control-interface: add admin-frontend (universal-chart) to base, route it in vad istio-config

New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.

Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.

infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
ivan 2026-10-02 15:34:54 +05:00
parent 0bd15c6ae5
commit 5564778337
3 changed files with 127 additions and 0 deletions

View File

@ -0,0 +1,113 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: admin-frontend
namespace: control-interface
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.7"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
admin-frontend:
enabled: true
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/admin-frontend:contour_9dc27b40
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: admin-frontend
replicaCount:
_default: 1
port:
_default: 80
resources:
requests:
cpu:
_default: 100m
memory:
_default: 100Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: admin-frontend-svc
type:
_default: ClusterIP
port:
_default: 8080
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411"
proxy.istio.io/config: |-
tracing:
sampling: 100
zipkin:
address: signoz-otel-collector-external.signoz.svc.cluster.local:9411
custom_tags:
k8s.pod.name:
environment:
name: POD_NAME
k8s.namespace.name:
environment:
name: POD_NAMESPACE
k8s.pod.ip:
environment:
name: INSTANCE_IP
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,4 +4,5 @@ kind: Kustomization
namespace: control-interface namespace: control-interface
resources: resources:
- helmrelease.yaml - helmrelease.yaml
- admin-frontend.yaml

View File

@ -399,6 +399,19 @@ spec:
rewrite: / rewrite: /
service: frontend-svc.control-interface.svc.cluster.local service: frontend-svc.control-interface.svc.cluster.local
port: 8080 port: 8080
admin-frontend:
name: admin-frontend-virt-service
namespace: default
hosts:
- sarex.vadroad.ru
gateways:
- default/platform-gateway
routes:
- path:
prefix: /admin-frontend/static/
rewrite: /
service: admin-frontend-svc.control-interface.svc.cluster.local
port: 8080
s3-proxy-media: s3-proxy-media:
name: s3-proxy-media-virt-service name: s3-proxy-media-virt-service
namespace: default namespace: default