Skip to content

Repository files navigation

ArrGate

ArrGate is a Go terminal application for discovering Docker media stacks and safely adding SSO, private backend networking, recovery, backups, verification and drift checks. It protects browser routes while preserving native internal API access.

External Arr authentication is safe only after backend isolation is verified. Proxy SSO does not create application roles, and generic forward-auth may not work for media clients. Keep application APIs protected by native API credentials.

Quick start

go build ./cmd/arrgate
arrgate init --config arrgate.yaml
arrgate config validate --config arrgate.yaml
arrgate config render --config arrgate.yaml
arrgate discover --config arrgate.yaml
arrgate import --output arrgate.import.yaml
arrgate plan --config arrgate.yaml
arrgate preflight --config arrgate.yaml
arrgate apply --config arrgate.yaml --dry-run
arrgate verify --config arrgate.yaml
arrgate transactions list

For the complete Compose mutation path, start with examples/authentik-caddy-serrvarr.yaml. After reviewing its plan and replacing the Authentik placeholders, apply it with:

arrgate apply --config ./examples/authentik-caddy-serrvarr.yaml --non-interactive --approve

When proxy.compose_file is set, ArrGate validates a staged candidate with docker compose config, records backups in the transaction journal, removes published ports from protected applications, and recreates only the affected Caddy/Servarr services. --non-interactive deliberately requires --approve.

import is deliberately non-destructive: it emits disabled candidates only. Review the generated upstreams, replace the example DNS names, set the Authentik URL and policy, then explicitly enable applications.

preflight proves the safety prerequisite for external_auth: either a configured Compose transaction will remove protected published ports, or Docker discovery must confirm that every backend is already private. apply enforces the same gate and refuses to enable external authentication when that proof is missing.

Operational commands

printf '%s\n' "$AUTHENTIK_TOKEN" | arrgate secrets set authentik --stdin
arrgate secrets get keyring:arrgate/authentik
arrgate doctor --config arrgate.yaml
arrgate backup ./Caddyfile ./arrgate.yaml
arrgate export support-bundle --config arrgate.yaml
arrgate recovery enable --duration 15m
arrgate recovery extend --duration 15m

For live Authentik application management, configure the token reference plus the three existing flow UUIDs. ArrGate creates only deterministic arrgate-<installation>-<application> provider/application pairs and refuses to overwrite a resource that points at a different endpoint:

identity:
  provider: authentik
  mode: existing
  base_url: https://auth.home.example.com
  token_secret_ref: keyring:arrgate/authentik
  authentik:
    authentication_flow: <uuid>
    authorization_flow: <uuid>
    invalidation_flow: <uuid>

Support bundles exclude the OS keyring and redact identity-secret references. verify fails when a route accepts unauthenticated or spoofed identity-header requests; it does not pretend authenticated workflows or native API calls have passed without usable test credentials.

See architecture, security model, and the integration matrix. The initial implementation supports the safe foundation and Caddy/Auth-entik/Arr path; unsupported live adapters return clear errors instead of applying unsafe guesses.

About

No description, website, or topics provided.

Resources

Contributing

Security policy

Stars

7 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages