Compare commits
1 Commits
main
..
931bfcf923
| Author | SHA1 | Date | |
|---|---|---|---|
| 931bfcf923 |
@@ -5,9 +5,7 @@ metadata:
|
||||
name: arrproxy-api
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
# Wave 2: start only after the wave-0 CNPG Cluster and VSO-synced Secrets
|
||||
# exist. The api self-migrates at startup under a Postgres advisory lock and
|
||||
# holds /readyz until the schema is current, so no migration ordering is needed.
|
||||
# Wave 2: serve only after the wave-1 migrate Job completes.
|
||||
argocd.argoproj.io/sync-wave: "2"
|
||||
secret.reloader.stakater.com/reload: "arrproxy-pepper,arrproxy-admin-token,arrproxy-db-app,sonarr-adult-apikey,radarr-adult-apikey,sonarr-kids-apikey,radarr-kids-apikey"
|
||||
configmap.reloader.stakater.com/reload: "arrproxy-tiers"
|
||||
@@ -36,7 +34,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: api
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.6.1
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.4.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
|
||||
@@ -1,11 +1,9 @@
|
||||
---
|
||||
# External (DMZ) front for the arrstack, served on arrstack.unkin.net via the
|
||||
# external Traefik (LB VIP 198.18.199.0). The apex arrstack.unkin.net A record
|
||||
# lives in the bind-operator unkin.net zone (bind-internal/authoritative), NOT
|
||||
# external-dns, so no external-dns annotation here. Public TLS is terminated with
|
||||
# the real Let's Encrypt *.unkin.net wildcard, centrally minted once in the
|
||||
# cert-manager namespace (Certificate wildcard-unkin-net) and reflected into this
|
||||
# namespace by the emberstack reflector as wildcard-unkin-net-tls, not Vault PKI.
|
||||
# external Traefik (LB VIP 198.18.199.0). cert-manager mints arrproxy-gateway-tls
|
||||
# (CN arrstack.unkin.net) off the internal Vault-PKI CA. The apex arrstack.unkin.net
|
||||
# A record lives in the bind-operator unkin.net zone (bind-internal/authoritative),
|
||||
# NOT external-dns, so no external-dns annotation here.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
@@ -13,6 +11,9 @@ metadata:
|
||||
traefik.io/instance: external
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "2"
|
||||
cert-manager.io/cluster-issuer: vault-issuer
|
||||
cert-manager.io/common-name: arrstack.unkin.net
|
||||
cert-manager.io/private-key-size: "4096"
|
||||
name: arrproxy
|
||||
namespace: arrstack
|
||||
spec:
|
||||
@@ -37,4 +38,4 @@ spec:
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: wildcard-unkin-net-tls
|
||||
name: arrproxy-gateway-tls
|
||||
|
||||
@@ -5,6 +5,8 @@ kind: Kustomization
|
||||
resources:
|
||||
- cnpg_cluster.yaml
|
||||
- cnpg_backup.yaml
|
||||
- migrations-configmap.yaml
|
||||
- migrate-job.yaml
|
||||
- vaultstaticsecret.yaml
|
||||
- tiers-configmap.yaml
|
||||
- oauth2-proxy-configmap.yaml
|
||||
|
||||
@@ -0,0 +1,92 @@
|
||||
---
|
||||
# Applies the arrproxy schema once per sync, before the api rolls, so the serve
|
||||
# replicas never race migrations (arrproxy-api does not self-migrate). Runs as the
|
||||
# CNPG-minted app user so the tokens table is owned by that role.
|
||||
#
|
||||
# Sync-phase hook at wave 1 (NOT PreSync): the CNPG Cluster + generated
|
||||
# arrproxy-db-app Secret apply at wave 0 and ArgoCD waits for the Cluster to be
|
||||
# Healthy before starting wave 1, so Postgres exists before migrate connects.
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: arrproxy-migrate
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/hook: Sync
|
||||
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
|
||||
argocd.argoproj.io/sync-wave: "1"
|
||||
spec:
|
||||
backoffLimit: 6
|
||||
ttlSecondsAfterFinished: 600
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: arrproxy-migrate
|
||||
spec:
|
||||
serviceAccountName: default
|
||||
automountServiceAccountToken: false
|
||||
restartPolicy: Never
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 65532
|
||||
runAsGroup: 65532
|
||||
fsGroup: 65532
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: migrate
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/postgres:18-alpine
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: HOME
|
||||
value: /tmp
|
||||
- name: PGUSER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: arrproxy-db-app
|
||||
key: username
|
||||
- name: PGPASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: arrproxy-db-app
|
||||
key: password
|
||||
- name: PGHOST
|
||||
value: arrproxy-db-rw.arrstack.svc.cluster.local
|
||||
- name: PGPORT
|
||||
value: "5432"
|
||||
- name: PGDATABASE
|
||||
value: arrproxy
|
||||
- name: PGSSLMODE
|
||||
value: require
|
||||
command:
|
||||
- psql
|
||||
- -v
|
||||
- ON_ERROR_STOP=1
|
||||
- -f
|
||||
- /migrations/0001_init.sql
|
||||
volumeMounts:
|
||||
- name: migrations
|
||||
mountPath: /migrations
|
||||
readOnly: true
|
||||
- name: tmp
|
||||
mountPath: /tmp
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
volumes:
|
||||
- name: migrations
|
||||
configMap:
|
||||
name: arrproxy-migrations
|
||||
- name: tmp
|
||||
emptyDir:
|
||||
sizeLimit: 64Mi
|
||||
@@ -0,0 +1,29 @@
|
||||
---
|
||||
# arrproxy schema, mirrored from the arrproxy repo migrations/0001_init.sql
|
||||
# (v0.1.0). arrproxy-api does NOT self-migrate, so the wave-1 migrate Job applies
|
||||
# this once per sync as the app user. Keep in sync with the repo on schema bumps.
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: arrproxy-migrations
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "0"
|
||||
data:
|
||||
0001_init.sql: |
|
||||
-- arrproxy token store. Only token hashes are persisted; plaintext is shown
|
||||
-- once at mint time and never recoverable.
|
||||
CREATE TABLE IF NOT EXISTS tokens (
|
||||
id TEXT PRIMARY KEY,
|
||||
subject TEXT NOT NULL,
|
||||
label TEXT NOT NULL DEFAULT '',
|
||||
token_hash TEXT NOT NULL UNIQUE,
|
||||
apps TEXT[] NOT NULL DEFAULT '{}',
|
||||
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
|
||||
expires_at TIMESTAMPTZ,
|
||||
disabled BOOLEAN NOT NULL DEFAULT false,
|
||||
last_used_at TIMESTAMPTZ
|
||||
);
|
||||
|
||||
CREATE INDEX IF NOT EXISTS tokens_subject_idx ON tokens (subject);
|
||||
CREATE INDEX IF NOT EXISTS tokens_token_hash_idx ON tokens (token_hash);
|
||||
@@ -35,7 +35,7 @@ spec:
|
||||
# identity.unkin.net serves a Vault-PKI cert; combine the system roots
|
||||
# with the internal CA so oauth2-proxy's OIDC HTTP client trusts it.
|
||||
- name: combine-certs
|
||||
image: docker.io/library/alpine:3
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
|
||||
@@ -31,7 +31,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: ui
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.6.1
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-ui:v0.4.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
|
||||
@@ -8,12 +8,9 @@ resources:
|
||||
- pv-media-tv.yaml
|
||||
- pv-media-movies.yaml
|
||||
- pv-mediafs.yaml
|
||||
- pv-mediastore.yaml
|
||||
- pvc-media-tv.yaml
|
||||
- pvc-media-movies.yaml
|
||||
- pvc-mediafs.yaml
|
||||
- pvc-mediastore.yaml
|
||||
- mediastore-bootstrap-job.yaml
|
||||
- media-bucket.yaml
|
||||
- backups-bucket.yaml
|
||||
- postgres
|
||||
|
||||
@@ -1,74 +0,0 @@
|
||||
---
|
||||
# Seeds the directory skeleton on the freshly created mediastore subvolume so
|
||||
# the arrs, nzbget and both jellyfins mount subPaths that already exist and are
|
||||
# owned by uid/gid 1000 (the uid every arrstack media pod runs as). mkdir -p is
|
||||
# idempotent, so re-running it on every sync is harmless and self-heals a tree
|
||||
# someone deleted by hand.
|
||||
#
|
||||
# Sync hook with BeforeHookCreation delete: ArgoCD replaces the completed Job
|
||||
# each sync instead of failing on the immutable pod template. No sync-wave is
|
||||
# needed -- the PVC applies in the same wave and the pod simply stays Pending
|
||||
# until it binds.
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: mediastore-bootstrap
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
argocd.argoproj.io/hook: Sync
|
||||
argocd.argoproj.io/hook-delete-policy: BeforeHookCreation
|
||||
spec:
|
||||
backoffLimit: 6
|
||||
ttlSecondsAfterFinished: 600
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: mediastore-bootstrap
|
||||
spec:
|
||||
serviceAccountName: default
|
||||
automountServiceAccountToken: false
|
||||
restartPolicy: Never
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
fsGroupChangePolicy: OnRootMismatch
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: mkdir
|
||||
image: docker.io/library/alpine:3
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
set -eu
|
||||
mkdir -p \
|
||||
/media/fafflix/tvseries \
|
||||
/media/fafflix/movies \
|
||||
/media/cheeztv/tvseries \
|
||||
/media/cheeztv/movies \
|
||||
/media/nzbget/downloads/complete
|
||||
ls -la /media
|
||||
volumeMounts:
|
||||
- name: mediastore
|
||||
mountPath: /media
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 128Mi
|
||||
volumes:
|
||||
- name: mediastore
|
||||
persistentVolumeClaim:
|
||||
claimName: mediastore
|
||||
@@ -1,32 +0,0 @@
|
||||
---
|
||||
# Static PV for the shared MEDIASTORE CephFS subvolume: one 10Ti filesystem
|
||||
# holding every library plus the nzbget download tree, so arr imports are
|
||||
# same-filesystem hardlink moves across tv AND movies. Same rootPath as the
|
||||
# fafflix/cheeztv mediastore PVs; each namespace gets its own PV (unique name +
|
||||
# volumeHandle) pinned by claimRef.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
name: arrstack-mediastore
|
||||
spec:
|
||||
capacity:
|
||||
storage: 10Ti
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: ""
|
||||
volumeMode: Filesystem
|
||||
claimRef:
|
||||
namespace: arrstack
|
||||
name: mediastore
|
||||
csi:
|
||||
driver: cephfs.csi.ceph.com
|
||||
volumeHandle: arrstack-mediastore-static
|
||||
nodeStageSecretRef:
|
||||
name: csi-cephfs-secret
|
||||
namespace: csi-cephfs
|
||||
volumeAttributes:
|
||||
staticVolume: "true"
|
||||
clusterID: cephfs_csi_ssd_ec_4_1
|
||||
fsName: cephfs
|
||||
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
|
||||
@@ -1,22 +0,0 @@
|
||||
---
|
||||
# Whole media tree (/fafflix, /cheeztv, /nzbget) on one RWX filesystem, shared
|
||||
# across the sonarr/radarr/nzbget pods. Statically bound to the
|
||||
# arrstack-mediastore PV (the same CephFS subvolume fafflix and cheeztv mount).
|
||||
# storageClassName "" + volumeName disables dynamic provisioning and binds the
|
||||
# pre-created static PV.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: mediastore
|
||||
namespace: arrstack
|
||||
annotations:
|
||||
k8up.io/backup: "false"
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Ti
|
||||
storageClassName: ""
|
||||
volumeName: arrstack-mediastore
|
||||
volumeMode: Filesystem
|
||||
@@ -28,7 +28,7 @@ metadata:
|
||||
spec:
|
||||
shards: 1
|
||||
replicas: 2
|
||||
image: docker.io/valkey/valkey:9.0.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/valkey/valkey:9.0.0
|
||||
exporter:
|
||||
enabled: false
|
||||
scheduling:
|
||||
|
||||
@@ -36,7 +36,7 @@ spec:
|
||||
mountPath: /combined-certs
|
||||
containers:
|
||||
- name: api
|
||||
image: git.unkin.net/unkin/artifactapi:v3.11.2
|
||||
image: git.unkin.net/unkin/artifactapi:v3.11.1
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
|
||||
@@ -1,21 +1,4 @@
|
||||
---
|
||||
# Path split between the authenticated UI and the unauthenticated machine API.
|
||||
# Longest matching prefix wins, so the two UI rules take precedence over "/".
|
||||
#
|
||||
# AUTHENTICATED (oauth2 Service -> oauth2-proxy -> ui Service):
|
||||
# /oauth2 oauth2-proxy sign_in / start / callback / sign_out
|
||||
# /ui the human-facing SPA
|
||||
#
|
||||
# NOT AUTHENTICATED (artifactapi Service, unchanged):
|
||||
# /api/v1/{remote,local,virtual}/* package proxy reads (yum/dnf, pip, ...)
|
||||
# /api/v2/remotes|virtuals|locals/* management API + the UI's own XHR calls
|
||||
# /api/v2/remotes/{name}/files/* CI publish uploads (PUT) and downloads
|
||||
# /v2/* Docker Registry V2 (containerd, buildah)
|
||||
# /terraform/v1/providers/* Terraform provider registry
|
||||
# /.well-known/terraform.json Terraform service discovery
|
||||
# /health, /version, / probes and the redirect to /ui/
|
||||
# Those clients cannot complete a browser OIDC flow, so they must never be
|
||||
# routed through oauth2-proxy.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
@@ -39,17 +22,7 @@ spec:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: oauth2
|
||||
port: 80
|
||||
weight: 1
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /oauth2
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: oauth2
|
||||
name: ui
|
||||
port: 80
|
||||
weight: 1
|
||||
matches:
|
||||
|
||||
@@ -12,8 +12,6 @@ resources:
