au.unkin.net
name: http
port: 80
protocol: HTTP
- allowedRoutes:
namespaces:
from: Same
hostname: repospawner.k8s.syd1.au.unkin.net
name: https
port: 443
protocol: HTTPS
tls:
certificateRefs:
- group: ""
kind: Secret
name: repospawner-tls
mode: Terminate
@@ -1,49 +0,0 @@
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: repospawner-external-http-redirect
namespace: repospawner
spec:
hostnames:
- repospawner.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: repospawner-external
sectionName: http
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: repospawner-external
namespace: repospawner
spec:
hostnames:
- repospawner.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: repospawner-external
sectionName: https
rules:
- backendRefs:
- group: ""
kind: Service
name: repospawner-oauth2
port: 4180
weight: 1
matches:
- path:
type: PathPrefix
value: /
-49
View File
@@ -1,49 +0,0 @@
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: repospawner-http-redirect
namespace: repospawner
spec:
hostnames:
- repospawner.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: repospawner
sectionName: http
rules:
- filters:
- type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
matches:
- path:
type: PathPrefix
value: /
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: repospawner
namespace: repospawner
spec:
hostnames:
- repospawner.k8s.syd1.au.unkin.net
parentRefs:
- group: gateway.networking.k8s.io
kind: Gateway
name: repospawner
sectionName: https
rules:
- backendRefs:
- group: ""
kind: Service
name: repospawner-oauth2
port: 4180
weight: 1
matches:
- path:
type: PathPrefix
value: /
-18
View File
@@ -1,18 +0,0 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- namespace.yaml
- serviceaccount.yaml
- vaultauth.yaml
- rbac.yaml
- vaultstaticsecret.yaml
- deployment.yaml
- oauth2-proxy-configmap.yaml
- oauth2-proxy-deployment.yaml
- service.yaml
- gateway.yaml
- httproute.yaml
- gateway-external.yaml
- httproute-external.yaml
-7
View File
@@ -1,7 +0,0 @@
---
apiVersion: v1
kind: Namespace
metadata:
labels:
app.kubernetes.io/name: repospawner
name: repospawner
@@ -1,45 +0,0 @@
---
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
# from the oauth-credentials Secret). Single auth front for repospawner on both
# host names; access is gated here on the akP-repospawner-admin Authentik group
# and re-checked by the app from X-Forwarded-Groups.
apiVersion: v1
kind: ConfigMap
metadata:
name: repospawner-oauth2-env
namespace: repospawner
data:
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
OAUTH2_PROXY_PROVIDER: "oidc"
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/repospawner/"
# Relative (host-less) redirect URL: with reverse-proxy mode on, oauth2-proxy
# derives scheme+host per request from X-Forwarded-Proto/Host, so the same
# deployment serves BOTH the external repospawner.unkin.net and internal
# repospawner.k8s.syd1.au.unkin.net callbacks. Both absolute callback URIs are
# registered on the Authentik provider (terraform-authentik, separate PR).
OAUTH2_PROXY_REDIRECT_URL: "/oauth2/callback"
OAUTH2_PROXY_UPSTREAMS: "http://repospawner.repospawner.svc.cluster.local:8080/"
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
# Populate session.Groups from the Authentik ak_groups claim; pass-user-headers
# then emits it as a single comma-joined X-Forwarded-Groups header.
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-repospawner-admin"
# Forward identity + groups to repospawner as X-Forwarded-{User,Email,Groups}.
# NOTE: set-xauthrequest is intentionally NOT set -- it only populates
# auth_request *response* headers, which never reach a proxied upstream.
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
# Authentik hardcodes email_verified=false in the id_token; authorization is
# enforced via ak_groups, so accepting the unverified email is safe.
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
OAUTH2_PROXY_COOKIE_SECURE: "true"
