ArrGate is a Go terminal application for discovering Docker media stacks and safely adding SSO, private backend networking, recovery, backups, verification and drift checks. It protects browser routes while preserving native internal API access.
External Arr authentication is safe only after backend isolation is verified. Proxy SSO does not create application roles, and generic forward-auth may not work for media clients. Keep application APIs protected by native API credentials.
go build ./cmd/arrgate
arrgate init --config arrgate.yaml
arrgate config validate --config arrgate.yaml
arrgate config render --config arrgate.yaml
arrgate discover --config arrgate.yaml
arrgate import --output arrgate.import.yaml
arrgate plan --config arrgate.yaml
arrgate preflight --config arrgate.yaml
arrgate apply --config arrgate.yaml --dry-run
arrgate verify --config arrgate.yaml
arrgate transactions listFor the complete Compose mutation path, start with
examples/authentik-caddy-serrvarr.yaml.
After reviewing its plan and replacing the Authentik placeholders, apply it with:
arrgate apply --config ./examples/authentik-caddy-serrvarr.yaml --non-interactive --approveWhen proxy.compose_file is set, ArrGate validates a staged candidate with
docker compose config, records backups in the transaction journal, removes
published ports from protected applications, and recreates only the affected
Caddy/Servarr services. --non-interactive deliberately requires --approve.
import is deliberately non-destructive: it emits disabled candidates only. Review the generated upstreams, replace the example DNS names, set the Authentik URL and policy, then explicitly enable applications.
preflight proves the safety prerequisite for external_auth: either a configured
Compose transaction will remove protected published ports, or Docker discovery
must confirm that every backend is already private. apply enforces the same
gate and refuses to enable external authentication when that proof is missing.
printf '%s\n' "$AUTHENTIK_TOKEN" | arrgate secrets set authentik --stdin
arrgate secrets get keyring:arrgate/authentik
arrgate doctor --config arrgate.yaml
arrgate backup ./Caddyfile ./arrgate.yaml
arrgate export support-bundle --config arrgate.yaml
arrgate recovery enable --duration 15m
arrgate recovery extend --duration 15mFor live Authentik application management, configure the token reference plus the three existing flow UUIDs. ArrGate creates only deterministic arrgate-<installation>-<application> provider/application pairs and refuses to overwrite a resource that points at a different endpoint:
identity:
provider: authentik
mode: existing
base_url: https://auth.home.example.com
token_secret_ref: keyring:arrgate/authentik
authentik:
authentication_flow: <uuid>
authorization_flow: <uuid>
invalidation_flow: <uuid>Support bundles exclude the OS keyring and redact identity-secret references. verify fails when a route accepts unauthenticated or spoofed identity-header requests; it does not pretend authenticated workflows or native API calls have passed without usable test credentials.
See architecture, security model, and the integration matrix. The initial implementation supports the safe foundation and Caddy/Auth-entik/Arr path; unsupported live adapters return clear errors instead of applying unsafe guesses.