From 4ced4d67facd38cc84cecf9bd9d846acf3a1bd6f Mon Sep 17 00:00:00 2001 From: Michael Thomson Date: Wed, 9 Oct 2024 14:09:06 -0400 Subject: [PATCH] radarr middleware Signed-off-by: Michael Thomson --- media/radarr/ingress.yaml | 2 +- traefik/radarr-middleware.yaml | 24 ++++++++++++++++++++++++ 2 files changed, 25 insertions(+), 1 deletion(-) create mode 100644 traefik/radarr-middleware.yaml diff --git a/media/radarr/ingress.yaml b/media/radarr/ingress.yaml index 90fd5c8..0234731 100644 --- a/media/radarr/ingress.yaml +++ b/media/radarr/ingress.yaml @@ -6,7 +6,7 @@ metadata: annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" - traefik.ingress.kubernetes.io/router.middlewares: authentik-ak-outpost-radarr@kubernetescrd + traefik.ingress.kubernetes.io/router.middlewares: authentik-radarr@kubernetescrd spec: rules: - host: radarr.michaelthomson.dev diff --git a/traefik/radarr-middleware.yaml b/traefik/radarr-middleware.yaml new file mode 100644 index 0000000..b6814c2 --- /dev/null +++ b/traefik/radarr-middleware.yaml @@ -0,0 +1,24 @@ +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: radarr + namespace: authentik +spec: + forwardAuth: + address: https://radarr.michaelthomson.dev/outpost.goauthentik.io/auth/traefik + trustForwardHeader: true + authResponseHeaders: + - X-authentik-username + - X-authentik-groups + - X-authentik-email + - X-authentik-name + - X-authentik-uid + - X-authentik-jwt + - X-authentik-meta-jwks + - X-authentik-meta-outpost + - X-authentik-meta-provider + - X-authentik-meta-app + - X-authentik-meta-version + - authorization + tls: + certSecret: letsencrypt-wildcard-cert-michaelthomson.dev