|
||||
- gateway.yaml
|
||||
- httproute.yaml
|
||||
- namespace.yaml
|
||||
- oauth2-proxy-configmap.yaml
|
||||
- oauth2-proxy-deployment.yaml
|
||||
- redis-deployment.yaml
|
||||
- services.yaml
|
||||
- ui-deployment.yaml
|
||||
|
||||
@@ -1,46 +0,0 @@
|
||||
---
|
||||
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
|
||||
# from the oauth-credentials Secret).
|
||||
#
|
||||
# SCOPE: this proxy fronts the artifactapi web UI ONLY. The HTTPRoute sends just
|
||||
# /ui and /oauth2 here; every machine surface (/api/v1, /api/v2, /v2 docker
|
||||
# registry, /terraform, /.well-known/terraform.json, /health, /version, /) goes
|
||||
# straight to the api Service and is NOT authenticated. yum/dnf, containerd
|
||||
# registry mirrors, docker/buildah, terraform init and Woodpecker publish steps
|
||||
# cannot complete a browser OIDC flow, so they must never reach this container.
|
||||
# Its only upstream is the ui Service -- there is deliberately no api upstream.
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: artifactapi-oauth2-env
|
||||
namespace: artifactapi
|
||||
data:
|
||||
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||
OAUTH2_PROXY_METRICS_ADDRESS: "0.0.0.0:44180"
|
||||
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||
# Publicly-trusted Authentik host: the authorize step is a browser redirect,
|
||||
# so the issuer must present a cert every user's browser already trusts (the
|
||||
# k8s host serves an internal-CA cert). Slug from terraform-authentik.
|
||||
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/artifactapi/"
|
||||
OAUTH2_PROXY_REDIRECT_URL: "https://artifactapi.k8s.syd1.au.unkin.net/oauth2/callback"
|
||||
OAUTH2_PROXY_UPSTREAMS: "http://ui.artifactapi.svc.cluster.local:80/"
|
||||
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
||||
# Populate session.Groups from the Authentik hierarchical ak_groups claim.
|
||||
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
||||
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-artifactapi-admin"
|
||||
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
||||
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
||||
# enforced via ak_groups, so accepting the unverified email is safe.
|
||||
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
||||
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
||||
OAUTH2_PROXY_COOKIE_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_WHITELIST_DOMAINS: "artifactapi.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||
# Back-channel discovery/token calls resolve the issuer inside the cluster,
|
||||
# where it is served under the internal unkin.net CA rather than the publicly
|
||||
# trusted cert the browser sees. Trust the bundle the combine-certs init
|
||||
# container assembles, as every other oauth2-proxy in the estate does.
|
||||
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
||||
@@ -1,136 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: oauth2
|
||||
namespace: artifactapi
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: oauth2
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: oauth2
|
||||
spec:
|
||||
serviceAccountName: default
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 65532
|
||||
runAsGroup: 65532
|
||||
fsGroup: 65532
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
initContainers:
|
||||
# The Authentik issuer is served behind the internal unkin.net CA;
|
||||
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
|
||||
# trusts the discovery endpoint.
|
||||
- name: combine-certs
|
||||
image: docker.io/library/alpine:3
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||
volumeMounts:
|
||||
- name: vault-ca-cert
|
||||
mountPath: /custom-ca
|
||||
readOnly: true
|
||||
- name: combined-certs
|
||||
mountPath: /combined-certs
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 64Mi
|
||||
containers:
|
||||
- name: oauth2-proxy
|
||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 4180
|
||||
name: http
|
||||
protocol: TCP
|
||||
- containerPort: 44180
|
||||
name: metrics
|
||||
protocol: TCP
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: artifactapi-oauth2-env
|
||||
optional: false
|
||||
env:
|
||||
- name: OAUTH2_PROXY_CLIENT_ID
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_id
|
||||
- name: OAUTH2_PROXY_CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_secret
|
||||
- name: OAUTH2_PROXY_COOKIE_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: cookie_secret
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ready
|
||||
port: http
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
volumeMounts:
|
||||
- name: combined-certs
|
||||
mountPath: /etc/ssl/combined
|
||||
readOnly: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
volumes:
|
||||
- name: vault-ca-cert
|
||||
secret:
|
||||
secretName: vault-ca-cert
|
||||
items:
|
||||
- key: ca.crt
|
||||
path: ca.crt
|
||||
- name: combined-certs
|
||||
emptyDir: {}
|
||||
restartPolicy: Always
|
||||
@@ -54,7 +54,7 @@ spec:
|
||||
successThreshold: 1
|
||||
timeoutSeconds: 5
|
||||
- name: metrics-exporter
|
||||
image: docker.io/oliver006/redis_exporter:v1.89.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 9121
|
||||
|
||||
@@ -16,26 +16,6 @@ spec:
|
||||
sessionAffinity: None
|
||||
type: ClusterIP
|
||||
---
|
||||
# Authenticated front door for the web UI only: api-route sends /ui and /oauth2
|
||||
# here, oauth2-proxy authenticates and forwards to the ui Service. Every other
|
||||
# path reaches the api Service above directly and stays unauthenticated.
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: oauth2
|
||||
namespace: artifactapi
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- name: http
|
||||
port: 80
|
||||
protocol: TCP
|
||||
targetPort: http
|
||||
selector:
|
||||
app: oauth2
|
||||
sessionAffinity: None
|
||||
type: ClusterIP
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
|
||||
@@ -22,7 +22,7 @@ spec:
|
||||
automountServiceAccountToken: true
|
||||
containers:
|
||||
- name: ui
|
||||
image: git.unkin.net/unkin/artifactapi-ui:v3.11.2
|
||||
image: git.unkin.net/unkin/artifactapi-ui:v3.11.1
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 80
|
||||
|
||||
@@ -32,26 +32,3 @@ spec:
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
---
|
||||
# Authentik OIDC client for the artifactapi UI front door (client_id,
|
||||
# client_secret, cookie_secret). Seeded out of band at
|
||||
# kv/kubernetes/namespace/artifactapi/default/oauth-credentials; the default
|
||||
# k8s auth role already grants the artifactapi/default ServiceAccount read on
|
||||
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so no
|
||||
# terraform-vault change is needed. Consumed by the oauth2 Deployment.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: oauth-credentials
|
||||
namespace: artifactapi
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
name: oauth-credentials
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/artifactapi/default/oauth-credentials
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
|
||||
@@ -14,17 +14,3 @@ spec:
|
||||
podMetricsEndpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
---
|
||||
# Scrape the UI oauth2-proxy (:44180), which exposes sign-in/authz counters.
|
||||
apiVersion: operator.victoriametrics.com/v1beta1
|
||||
kind: VMPodScrape
|
||||
metadata:
|
||||
name: oauth2
|
||||
namespace: artifactapi
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: oauth2
|
||||
podMetricsEndpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
|
||||
@@ -64,12 +64,8 @@ spec:
|
||||
archive_mode: "on"
|
||||
archive_timeout: 5min
|
||||
dynamic_shared_memory_type: posix
|
||||
effective_cache_size: 1536MB
|
||||
effective_cache_size: 256MB
|
||||
full_page_writes: "on"
|
||||
# Replicas report their oldest xmin to the primary, so multi-second reads on
|
||||
# a hot standby stop exhausting max_standby_streaming_delay and being
|
||||
# cancelled. Retained-dead-tuple cost is negligible on a ~155MB database.
|
||||
hot_standby_feedback: "on"
|
||||
log_destination: csvlog
|
||||
log_directory: /controller/log
|
||||
log_filename: postgres
|
||||
@@ -81,12 +77,7 @@ spec:
|
||||
max_parallel_workers: "16"
|
||||
max_replication_slots: "16"
|
||||
max_worker_processes: "16"
|
||||
# A pg_stat_statements.* parameter is what makes CNPG treat the extension as
|
||||
# managed and run CREATE EXTENSION in every database; preloading alone does
|
||||
# not create it.
|
||||
pg_stat_statements.max: "10000"
|
||||
pg_stat_statements.track: top
|
||||
shared_buffers: 512MB
|
||||
shared_buffers: 128MB
|
||||
shared_memory_type: mmap
|
||||
ssl_max_protocol_version: TLSv1.3
|
||||
ssl_min_protocol_version: TLSv1.3
|
||||
@@ -95,9 +86,6 @@ spec:
|
||||
wal_log_hints: "on"
|
||||
wal_receiver_timeout: 5s
|
||||
wal_sender_timeout: 5s
|
||||
# CNPG merges this with the libraries it manages itself.
|
||||
shared_preload_libraries:
|
||||
- pg_stat_statements
|
||||
syncReplicaElectionConstraint:
|
||||
enabled: false
|
||||
primaryUpdateMethod: restart
|
||||
@@ -117,16 +105,13 @@ spec:
|
||||
updateInterval: 30
|
||||
resources:
|
||||
limits:
|
||||
# 500m is a 50ms CFS quota per 100ms period, exhausted by bursts even at
|
||||
# ~0.01 cores average, so every query pays throttle latency.
|
||||
cpu: "2"
|
||||
cpu: 500m
|
||||
# 512Mi OOMKilled replicas under load (shared_buffers 128MB +
|
||||
# max_connections 200 leave no headroom) — see incident 2026-07-28.
|
||||
# shared_buffers 512MB needs the same headroom multiple, hence 2Gi.
|
||||
memory: 2Gi
|
||||
requests:
|
||||
cpu: 500m
|
||||
memory: 1Gi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 512Mi
|
||||
smartShutdownTimeout: 180
|
||||
startDelay: 3600
|
||||
stopDelay: 1800
|
||||
|
||||
@@ -1,47 +1,4 @@
|
||||
---
|
||||
# External (DMZ) front for public identity.unkin.net, served via the external
|
||||
# Traefik (LB VIP 198.18.199.0). The apex identity.unkin.net A record lives in
|
||||
# the bind-operator unkin.net zone (bind-internal/authoritative), NOT
|
||||
# external-dns, so no external-dns annotation here. Public TLS is terminated with
|
||||
# the real Let's Encrypt *.unkin.net wildcard, centrally minted once in the
|
||||
# cert-manager namespace (Certificate wildcard-unkin-net) and reflected into this
|
||||
# namespace by the emberstack reflector as wildcard-unkin-net-tls, not Vault PKI.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
labels:
|
||||
traefik.io/instance: external
|
||||
annotations:
|
||||
argocd.argoproj.io/sync-wave: "2"
|
||||
name: authentik
|
||||
namespace: authentik
|
||||
spec:
|
||||
gatewayClassName: traefik-external
|
||||
listeners:
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: identity.unkin.net
|
||||
name: http
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: identity.unkin.net
|
||||
name: https
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
tls:
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: wildcard-unkin-net-tls
|
||||
mode: Terminate
|
||||
---
|
||||
# Cluster hostname variant, identity.k8s.syd1.au.unkin.net. Internal Traefik,
|
||||
# external-dns at 198.18.200.4. Own leaf from the Vault PKI issuer via the
|
||||
# cert-manager gateway-shim; the common-name keys off this cluster host.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
@@ -49,11 +6,11 @@ metadata:
|
||||
traefik.io/instance: internal
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: vault-issuer
|
||||
cert-manager.io/common-name: identity.k8s.syd1.au.unkin.net
|
||||
cert-manager.io/common-name: identity.unkin.net
|
||||
cert-manager.io/private-key-size: "4096"
|
||||
external-dns.alpha.kubernetes.io/hostname: identity.k8s.syd1.au.unkin.net
|
||||
external-dns.alpha.kubernetes.io/hostname: identity.unkin.net,identity.k8s.syd1.au.unkin.net
|
||||
external-dns.alpha.kubernetes.io/target: 198.18.200.4
|
||||
name: authentik-internal
|
||||
name: authentik
|
||||
namespace: authentik
|
||||
spec:
|
||||
gatewayClassName: traefik-internal
|
||||
@@ -61,14 +18,14 @@ spec:
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: identity.k8s.syd1.au.unkin.net
|
||||
hostname: identity.unkin.net
|
||||
name: http
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: identity.k8s.syd1.au.unkin.net
|
||||
hostname: identity.unkin.net
|
||||
name: https
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
@@ -78,3 +35,23 @@ spec:
|
||||
kind: Secret
|
||||
name: authentik-tls
|
||||
mode: Terminate
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: identity.k8s.syd1.au.unkin.net
|
||||
name: http-internal
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: identity.k8s.syd1.au.unkin.net
|
||||
name: https-internal
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
tls:
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: authentik-tls
|
||||
mode: Terminate
|
||||
|
||||
@@ -7,11 +7,16 @@ metadata:
|
||||
spec:
|
||||
hostnames:
|
||||
- identity.unkin.net
|
||||
- identity.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: authentik
|
||||
sectionName: http
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: authentik
|
||||
sectionName: http-internal
|
||||
rules:
|
||||
- filters:
|
||||
- type: RequestRedirect
|
||||
@@ -31,93 +36,17 @@ metadata:
|
||||
spec:
|
||||
hostnames:
|
||||
- identity.unkin.net
|
||||
- identity.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: authentik
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: authentik-server
|
||||
port: 80
|
||||
weight: 1
|
||||
filters:
|
||||
- type: URLRewrite
|
||||
urlRewrite:
|
||||
path:
|
||||
type: ReplaceFullPath
|
||||
replaceFullPath: /application/o/token/
|
||||
matches:
|
||||
- path:
|
||||
type: Exact
|
||||
value: /application/o/token
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: authentik-server
|
||||
port: 80
|
||||
weight: 1
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: authentik-http-redirect-internal
|
||||
namespace: authentik
|
||||
spec:
|
||||
hostnames:
|
||||
- identity.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: authentik-internal
|
||||
sectionName: http
|
||||
name: authentik
|
||||
sectionName: https-internal
|
||||
rules:
|
||||
- filters:
|
||||
- type: RequestRedirect
|
||||
requestRedirect:
|
||||
scheme: https
|
||||
statusCode: 301
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: authentik-internal
|
||||
namespace: authentik
|
||||
spec:
|
||||
hostnames:
|
||||
- identity.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: authentik-internal
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: authentik-server
|
||||
port: 80
|
||||
weight: 1
|
||||
filters:
|
||||
- type: URLRewrite
|
||||
urlRewrite:
|
||||
path:
|
||||
type: ReplaceFullPath
|
||||
replaceFullPath: /application/o/token/
|
||||
matches:
|
||||
- path:
|
||||
type: Exact
|
||||
value: /application/o/token
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
|
||||
@@ -10,16 +10,12 @@ resources:
|
||||
- httproute.yaml
|
||||
- ldap-gateway.yaml
|
||||
- ldap-httproute.yaml
|
||||
- ldap-outpost-deployment.yaml
|
||||
- ldap-outpost-vaultstaticsecret.yaml
|
||||
- ldap-outpost-vmpodscrape.yaml
|
||||
- ldap-service.yaml
|
||||
- ldap-tlsroute.yaml
|
||||
- namespace.yaml
|
||||
- redis-deployment.yaml
|
||||
- redis-pvc.yaml
|
||||
- redis-service.yaml
|
||||
- server-vmpodscrape.yaml
|
||||
- vaultauth.yaml
|
||||
- vaultstaticsecret.yaml
|
||||
- vmpodscrape.yaml
|
||||
|
||||
@@ -1,104 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: authentik-ldap-outpost
|
||||
namespace: authentik
|
||||
labels:
|
||||
app.kubernetes.io/name: authentik
|
||||
app.kubernetes.io/component: ldap
|
||||
spec:
