Add arrstack creds role and k8s auth for mediamark #141

Merged
benvin merged 1 commits from benvin/mediamark-arrstack-role into master 2026-08-30 09:40:27 +10:00
Member

Why

mediamark (kids-content marking UI, namespace mediamark) needs Sonarr/Radarr access to list series/movies and read metadata + artwork. It should get ephemeral virtual arrproxy keys from the arrstack secrets engine via arrproxy, not a copy of the static app API keys.

How

  • config/arrstack_secret_backend_role/arrstack/mediamark.yaml — role minting keys scoped to sonarr + radarr (no prowlarr), ttl: 60 / max_ttl: 86400, mirroring the existing per-app roles.
  • config/auth_kubernetes_role/k8s/au/syd1/mediamark.yaml — k8s auth role mediamark, bound to serviceaccount default in namespace mediamark, token_ttl/token_max_ttl 600, audience vault.
  • policies/arrstack/creds/mediamark.yamlread on arrstack/creds/mediamark, granted to k8s/au/syd1: [mediamark] only (deliberately not the shared default k8s role, which would expose the creds to every namespace).

Engine mount/config and the existing roles are untouched.

Note

The companion argocd-apps change consumes arrstack/creds/mediamark via a VaultDynamicSecret (response fields: token, id, apps, subject, expires_at).

GET/HEAD-only is not expressible today. arrstack_secret_backend_role carries apps/ttl/max_ttl only, and arrproxy scopes machine tokens by app — the GET/HEAD restriction on the cheeztv/kids tier is a grant on an OIDC group, not on a minted token. The role is scoped as tightly as the engine allows and the limitation is documented in the yaml; per-token method scoping needs a plugin + arrproxy feature.

## Why mediamark (kids-content marking UI, namespace `mediamark`) needs Sonarr/Radarr access to list series/movies and read metadata + artwork. It should get ephemeral virtual arrproxy keys from the arrstack secrets engine via arrproxy, not a copy of the static app API keys. ## How - `config/arrstack_secret_backend_role/arrstack/mediamark.yaml` — role minting keys scoped to `sonarr` + `radarr` (no prowlarr), `ttl: 60` / `max_ttl: 86400`, mirroring the existing per-app roles. - `config/auth_kubernetes_role/k8s/au/syd1/mediamark.yaml` — k8s auth role `mediamark`, bound to serviceaccount `default` in namespace `mediamark`, `token_ttl`/`token_max_ttl` 600, audience `vault`. - `policies/arrstack/creds/mediamark.yaml` — `read` on `arrstack/creds/mediamark`, granted to `k8s/au/syd1: [mediamark]` only (deliberately not the shared `default` k8s role, which would expose the creds to every namespace). Engine mount/config and the existing roles are untouched. ## Note The companion argocd-apps change consumes `arrstack/creds/mediamark` via a `VaultDynamicSecret` (response fields: `token`, `id`, `apps`, `subject`, `expires_at`). **GET/HEAD-only is not expressible today.** `arrstack_secret_backend_role` carries `apps`/`ttl`/`max_ttl` only, and arrproxy scopes machine tokens by app — the GET/HEAD restriction on the cheeztv/kids tier is a grant on an OIDC *group*, not on a minted token. The role is scoped as tightly as the engine allows and the limitation is documented in the yaml; per-token method scoping needs a plugin + arrproxy feature.
unkin-agent added 1 commit 2026-08-30 00:09:12 +10:00
Add arrstack creds role and k8s auth for mediamark
ci/woodpecker/pr/plan Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
94c8811251
mediamark should consume ephemeral virtual sonarr/radarr keys from the
arrstack engine instead of copies of the static app API keys.

- add arrstack role "mediamark" scoped to sonarr + radarr (60s ttl, 24h
  max_ttl, mirroring the existing per-app roles)
- add k8s/au/syd1 auth role "mediamark" bound to serviceaccount default in
  namespace mediamark
- grant read on arrstack/creds/mediamark to that role only
benvin merged commit 9fa51f401a into master 2026-08-30 09:40:27 +10:00
benvin deleted branch benvin/mediamark-arrstack-role 2026-08-30 09:40:27 +10:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/terraform-vault#141