++ sarex-contour: kafka + rabbitmq

infrastructure/kafka/sarex-contour, infrastructure/rabbitmq/sarex-contour
(values по образцу yc-k8s-test, controller-only kafka KRaft, rabbitmq
1 реплика, local-path). Vault для них уже заведён отдельно (terraform
environments.sarex-contour.vault, kafka/rabbitmq policy+role+kv).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
ivan 2026-09-11 17:17:00 +05:00
parent 49342404c0
commit 0c882d76c2
5 changed files with 116 additions and 0 deletions

View File

@ -9,6 +9,8 @@ resources:
- ../../infrastructure/istio-pilot/sarex-contour - ../../infrastructure/istio-pilot/sarex-contour
- ../../infrastructure/istio-gateway/sarex-contour - ../../infrastructure/istio-gateway/sarex-contour
- ../../infrastructure/vault/sarex-contour - ../../infrastructure/vault/sarex-contour
- ../../infrastructure/kafka/sarex-contour
- ../../infrastructure/rabbitmq/sarex-contour
# apps # apps
- ../../apps/control-interface/sarex-contour - ../../apps/control-interface/sarex-contour

View File

@ -0,0 +1,60 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: kafka
namespace: kafka
spec:
interval: 5m
timeout: 10m
values:
global:
imagePullSecrets:
- regcred
defaultStorageClass: local-path
image:
pullSecrets:
- regcred
controller:
replicaCount: 1
automountServiceAccountToken: true
persistence:
size: 8Gi
storageClass: local-path
overrideConfiguration:
authorizer.class.name: org.apache.kafka.metadata.authorizer.StandardAuthorizer
allow.everyone.if.no.acl.found: true
super.users: User:controller_user;User:inter_broker_user
offsets.topic.replication.factor: 1
transaction.state.log.replication.factor: 1
transaction.state.log.min.isr: 1
default.replication.factor: 1
min.insync.replicas: 1
broker:
replicaCount: 0
automountServiceAccountToken: true
listeners:
client:
protocol: SASL_SSL
sslClientAuth: "none"
provisioning:
enabled: false
sasl:
managedExistingSecret:
enabled: false
existingSecret: ""
enabledMechanisms: PLAIN,SCRAM-SHA-512
interBrokerMechanism: PLAIN
controllerMechanism: PLAIN
client:
users: []
passwords: ""
tls:
type: PEM
vault:
enabled: true
role: kafka
authPath: auth/kubernetes
secretPath: secrets/data/kafka/bootstrap
clusterIdKey: clusterId
interBrokerPasswordKey: interBrokerPassword
controllerPasswordKey: controllerPassword

View File

@ -0,0 +1,6 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: kafka.yaml

View File

@ -0,0 +1,6 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: rabbitmq.yaml

View File

@ -0,0 +1,42 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: rabbitmq
namespace: rabbitmq
spec:
interval: 5m
timeout: 10m
values:
global:
security:
allowInsecureImages: true
virtualService: null
gateway: null
certificate: null
metrics:
serviceMonitor:
enabled: false
default:
enabled: false
perObject:
enabled: false
detailed:
enabled: false
extraServiceMonitors: []
replicaCount: 1
resources:
requests:
memory: 1Gi
persistence:
storageClass: local-path
size: 10Gi
auth:
securePassword: true
existingPasswordSecret: ""
vault:
enabled: true
role: rabbitmq
authPath: auth/kubernetes
secretPath: secrets/data/rabbitmq/auth
usernameKey: username
passwordKey: password