|
||||
# Outposts are stateless; run two replicas for availability.
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: authentik
|
||||
app.kubernetes.io/component: ldap
|
||||
template:
|
||||
metadata:
|
||||
annotations:
|
||||
secret.reloader.stakater.com/reload: "authentik-ldap-outpost-token,vault-ca-cert"
|
||||
labels:
|
||||
app.kubernetes.io/name: authentik
|
||||
app.kubernetes.io/component: ldap
|
||||
spec:
|
||||
# The outpost validates the authentik core cert (identity.k8s.syd1.au.unkin.net,
|
||||
# signed by the internal unkin.net CA). Combine the base image's public roots
|
||||
# with the reflected vault-ca-cert into one bundle that SSL_CERT_FILE points at,
|
||||
# so AUTHENTIK_INSECURE stays false.
|
||||
initContainers:
|
||||
- name: combine-certs
|
||||
image: alpine:3
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||
volumeMounts:
|
||||
- name: vault-ca-cert
|
||||
mountPath: /custom-ca
|
||||
readOnly: true
|
||||
- name: combined-certs
|
||||
mountPath: /combined-certs
|
||||
resources:
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
requests:
|
||||
cpu: 25m
|
||||
memory: 32Mi
|
||||
containers:
|
||||
- name: ldap
|
||||
image: ghcr.io/goauthentik/ldap:2026.5.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
env:
|
||||
- name: AUTHENTIK_HOST
|
||||
value: https://identity.k8s.syd1.au.unkin.net
|
||||
- name: AUTHENTIK_INSECURE
|
||||
value: "false"
|
||||
- name: SSL_CERT_FILE
|
||||
value: /etc/ssl/combined/ca-certificates.crt
|
||||
- name: AUTHENTIK_TOKEN
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: authentik-ldap-outpost-token
|
||||
key: token
|
||||
ports:
|
||||
- containerPort: 3389
|
||||
name: ldap
|
||||
protocol: TCP
|
||||
- containerPort: 6636
|
||||
name: ldaps
|
||||
protocol: TCP
|
||||
- containerPort: 9300
|
||||
name: metrics
|
||||
protocol: TCP
|
||||
livenessProbe:
|
||||
tcpSocket:
|
||||
port: ldap
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 15
|
||||
readinessProbe:
|
||||
tcpSocket:
|
||||
port: ldap
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
resources:
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 128Mi
|
||||
volumeMounts:
|
||||
- name: combined-certs
|
||||
mountPath: /etc/ssl/combined
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: vault-ca-cert
|
||||
secret:
|
||||
secretName: vault-ca-cert
|
||||
items:
|
||||
- key: ca.crt
|
||||
path: ca.crt
|
||||
- name: combined-certs
|
||||
emptyDir: {}
|
||||
@@ -1,20 +0,0 @@
|
||||
---
|
||||
# Outpost API token, issued by authentik for the LDAP outpost and seeded into
|
||||
# Vault by the terraform-authentik apply. The KV value must exist at this path
|
||||
# with a `token` key before the outpost can connect.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: authentik-ldap-outpost-token
|
||||
namespace: authentik
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
name: authentik-ldap-outpost-token
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/authentik/default/outpost-token
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
@@ -1,16 +0,0 @@
|
||||
---
|
||||
# Scrape the LDAP outpost's Prometheus endpoint (:9300). Picked up by the
|
||||
# observability VMAgent (selectAllByDefault).
|
||||
apiVersion: operator.victoriametrics.com/v1beta1
|
||||
kind: VMPodScrape
|
||||
metadata:
|
||||
name: authentik-ldap-outpost
|
||||
namespace: authentik
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: authentik
|
||||
app.kubernetes.io/component: ldap
|
||||
podMetricsEndpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
@@ -7,10 +7,6 @@ metadata:
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- name: ldap
|
||||
port: 3389
|
||||
protocol: TCP
|
||||
targetPort: 3389
|
||||
- name: ldaps
|
||||
port: 6636
|
||||
protocol: TCP
|
||||
|
||||
@@ -53,7 +53,7 @@ spec:
|
||||
- mountPath: /data
|
||||
name: redis-data
|
||||
- name: metrics-exporter
|
||||
image: docker.io/oliver006/redis_exporter:v1.89.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 9121
|
||||
|
||||
@@ -1,16 +0,0 @@
|
||||
---
|
||||
# Scrape the authentik server's django_prometheus endpoint (:9300). Picked up
|
||||
# by the observability VMAgent (selectAllByDefault).
|
||||
apiVersion: operator.victoriametrics.com/v1beta1
|
||||
kind: VMPodScrape
|
||||
metadata:
|
||||
name: authentik-server
|
||||
namespace: authentik
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app.kubernetes.io/name: authentik
|
||||
app.kubernetes.io/component: server
|
||||
podMetricsEndpoints:
|
||||
- port: metrics
|
||||
path: /metrics
|
||||
@@ -16,9 +16,9 @@ spec:
|
||||
type: A
|
||||
ttl: 600
|
||||
values:
|
||||
# traefik-EXTERNAL (DMZ) gateway VIP; the authentik Gateway serves the
|
||||
# traefik-internal gateway VIP; the authentik Gateway serves the
|
||||
# identity.unkin.net hostname there.
|
||||
- 198.18.199.0
|
||||
- 198.18.200.4
|
||||
---
|
||||
# PRODUCTION CUTOVER RECORD — intentionally commented out.
|
||||
# git.unkin.net currently resolves to the LIVE VM forge (HAProxy VRRP VIP
|
||||
@@ -135,21 +135,6 @@ spec:
|
||||
---
|
||||
apiVersion: bind.unkin.net/v1alpha1
|
||||
kind: DNSRecord
|
||||
metadata:
|
||||
name: cheeztv-dns-internal
|
||||
namespace: bind-internal
|
||||
spec:
|
||||
zoneRef: unkin-net
|
||||
name: cheeztv
|
||||
type: A
|
||||
ttl: 600
|
||||
values:
|
||||
# traefik-internal gateway VIP; the cheeztv Gateway serves cheeztv.unkin.net
|
||||
# there.
|
||||
- 198.18.200.4
|
||||
---
|
||||
apiVersion: bind.unkin.net/v1alpha1
|
||||
kind: DNSRecord
|
||||
metadata:
|
||||
name: watchstate-dns-internal
|
||||
namespace: bind-internal
|
||||
|
||||
@@ -21,7 +21,7 @@ spec:
|
||||
runAsNonRoot: true
|
||||
containers:
|
||||
- name: operator
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.7
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/bind-operator:v0.2.6
|
||||
args:
|
||||
- --metrics-bind-address=:8080
|
||||
- --health-probe-bind-address=:8081
|
||||
|
||||
@@ -6,7 +6,7 @@ resources:
|
||||
- namespace.yaml
|
||||
# CRDs are pulled from the bind-operator repo at the matching tag rather than
|
||||
# vendored here, so they never drift from the operator.
|
||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.7/config/crd/install.yaml
|
||||
- https://git.unkin.net/unkin/bind-operator/raw/tag/v0.2.6/config/crd/install.yaml
|
||||
- rbac.yaml
|
||||
- agent-dns-rbac.yaml
|
||||
- deployment.yaml
|
||||
|
||||
@@ -14,9 +14,9 @@ spec:
|
||||
secretTemplate:
|
||||
annotations:
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
|
||||
reflector.v1.k8s.emberstack.com/reflection-allowed-namespaces: "cheeztv"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-enabled: "true"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv,arrstack,authentik,gitea,watchstate,mediamark,repospawner"
|
||||
reflector.v1.k8s.emberstack.com/reflection-auto-namespaces: "cheeztv"
|
||||
privateKey:
|
||||
size: 4096
|
||||
dnsNames:
|
||||
|
||||
@@ -15,12 +15,9 @@ resources:
|
||||
- pvc-transcode.yaml
|
||||
- pv-media-tv.yaml
|
||||
- pv-media-movies.yaml
|
||||
- pv-mediastore.yaml
|
||||
- pvc-media-tv.yaml
|
||||
- pvc-media-movies.yaml
|
||||
- pvc-mediastore.yaml
|
||||
- statefulset.yaml
|
||||
- plugin-configmap.yaml
|
||||
- pdb.yaml
|
||||
- service.yaml
|
||||
- valkey.yaml
|
||||
|
||||
@@ -1,97 +0,0 @@
|
||||
---
|
||||
# Declarative config for the browser-auth plugins bundled in the jellyfin-ha
|
||||
# image (jellyfin-plugin-sso, jellyfin-plugin-ldapauth). Rendered into
|
||||
# /config/plugins/configurations/ by the inject-plugin-config initContainer,
|
||||
# which substitutes the OidSecret / LdapBindPassword placeholders from the
|
||||
# VSO-synced oauth-credentials Secret so no secret is committed here. The SSO
|
||||
# provider key "authentik" must match the redirect path segment registered on
|
||||
# the shared Authentik "jellyfin" OAuth2 client. Roles/AdminRoles are matched
|
||||
# against the hierarchical Authentik groups claim (akP-jellyfin-user grants
|
||||
# login, akP-jellyfin-admin grants Jellyfin admin; global admins inherit the
|
||||
# latter via akR-global-admin).
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: cheeztv-plugin-config
|
||||
namespace: cheeztv
|
||||
data:
|
||||
SSO-Auth.xml: |
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<SamlConfigs />
|
||||
<OidConfigs>
|
||||
<item>
|
||||
<key>
|
||||
<string>authentik</string>
|
||||
</key>
|
||||
<value>
|
||||
<PluginConfiguration>
|
||||
<OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||
<OidClientId>jellyfin</OidClientId>
|
||||
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
||||
<Enabled>true</Enabled>
|
||||
<EnableAuthorization>true</EnableAuthorization>
|
||||
<EnableAllFolders>true</EnableAllFolders>
|
||||
<EnabledFolders />
|
||||
<AdminRoles>
|
||||
<string>akP-jellyfin-admin</string>
|
||||
</AdminRoles>
|
||||
<Roles>
|
||||
<string>akP-jellyfin-user</string>
|
||||
<string>akP-jellyfin-admin</string>
|
||||
</Roles>
|
||||
<EnableFolderRoles>false</EnableFolderRoles>
|
||||
<EnableLiveTvRoles>false</EnableLiveTvRoles>
|
||||
<EnableLiveTv>false</EnableLiveTv>
|
||||
<EnableLiveTvManagement>false</EnableLiveTvManagement>
|
||||
<LiveTvRoles />
|
||||
<LiveTvManagementRoles />
|
||||
<FolderRoleMappings />
|
||||
<RoleClaim>ak_groups</RoleClaim>
|
||||
<OidScopes>
|
||||
<string>openid</string>
|
||||
<string>profile</string>
|
||||
<string>email</string>
|
||||
<string>ak_groups</string>
|
||||
</OidScopes>
|
||||
<CanonicalLinks></CanonicalLinks>
|
||||
<DisableHttps>false</DisableHttps>
|
||||
<DoNotValidateEndpoints>false</DoNotValidateEndpoints>
|
||||
<DoNotValidateIssuerName>false</DoNotValidateIssuerName>
|
||||
<SchemeOverride>https</SchemeOverride>
|
||||
</PluginConfiguration>
|
||||
</value>
|
||||
</item>
|
||||
</OidConfigs>
|
||||
</PluginConfiguration>
|
||||
LDAP-Auth.xml: |
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<LdapServer>authentik-ldap.authentik.svc.cluster.local</LdapServer>
|
||||
<LdapPort>6636</LdapPort>
|
||||
<UseSsl>true</UseSsl>
|
||||
<UseStartTls>false</UseStartTls>
|
||||
<SkipSslVerify>true</SkipSslVerify>
|
||||
<LdapBindUser>cn=jellyfin-ldap,ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBindUser>
|
||||
<LdapBindPassword>@@LDAP_BIND_PASSWORD@@</LdapBindPassword>
|
||||
<LdapBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBaseDn>
|
||||
<LdapSearchFilter>(objectClass=user)</LdapSearchFilter>
|
||||
<LdapAdminBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapAdminBaseDn>
|
||||
<LdapAdminFilter>(memberOf=cn=akP-jellyfin-admin,ou=groups,DC=ldap,DC=goauthentik,DC=io)</LdapAdminFilter>
|
||||
<EnableLdapAdminFilterMemberUid>false</EnableLdapAdminFilterMemberUid>
|
||||
<LdapSearchAttributes>uid, cn, mail, displayName</LdapSearchAttributes>
|
||||
<CreateUsersFromLdap>true</CreateUsersFromLdap>
|
||||
<AllowPassChange>false</AllowPassChange>
|
||||
<LdapUidAttribute>cn</LdapUidAttribute>
|
||||
<LdapUsernameAttribute>cn</LdapUsernameAttribute>
|
||||
<LdapPasswordAttribute>userPassword</LdapPasswordAttribute>
|
||||
<EnableAllFolders>true</EnableAllFolders>
|
||||
<EnabledFolders />
|
||||
</PluginConfiguration>
|
||||
branding.xml: |
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<BrandingOptions xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<LoginDisclaimer><p style="text-align:center"><a href="/sso/OID/start/authentik">Sign in with SSO</a></p></LoginDisclaimer>
|
||||
<CustomCss></CustomCss>
|
||||
<SplashscreenEnabled>false</SplashscreenEnabled>
|
||||
</BrandingOptions>
|
||||
@@ -1,31 +0,0 @@
|
||||
---
|
||||
# Static PV for the shared MEDIASTORE CephFS subvolume. Same rootPath as
|
||||
# arrstack's mediastore PV so the arrs write and cheeztv reads the identical
|
||||
# library tree (cheeztv scans /cheeztv/{tvseries,movies}); each namespace gets
|
||||
# its own PV (unique name + volumeHandle) pinned by claimRef.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
name: cheeztv-mediastore
|
||||
spec:
|
||||
capacity:
|
||||
storage: 10Ti
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: ""
|
||||
volumeMode: Filesystem
|
||||
claimRef:
|
||||
namespace: cheeztv
|
||||
name: cheeztv-mediastore
|
||||
csi:
|
||||
driver: cephfs.csi.ceph.com
|
||||
volumeHandle: cheeztv-mediastore-static
|
||||
nodeStageSecretRef:
|
||||
name: csi-cephfs-secret
|
||||
namespace: csi-cephfs
|
||||
volumeAttributes:
|
||||
staticVolume: "true"
|
||||
clusterID: cephfs_csi_ssd_ec_4_1
|
||||
fsName: cephfs
|
||||
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
|
||||
@@ -1,24 +0,0 @@
|
||||
---
|
||||
# Shared media tree, read-many across replicas. Statically bound to the
|
||||
# cheeztv-mediastore PV (the CephFS subvolume also used by arrstack and
|
||||
# fafflix). storageClassName "" + volumeName disables dynamic provisioning and
|
||||
# binds the pre-created static PV.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: cheeztv-mediastore
|
||||
namespace: cheeztv
|
||||
annotations:
