Decision. A request front-end
Alternative. Direct access to Sonarr and Radarr for everyone
Why. Users get a clean request flow; the automation apps keep their admin surface private.
Where the household requests films and shows; approvals flow into Radarr and Sonarr
Seerr is the request front-end: requests land as watched items in Sonarr and Radarr without anyone touching their UIs.
templates/seerr/seerr-rollout.yaml Seerr Rollout
{{- $projectName := .Values.global.projectName }}
{{- $imagePullSecretsName := .Values.global.imagePullSecretsName }}
{{- $configBasePath := .Values.global.configBasePath -}}
{{- $timeZone := .Values.global.timeZone -}}
{{- $userID := .Values.global.userID -}}
{{- with .Values.applications.seerr }}
apiVersion: argoproj.io/v1alpha1
kind: Rollout
metadata:
name: {{ .name }}
namespace: {{ $projectName }}
spec:
replicas: 1
strategy:
canary:
maxSurge: 0
maxUnavailable: 1
steps:
- setWeight: 100
selector:
matchLabels:
app: {{ .name }}
template:
metadata:
labels:
app: {{ .name }}
spec:
{{- include "media-systems.nodePlacement" $ | nindent 6 }}
serviceAccount: {{ $projectName }}-service-account
serviceAccountName: {{ $projectName }}-service-account
automountServiceAccountToken: true
containers:
- name: {{ .name }}
image: {{ .image }}
imagePullPolicy: IfNotPresent
ports:
- name: {{ .name | substr 0 9 }}-http
containerPort: {{ .ports.http }}
protocol: TCP
env:
- name: PGID
value: {{ $userID | quote }}
- name: PUID
value: {{ $userID | quote }}
- name: TZ
value: {{ $timeZone | quote }}
volumeMounts:
- name: {{ .name }}-config
mountPath: {{ .configMount }}
resources: {}
dnsPolicy: ClusterFirst
restartPolicy: Always
schedulerName: default-scheduler
volumes:
- name: {{ .name }}-config
hostPath:
path: {{ $configBasePath }}/{{ .name }}
type: DirectoryOrCreate
{{- end -}} Decision. A request front-end
Alternative. Direct access to Sonarr and Radarr for everyone
Why. Users get a clean request flow; the automation apps keep their admin surface private.