20c603dd84
Adds the arrproxy front door to the arrstack app: the external, oauth-gated entry to sonarr/radarr/prowlarr with per-user API-key brokering, wired to match the arrproxy v0.1.0 code (ports, routes, identity headers, keys dir). Topology (apps/base/arrstack/arrproxy): - oauth2-proxy Deployment/Service is the single front (Authentik OIDC), path- routing via --upstreams to arrproxy-ui (/, static SPA) and arrproxy-api (/api token API + /<app> proxy). skip-auth-regex ^/[^/]+/api bypasses auth only for the *arr proxy API (/sonarr/api...), keeping /api/tokens + /api/me and the UI authenticated. - Identity+groups reach the api via --pass-user-headers (X-Forwarded-*); the api reads ARRPROXY_GROUPS_HEADER=X-Forwarded-Groups (set-xauthrequest is auth_request-response-only and never reaches an upstream). - oauth2-proxy trusts identity.unkin.net's internal-CA cert via a combine-certs initContainer (system roots + vault-ca-cert). - CNPG token store (arrproxy-db, 2 instances, cephrgw backups); a wave-1 Sync hook Job applies the schema (arrproxy-api does not self-migrate). - VaultStaticSecrets for the seeded ARRPROXY_PEPPER and the oauth-credentials; the real *arr keys reuse the existing <app>-apikey Secrets (projected one file per app into /etc/arrproxy/keys). - External Gateway (traefik-external, arrstack.unkin.net, vault-issuer TLS) + HTTPRoute to the oauth2-proxy entry. Also adds the arrstack.unkin.net apex A record (-> external DMZ VIP 198.18.199.0) to the bind-operator unkin.net zone.
50 lines
1.5 KiB
YAML
50 lines
1.5 KiB
YAML
---
|
|
# Per-deployment token-hash pepper. Seeded (openssl rand) at
|
|
# kv/kubernetes/namespace/arrstack/default/arrproxy-pepper (key: pepper); the
|
|
# default k8s role's templated policy already grants read on
|
|
# kv/data/kubernetes/namespace/{{sa_namespace}}/{{sa_name}}/* for the
|
|
# arrstack/default ServiceAccount, so no terraform-vault change is needed. VSO
|
|
# syncs it into the arrproxy-pepper Secret consumed by arrproxy-api as
|
|
# ARRPROXY_PEPPER.
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: arrproxy-pepper
|
|
namespace: arrstack
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "0"
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: arrproxy-pepper
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/arrstack/default/arrproxy-pepper
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|
|
---
|
|
# Authentik OIDC client for the arrstack front door (client_id, client_secret,
|
|
# cookie_secret), created by terraform-authentik at
|
|
# kv/kubernetes/namespace/arrstack/default/oauth-credentials. VSO syncs it into
|
|
# the oauth-credentials Secret consumed by the oauth2-proxy Deployment.
|
|
apiVersion: secrets.hashicorp.com/v1beta1
|
|
kind: VaultStaticSecret
|
|
metadata:
|
|
name: oauth-credentials
|
|
namespace: arrstack
|
|
annotations:
|
|
argocd.argoproj.io/sync-wave: "0"
|
|
spec:
|
|
destination:
|
|
create: true
|
|
name: oauth-credentials
|
|
overwrite: true
|
|
hmacSecretData: true
|
|
mount: kv
|
|
path: kubernetes/namespace/arrstack/default/oauth-credentials
|
|
refreshAfter: 5m
|
|
type: kv-v2
|
|
vaultAuthRef: default
|