|
||||
# Exclude from the cheeztv-config k8up Schedule (skipWithoutAnnotation is
|
||||
# false cluster-wide, so unannotated PVCs are swept in). Only cheeztv-config
|
||||
# is backed up; the media library is not restic-backup material.
|
||||
k8up.io/backup: "false"
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Ti
|
||||
storageClassName: ""
|
||||
volumeName: cheeztv-mediastore
|
||||
volumeMode: Filesystem
|
||||
@@ -13,4 +13,6 @@ spec:
|
||||
targetPort: http
|
||||
selector:
|
||||
app: cheeztv
|
||||
# Pin each client to one replica to reduce transcode-session churn/takeover.
|
||||
sessionAffinity: ClientIP
|
||||
type: ClusterIP
|
||||
|
||||
@@ -4,8 +4,6 @@ kind: StatefulSet
|
||||
metadata:
|
||||
name: cheeztv
|
||||
namespace: cheeztv
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
# HA: two replicas coordinate transcode session ownership through Valkey and
|
||||
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
||||
@@ -111,60 +109,9 @@ spec:
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
# Render the SSO/LDAP plugin configs into the shared config volume,
|
||||
# substituting the client secret and LDAP bind password from the
|
||||
# VSO-synced oauth-credentials Secret (never committed). Plugin configs
|
||||
# are fully managed here so they are overwritten every start; the login
|
||||
# button branding is written only when absent so admin edits survive.
|
||||
- name: inject-plugin-config
|
||||
image: busybox:1.37.0
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
mkdir -p /config/plugins/configurations /config/config
|
||||
chown 1000:1000 /config/plugins /config/plugins/configurations /config/config
|
||||
esc() { printf '%s' "$1" | sed -e 's/[&|\\]/\\&/g'; }
|
||||
cs=$(esc "${CLIENT_SECRET}")
|
||||
lp=$(esc "${LDAP_BIND_PASSWORD}")
|
||||
sed "s|@@CLIENT_SECRET@@|${cs}|" /templates/SSO-Auth.xml > /config/plugins/configurations/SSO-Auth.xml
|
||||
sed "s|@@LDAP_BIND_PASSWORD@@|${lp}|" /templates/LDAP-Auth.xml > /config/plugins/configurations/LDAP-Auth.xml
|
||||
chown 1000:1000 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
|
||||
chmod 600 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
|
||||
if [ ! -e /config/config/branding.xml ]; then
|
||||
cp /templates/branding.xml /config/config/branding.xml
|
||||
chown 1000:1000 /config/config/branding.xml
|
||||
chmod 664 /config/config/branding.xml
|
||||
fi
|
||||
env:
|
||||
- name: CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_secret
|
||||
optional: true
|
||||
- name: LDAP_BIND_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: ldap_bind_password
|
||||
optional: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
- name: plugin-config
|
||||
mountPath: /templates
|
||||
readOnly: true
|
||||
containers:
|
||||
- name: cheeztv
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.1.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
@@ -275,9 +222,6 @@ spec:
|
||||
subPath: kids
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: plugin-config
|
||||
configMap:
|
||||
name: cheeztv-plugin-config
|
||||
- name: config
|
||||
persistentVolumeClaim:
|
||||
claimName: cheeztv-config
|
||||
|
||||
@@ -22,27 +22,3 @@ spec:
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
---
|
||||
# Shared Authentik "jellyfin" OAuth2 client secret (key: client_secret) plus the
|
||||
# LDAP outpost bind password (key: ldap_bind_password) for the auth plugins.
|
||||
# The default k8s role's templated policy is namespace-scoped
|
||||
# (kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*), so each instance
|
||||
# reads its own namespace path; the SAME shared values must be seeded at both
|
||||
# fafflix and cheeztv paths. VSO syncs into the oauth-credentials Secret, whose
|
||||
# keys the inject-plugin-config initContainer substitutes into the plugin XML.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: oauth-credentials
|
||||
namespace: cheeztv
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
name: oauth-credentials
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/cheeztv/default/oauth-credentials
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
|
||||
@@ -21,7 +21,7 @@ spec:
|
||||
runAsNonRoot: true
|
||||
containers:
|
||||
- name: operator
|
||||
image: git.unkin.net/unkin/kea-operator:v0.1.5
|
||||
image: git.unkin.net/unkin/kea-operator:v0.1.3
|
||||
args:
|
||||
- --metrics-bind-address=:8080
|
||||
- --health-probe-bind-address=:8081
|
||||
|
||||
@@ -23,7 +23,7 @@ spec:
|
||||
automountServiceAccountToken: true
|
||||
containers:
|
||||
- name: encapi
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi:v0.1.2
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi:v0.1.1
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
|
||||
@@ -15,12 +15,9 @@ resources:
|
||||
- pvc-transcode.yaml
|
||||
- pv-media-tv.yaml
|
||||
- pv-media-movies.yaml
|
||||
- pv-mediastore.yaml
|
||||
- pvc-media-tv.yaml
|
||||
- pvc-media-movies.yaml
|
||||
- pvc-mediastore.yaml
|
||||
- statefulset.yaml
|
||||
- plugin-configmap.yaml
|
||||
- pdb.yaml
|
||||
- service.yaml
|
||||
- valkey.yaml
|
||||
|
||||
@@ -1,97 +0,0 @@
|
||||
---
|
||||
# Declarative config for the browser-auth plugins bundled in the jellyfin-ha
|
||||
# image (jellyfin-plugin-sso, jellyfin-plugin-ldapauth). Rendered into
|
||||
# /config/plugins/configurations/ by the inject-plugin-config initContainer,
|
||||
# which substitutes the OidSecret / LdapBindPassword placeholders from the
|
||||
# VSO-synced oauth-credentials Secret so no secret is committed here. The SSO
|
||||
# provider key "authentik" must match the redirect path segment registered on
|
||||
# the shared Authentik "jellyfin" OAuth2 client. Roles/AdminRoles are matched
|
||||
# against the hierarchical Authentik groups claim (akP-jellyfin-user grants
|
||||
# login, akP-jellyfin-admin grants Jellyfin admin; global admins inherit the
|
||||
# latter via akR-global-admin).
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: fafflix-plugin-config
|
||||
namespace: fafflix
|
||||
data:
|
||||
SSO-Auth.xml: |
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<SamlConfigs />
|
||||
<OidConfigs>
|
||||
<item>
|
||||
<key>
|
||||
<string>authentik</string>
|
||||
</key>
|
||||
<value>
|
||||
<PluginConfiguration>
|
||||
<OidEndpoint>https://identity.unkin.net/application/o/jellyfin/</OidEndpoint>
|
||||
<OidClientId>jellyfin</OidClientId>
|
||||
<OidSecret>@@CLIENT_SECRET@@</OidSecret>
|
||||
<Enabled>true</Enabled>
|
||||
<EnableAuthorization>true</EnableAuthorization>
|
||||
<EnableAllFolders>true</EnableAllFolders>
|
||||
<EnabledFolders />
|
||||
<AdminRoles>
|
||||
<string>akP-jellyfin-admin</string>
|
||||
</AdminRoles>
|
||||
<Roles>
|
||||
<string>akP-jellyfin-user</string>
|
||||
<string>akP-jellyfin-admin</string>
|
||||
</Roles>
|
||||
<EnableFolderRoles>false</EnableFolderRoles>
|
||||
<EnableLiveTvRoles>false</EnableLiveTvRoles>
|
||||
<EnableLiveTv>false</EnableLiveTv>
|
||||
<EnableLiveTvManagement>false</EnableLiveTvManagement>
|
||||
<LiveTvRoles />
|
||||
<LiveTvManagementRoles />
|
||||
<FolderRoleMappings />
|
||||
<RoleClaim>ak_groups</RoleClaim>
|
||||
<OidScopes>
|
||||
<string>openid</string>
|
||||
<string>profile</string>
|
||||
<string>email</string>
|
||||
<string>ak_groups</string>
|
||||
</OidScopes>
|
||||
<CanonicalLinks></CanonicalLinks>
|
||||
<DisableHttps>false</DisableHttps>
|
||||
<DoNotValidateEndpoints>false</DoNotValidateEndpoints>
|
||||
<DoNotValidateIssuerName>false</DoNotValidateIssuerName>
|
||||
<SchemeOverride>https</SchemeOverride>
|
||||
</PluginConfiguration>
|
||||
</value>
|
||||
</item>
|
||||
</OidConfigs>
|
||||
</PluginConfiguration>
|
||||
LDAP-Auth.xml: |
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<PluginConfiguration xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<LdapServer>authentik-ldap.authentik.svc.cluster.local</LdapServer>
|
||||
<LdapPort>6636</LdapPort>
|
||||
<UseSsl>true</UseSsl>
|
||||
<UseStartTls>false</UseStartTls>
|
||||
<SkipSslVerify>true</SkipSslVerify>
|
||||
<LdapBindUser>cn=jellyfin-ldap,ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBindUser>
|
||||
<LdapBindPassword>@@LDAP_BIND_PASSWORD@@</LdapBindPassword>
|
||||
<LdapBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapBaseDn>
|
||||
<LdapSearchFilter>(objectClass=user)</LdapSearchFilter>
|
||||
<LdapAdminBaseDn>ou=users,DC=ldap,DC=goauthentik,DC=io</LdapAdminBaseDn>
|
||||
<LdapAdminFilter>(memberOf=cn=akP-jellyfin-admin,ou=groups,DC=ldap,DC=goauthentik,DC=io)</LdapAdminFilter>
|
||||
<EnableLdapAdminFilterMemberUid>false</EnableLdapAdminFilterMemberUid>
|
||||
<LdapSearchAttributes>uid, cn, mail, displayName</LdapSearchAttributes>
|
||||
<CreateUsersFromLdap>true</CreateUsersFromLdap>
|
||||
<AllowPassChange>false</AllowPassChange>
|
||||
<LdapUidAttribute>cn</LdapUidAttribute>
|
||||
<LdapUsernameAttribute>cn</LdapUsernameAttribute>
|
||||
<LdapPasswordAttribute>userPassword</LdapPasswordAttribute>
|
||||
<EnableAllFolders>true</EnableAllFolders>
|
||||
<EnabledFolders />
|
||||
</PluginConfiguration>
|
||||
branding.xml: |
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<BrandingOptions xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
|
||||
<LoginDisclaimer><p style="text-align:center"><a href="/sso/OID/start/authentik">Sign in with SSO</a></p></LoginDisclaimer>
|
||||
<CustomCss></CustomCss>
|
||||
<SplashscreenEnabled>false</SplashscreenEnabled>
|
||||
</BrandingOptions>
|
||||
@@ -1,31 +0,0 @@
|
||||
---
|
||||
# Static PV for the shared MEDIASTORE CephFS subvolume. Same rootPath as
|
||||
# arrstack's mediastore PV so the arrs write and fafflix reads the identical
|
||||
# library tree (fafflix scans /fafflix/{tvseries,movies}); each namespace gets
|
||||
# its own PV (unique name + volumeHandle) pinned by claimRef.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
name: fafflix-mediastore
|
||||
spec:
|
||||
capacity:
|
||||
storage: 10Ti
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: ""
|
||||
volumeMode: Filesystem
|
||||
claimRef:
|
||||
namespace: fafflix
|
||||
name: fafflix-mediastore
|
||||
csi:
|
||||
driver: cephfs.csi.ceph.com
|
||||
volumeHandle: fafflix-mediastore-static
|
||||
nodeStageSecretRef:
|
||||
name: csi-cephfs-secret
|
||||
namespace: csi-cephfs
|
||||
volumeAttributes:
|
||||
staticVolume: "true"
|
||||
clusterID: cephfs_csi_ssd_ec_4_1
|
||||
fsName: cephfs
|
||||
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
|
||||
@@ -1,24 +0,0 @@
|
||||
---
|
||||
# Shared media tree, read-many across replicas. Statically bound to the
|
||||
# fafflix-mediastore PV (the CephFS subvolume also used by arrstack and
|
||||
# cheeztv). storageClassName "" + volumeName disables dynamic provisioning and
|
||||
# binds the pre-created static PV.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: fafflix-mediastore
|
||||
namespace: fafflix
|
||||
annotations:
|
||||
# Exclude from the fafflix-config k8up Schedule (skipWithoutAnnotation is
|
||||
# false cluster-wide, so unannotated PVCs are swept in). Only fafflix-config
|
||||
# is backed up; the media library is not restic-backup material.
|
||||
k8up.io/backup: "false"
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Ti
|
||||
storageClassName: ""
|
||||
volumeName: fafflix-mediastore
|
||||
volumeMode: Filesystem
|
||||
@@ -13,4 +13,6 @@ spec:
|
||||
targetPort: http
|
||||
selector:
|
||||
app: fafflix
|
||||
# Pin each client to one replica to reduce transcode-session churn/takeover.
|
||||
sessionAffinity: ClientIP
|
||||
type: ClusterIP
|
||||
|
||||
@@ -4,8 +4,6 @@ kind: StatefulSet
|
||||
metadata:
|
||||
name: fafflix
|
||||
namespace: fafflix
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
spec:
|
||||
# HA: two replicas coordinate transcode session ownership through Valkey and
|
||||
# resume each other's HLS segments off the shared RWX transcode PVC. Stable
|
||||
@@ -111,60 +109,9 @@ spec:
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
# Render the SSO/LDAP plugin configs into the shared config volume,
|
||||
# substituting the client secret and LDAP bind password from the
|
||||
# VSO-synced oauth-credentials Secret (never committed). Plugin configs
|
||||
# are fully managed here so they are overwritten every start; the login
|
||||
# button branding is written only when absent so admin edits survive.
|
||||
- name: inject-plugin-config
|
||||
image: busybox:1.37.0
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
mkdir -p /config/plugins/configurations /config/config
|
||||
chown 1000:1000 /config/plugins /config/plugins/configurations /config/config
|
||||
esc() { printf '%s' "$1" | sed -e 's/[&|\\]/\\&/g'; }
|
||||
cs=$(esc "${CLIENT_SECRET}")
|
||||
lp=$(esc "${LDAP_BIND_PASSWORD}")
|
||||
sed "s|@@CLIENT_SECRET@@|${cs}|" /templates/SSO-Auth.xml > /config/plugins/configurations/SSO-Auth.xml
|
||||
sed "s|@@LDAP_BIND_PASSWORD@@|${lp}|" /templates/LDAP-Auth.xml > /config/plugins/configurations/LDAP-Auth.xml
|
||||
chown 1000:1000 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
|
||||
chmod 600 /config/plugins/configurations/SSO-Auth.xml /config/plugins/configurations/LDAP-Auth.xml
|
||||
if [ ! -e /config/config/branding.xml ]; then
|
||||
cp /templates/branding.xml /config/config/branding.xml
|
||||
chown 1000:1000 /config/config/branding.xml
|
||||
chmod 664 /config/config/branding.xml
|
||||
fi
|
||||
env:
|
||||
- name: CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_secret
|
||||
optional: true
|
||||
- name: LDAP_BIND_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: ldap_bind_password
|
||||
optional: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
volumeMounts:
|
||||
- name: config
|
||||
mountPath: /config
|
||||
- name: plugin-config
|
||||
mountPath: /templates
|
||||
readOnly: true
|
||||
containers:
|
||||
- name: fafflix
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/jellyfin-ha:v0.1.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
@@ -289,9 +236,6 @@ spec:
|
||||
subPath: kids
|
||||
readOnly: true
|
||||
volumes:
|
||||
- name: plugin-config
|
||||
configMap:
|
||||
name: fafflix-plugin-config
|
||||
- name: config
|
||||
persistentVolumeClaim:
|
||||
claimName: fafflix-config
|
||||
|
||||
@@ -22,27 +22,3 @@ spec:
