arrstack: wire arrproxy v0.4.0 tier routing (fafflix/cheeztv) #416
Reference in New Issue
Block a user
Delete Branch "benvin/arrproxy-tier-wiring"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
The old bare
sonarr/radarrServices are gone, but arrproxy still ran the v0.3.x built-in default topology pointing at non-existentsonarr/radarrupstreams and mounted deadsonarr-apikey/radarr-apikeySecrets. This cuts the front door over to arrproxy v0.4.0 tier routing so the adult (fafflix,/3aa168) and kids (cheeztv,/3df803) *arr instances are reachable again, with per-tier group authorization.Changes
arrproxy-apiandarrproxy-uiimages tov0.4.0.arrproxy-tiersConfigMap (ARRPROXY_TIERS_FILE):fafflix+cheeztvtiers, each with sonarr/radarr upstreams, route hash, key subdir and group grants. Adults (akP-media-fafflix) reach both tiers all methods; kids (akP-media-cheeztv) reach only cheeztv, GET/HEAD.legacyRoutes:falseretires the unprefixed routes./<hash>and proxies/<app>/..., each upstream URL carries the/<hash>path segment so the joined upstream path (/3aa168/sonarr/...) matches the *arr's own UrlBase.{sonarr,radarr}-{adult,kids}-apikeySecrets under<keyDir>/<app>(adult/*,kids/*); refresh reloader annotations./3aa168and/3df803to arrproxy-api (drop dead/sonarr/radarr/prowlarr; prowlarr is served directly), and widenSKIP_AUTH_REGEXto^/[^/]+/[^/]+/apifor the hash-prefixed tier api paths.Group headers keep flowing via the existing Authentik
ak_groupsclaim -> oauth2-proxyX-Forwarded-Groupsmechanism. Validated withkustomize build+ repo kubeconform (88/88 valid). No new Vault seeds required — the per-instance apikey Secrets already exist.The old bare sonarr/radarr Services are gone; arrproxy still ran the v0.3.x default topology pointing at non-existent upstreams and dead sonarr/radarr apikey Secrets. Cut the front door over to arrproxy v0.4.0 tier routing so the adult (fafflix, /3aa168) and kids (cheeztv, /3df803) *arr instances are reachable again with per-tier group authorization. - Bump arrproxy-api and arrproxy-ui images to v0.4.0. - Add arrproxy-tiers ConfigMap (ARRPROXY_TIERS_FILE): fafflix + cheeztv tiers, each with sonarr/radarr upstreams, route hash, key subdir and group grants. Adults (akP-media-fafflix) reach both tiers all methods; kids (akP-media-cheeztv) reach only cheeztv, GET/HEAD. legacyRoutes:false retires the unprefixed routes. arrproxy strips /<hash> and proxies /<app>/..., so each upstream URL carries the /<hash> path segment to line up with the *arr's own UrlBase (/3aa168/sonarr etc.). - Mount the tiers file and rework the projected keys volume to the real per-instance {sonarr,radarr}-{adult,kids}-apikey Secrets under <keyDir>/<app> (adult/*, kids/*); refresh the reloader annotations. - oauth2-proxy: route /3aa168 and /3df803 to arrproxy-api (drop dead /sonarr /radarr /prowlarr; prowlarr is served directly), and widen SKIP_AUTH_REGEX to ^/[^/]+/[^/]+/api for the hash-prefixed tier api paths.