Files
argocd-apps/apps/base/arrstack/arrproxy/services.yaml
T
unkin-agent 20c603dd84
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
deploy arrproxy (oauth2-gated *arr proxy + per-user API keys)
Adds the arrproxy front door to the arrstack app: the external, oauth-gated
entry to sonarr/radarr/prowlarr with per-user API-key brokering, wired to match
the arrproxy v0.1.0 code (ports, routes, identity headers, keys dir).

Topology (apps/base/arrstack/arrproxy):
- oauth2-proxy Deployment/Service is the single front (Authentik OIDC), path-
  routing via --upstreams to arrproxy-ui (/, static SPA) and arrproxy-api
  (/api token API + /<app> proxy). skip-auth-regex ^/[^/]+/api bypasses auth
  only for the *arr proxy API (/sonarr/api...), keeping /api/tokens + /api/me
  and the UI authenticated.
- Identity+groups reach the api via --pass-user-headers (X-Forwarded-*); the api
  reads ARRPROXY_GROUPS_HEADER=X-Forwarded-Groups (set-xauthrequest is
  auth_request-response-only and never reaches an upstream).
- oauth2-proxy trusts identity.unkin.net's internal-CA cert via a combine-certs
  initContainer (system roots + vault-ca-cert).
- CNPG token store (arrproxy-db, 2 instances, cephrgw backups); a wave-1 Sync
  hook Job applies the schema (arrproxy-api does not self-migrate).
- VaultStaticSecrets for the seeded ARRPROXY_PEPPER and the oauth-credentials;
  the real *arr keys reuse the existing <app>-apikey Secrets (projected one file
  per app into /etc/arrproxy/keys).
- External Gateway (traefik-external, arrstack.unkin.net, vault-issuer TLS) +
  HTTPRoute to the oauth2-proxy entry.

Also adds the arrstack.unkin.net apex A record (-> external DMZ VIP 198.18.199.0)
to the bind-operator unkin.net zone.
2026-08-16 21:45:18 +10:00

60 lines
1.1 KiB
YAML

---
# Front-door entry Service: the HTTPRoute for arrstack.unkin.net targets this.
# All traffic (UI, token API, and the *arr proxy) enters via oauth2-proxy.
apiVersion: v1
kind: Service
metadata:
name: arrproxy
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "2"
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 80
protocol: TCP
targetPort: http
selector:
app: arrproxy-oauth2
sessionAffinity: None
type: ClusterIP
---
apiVersion: v1
kind: Service
metadata:
name: arrproxy-api
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "2"
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 8080
protocol: TCP
targetPort: http
selector:
app: arrproxy-api
sessionAffinity: None
type: ClusterIP
---
apiVersion: v1
kind: Service
metadata:
name: arrproxy-ui
namespace: arrstack
annotations:
argocd.argoproj.io/sync-wave: "2"
spec:
internalTrafficPolicy: Cluster
ports:
- name: http
port: 8080
protocol: TCP
targetPort: http
selector:
app: arrproxy-ui
sessionAffinity: None
type: ClusterIP