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
---
|
||||
# Shared Authentik "jellyfin" OAuth2 client secret (key: client_secret) plus the
|
||||
# LDAP outpost bind password (key: ldap_bind_password) for the auth plugins.
|
||||
# The default k8s role's templated policy is namespace-scoped
|
||||
# (kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*), so each instance
|
||||
# reads its own namespace path; the SAME shared values must be seeded at both
|
||||
# fafflix and cheeztv paths. VSO syncs into the oauth-credentials Secret, whose
|
||||
# keys the inject-plugin-config initContainer substitutes into the plugin XML.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: oauth-credentials
|
||||
namespace: fafflix
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
name: oauth-credentials
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/fafflix/default/oauth-credentials
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
|
||||
@@ -83,7 +83,7 @@ spec:
|
||||
- mountPath: /data
|
||||
name: data
|
||||
- name: metrics-exporter
|
||||
image: docker.io/oliver006/redis_exporter:v1.89.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 9121
|
||||
|
||||
@@ -26,6 +26,13 @@ spec:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_secret
|
||||
# identity.unkin.net is served by the internal unkin.net CA, which
|
||||
# the stock Grafana image doesn't trust. Mount the reflected
|
||||
# vault-ca-cert and point generic_oauth's tls_client_ca at it.
|
||||
volumeMounts:
|
||||
- name: vault-ca-cert
|
||||
mountPath: /etc/grafana/vault-ca
|
||||
readOnly: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: 100m
|
||||
@@ -33,6 +40,13 @@ spec:
|
||||
limits:
|
||||
cpu: "1"
|
||||
memory: 1Gi
|
||||
volumes:
|
||||
- name: vault-ca-cert
|
||||
secret:
|
||||
secretName: vault-ca-cert
|
||||
items:
|
||||
- key: ca.crt
|
||||
path: ca.crt
|
||||
config:
|
||||
server:
|
||||
root_url: "https://grafana.k8s.syd1.au.unkin.net"
|
||||
@@ -57,6 +71,9 @@ spec:
|
||||
auth_url: "https://identity.unkin.net/application/o/authorize/"
|
||||
token_url: "https://identity.unkin.net/application/o/token/"
|
||||
api_url: "https://identity.unkin.net/application/o/userinfo/"
|
||||
# Trust the internal unkin.net CA that signs identity.unkin.net's cert
|
||||
# (mounted from the reflected vault-ca-cert Secret).
|
||||
tls_client_ca: "/etc/grafana/vault-ca/ca.crt"
|
||||
# Authentik permission groups -> Grafana roles. akP-grafana-admin is granted
|
||||
# to akR-global-admin members (and direct members) via terraform-authentik.
|
||||
role_attribute_path: "contains(ak_groups[*], 'akP-grafana-admin') && 'Admin' || 'Viewer'"
|
||||
|
||||
@@ -61,7 +61,7 @@ spec:
|
||||
mountPropagation: None
|
||||
name: data
|
||||
- name: metrics-exporter
|
||||
image: docker.io/oliver006/redis_exporter:v1.89.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 9121
|
||||
|
||||
@@ -87,7 +87,7 @@ spec:
|
||||
runAsGroup: 101
|
||||
containers:
|
||||
- name: clickhouse
|
||||
image: docker.io/clickhouse/clickhouse-server:24.8
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/clickhouse/clickhouse-server:24.8
|
||||
resources:
|
||||
requests:
|
||||
cpu: 500m
|
||||
|
||||
@@ -32,7 +32,7 @@ spec:
|
||||
runAsGroup: 101
|
||||
containers:
|
||||
- name: clickhouse-schema
|
||||
image: docker.io/clickhouse/clickhouse-server:24.8
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/clickhouse/clickhouse-server:24.8
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
|
||||
@@ -34,7 +34,7 @@ spec:
|
||||
# identity.unkin.net serves a Vault-PKI cert; combine the system roots
|
||||
# with the internal CA so oauth2-proxy's OIDC HTTP client trusts it.
|
||||
- name: combine-certs
|
||||
image: docker.io/library/alpine:3
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
|
||||
@@ -58,7 +58,7 @@ spec:
|
||||
runAsGroup: 1000
|
||||
containers:
|
||||
- name: nats-bootstrap
|
||||
image: docker.io/natsio/nats-box:0.18.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/natsio/nats-box:0.18.0
|
||||
# nats CLI stats the working directory when loading its response
|
||||
# schemas; under readOnlyRootFilesystem + runAsUser 1000 the image's
|
||||
# default WORKDIR is not accessible ("stat .: permission denied"), so
|
||||
|
||||
@@ -1,114 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: mediamark
|
||||
namespace: mediamark
|
||||
annotations:
|
||||
secret.reloader.stakater.com/reload: "arrstack-virtual-key"
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: mediamark
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: mediamark
|
||||
spec:
|
||||
serviceAccountName: default
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
# 1000:1000 matches the media tree ownership on the shared mediastore
|
||||
# subvolume; mediamark hardlinks/renames files the *arr apps own, so it
|
||||
# deliberately does NOT run as the usual 65532.
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: mediamark
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/mediamark:v0.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: http
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: MEDIAMARK_MEDIA_ROOT
|
||||
value: /media
|
||||
- name: MEDIAMARK_KEYS_DIR
|
||||
value: /etc/mediamark/keys
|
||||
# Virtual keys are only honoured by arrproxy, which validates the
|
||||
# machine token and injects the real per-app key upstream; the
|
||||
# sonarr/radarr Services would reject them.
|
||||
- name: MEDIAMARK_SONARR_URL
|
||||
value: http://arrproxy-api.arrstack.svc.cluster.local:8080/3aa168/sonarr
|
||||
- name: MEDIAMARK_RADARR_URL
|
||||
value: http://arrproxy-api.arrstack.svc.cluster.local:8080/3aa168/radarr
|
||||
# oauth2-proxy --pass-user-headers forwards the Authentik groups as a
|
||||
# comma-joined X-Forwarded-Groups; X-Auth-Request-Groups is
|
||||
# auth_request-response-only and never reaches a proxied upstream.
|
||||
- name: MEDIAMARK_GROUPS_HEADER
|
||||
value: X-Forwarded-Groups
|
||||
- name: MEDIAMARK_ALLOWED_GROUPS
|
||||
value: akP-mediamark-user
|
||||
volumeMounts:
|
||||
- name: mediastore
|
||||
mountPath: /media
|
||||
- name: arr-keys
|
||||
mountPath: /etc/mediamark/keys
|
||||
readOnly: true
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /livez
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: http
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
volumes:
|
||||
- name: mediastore
|
||||
persistentVolumeClaim:
|
||||
claimName: mediamark-mediastore
|
||||
# One ephemeral virtual key covers both apps, so the same token lands on
|
||||
# both per-app files under MEDIAMARK_KEYS_DIR; mediamark re-reads the
|
||||
# file per request, so lease renewal rotates in place.
|
||||
- name: arr-keys
|
||||
projected:
|
||||
sources:
|
||||
- secret:
|
||||
name: arrstack-virtual-key
|
||||
items:
|
||||
- key: token
|
||||
path: sonarr
|
||||
- key: token
|
||||
path: radarr
|
||||
restartPolicy: Always
|
||||
@@ -1,39 +0,0 @@
|
||||
---
|
||||
# External (DMZ) front for mediamark on mediamark.unkin.net via the external
|
||||
# Traefik (LB VIP 198.18.199.0). TLS terminates with the real Let's Encrypt
|
||||
# *.unkin.net wildcard (Certificate wildcard-unkin-net in cert-manager,
|
||||
# reflected into this namespace as wildcard-unkin-net-tls by the emberstack
|
||||
# reflector), so there is no cert-manager annotation here. The apex
|
||||
# mediamark.unkin.net A record lives in the bind-operator unkin.net zone, NOT
|
||||
# external-dns, so no external-dns annotation either. oauth2-proxy fronts both
|
||||
# hostnames.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
labels:
|
||||
traefik.io/instance: external
|
||||
name: mediamark-external
|
||||
namespace: mediamark
|
||||
spec:
|
||||
gatewayClassName: traefik-external
|
||||
listeners:
|
||||
- name: http
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
hostname: mediamark.unkin.net
|
||||
allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
- name: https
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
hostname: mediamark.unkin.net
|
||||
allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
tls:
|
||||
mode: Terminate
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: wildcard-unkin-net-tls
|
||||
@@ -1,38 +0,0 @@
|
||||
---
|
||||
# Internal front for mediamark (cf. watchstate).
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
labels:
|
||||
traefik.io/instance: internal
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: vault-issuer
|
||||
cert-manager.io/common-name: mediamark.k8s.syd1.au.unkin.net
|
||||
cert-manager.io/private-key-size: "4096"
|
||||
external-dns.alpha.kubernetes.io/hostname: mediamark.k8s.syd1.au.unkin.net
|
||||
external-dns.alpha.kubernetes.io/target: 198.18.200.4
|
||||
name: mediamark
|
||||
namespace: mediamark
|
||||
spec:
|
||||
gatewayClassName: traefik-internal
|
||||
listeners:
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: mediamark.k8s.syd1.au.unkin.net
|
||||
name: http
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: mediamark.k8s.syd1.au.unkin.net
|
||||
name: https
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
tls:
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: mediamark-tls
|
||||
mode: Terminate
|
||||
@@ -1,49 +0,0 @@
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: mediamark-external-http-redirect
|
||||
namespace: mediamark
|
||||
spec:
|
||||
hostnames:
|
||||
- mediamark.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: mediamark-external
|
||||
sectionName: http
|
||||
rules:
|
||||
- filters:
|
||||
- type: RequestRedirect
|
||||
requestRedirect:
|
||||
scheme: https
|
||||
statusCode: 301
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: mediamark-external
|
||||
namespace: mediamark
|
||||
spec:
|
||||
hostnames:
|
||||
- mediamark.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: mediamark-external
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: mediamark-oauth2
|
||||
port: 4180
|
||||
weight: 1
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
@@ -1,49 +0,0 @@
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: mediamark-http-redirect
|
||||
namespace: mediamark
|
||||
spec:
|
||||
hostnames:
|
||||
- mediamark.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: mediamark
|
||||
sectionName: http
|
||||
rules:
|
||||
- filters:
|
||||
- type: RequestRedirect
|
||||
requestRedirect:
|
||||
scheme: https
|
||||
statusCode: 301
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: mediamark
|
||||
namespace: mediamark
|
||||
spec:
|
||||
hostnames:
|
||||
- mediamark.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: mediamark
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: mediamark-oauth2
|
||||
port: 4180
|
||||
weight: 1
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
@@ -1,19 +0,0 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- vaultauth.yaml
|
||||
- vaultstaticsecret.yaml
|
||||
- vaultdynamicsecret.yaml
|
||||
- pv-mediastore.yaml
|
||||
- pvc-mediastore.yaml
|
||||
- deployment.yaml
|
||||
- oauth2-proxy-configmap.yaml
|
||||
- oauth2-proxy-deployment.yaml
|
||||
- service.yaml
|
||||
- gateway.yaml
|
||||
- httproute.yaml
|
||||
- gateway-external.yaml
|
||||
- httproute-external.yaml
|
||||
@@ -1,7 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: mediamark
|
||||
name: mediamark
|
||||
@@ -1,45 +0,0 @@
|
||||
---
|
||||
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
|
||||
# from the oauth-credentials Secret). Single auth front for mediamark on both
|
||||
# host names; access is gated here on the akP-mediamark-user Authentik group and
|
||||
# re-checked by the app from X-Forwarded-Groups.
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: mediamark-oauth2-env
|
||||
namespace: mediamark
|
||||
data:
|
||||
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/mediamark/"
|
||||
# Relative (host-less) redirect URL: with reverse-proxy mode on, oauth2-proxy
|
||||
# derives scheme+host per request from X-Forwarded-Proto/Host, so the same
|
||||
# deployment serves BOTH the external mediamark.unkin.net and internal
|
||||
# mediamark.k8s.syd1.au.unkin.net callbacks. Both absolute callback URIs are
|
||||
# registered on the Authentik provider (terraform-authentik, separate PR).
|
||||
OAUTH2_PROXY_REDIRECT_URL: "/oauth2/callback"
|
||||
OAUTH2_PROXY_UPSTREAMS: "http://mediamark.mediamark.svc.cluster.local:8080/"
|
||||
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
||||
# Populate session.Groups from the Authentik ak_groups claim; pass-user-headers
|
||||
# then emits it as a single comma-joined X-Forwarded-Groups header.
|
||||
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
||||
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-mediamark-user"
|
||||
# Forward identity + groups to mediamark as X-Forwarded-{User,Email,Groups}.
|
||||
# NOTE: set-xauthrequest is intentionally NOT set -- it only populates
|
||||
# auth_request *response* headers, which never reach a proxied upstream.
|
||||
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
||||
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
||||
# enforced via ak_groups, so accepting the unverified email is safe.
|
||||
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
||||
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
||||
# One cookie domain per host (a single parent-domain cookie can't span
|
||||
# unkin.net and k8s.syd1.au.unkin.net cleanly); oauth2-proxy picks the domain
|
||||
# matching the request host. Whitelist both so post-auth `rd` redirects to
|
||||
# either front door are honoured.
|
||||
OAUTH2_PROXY_COOKIE_DOMAINS: "mediamark.unkin.net,mediamark.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_WHITELIST_DOMAINS: "mediamark.unkin.net,mediamark.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
||||
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||
@@ -1,133 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: mediamark-oauth2
|
||||
namespace: mediamark
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: mediamark-oauth2
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: mediamark-oauth2
|
||||
spec:
|
||||
serviceAccountName: default
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 65532
|
||||
runAsGroup: 65532
|
||||
fsGroup: 65532
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
initContainers:
