diff --git a/media/sonarr/ingress.yaml b/media/sonarr/ingress.yaml index e6f2a5d..25cf365 100644 --- a/media/sonarr/ingress.yaml +++ b/media/sonarr/ingress.yaml @@ -6,6 +6,7 @@ metadata: annotations: traefik.ingress.kubernetes.io/router.entrypoints: websecure traefik.ingress.kubernetes.io/router.tls: "true" + traefik.ingress.kubernetes.io/router.middlewares: authentik-sonarr@kubernetescrd spec: rules: - host: sonarr.michaelthomson.dev diff --git a/traefik/sonarr-middleware.yaml b/traefik/sonarr-middleware.yaml new file mode 100644 index 0000000..83b6fde --- /dev/null +++ b/traefik/sonarr-middleware.yaml @@ -0,0 +1,23 @@ +apiVersion: traefik.containo.us/v1alpha1 +kind: Middleware +metadata: + name: sonarr + namespace: authentik +spec: + forwardAuth: + address: https://sonarr.michaelthomson.dev:9000/outpost.goauthentik.io/auth/traefik + trustForwardHeader: true + authResponseHeaders: + - X-authentik-username + - X-authentik-groups + - X-authentik-email + - X-authentik-name + - X-authentik-uid + - X-authentik-jwt + - X-authentik-meta-jwks + - X-authentik-meta-outpost + - X-authentik-meta-provider + - X-authentik-meta-app + - X-authentik-meta-version + tls: + certSecret: letsencrypt-wildcard-cert-michaelthomson.dev