f15d768227
Convert the three *arr apps from single-replica upstream LinuxServer/SQLite to our -unkin2 forks running active-active (replicas 3) on a shared CNPG Postgres cluster. - new apps/base/arrstack/postgres/: CNPG Cluster arrstack-postgres (3 instances, 3 managed login roles sonarr/radarr/prowlarr, throwaway initdb owner), per-app Database CRDs (<app>-main), cephrgw backup bucket + nightly ScheduledBackup, and 3 VaultStaticSecrets syncing the <app>-db role credentials. - per app: image -> docker-internal/<app>:v<base>-unkin2; replicas 3 + RollingUpdate; drop the apikey-init initContainer + PUID/PGID/TZ; run the binary directly with -nosingleinstancecheck; env from a new ConfigMap plus Postgres user/password and the API key from Secrets; /config PVC -> RWX cephfs-raid5-retain (shared).
25 lines
1.0 KiB
YAML
25 lines
1.0 KiB
YAML
---
|
|
# Non-secret env for the -unkin2 fork. The fork reads Servarr config from
|
|
# Prowlarr__<Section>__<Key> env (no config.xml edits, no s6/PUID). Postgres
|
|
# wiring points every replica at the same shared DB (arrstack-postgres-rw /
|
|
# prowlarr-main); Auth__Method=External defers UI auth to arrproxy/oauth2-proxy;
|
|
# Server__UrlBase keeps the /prowlarr prefix so arrproxy path-routing works;
|
|
# App__InstanceName is identical across replicas (shared session-cookie name).
|
|
# User/Password/ApiKey come from Secrets (see deployment.yaml), not here.
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: prowlarr-env
|
|
namespace: arrstack
|
|
data:
|
|
Prowlarr__Postgres__Host: arrstack-postgres-rw.arrstack.svc.cluster.local
|
|
Prowlarr__Postgres__Port: "5432"
|
|
Prowlarr__Postgres__MainDb: prowlarr-main
|
|
Prowlarr__Log__DbEnabled: "false"
|
|
Prowlarr__Auth__Method: External
|
|
Prowlarr__Auth__Required: DisabledForLocalAddresses
|
|
Prowlarr__App__InstanceName: Prowlarr
|
|
Prowlarr__Server__Port: "9696"
|
|
Prowlarr__Server__UrlBase: /prowlarr
|
|
Prowlarr__Update__Mechanism: External
|