|
||||
# The Authentik issuer is served behind the internal unkin.net CA;
|
||||
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
|
||||
# trusts the discovery endpoint.
|
||||
- name: combine-certs
|
||||
image: docker.io/library/alpine:3
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||
volumeMounts:
|
||||
- name: vault-ca-cert
|
||||
mountPath: /custom-ca
|
||||
readOnly: true
|
||||
- name: combined-certs
|
||||
mountPath: /combined-certs
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 64Mi
|
||||
containers:
|
||||
- name: oauth2-proxy
|
||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 4180
|
||||
name: http
|
||||
protocol: TCP
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: mediamark-oauth2-env
|
||||
optional: false
|
||||
env:
|
||||
- name: OAUTH2_PROXY_CLIENT_ID
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_id
|
||||
- name: OAUTH2_PROXY_CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_secret
|
||||
- name: OAUTH2_PROXY_COOKIE_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: cookie_secret
|
||||
volumeMounts:
|
||||
- name: combined-certs
|
||||
mountPath: /etc/ssl/combined
|
||||
readOnly: true
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ready
|
||||
port: http
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
volumes:
|
||||
- name: vault-ca-cert
|
||||
secret:
|
||||
secretName: vault-ca-cert
|
||||
items:
|
||||
- key: ca.crt
|
||||
path: ca.crt
|
||||
- name: combined-certs
|
||||
emptyDir: {}
|
||||
restartPolicy: Always
|
||||
@@ -1,32 +0,0 @@
|
||||
---
|
||||
# Static PV for the shared MEDIASTORE CephFS subvolume, same rootPath as the
|
||||
# arrstack/fafflix/cheeztv mediastore PVs. Each namespace gets its own PV
|
||||
# (unique name + volumeHandle) pinned by claimRef; mediamark reads and rewrites
|
||||
# the same library tree the *arr apps import into, so it must be the same
|
||||
# filesystem (hardlink-safe).
|
||||
apiVersion: v1
|
||||
kind: PersistentVolume
|
||||
metadata:
|
||||
name: mediamark-mediastore
|
||||
spec:
|
||||
capacity:
|
||||
storage: 10Ti
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
persistentVolumeReclaimPolicy: Retain
|
||||
storageClassName: ""
|
||||
volumeMode: Filesystem
|
||||
claimRef:
|
||||
namespace: mediamark
|
||||
name: mediamark-mediastore
|
||||
csi:
|
||||
driver: cephfs.csi.ceph.com
|
||||
volumeHandle: mediamark-mediastore-static
|
||||
nodeStageSecretRef:
|
||||
name: csi-cephfs-secret
|
||||
namespace: csi-cephfs
|
||||
volumeAttributes:
|
||||
staticVolume: "true"
|
||||
clusterID: cephfs_csi_ssd_ec_4_1
|
||||
fsName: cephfs
|
||||
rootPath: /volumes/csi_ssd_ec_4_1/mediastore/a0152dac-a51b-4b95-ac5e-ecdd99bfe3f1
|
||||
@@ -1,20 +0,0 @@
|
||||
---
|
||||
# Statically bound to the mediamark-mediastore PV; storageClassName "" +
|
||||
# volumeName disables dynamic provisioning. Not backed up here -- the media tree
|
||||
# is backed up once from arrstack.
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: mediamark-mediastore
|
||||
namespace: mediamark
|
||||
annotations:
|
||||
k8up.io/backup: "false"
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteMany
|
||||
resources:
|
||||
requests:
|
||||
storage: 10Ti
|
||||
storageClassName: ""
|
||||
volumeName: mediamark-mediastore
|
||||
volumeMode: Filesystem
|
||||
@@ -1,36 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: mediamark
|
||||
namespace: mediamark
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- name: http
|
||||
port: 8080
|
||||
protocol: TCP
|
||||
targetPort: http
|
||||
selector:
|
||||
app: mediamark
|
||||
sessionAffinity: None
|
||||
type: ClusterIP
|
||||
---
|
||||
# Front-door entry Service: both HTTPRoutes target this; all traffic enters via
|
||||
# oauth2-proxy.
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: mediamark-oauth2
|
||||
namespace: mediamark
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- name: http
|
||||
port: 4180
|
||||
protocol: TCP
|
||||
targetPort: http
|
||||
selector:
|
||||
app: mediamark-oauth2
|
||||
sessionAffinity: None
|
||||
type: ClusterIP
|
||||
@@ -1,38 +0,0 @@
|
||||
---
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultAuth
|
||||
metadata:
|
||||
name: default
|
||||
namespace: mediamark
|
||||
spec:
|
||||
allowedNamespaces:
|
||||
- mediamark
|
||||
kubernetes:
|
||||
audiences:
|
||||
- vault
|
||||
role: default
|
||||
serviceAccount: default
|
||||
tokenExpirationSeconds: 600
|
||||
method: kubernetes
|
||||
mount: k8s/au/syd1
|
||||
vaultConnectionRef: vso-system/default
|
||||
---
|
||||
# Separate auth for the arrstack secrets engine: the `mediamark` k8s role is the
|
||||
# only one whose policy grants arrstack/creds/mediamark.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultAuth
|
||||
metadata:
|
||||
name: arrstack-creds
|
||||
namespace: mediamark
|
||||
spec:
|
||||
allowedNamespaces:
|
||||
- mediamark
|
||||
kubernetes:
|
||||
audiences:
|
||||
- vault
|
||||
role: mediamark
|
||||
serviceAccount: default
|
||||
tokenExpirationSeconds: 600
|
||||
method: kubernetes
|
||||
mount: k8s/au/syd1
|
||||
vaultConnectionRef: vso-system/default
|
||||
@@ -1,21 +0,0 @@
|
||||
---
|
||||
# Ephemeral arrstack virtual key. The engine mints one machine token covering
|
||||
# both radarr and sonarr; it is only honoured by arrproxy, which validates it and
|
||||
# swaps in the real per-app key upstream. Role ttl is 60s, so VSO renews the
|
||||
# lease continuously (renewalPercent default 67) and rewrites the secret; the
|
||||
# reloader annotation restarts pods when the token actually changes.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultDynamicSecret
|
||||
metadata:
|
||||
name: arrstack-virtual-key
|
||||
namespace: mediamark
|
||||
spec:
|
||||
allowStaticCreds: false
|
||||
destination:
|
||||
create: true
|
||||
name: arrstack-virtual-key
|
||||
overwrite: true
|
||||
mount: arrstack
|
||||
path: creds/mediamark
|
||||
revoke: true
|
||||
vaultAuthRef: arrstack-creds
|
||||
@@ -1,22 +0,0 @@
|
||||
---
|
||||
# Authentik OIDC client for the mediamark front door (client_id, client_secret,
|
||||
# cookie_secret) at kv/kubernetes/namespace/mediamark/default/oauth-credentials.
|
||||
# The default k8s role's templated policy already grants read on
|
||||
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/*, so no
|
||||
# terraform-vault change is needed.
|
||||
apiVersion: secrets.hashicorp.com/v1beta1
|
||||
kind: VaultStaticSecret
|
||||
metadata:
|
||||
name: oauth-credentials
|
||||
namespace: mediamark
|
||||
spec:
|
||||
destination:
|
||||
create: true
|
||||
name: oauth-credentials
|
||||
overwrite: true
|
||||
hmacSecretData: true
|
||||
mount: kv
|
||||
path: kubernetes/namespace/mediamark/default/oauth-credentials
|
||||
refreshAfter: 5m
|
||||
type: kv-v2
|
||||
vaultAuthRef: default
|
||||
@@ -83,7 +83,7 @@ spec:
|
||||
- mountPath: /data
|
||||
name: data
|
||||
- name: metrics-exporter
|
||||
image: docker.io/oliver006/redis_exporter:v1.89.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/oliver006/redis_exporter:v1.89.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 9121
|
||||
|
||||
@@ -6,11 +6,14 @@ metadata:
|
||||
namespace: pdbmux
|
||||
data:
|
||||
PDBMUX_LISTEN: ":8080"
|
||||
# Two PuppetDB backends merged during the VM -> k8s migration, in precedence
|
||||
# order (first wins ties / pass-through):
|
||||
# new = the in-cluster k8s PuppetDB (plain HTTP on 8080; in-cluster address
|
||||
# is preferred over the external gateway to avoid a hairpin)
|
||||
# Two PuppetDB backends merged during the VM -> k8s migration:
|
||||
# old = legacy Consul-registered puppetdbapi (reachable from pods via the
|
||||
# Consul DNS the puppet workloads already use)
|
||||
PDBMUX_BACKENDS: "new=http://puppetdb.puppet.svc.cluster.local:8080,old=http://puppetdbapi.service.consul:8080"
|
||||
# new = the in-cluster k8s PuppetDB (plain HTTP on 8080; in-cluster address
|
||||
# is preferred over the external gateway to avoid a hairpin).
|
||||
PDBMUX_BACKENDS: "old=http://puppetdbapi.service.consul:8080,new=http://puppetdb.puppet.svc.cluster.local:8080"
|
||||
# "new" (the k8s PuppetDB) is the primary for non-merged pass-through and the
|
||||
# preferred backend for ties / static-merge fallback.
|
||||
PDBMUX_PRIMARY: "new"
|
||||
PDBMUX_PREFER: "new"
|
||||
PDBMUX_MERGE: "freshness"
|
||||
|
||||
@@ -25,14 +25,15 @@ spec:
|
||||
- name: pdbmux
|
||||
# Image is published by the pdbmux repo's .woodpecker/docker.yaml on
|
||||
# a v* tag. It only exists after that tag is cut (see PR merge gates).
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.4.0
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/pdbmux:v0.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: http
|
||||
protocol: TCP
|
||||
envFrom:
|
||||
# PDBMUX_LISTEN / PDBMUX_BACKENDS / PDBMUX_MERGE
|
||||
# PDBMUX_LISTEN / PDBMUX_BACKENDS / PDBMUX_PRIMARY / PDBMUX_PREFER /
|
||||
# PDBMUX_MERGE
|
||||
- configMapRef:
|
||||
name: pdbmux-env
|
||||
optional: false
|
||||
|
||||
@@ -11,10 +11,9 @@ metadata:
|
||||
namespace: puppet
|
||||
data:
|
||||
OPENVOXSERVER_PORT: "8140"
|
||||
OPENVOXSERVER_ENVIRONMENT_TIMEOUT: "0"
|
||||
DNS_ALT_NAMES: "puppetserver-compiler,puppet,puppet.k8s.syd1.au.unkin.net"
|
||||
OPENVOXDB_SERVER_URLS: "https://puppetdb:8081"
|
||||
CA_ENABLED: "false"
|
||||
CA_HOSTNAME: "puppetca"
|
||||
CA_PORT: "8140"
|
||||
OPENVOXSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
|
||||
PUPPETSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
|
||||
|
||||
@@ -12,4 +12,4 @@ metadata:
|
||||
data:
|
||||
PUPPET_DATA_DIR: "/etc/puppetlabs/code/environments"
|
||||
PUPPET_SSL_DIR: "/etc/puppetlabs/puppet/ssl/certs"
|
||||
OPENVOXSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
|
||||
PUPPETSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
|
||||
|
||||
@@ -12,8 +12,7 @@ metadata:
|
||||
data:
|
||||
OPENVOXSERVER_HOSTNAME: "puppet"
|
||||
OPENVOXSERVER_PORT: "8140"
|
||||
OPENVOXSERVER_ENVIRONMENT_TIMEOUT: "0"
|
||||
DNS_ALT_NAMES: "puppet,puppetserver-agents-to-puppet,puppetca,puppet-headless,puppetca.k8s.syd1.au.unkin.net,puppet.k8s.syd1.au.unkin.net"
|
||||
OPENVOXDB_SERVER_URLS: "https://puppetdb:8081"
|
||||
CA_ALLOW_SUBJECT_ALT_NAMES: "true"
|
||||
OPENVOXSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
|
||||
PUPPETSERVER_JAVA_ARGS: "-Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false"
|
||||
|
||||
@@ -99,23 +99,6 @@ spec:
|
||||
- mountPath: /docker-custom-entrypoint.d/post-startup/additional-ruby-gems.sh
|
||||
name: additional-ruby-gems
|
||||
subPath: additional-ruby-gems.sh
|
||||
- mountPath: /configmaps/auth.conf
|
||||
name: compiler-auth-conf
|
||||
subPath: auth.conf
|
||||
- mountPath: /docker-custom-entrypoint.d/pre-default/10-auth-conf.sh
|
||||
name: compiler-auth-conf-seed
|
||||
subPath: 10-auth-conf.sh
|
||||
- mountPath: /docker-custom-entrypoint.d/pre-default/20-vault-helpers.sh
|
||||
name: compiler-vault-helpers-seed
|
||||
subPath: 20-vault-helpers.sh
|
||||
- mountPath: /opt/certmanager/config.yaml
|
||||
name: certmanager-config
|
||||
subPath: certmanager.yaml
|
||||
readOnly: true
|
||||
- mountPath: /opt/sshsignhost/config.yaml
|
||||
name: sshsignhost-config
|
||||
subPath: sshsignhost.yaml
|
||||
readOnly: true
|
||||
initContainers:
|
||||
- name: copy-configmaps
|
||||
image: busybox:1.35
|
||||
@@ -160,7 +143,7 @@ spec:
|
||||
touch /opt/puppetlabs/server/data/puppetserver/dropsonde/bin/dropsonde
|
||||
chown puppet:puppet -R /opt/puppetlabs/server/data/puppetserver/
|
||||
env:
|
||||
- name: OPENVOXSERVER_JAVA_ARGS
|
||||
- name: PUPPETSERVER_JAVA_ARGS
|
||||
value: -Xms1024m -Xmx3072m -Dcom.sun.management.jmxremote.port=31000 -Dcom.sun.management.jmxremote.authenticate=false -Dcom.sun.management.jmxremote.ssl=false
|
||||
resources:
|
||||
limits:
|
||||
@@ -213,38 +196,7 @@ spec:
|
||||
echo "$EXPECTED encapic" | sha256sum -c -
|
||||
install -m 0755 encapic /opt/bin/encapic
|
||||
|
||||
# Puppet shells out to these two from generate() during catalog
|
||||
# compilation: profiles::pki::vault runs certmanager and
|
||||
# profiles::ssh::sign runs sshsignhost.
|
||||
install_release() {
|
||||
name=$1
|
||||
version=$2
|
||||
asset="$name-linux-amd64"
|
||||
base="https://git.unkin.net/unkin/$name/releases/download/$version"
|
||||
curl -fsSL -o "$name" "$base/$asset"
|
||||
curl -fsSL -o "$name.checksums" "$base/checksums.txt"
|
||||
# checksums.txt covers every release asset; pick the line for the
|
||||
# one we downloaded and verify it under our local filename.
|
||||
expected=$(awk -v a="$asset" '$NF == a || $NF == "*"a {print $1}' "$name.checksums")
|
||||
if [ -z "$expected" ]; then
|
||||
echo "no checksum for $asset in $version checksums.txt" >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "$expected $name" | sha256sum -c -
|
||||
install -m 0755 "$name" "/opt/bin/$name"
|
||||
}
|
||||
|
||||
install_release certmanager v0.2.0
|
||||
install_release sshsignhost v0.1.0
|
||||
|
||||
echo "Shared binaries setup completed"
|
||||
resources:
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 256Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 64Mi
|
||||
volumeMounts:
|
||||
- mountPath: /opt/bin/
|
||||
name: puppet-shared-bins
|
||||
@@ -282,22 +234,5 @@ spec:
|
||||
configMap:
|
||||
name: additional-ruby-gems
|
||||
defaultMode: 0755
|
||||
- name: compiler-auth-conf
|
||||
configMap:
|
||||
name: compiler-auth.conf
|
||||
- name: compiler-auth-conf-seed
|
||||
configMap:
|
||||
name: compiler-auth-conf-seed
|
||||
defaultMode: 0755
|
||||
- name: compiler-vault-helpers-seed
|
||||
configMap:
|
||||
name: compiler-vault-helpers-seed
|
||||
defaultMode: 0755
|
||||
- name: certmanager-config
|
||||
configMap:
|
||||
name: certmanager-config
|
||||
- name: sshsignhost-config
|
||||
configMap:
|
||||
name: sshsignhost-config
|
||||
strategy:
|
||||
type: RollingUpdate
|
||||
|
||||
@@ -54,31 +54,6 @@ configMapGenerator:
|
||||
- resources/compiler/puppetdb.conf
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: compiler-auth.conf
|
||||
files:
|
||||
- resources/compiler/auth.conf
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: compiler-auth-conf-seed
|
||||
files:
|
||||
- resources/compiler/10-auth-conf.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: compiler-vault-helpers-seed
|
||||
files:
|
||||
- resources/compiler/20-vault-helpers.sh
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: certmanager-config
|
||||
files:
|
||||
- resources/compiler/certmanager.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: sshsignhost-config
|
||||
files:
|
||||
- resources/compiler/sshsignhost.yaml
|
||||
options:
|
||||
disableNameSuffixHash: true
|
||||
- name: additional-ruby-gems
|
||||
files:
|
||||
- resources/additional-ruby-gems.sh
|
||||
|
||||
@@ -6,6 +6,4 @@ echo "Installing additional Ruby gems..."
