--- # Non-secret oauth2-proxy configuration (client_id/secret/cookie_secret come from # the oauth-credentials Secret). oauth2-proxy is the single auth front for the # arrstack: it authenticates the UI and the token API against Authentik, and path- # routes to the arrproxy-ui / arrproxy-api upstreams. //api is exempted from # auth (SKIP_AUTH_REGEX) so *arr clients presenting a per-user token reach the api # directly; the api then validates the token. Everything else requires the oauth # session and receives identity via X-Forwarded-* / X-Auth-Request-* headers. apiVersion: v1 kind: ConfigMap metadata: name: arrproxy-oauth2-env namespace: arrstack annotations: argocd.argoproj.io/sync-wave: "2" data: OAUTH2_PROXY_HTTP_ADDRESS: "0.0.0.0:4180" OAUTH2_PROXY_PROVIDER: "oidc" # Authentik arrstack app discovery issuer (served by the internal unkin.net CA; # trusted via PROVIDER_CA_FILES below). CONFIRM the slug matches the Authentik # application (terraform-authentik PR #18). OAUTH2_PROXY_OIDC_ISSUER_URL: "https://identity.unkin.net/application/o/arrstack/" OAUTH2_PROXY_REDIRECT_URL: "https://arrstack.unkin.net/oauth2/callback" # Longest-prefix wins: /api and / go to arrproxy-api, everything else # (the SPA + static assets) to arrproxy-ui. OAUTH2_PROXY_UPSTREAMS: "http://arrproxy-ui.arrstack.svc.cluster.local:8080/,http://arrproxy-api.arrstack.svc.cluster.local:8080/api/,http://arrproxy-api.arrstack.svc.cluster.local:8080/sonarr/,http://arrproxy-api.arrstack.svc.cluster.local:8080/radarr/,http://arrproxy-api.arrstack.svc.cluster.local:8080/prowlarr/" OAUTH2_PROXY_SCOPE: "openid email profile ak_groups" # Populate session.Groups from the Authentik ak_groups claim; pass-user-headers # then emits it as a single comma-joined X-Forwarded-Groups header. OAUTH2_PROXY_OIDC_GROUPS_CLAIM: "ak_groups" # Forward identity + groups to arrproxy-api as X-Forwarded-{User,Email,Groups} # (the api reads these; ARRPROXY_GROUPS_HEADER=X-Forwarded-Groups). NOTE: # set-xauthrequest is intentionally NOT set -- it only populates auth_request # *response* headers, which never reach an --upstreams-proxied backend. OAUTH2_PROXY_PASS_USER_HEADERS: "true" # Bypass auth ONLY for the *arr proxy API (//api...): this matches # /sonarr/api but NOT /api/tokens or /api/me (which stay authenticated). OAUTH2_PROXY_SKIP_AUTH_REGEX: "^/[^/]+/api" OAUTH2_PROXY_EMAIL_DOMAINS: "*" # Authentik hardcodes email_verified=false in the id_token; without this # oauth2-proxy rejects the session ("email ... isn't verified") -> 500 on # /oauth2/callback. Authorization is enforced downstream via ak_groups, so # accepting the unverified email here is safe. OAUTH2_PROXY_INSECURE_OIDC_ALLOW_UNVERIFIED_EMAIL: "true" OAUTH2_PROXY_COOKIE_SECURE: "true" OAUTH2_PROXY_COOKIE_DOMAINS: "arrstack.unkin.net" OAUTH2_PROXY_WHITELIST_DOMAINS: "arrstack.unkin.net" OAUTH2_PROXY_REVERSE_PROXY: "true" OAUTH2_PROXY_PROVIDER_CA_FILES: "/etc/ssl/combined/ca-certificates.crt" OAUTH2_PROXY_CODE_CHALLENGE_METHOD: "S256" OAUTH2_PROXY_SKIP_PROVIDER_BUTTON: "true"