Files
argocd-apps/apps/base/arrstack/arrproxy/oauth2-proxy-deployment.yaml
T
unkin-agent 20c603dd84
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
deploy arrproxy (oauth2-gated *arr proxy + per-user API keys)
Adds the arrproxy front door to the arrstack app: the external, oauth-gated
entry to sonarr/radarr/prowlarr with per-user API-key brokering, wired to match
the arrproxy v0.1.0 code (ports, routes, identity headers, keys dir).

Topology (apps/base/arrstack/arrproxy):
- oauth2-proxy Deployment/Service is the single front (Authentik OIDC), path-
  routing via --upstreams to arrproxy-ui (/, static SPA) and arrproxy-api
  (/api token API + /<app> proxy). skip-auth-regex ^/[^/]+/api bypasses auth
  only for the *arr proxy API (/sonarr/api...), keeping /api/tokens + /api/me
  and the UI authenticated.
- Identity+groups reach the api via --pass-user-headers (X-Forwarded-*); the api
  reads ARRPROXY_GROUPS_HEADER=X-Forwarded-Groups (set-xauthrequest is
  auth_request-response-only and never reaches an upstream).
- oauth2-proxy trusts identity.unkin.net's internal-CA cert via a combine-certs
  initContainer (system roots + vault-ca-cert).
- CNPG token store (arrproxy-db, 2 instances, cephrgw backups); a wave-1 Sync
  hook Job applies the schema (arrproxy-api does not self-migrate).
- VaultStaticSecrets for the seeded ARRPROXY_PEPPER and the oauth-credentials;
  the real *arr keys reuse the existing <app>-apikey Secrets (projected one file
  per app into /etc/arrproxy/keys).
- External Gateway (traefik-external, arrstack.unkin.net, vault-issuer TLS) +
  HTTPRoute to the oauth2-proxy entry.

Also adds the arrstack.unkin.net apex A record (-> external DMZ VIP 198.18.199.0)
to the bind-operator unkin.net zone.
2026-08-16 21:45:18 +10:00

134 lines
3.8 KiB
YAML

---
apiVersion: apps/v1
kind: Deployment
metadata:
name: arrproxy-oauth2
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "2"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "oauth-credentials,vault-ca-cert"
spec:
replicas: 2
selector:
matchLabels:
app: arrproxy-oauth2
strategy:
rollingUpdate:
maxUnavailable: 1
type: RollingUpdate
template:
metadata:
labels:
app: arrproxy-oauth2
spec:
serviceAccountName: default
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 65532
runAsGroup: 65532
fsGroup: 65532
seccompProfile:
type: RuntimeDefault
initContainers:
# identity.unkin.net serves a Vault-PKI cert; combine the system roots
# with the internal CA so oauth2-proxy's OIDC HTTP client trusts it.
- name: combine-certs
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/library/alpine:3
imagePullPolicy: IfNotPresent
command:
- sh
- -c
- cat /etc/ssl/certs/ca-certificates.crt /custom-ca/ca.crt > /combined-certs/ca-certificates.crt
volumeMounts:
- name: vault-ca-cert
mountPath: /custom-ca
readOnly: true
- name: combined-certs
mountPath: /combined-certs
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 32Mi
limits:
cpu: 200m
memory: 64Mi
containers:
- name: oauth2-proxy
image: artifactapi.k8s.syd1.au.unkin.net/ghcr/oauth2-proxy/oauth2-proxy:v7.15.3
imagePullPolicy: IfNotPresent
ports:
- containerPort: 4180
name: http
protocol: TCP
envFrom:
- configMapRef:
name: arrproxy-oauth2-env
optional: false
env:
- name: OAUTH2_PROXY_CLIENT_ID
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_id
- name: OAUTH2_PROXY_CLIENT_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: client_secret
- name: OAUTH2_PROXY_COOKIE_SECRET
valueFrom:
secretKeyRef:
name: oauth-credentials
key: cookie_secret
volumeMounts:
- name: combined-certs
mountPath: /etc/ssl/combined
readOnly: true
livenessProbe:
httpGet:
path: /ping
port: http
initialDelaySeconds: 10
periodSeconds: 30
timeoutSeconds: 5
failureThreshold: 3
readinessProbe:
httpGet:
path: /ready
port: http
initialDelaySeconds: 5
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
resources:
requests:
cpu: 50m
memory: 64Mi
limits:
cpu: 500m
memory: 256Mi
volumes:
- name: vault-ca-cert
secret:
secretName: vault-ca-cert
items:
- key: ca.crt
path: ca.crt
- name: combined-certs
emptyDir: {}
restartPolicy: Always