|
||||
/opt/puppetlabs/puppet/bin/gem install ipaddr
|
||||
/opt/puppetlabs/puppet/bin/gem install hiera-eyaml
|
||||
/opt/puppetlabs/puppet/bin/gem install toml
|
||||
# Under set -e a failed install kills the entrypoint post-startup hooks, taking down an already-serving compiler.
|
||||
/opt/puppetlabs/bin/puppetserver gem install toml
|
||||
echo "Additional Ruby gems installed successfully"
|
||||
|
||||
@@ -1,14 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
SRC=/configmaps/auth.conf
|
||||
DST=/etc/puppetlabs/puppetserver/conf.d/auth.conf
|
||||
|
||||
# Copied rather than mounted: the entrypoint chowns conf.d and rewrites auth.conf,
|
||||
# both of which fail on a read-only configmap mount and abort container startup.
|
||||
if [ ! -s "$SRC" ]; then
|
||||
echo "FATAL: $SRC missing or empty; refusing to start on the image default auth.conf" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
cp "$SRC" "$DST"
|
||||
@@ -1,29 +0,0 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
BIN_DIR=/opt/bin
|
||||
CA=/opt/vault-ca-cert.crt
|
||||
|
||||
if [ ! -s "$CA" ]; then
|
||||
echo "FATAL: $CA missing or empty; certmanager and sshsignhost cannot verify Vault" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# profiles::pki::vault and profiles::ssh::sign shell out to fixed /usr/local/bin
|
||||
# paths from generate(); the binaries ship on the shared PVC, and /usr/local/bin
|
||||
# lives in the image. Wrappers rather than symlinks because neither binary reads
|
||||
# a CA path from its config: SSL_CERT_FILE scopes the internal CA to these two
|
||||
# processes instead of the puppetserver JVM's own trust store.
|
||||
for bin in certmanager sshsignhost; do
|
||||
if [ ! -x "$BIN_DIR/$bin" ]; then
|
||||
echo "FATAL: $BIN_DIR/$bin missing; generate() would abort every catalog compile" >&2
|
||||
exit 1
|
||||
fi
|
||||
cat > "/usr/local/bin/$bin" <<WRAPPER
|
||||
#!/bin/sh
|
||||
SSL_CERT_FILE=$CA
|
||||
export SSL_CERT_FILE
|
||||
exec $BIN_DIR/$bin "\$@"
|
||||
WRAPPER
|
||||
chmod 0755 "/usr/local/bin/$bin"
|
||||
done
|
||||
@@ -1,320 +0,0 @@
|
||||
# Copied into conf.d at startup by 10-auth-conf.sh; the entrypoint then appends the
|
||||
# admin API cache rule and re-renders the result, so the running file is not byte-identical.
|
||||
authorization: {
|
||||
version: 1
|
||||
rules: [
|
||||
{
|
||||
# Allow nodes to retrieve their own catalog
|
||||
match-request: {
|
||||
path: "^/puppet/v3/catalog/([^/]+)$"
|
||||
type: regex
|
||||
method: [get, post]
|
||||
}
|
||||
allow: "$1"
|
||||
sort-order: 500
|
||||
name: "puppetlabs v3 catalog from agents"
|
||||
},
|
||||
{
|
||||
# Allow catalog-diff to retrieve catalogs on behalf of others.
|
||||
# sort-order 400 must stay lower than the puppetlabs deny that follows: rules
|
||||
# sort by [sort-order, name] and the first match wins.
|
||||
match-request: {
|
||||
path: "^/puppet/v4/catalog/?$"
|
||||
type: regex
|
||||
method: post
|
||||
}
|
||||
allow: "catalog-diff.main.unkin.net"
|
||||
sort-order: 400
|
||||
name: "unkin v4 catalog for catalog-diff"
|
||||
},
|
||||
{
|
||||
# Allow services to retrieve catalogs on behalf of others
|
||||
match-request: {
|
||||
path: "^/puppet/v4/catalog/?$"
|
||||
type: regex
|
||||
method: post
|
||||
}
|
||||
deny: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs v4 catalog for services"
|
||||
},
|
||||
{
|
||||
# Allow nodes to retrieve the certificate they requested earlier
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/certificate/"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow-unauthenticated: true
|
||||
sort-order: 500
|
||||
name: "puppetlabs certificate"
|
||||
},
|
||||
{
|
||||
# Allow all nodes to access the certificate revocation list
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/certificate_revocation_list/ca"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow-unauthenticated: true
|
||||
sort-order: 500
|
||||
name: "puppetlabs crl"
|
||||
},
|
||||
{
|
||||
# Allow nodes to request a new certificate
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/certificate_request"
|
||||
type: path
|
||||
method: [get, put]
|
||||
}
|
||||
allow-unauthenticated: true
|
||||
sort-order: 500
|
||||
name: "puppetlabs csr"
|
||||
},
|
||||
{
|
||||
# Allow nodes to renew their certificate
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/certificate_renewal"
|
||||
type: path
|
||||
method: post
|
||||
}
|
||||
# this endpoint should never be unauthenticated, as it requires the cert to be provided.
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs certificate renewal"
|
||||
},
|
||||
{
|
||||
# Allow the CA CLI to access the certificate_status endpoint
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/certificate_status"
|
||||
type: path
|
||||
method: [get, put, delete]
|
||||
}
|
||||
allow: {
|
||||
extensions: {
|
||||
pp_cli_auth: "true"
|
||||
}
|
||||
}
|
||||
sort-order: 500
|
||||
name: "puppetlabs cert status"
|
||||
},
|
||||
{
|
||||
match-request: {
|
||||
path: "^/puppet-ca/v1/certificate_revocation_list$"
|
||||
type: regex
|
||||
method: put
|
||||
}
|
||||
allow: {
|
||||
extensions: {
|
||||
pp_cli_auth: "true"
|
||||
}
|
||||
}
|
||||
sort-order: 500
|
||||
name: "puppetlabs CRL update"
|
||||
},
|
||||
{
|
||||
# Allow the CA CLI to access the certificate_statuses endpoint
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/certificate_statuses"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow: {
|
||||
extensions: {
|
||||
pp_cli_auth: "true"
|
||||
}
|
||||
}
|
||||
sort-order: 500
|
||||
name: "puppetlabs cert statuses"
|
||||
},
|
||||
{
|
||||
# Allow authenticated access to the CA expirations endpoint
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/expirations"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs CA cert and CRL expirations"
|
||||
},
|
||||
{
|
||||
# Allow the CA CLI to access the certificate clean endpoint
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/clean"
|
||||
type: path
|
||||
method: put
|
||||
}
|
||||
allow: {
|
||||
extensions: {
|
||||
pp_cli_auth: "true"
|
||||
}
|
||||
}
|
||||
sort-order: 500
|
||||
name: "puppetlabs cert clean"
|
||||
},
|
||||
{
|
||||
# Allow the CA CLI to access the certificate sign endpoint
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/sign"
|
||||
type: path
|
||||
method: post
|
||||
}
|
||||
allow: {
|
||||
extensions: {
|
||||
pp_cli_auth: "true"
|
||||
}
|
||||
}
|
||||
sort-order: 500
|
||||
name: "puppetlabs cert sign"
|
||||
},
|
||||
{
|
||||
# Allow the CA CLI to access the certificate sign all endpoint
|
||||
match-request: {
|
||||
path: "/puppet-ca/v1/sign/all"
|
||||
type: path
|
||||
method: post
|
||||
}
|
||||
allow: {
|
||||
extensions: {
|
||||
pp_cli_auth: "true"
|
||||
}
|
||||
}
|
||||
sort-order: 500
|
||||
name: "puppetlabs cert sign all"
|
||||
},
|
||||
{
|
||||
# Allow unauthenticated access to the status service endpoint
|
||||
match-request: {
|
||||
path: "/status/v1/services"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow-unauthenticated: true
|
||||
sort-order: 500
|
||||
name: "puppetlabs status service - full"
|
||||
},
|
||||
{
|
||||
match-request: {
|
||||
path: "/status/v1/simple"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow-unauthenticated: true
|
||||
sort-order: 500
|
||||
name: "puppetlabs status service - simple"
|
||||
},
|
||||
{
|
||||
match-request: {
|
||||
path: "/puppet/v3/environments"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs environments"
|
||||
},
|
||||
{
|
||||
# Allow nodes to access all file_bucket_files. Note that access for
|
||||
# the 'delete' method is forbidden by Puppet regardless of the
|
||||
# configuration of this rule.
|
||||
match-request: {
|
||||
path: "/puppet/v3/file_bucket_file"
|
||||
type: path
|
||||
method: [get, head, post, put]
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs file bucket file"
|
||||
},
|
||||
{
|
||||
# Allow nodes to access all file_content. Note that access for the
|
||||
# 'delete' method is forbidden by Puppet regardless of the
|
||||
# configuration of this rule.
|
||||
match-request: {
|
||||
path: "/puppet/v3/file_content"
|
||||
type: path
|
||||
method: [get, post]
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs file content"
|
||||
},
|
||||
{
|
||||
# Allow nodes to access all file_metadata. Note that access for the
|
||||
# 'delete' method is forbidden by Puppet regardless of the
|
||||
# configuration of this rule.
|
||||
match-request: {
|
||||
path: "/puppet/v3/file_metadata"
|
||||
type: path
|
||||
method: [get, post]
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs file metadata"
|
||||
},
|
||||
{
|
||||
# Allow nodes to retrieve only their own node definition
|
||||
match-request: {
|
||||
path: "^/puppet/v3/node/([^/]+)$"
|
||||
type: regex
|
||||
method: get
|
||||
}
|
||||
allow: "$1"
|
||||
sort-order: 500
|
||||
name: "puppetlabs node"
|
||||
},
|
||||
{
|
||||
# Allow nodes to store only their own reports
|
||||
match-request: {
|
||||
path: "^/puppet/v3/report/([^/]+)$"
|
||||
type: regex
|
||||
method: put
|
||||
}
|
||||
allow: "$1"
|
||||
sort-order: 500
|
||||
name: "puppetlabs report"
|
||||
},
|
||||
{
|
||||
# Allow nodes to update their own facts
|
||||
match-request: {
|
||||
path: "^/puppet/v3/facts/([^/]+)$"
|
||||
type: regex
|
||||
method: put
|
||||
}
|
||||
allow: "$1"
|
||||
sort-order: 500
|
||||
name: "puppetlabs facts"
|
||||
},
|
||||
{
|
||||
match-request: {
|
||||
path: "/puppet/v3/static_file_content"
|
||||
type: path
|
||||
method: get
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppetlabs static file content"
|
||||
},
|
||||
{
|
||||
match-request: {
|
||||
path: "/puppet/v3/tasks"
|
||||
type: path
|
||||
}
|
||||
allow: "*"
|
||||
sort-order: 500
|
||||
name: "puppet tasks information"
|
||||
},
|
||||
{
|
||||
# Deny everything else. This ACL is not strictly
|
||||
# necessary, but illustrates the default policy
|
||||
match-request: {
|
||||
path: "/"
|
||||
type: path
|
||||
}
|
||||
deny: "*"
|
||||
sort-order: 999
|
||||
name: "puppetlabs deny all"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -1,12 +0,0 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_certmanager
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: pki_int
|
||||
role_name: servers_default
|
||||
output_path: /tmp/certmanager
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
@@ -1,11 +0,0 @@
|
||||
---
|
||||
vault:
|
||||
addr: https://vault.service.consul:8200
|
||||
auth_method: kubernetes
|
||||
k8s_mount: k8s/au/syd1
|
||||
k8s_role: puppet_sshsigner
|
||||
jwt_path: /var/run/secrets/kubernetes.io/serviceaccount/token
|
||||
mount_point: sshca
|
||||
role_name: signhost
|
||||
tls_skip_verify: false
|
||||
timeout: 30s
|
||||
@@ -1,123 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
annotations:
|
||||
secret.reloader.stakater.com/reload: "repospawner-woodpecker"
|
||||
spec:
|
||||
# Request state lives in memory and is rebuilt from Job labels on startup, so
|
||||
# exactly one replica may exist at a time.
|
||||
replicas: 1
|
||||
selector:
|
||||
matchLabels:
|
||||
app: repospawner
|
||||
strategy:
|
||||
type: Recreate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: repospawner
|
||||
spec:
|
||||
serviceAccountName: repospawner
|
||||
automountServiceAccountToken: true
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 65532
|
||||
runAsGroup: 65532
|
||||
fsGroup: 65532
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: repospawner
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/repospawner:v0.1.1
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 8080
|
||||
name: http
|
||||
protocol: TCP
|
||||
env:
