debug: temporarily route Jellyfin ingress through header-capture proxy
Some checks failed
validate / lint (push) Failing after 1s
Some checks failed
validate / lint (push) Failing after 1s
Adds a transparent nginx passthrough that logs auth-related request headers (Authorization, X-Emby-Authorization, X-Emby-Token, X-MediaBrowser-Token, User-Agent) to diagnose why the Filebar iOS app gets 400s on /Users/AuthenticateByName against Jellyfin 12.0. All traffic still reaches the real jellyfin Service unchanged. Revert the Ingress backend and remove jellyfin-header-debug.yaml once captured. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016EQrGkfXFae4PZG9QfPRf4
This commit is contained in:
parent
40f6d05c4b
commit
2c46ae33c9
82
manifests/media/jellyfin-header-debug.yaml
Normal file
82
manifests/media/jellyfin-header-debug.yaml
Normal file
@ -0,0 +1,82 @@
|
|||||||
|
# Apply: kubectl apply -f manifests/media/jellyfin-header-debug.yaml
|
||||||
|
# Delete: kubectl delete -f manifests/media/jellyfin-header-debug.yaml
|
||||||
|
# Description: TEMPORARY diagnostic proxy that transparently forwards to the
|
||||||
|
# real jellyfin Service while logging auth-related request headers to stdout.
|
||||||
|
# Used to capture what the Filebar iOS app sends on /Users/AuthenticateByName
|
||||||
|
# so we can see why Jellyfin 12.0 rejects it. Swap the jellyfin Ingress
|
||||||
|
# backend to jellyfin-debug-proxy to route traffic through this, capture
|
||||||
|
# logs, then swap back and delete this file/PR once done -- not meant to
|
||||||
|
# stay in the cluster long-term.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: jellyfin-debug-proxy-conf
|
||||||
|
namespace: jellyfin
|
||||||
|
data:
|
||||||
|
default.conf: |
|
||||||
|
map $http_upgrade $connection_upgrade {
|
||||||
|
default upgrade;
|
||||||
|
'' close;
|
||||||
|
}
|
||||||
|
log_format jf_debug '$time_iso8601 client=$remote_addr method=$request_method uri="$request_uri" '
|
||||||
|
'status=$status '
|
||||||
|
'user_agent="$http_user_agent" '
|
||||||
|
'authorization="$http_authorization" '
|
||||||
|
'x_emby_authorization="$http_x_emby_authorization" '
|
||||||
|
'x_emby_token="$http_x_emby_token" '
|
||||||
|
'x_mediabrowser_token="$http_x_mediabrowser_token"';
|
||||||
|
server {
|
||||||
|
listen 8080;
|
||||||
|
access_log /dev/stdout jf_debug;
|
||||||
|
location / {
|
||||||
|
proxy_pass http://jellyfin.jellyfin.svc.cluster.local:80;
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header X-Real-IP $remote_addr;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
|
proxy_set_header X-Forwarded-Proto $scheme;
|
||||||
|
proxy_set_header Upgrade $http_upgrade;
|
||||||
|
proxy_set_header Connection $connection_upgrade;
|
||||||
|
proxy_read_timeout 3600s;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
---
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: jellyfin-debug-proxy
|
||||||
|
namespace: jellyfin
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: jellyfin-debug-proxy
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: jellyfin-debug-proxy
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: nginx
|
||||||
|
image: nginx:1.27-alpine
|
||||||
|
ports:
|
||||||
|
- containerPort: 8080
|
||||||
|
volumeMounts:
|
||||||
|
- name: conf
|
||||||
|
mountPath: /etc/nginx/conf.d
|
||||||
|
volumes:
|
||||||
|
- name: conf
|
||||||
|
configMap:
|
||||||
|
name: jellyfin-debug-proxy-conf
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: jellyfin-debug-proxy
|
||||||
|
namespace: jellyfin
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: jellyfin-debug-proxy
|
||||||
|
ports:
|
||||||
|
- port: 80
|
||||||
|
targetPort: 8080
|
||||||
@ -169,6 +169,9 @@ spec:
|
|||||||
pathType: Prefix
|
pathType: Prefix
|
||||||
backend:
|
backend:
|
||||||
service:
|
service:
|
||||||
name: jellyfin
|
# TEMPORARY: routed through jellyfin-debug-proxy (see
|
||||||
|
# jellyfin-header-debug.yaml) to capture auth headers from
|
||||||
|
# the Filebar app. Revert to `jellyfin` once done.
|
||||||
|
name: jellyfin-debug-proxy
|
||||||
port:
|
port:
|
||||||
number: 80
|
number: 80
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user