# One cookie domain per host (a single parent-domain cookie can't span
# unkin.net and k8s.syd1.au.unkin.net cleanly); oauth2-proxy picks the domain
# matching the request host. Whitelist both so post-auth `rd` redirects to
# either front door are honoured.
OAUTH2_PROXY_COOKIE_DOMAINS: "repospawner.unkin.net,repospawner.k8s.syd1.au.unkin.net"
OAUTH2_PROXY_WHITELIST_DOMAINS: "repospawner.unkin.net,repospawner.k8s.syd1.au.unkin.net"
OAUTH2_PROXY_REVERSE_PROXY: "true"
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
@@ -1,133 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: repospawner-oauth2
namespace: repospawner
annotations:
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
spec:
replicas: 2
selector:
matchLabels:
app: repospawner-oauth2
strategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app: repospawner-oauth2
spec:
serviceAccountName: default
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
initContainers:
# The Authentik issuer is served behind the internal unkin.net CA;
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
# trusts the discovery endpoint.
- name: combine-certs
image: docker.io/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
- -c
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
volumeMounts:
- name: vault-ca-cert
mountPath: /custom-ca
readOnly: true
- name: combined-certs
mountPath: /combined-certs
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 32Mi
limits:
cpu: 200m
memory: 64Mi
containers:
- name: oauth2-proxy
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
imagePullPolicy: IfNotPresent
ports:
- containerPort: 4180
name: http
protocol: TCP
envFrom:
- configMapRef:
name: repospawner-oauth2-env
optional: false
env:
- name: OAUTH2_PROXY_CLIENT_ID
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_id
- name: OAUTH2_PROXY_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_secret
- name: OAUTH2_PROXY_COOKIE_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: cookie_secret
volumeMounts:
- name: combined-certs
mountPath: /etc/ssl/combined
readOnly: true
livenessProbe:
httpGet:
path: /ping
port: http
initialDelaySeconds: 10
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /ready
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
- name: combined-certs
emptyDir: {}
restartPolicy: Always
-48
View File
@@ -1,48 +0,0 @@
---
# The server creates one Job per request phase and polls Job/Pod state to drive
# the state machine and rebuild it after a restart.
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: repospawner
namespace: repospawner
rules:
- apiGroups:
- batch
resources:
- jobs
verbs:
- create
- get
- list
- watch
- delete
- apiGroups:
- ""
resources:
- pods
verbs:
- get
- list
- watch
- apiGroups:
- ""
resources:
- pods/log
verbs:
- get
- list
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: repospawner
namespace: repospawner
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: Role
name: repospawner
subjects:
- kind: ServiceAccount
name: repospawner
namespace: repospawner
-36
View File
@@ -1,36 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: repospawner
namespace: repospawner
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 8080
protocol: TCP
targetPort: http
selector:
app: repospawner
sessionAffinity: None
type: ClusterIP
---
# Front-door entry Service: both HTTPRoutes target this; all traffic enters via
# oauth2-proxy.
apiVersion: v1
kind: Service
metadata:
name: repospawner-oauth2
namespace: repospawner
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 4180
protocol: TCP
targetPort: http
selector:
app: repospawner-oauth2
sessionAffinity: None
type: ClusterIP
@@ -1,8 +0,0 @@
---
# Bound to the Vault kubernetes auth role `repospawner`; the server and the Jobs
# it spawns both run as this account and log into Vault natively.
apiVersion: v1
kind: ServiceAccount
metadata:
name: repospawner
namespace: repospawner
-20
View File
@@ -1,20 +0,0 @@
---
# Only VSO uses this; repospawner itself authenticates to Vault directly with a
# projected audience-vault token, not through the operator.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultAuth
metadata:
name: default
namespace: repospawner
spec:
allowedNamespaces:
- repospawner
kubernetes:
audiences:
- vault
role: default
serviceAccount: default
tokenExpirationSeconds: 600
method: kubernetes
mount: k8s/au/syd1
vaultConnectionRef: vso-system/default
@@ -1,42 +0,0 @@
---
# Authentik OIDC client for the repospawner front door (client_id,
# client_secret, cookie_secret). The default k8s role's templated policy already
# grants read on kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so
# no terraform-vault change is needed.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: oauth-credentials
namespace: repospawner
spec:
destination:
create: true
name: oauth-credentials
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/repospawner/default/oauth-credentials
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
---
# Woodpecker API token (key `token`). Optional by design: without it the server
# still starts and refuses `woodpecker: true` requests with 503. The server
# mounts it to answer /api/capabilities; the enablement Job mounts the same
# secret by name via REPOSPAWNER_WOODPECKER_SECRET.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultStaticSecret
metadata:
name: repospawner-woodpecker
namespace: repospawner
spec:
destination:
create: true
name: repospawner-woodpecker
overwrite: true
hmacSecretData: true
mount: kv
path: kubernetes/namespace/repospawner/default/woodpecker
refreshAfter: 5m
type: kv-v2
vaultAuthRef: default
@@ -35,7 +35,7 @@ spec:
# system roots with the internal CA so oauth2-proxy's OIDC HTTP client
# trusts it.
- name: combine-certs
image: docker.io/library/alpine:3
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
-4
View File
@@ -10,12 +10,9 @@ resources:
- serviceaccount_arrproxy_ci.yaml
- serviceaccount_autobackup_operator_ci.yaml
- serviceaccount_ghp.yaml
- serviceaccount_golib_ci.yaml
- serviceaccount_kea_operator_ci.yaml
- serviceaccount_mediamark_ci.yaml
- serviceaccount_plugin_docker_buildx.yaml
- serviceaccount_jellyfin_ha_src.yaml
- serviceaccount_repospawner_ci.yaml
- serviceaccount_terraform_artifactapi.yaml
- serviceaccount_terraform_authentik.yaml
- serviceaccount_terraform_enc.yaml
@@ -26,6 +23,5 @@ resources:
- serviceaccount_terraform_radarr.yaml
- serviceaccount_terraform_sonarr.yaml
- serviceaccount_terraform_vault.yaml
- serviceaccount_vimpack_ci.yaml
- vaultauth.yaml
- vaultstaticsecret.yaml
@@ -1,6 +0,0 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: golib-ci
namespace: woodpecker
@@ -1,6 +0,0 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: mediamark-ci
namespace: woodpecker
@@ -1,6 +0,0 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: repospawner-ci
namespace: woodpecker
@@ -1,6 +0,0 @@
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: vimpack-ci
namespace: woodpecker
@@ -2,9 +2,10 @@
# resources in all namespaces (the logs cluster lives in the `logging` namespace).
# CRDs are installed at runtime by the chart's crdHook Job.
#
# Upstream official images; no Docker Hardened Image variant is adopted (DHI is
# subscription-gated and served from a private org namespace not reachable via
# the anonymous artifactapi dockerhub proxy).
# All images are pulled through the artifactapi dockerhub remote (no direct
# upstream). Upstream official images are used; no Docker Hardened Image variant
# is adopted (DHI is subscription-gated and served from a private org namespace
# not reachable via the anonymous artifactapi dockerhub proxy).
#
# Watch the logging namespace where the ClickHouseInstallation lives. The chart
# default (watchNamespaces: []) makes the operator watch ONLY its own namespace
@@ -13,7 +14,7 @@ watchNamespaces:
- logging
crdHook:
image:
repository: docker.io/bitnami/kubectl
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/bitnami/kubectl
resources:
requests:
cpu: 50m
@@ -24,7 +25,7 @@ crdHook:
operator:
image:
repository: docker.io/altinity/clickhouse-operator
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/altinity/clickhouse-operator
resources:
requests:
cpu: 100m
@@ -35,7 +36,7 @@ operator:
metrics:
image:
repository: docker.io/altinity/metrics-exporter
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/altinity/metrics-exporter
resources:
requests:
cpu: 50m
@@ -57,9 +57,10 @@ config:
- "_INBOX.>"
container:
# Upstream official nats; no DHI variant available.
# Pulled through the artifactapi dockerhub remote (upstream official nats;
# no DHI variant available for nats).
image:
repository: docker.io/library/nats
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/nats
tag: 2.14.2-alpine
env:
NATS_ADMIN_PASSWORD:
@@ -93,10 +94,10 @@ podTemplate:
annotations:
configmap.reloader.stakater.com/auto: "true"
# Config-reloader sidecar image.
# Config-reloader sidecar image, also through artifactapi.
reloader:
image:
repository: docker.io/natsio/nats-server-config-reloader
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/natsio/nats-server-config-reloader
tag: "0.23.0"
natsBox:
@@ -5,10 +5,10 @@
role: Agent
fullnameOverride: vector-agent
# distroless-libc (no DHI — subscription-gated/private-namespace, not reachable
# via the anon proxy).
# Pulled through the artifactapi dockerhub remote; distroless-libc (no DHI —
# subscription-gated/private-namespace, not reachable via the anon proxy).
image:
repository: docker.io/timberio/vector
repository: artifactapi.k8s.syd1.au.unkin.net/dockerhub/timberio/vector
tag: 0.57.0-distroless-libc
rbac:

Some files were not shown because too many files have changed in this diff Show More