|
||||
- name: REPOSPAWNER_NAMESPACE
|
||||
value: repospawner
|
||||
# The server passes its own image down to the Jobs, so this must
|
||||
# match the image above exactly.
|
||||
- name: REPOSPAWNER_IMAGE
|
||||
value: artifactapi.k8s.syd1.au.unkin.net/docker-internal/repospawner:v0.1.1
|
||||
- name: REPOSPAWNER_JOB_SERVICE_ACCOUNT
|
||||
value: repospawner
|
||||
- name: GITEA_URL
|
||||
value: https://git.unkin.net
|
||||
- name: REPOSPAWNER_TFGIT_REPO
|
||||
value: unkin/terraform-git
|
||||
- name: VAULT_ADDR
|
||||
value: https://vault.service.consul:8200
|
||||
- name: WOODPECKER_SERVER
|
||||
value: https://ci.k8s.syd1.au.unkin.net
|
||||
# Name only: the enablement Job mounts this Secret itself.
|
||||
- name: REPOSPAWNER_WOODPECKER_SECRET
|
||||
value: repospawner-woodpecker
|
||||
- name: REPOSPAWNER_WOODPECKER_TOKEN_FILE
|
||||
value: /etc/repospawner/woodpecker/token
|
||||
# oauth2-proxy --pass-user-headers forwards the Authentik groups as a
|
||||
# comma-joined X-Forwarded-Groups; X-Auth-Request-Groups is
|
||||
# auth_request-response-only and never reaches a proxied upstream.
|
||||
- name: REPOSPAWNER_GROUPS_HEADER
|
||||
value: X-Forwarded-Groups
|
||||
- name: REPOSPAWNER_ALLOWED_GROUPS
|
||||
value: akP-repospawner-admin
|
||||
volumeMounts:
|
||||
- name: vault-token
|
||||
mountPath: /var/run/secrets/vault
|
||||
readOnly: true
|
||||
- name: woodpecker-token
|
||||
mountPath: /etc/repospawner/woodpecker
|
||||
readOnly: true
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /livez
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /readyz
|
||||
port: http
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 300m
|
||||
memory: 256Mi
|
||||
volumes:
|
||||
# Native Vault kubernetes login: the default kubernetes.io token has the
|
||||
# wrong audience, so the app reads this audience-vault projection.
|
||||
- name: vault-token
|
||||
projected:
|
||||
sources:
|
||||
- serviceAccountToken:
|
||||
path: token
|
||||
audience: vault
|
||||
expirationSeconds: 600
|
||||
# Optional: absent, the server starts and refuses woodpecker requests.
|
||||
- name: woodpecker-token
|
||||
secret:
|
||||
secretName: repospawner-woodpecker
|
||||
optional: true
|
||||
items:
|
||||
- key: token
|
||||
path: token
|
||||
restartPolicy: Always
|
||||
@@ -1,39 +0,0 @@
|
||||
---
|
||||
# External (DMZ) front for repospawner on repospawner.unkin.net via the external
|
||||
# Traefik (LB VIP 198.18.199.0). TLS terminates with the real Let's Encrypt
|
||||
# *.unkin.net wildcard (Certificate wildcard-unkin-net in cert-manager,
|
||||
# reflected into this namespace as wildcard-unkin-net-tls by the emberstack
|
||||
# reflector), so there is no cert-manager annotation here. The apex
|
||||
# repospawner.unkin.net A record lives in the bind-operator unkin.net zone, NOT
|
||||
# external-dns, so no external-dns annotation either. oauth2-proxy fronts both
|
||||
# hostnames.
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
labels:
|
||||
traefik.io/instance: external
|
||||
name: repospawner-external
|
||||
namespace: repospawner
|
||||
spec:
|
||||
gatewayClassName: traefik-external
|
||||
listeners:
|
||||
- name: http
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
hostname: repospawner.unkin.net
|
||||
allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
- name: https
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
hostname: repospawner.unkin.net
|
||||
allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
tls:
|
||||
mode: Terminate
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: wildcard-unkin-net-tls
|
||||
@@ -1,38 +0,0 @@
|
||||
---
|
||||
# Internal front for repospawner (cf. mediamark).
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: Gateway
|
||||
metadata:
|
||||
labels:
|
||||
traefik.io/instance: internal
|
||||
annotations:
|
||||
cert-manager.io/cluster-issuer: vault-issuer
|
||||
cert-manager.io/common-name: repospawner.k8s.syd1.au.unkin.net
|
||||
cert-manager.io/private-key-size: "4096"
|
||||
external-dns.alpha.kubernetes.io/hostname: repospawner.k8s.syd1.au.unkin.net
|
||||
external-dns.alpha.kubernetes.io/target: 198.18.200.4
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
spec:
|
||||
gatewayClassName: traefik-internal
|
||||
listeners:
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: repospawner.k8s.syd1.au.unkin.net
|
||||
name: http
|
||||
port: 80
|
||||
protocol: HTTP
|
||||
- allowedRoutes:
|
||||
namespaces:
|
||||
from: Same
|
||||
hostname: repospawner.k8s.syd1.au.unkin.net
|
||||
name: https
|
||||
port: 443
|
||||
protocol: HTTPS
|
||||
tls:
|
||||
certificateRefs:
|
||||
- group: ""
|
||||
kind: Secret
|
||||
name: repospawner-tls
|
||||
mode: Terminate
|
||||
@@ -1,49 +0,0 @@
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: repospawner-external-http-redirect
|
||||
namespace: repospawner
|
||||
spec:
|
||||
hostnames:
|
||||
- repospawner.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: repospawner-external
|
||||
sectionName: http
|
||||
rules:
|
||||
- filters:
|
||||
- type: RequestRedirect
|
||||
requestRedirect:
|
||||
scheme: https
|
||||
statusCode: 301
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: repospawner-external
|
||||
namespace: repospawner
|
||||
spec:
|
||||
hostnames:
|
||||
- repospawner.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: repospawner-external
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: repospawner-oauth2
|
||||
port: 4180
|
||||
weight: 1
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
@@ -1,49 +0,0 @@
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: repospawner-http-redirect
|
||||
namespace: repospawner
|
||||
spec:
|
||||
hostnames:
|
||||
- repospawner.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: repospawner
|
||||
sectionName: http
|
||||
rules:
|
||||
- filters:
|
||||
- type: RequestRedirect
|
||||
requestRedirect:
|
||||
scheme: https
|
||||
statusCode: 301
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
---
|
||||
apiVersion: gateway.networking.k8s.io/v1
|
||||
kind: HTTPRoute
|
||||
metadata:
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
spec:
|
||||
hostnames:
|
||||
- repospawner.k8s.syd1.au.unkin.net
|
||||
parentRefs:
|
||||
- group: gateway.networking.k8s.io
|
||||
kind: Gateway
|
||||
name: repospawner
|
||||
sectionName: https
|
||||
rules:
|
||||
- backendRefs:
|
||||
- group: ""
|
||||
kind: Service
|
||||
name: repospawner-oauth2
|
||||
port: 4180
|
||||
weight: 1
|
||||
matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
value: /
|
||||
@@ -1,18 +0,0 @@
|
||||
---
|
||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||
kind: Kustomization
|
||||
|
||||
resources:
|
||||
- namespace.yaml
|
||||
- serviceaccount.yaml
|
||||
- vaultauth.yaml
|
||||
- rbac.yaml
|
||||
- vaultstaticsecret.yaml
|
||||
- deployment.yaml
|
||||
- oauth2-proxy-configmap.yaml
|
||||
- oauth2-proxy-deployment.yaml
|
||||
- service.yaml
|
||||
- gateway.yaml
|
||||
- httproute.yaml
|
||||
- gateway-external.yaml
|
||||
- httproute-external.yaml
|
||||
@@ -1,7 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
labels:
|
||||
app.kubernetes.io/name: repospawner
|
||||
name: repospawner
|
||||
@@ -1,45 +0,0 @@
|
||||
---
|
||||
# Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come
|
||||
# from the oauth-credentials Secret). Single auth front for repospawner on both
|
||||
# host names; access is gated here on the akP-repospawner-admin Authentik group
|
||||
# and re-checked by the app from X-Forwarded-Groups.
|
||||
apiVersion: v1
|
||||
kind: ConfigMap
|
||||
metadata:
|
||||
name: repospawner-oauth2-env
|
||||
namespace: repospawner
|
||||
data:
|
||||
OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180"
|
||||
OAUTH2_PROXY_PROVIDER: "oidc"
|
||||
OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/repospawner/"
|
||||
# Relative (host-less) redirect URL: with reverse-proxy mode on, oauth2-proxy
|
||||
# derives scheme+host per request from X-Forwarded-Proto/Host, so the same
|
||||
# deployment serves BOTH the external repospawner.unkin.net and internal
|
||||
# repospawner.k8s.syd1.au.unkin.net callbacks. Both absolute callback URIs are
|
||||
# registered on the Authentik provider (terraform-authentik, separate PR).
|
||||
OAUTH2_PROXY_REDIRECT_URL: "/oauth2/callback"
|
||||
OAUTH2_PROXY_UPSTREAMS: "http://repospawner.repospawner.svc.cluster.local:8080/"
|
||||
OAUTH2_PROXY_SCOPE: "openid email profile ak_groups"
|
||||
# Populate session.Groups from the Authentik ak_groups claim; pass-user-headers
|
||||
# then emits it as a single comma-joined X-Forwarded-Groups header.
|
||||
OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups"
|
||||
OAUTH2_PROXY_ALLOWED_GROUPS: "akP-repospawner-admin"
|
||||
# Forward identity + groups to repospawner as X-Forwarded-{User,Email,Groups}.
|
||||
# NOTE: set-xauthrequest is intentionally NOT set -- it only populates
|
||||
# auth_request *response* headers, which never reach a proxied upstream.
|
||||
OAUTH2_PROXY_PASS_USER_HEADERS: "true"
|
||||
OAUTH2_PROXY_EMAIL_DOMAINS: "*"
|
||||
# Authentik hardcodes email_verified=false in the id_token; authorization is
|
||||
# enforced via ak_groups, so accepting the unverified email is safe.
|
||||
OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true"
|
||||
OAUTH2_PROXY_COOKIE_SECURE: "true"
|
||||
# One cookie domain per host (a single parent-domain cookie can't span
|
||||
# unkin.net and k8s.syd1.au.unkin.net cleanly); oauth2-proxy picks the domain
|
||||
# matching the request host. Whitelist both so post-auth `rd` redirects to
|
||||
# either front door are honoured.
|
||||
OAUTH2_PROXY_COOKIE_DOMAINS: "repospawner.unkin.net,repospawner.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_WHITELIST_DOMAINS: "repospawner.unkin.net,repospawner.k8s.syd1.au.unkin.net"
|
||||
OAUTH2_PROXY_REVERSE_PROXY: "true"
|
||||
OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt"
|
||||
OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256"
|
||||
OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"
|
||||
@@ -1,133 +0,0 @@
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: repospawner-oauth2
|
||||
namespace: repospawner
|
||||
annotations:
|
||||
configmap.reloader.stakater.com/auto: "true"
|
||||
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
|
||||
spec:
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: repospawner-oauth2
|
||||
strategy:
|
||||
rollingUpdate:
|
||||
maxUnavailable: 1
|
||||
type: RollingUpdate
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: repospawner-oauth2
|
||||
spec:
|
||||
serviceAccountName: default
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 65532
|
||||
runAsGroup: 65532
|
||||
fsGroup: 65532
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
initContainers:
|
||||
# The Authentik issuer is served behind the internal unkin.net CA;
|
||||
# combine the system roots with it so oauth2-proxy's OIDC HTTP client
|
||||
# trusts the discovery endpoint.
|
||||
- name: combine-certs
|
||||
image: docker.io/library/alpine:3
|
||||
imagePullPolicy: IfNotPresent
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
|
||||
volumeMounts:
|
||||
- name: vault-ca-cert
|
||||
mountPath: /custom-ca
|
||||
readOnly: true
|
||||
- name: combined-certs
|
||||
mountPath: /combined-certs
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 32Mi
|
||||
limits:
|
||||
cpu: 200m
|
||||
memory: 64Mi
|
||||
containers:
|
||||
- name: oauth2-proxy
|
||||
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.3
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- containerPort: 4180
|
||||
name: http
|
||||
protocol: TCP
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: repospawner-oauth2-env
|
||||
optional: false
|
||||
env:
|
||||
- name: OAUTH2_PROXY_CLIENT_ID
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_id
|
||||
- name: OAUTH2_PROXY_CLIENT_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: client_secret
|
||||
- name: OAUTH2_PROXY_COOKIE_SECRET
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: oauth-credentials
|
||||
key: cookie_secret
|
||||
volumeMounts:
|
||||
- name: combined-certs
|
||||
mountPath: /etc/ssl/combined
|
||||
readOnly: true
|
||||
livenessProbe:
|
||||
httpGet:
|
||||
path: /ping
|
||||
port: http
|
||||
initialDelaySeconds: 10
|
||||
periodSeconds: 30
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
readinessProbe:
|
||||
httpGet:
|
||||
path: /ready
|
||||
port: http
|
||||
initialDelaySeconds: 5
|
||||
periodSeconds: 10
|
||||
timeoutSeconds: 5
|
||||
failureThreshold: 3
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
cpu: 500m
|
||||
memory: 256Mi
|
||||
volumes:
|
||||
- name: vault-ca-cert
|
||||
secret:
|
||||
secretName: vault-ca-cert
|
||||
items:
|
||||
- key: ca.crt
|
||||
path: ca.crt
|
||||
- name: combined-certs
|
||||
emptyDir: {}
|
||||
restartPolicy: Always
|
||||
@@ -1,48 +0,0 @@
|
||||
---
|
||||
# The server creates one Job per request phase and polls Job/Pod state to drive
|
||||
# the state machine and rebuild it after a restart.
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: Role
|
||||
metadata:
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
rules:
|
||||
- apiGroups:
|
||||
- batch
|
||||
resources:
|
||||
- jobs
|
||||
verbs:
|
||||
- create
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- delete
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
- watch
|
||||
- apiGroups:
|
||||
- ""
|
||||
resources:
|
||||
- pods/log
|
||||
verbs:
|
||||
- get
|
||||
- list
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: RoleBinding
|
||||
metadata:
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: Role
|
||||
name: repospawner
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
@@ -1,36 +0,0 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- name: http
|
||||
port: 8080
|
||||
protocol: TCP
|
||||
targetPort: http
|
||||
selector:
|
||||
app: repospawner
|
||||
sessionAffinity: None
|
||||
type: ClusterIP
|
||||
---
|
||||
# Front-door entry Service: both HTTPRoutes target this; all traffic enters via
|
||||
# oauth2-proxy.
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: repospawner-oauth2
|
||||
namespace: repospawner
|
||||
spec:
|
||||
internalTrafficPolicy: Cluster
|
||||
ports:
|
||||
- name: http
|
||||
port: 4180
|
||||
protocol: TCP
|
||||
targetPort: http
|
||||
selector:
|
||||
app: repospawner-oauth2
|
||||
sessionAffinity: None
|
||||
type: ClusterIP
|
||||
@@ -1,8 +0,0 @@
|
||||
---
|
||||
# Bound to the Vault kubernetes auth role `repospawner`; the server and the Jobs
|
||||
# it spawns both run as this account and log into Vault natively.
|
||||
apiVersion: v1
|
||||
kind: ServiceAccount
|
||||
metadata:
|
||||
name: repospawner
|
||||
namespace: repospawner
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user