--- apiVersion: apps/v1 kind: Deployment metadata: name: arrproxy-api namespace: arrstack annotations: # Wave 2: serve only after the wave-1 migrate Job completes. argocd.argoproj.io/sync-wave: "2" secret.reloader.stakater.com/reload: "arrproxy-pepper,arrproxy-db-app,sonarr-apikey,radarr-apikey,prowlarr-apikey" spec: replicas: 2 selector: matchLabels: app: arrproxy-api strategy: rollingUpdate: maxUnavailable: 1 type: RollingUpdate template: metadata: labels: app: arrproxy-api spec: serviceAccountName: default automountServiceAccountToken: false securityContext: runAsNonRoot: true runAsUser: 65532 runAsGroup: 65532 fsGroup: 65532 seccompProfile: type: RuntimeDefault containers: - name: api image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/arrproxy-api:v0.1.0 imagePullPolicy: IfNotPresent ports: - containerPort: 8080 name: http protocol: TCP env: - name: ARRPROXY_ADDR value: ":8080" # oauth2-proxy --pass-user-headers forwards identity to the upstream as # X-Forwarded-{User,Email,Groups} (a single comma-joined Groups value). # Email/User already match the api defaults; override the groups header # (default X-Auth-Request-Groups is auth_request-response-only and never # reaches this upstream) so group-based authorization works. - name: ARRPROXY_GROUPS_HEADER value: X-Forwarded-Groups # Real per-app *arr keys, projected one file per app under this dir # (sourced from the existing -apikey Secrets). The api injects # them server-side and redacts them from every proxied response. - name: ARRPROXY_KEYS_DIR value: /etc/arrproxy/keys - name: ARRPROXY_PEPPER valueFrom: secretKeyRef: name: arrproxy-pepper key: pepper # DSN assembled from the CNPG-generated arrproxy-db-app Secret; # $(VAR) expansion resolves the two env entries defined above it. - name: ARRPROXY_DB_USER valueFrom: secretKeyRef: name: arrproxy-db-app key: username - name: ARRPROXY_DB_PASSWORD valueFrom: secretKeyRef: name: arrproxy-db-app key: password - name: DATABASE_URL value: "postgres://$(ARRPROXY_DB_USER):$(ARRPROXY_DB_PASSWORD)@arrproxy-db-rw.arrstack.svc.cluster.local:5432/arrproxy?sslmode=require" volumeMounts: - name: arr-keys mountPath: /etc/arrproxy/keys readOnly: true - name: tmp mountPath: /tmp livenessProbe: httpGet: path: /livez port: http initialDelaySeconds: 10 periodSeconds: 30 timeoutSeconds: 5 failureThreshold: 3 readinessProbe: httpGet: path: /readyz port: http initialDelaySeconds: 5 periodSeconds: 10 timeoutSeconds: 5 failureThreshold: 3 securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true capabilities: drop: - ALL resources: requests: cpu: 100m memory: 128Mi limits: cpu: "1" memory: 512Mi volumes: # Real *arr API keys, one file per app named exactly so the api # reads /etc/arrproxy/keys/{sonarr,radarr,prowlarr}. Reuses the same # -apikey Secrets the *arr Deployments already consume. - name: arr-keys projected: sources: - secret: name: sonarr-apikey items: - key: apitoken path: sonarr - secret: name: radarr-apikey items: - key: apitoken path: radarr - secret: name: prowlarr-apikey items: - key: apitoken path: prowlarr - name: tmp emptyDir: sizeLimit: 64Mi restartPolicy: Always