++ uralkal apps

This commit is contained in:
Kochetkov S 2026-09-25 16:46:07 +03:00
parent e8ebed3689
commit 69c45fc7f1
11 changed files with 840 additions and 0 deletions

View File

@ -10,3 +10,7 @@ resources:
- ../../infrastructure/istio-gateway/uralkal
- ../../infrastructure/rabbitmq/uralkal
- ../../infrastructure/kafka/uralkal
- ../../infrastructure/zitadel/uralkal
- ../../infrastructure/camunda/uralkal
- ../../infrastructure/superset/uralkal
- ../../infrastructure/trino/uralkal

View File

@ -0,0 +1,322 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: camunda
namespace: camunda
spec:
dependsOn: []
interval: 5m
timeout: 15m
postRenderers:
- kustomize:
patches:
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: StatefulSet
namespace: camunda
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: batch
version: v1
kind: Job
namespace: camunda
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
name: camunda-connectors
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
name: camunda-identity
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
name: camunda-operate
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
name: camunda-optimize
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
name: camunda-tasklist
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: Deployment
namespace: camunda
name: camunda-zeebe-gateway
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- target:
group: apps
version: v1
kind: StatefulSet
namespace: camunda
name: camunda-zeebe
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
values:
global:
vault:
enabled: true
role: camunda
authPath: auth/kubernetes
secrets:
postgresql:
path: secrets/data/camunda/postgresql
keys:
password: password
postgresPassword: postgres-password
image:
pullSecrets:
- name: regcred
identity:
auth:
publicIssuerUrl: "https://camunda-keycloak.sarex.local.uralkali.com/auth/realms/camunda-platform"
identity:
redirectUrl: "https://camunda-identity.sarex.local.uralkali.com"
operate:
redirectUrl: "https://camunda.sarex.local.uralkali.com"
tasklist:
redirectUrl: "https://camunda-tasklist.sarex.local.uralkali.com"
optimize:
redirectUrl: "https://camunda-optimize.sarex.local.uralkali.com"
identityPostgresql:
enabled: false
auth:
usePasswordFiles: true
primary:
automountServiceAccountToken: true
persistence:
size: 10Gi
storageClass: local-path
identityKeycloak:
externalDatabase:
host: 10.133.0.249
port: 5432
user: bn_keycloak
database: bitnami_keycloak
password: ""
existingSecret: ""
existingSecretPasswordKey: password
postgresql:
enabled: false
auth:
usePasswordFiles: true
primary:
automountServiceAccountToken: true
persistence:
size: 10Gi
storageClass: local-path
vaultEnv:
enabled: true
role: camunda
authPath: auth/kubernetes
envFiles:
KEYCLOAK_ADMIN_PASSWORD:
path: secrets/data/camunda/keycloak-admin
key: admin-password
KEYCLOAK_PASSWORD:
path: secrets/data/camunda/keycloak-admin
key: admin-password
KEYCLOAK_DATABASE_PASSWORD:
path: secrets/data/camunda/postgresql
key: keycloak-password
global:
storageClass: local-path
tolerations: []
elasticsearch:
sysctlImage:
registry: cr.yandex
repository: crp3ccidau046kdj8g9q/contour/camunda/os-shell
tag: 12-debian-12-r32
pullSecrets:
- regcred
master:
replicaCount: 1
podAntiAffinityPreset: soft
persistence:
size: 10Gi
storageClass: local-path
tolerations: []
metrics:
enabled: false
serviceMonitor:
enabled: false
prometheusRule:
enabled: false
tolerations: []
camundaCanary:
enabled: false
prometheusServiceMonitor:
enabled: false
console:
image:
pullSecrets:
- name: regcred
tolerations: []
zeebe:
clusterSize: "1"
partitionCount: "1"
replicationFactor: "1"
pvcStorageClassName: local-path
image:
pullSecrets:
- name: regcred
tolerations: []
zeebeGateway:
replicas: 1
image:
pullSecrets:
- name: regcred
tolerations: []
identity:
fullURL: "https://camunda-identity.sarex.local.uralkali.com"
externalDatabase:
enabled: true
host: 10.133.0.249
port: 5432
username: identity
database: identity
password: ""
existingSecret: ""
existingSecretPasswordKey: password
image:
pullSecrets:
- name: regcred
tolerations: []
operate:
image:
pullSecrets:
- name: regcred
serviceAccount:
automountServiceAccountToken: true
tolerations: []
tasklist:
image:
pullSecrets:
- name: regcred
serviceAccount:
automountServiceAccountToken: true
tolerations: []
optimize:
image:
pullSecrets:
- name: regcred
serviceAccount:
automountServiceAccountToken: true
tolerations: []
executionIdentity:
image:
pullSecrets:
- name: regcred
tolerations: []
webModeler:
image:
pullSecrets:
- name: regcred
restapi:
tolerations: []
webapp:
tolerations: []
websockets:
tolerations: []
connectors:
image:
pullSecrets:
- name: regcred
serviceAccount:
automountServiceAccountToken: true
tolerations: []

View File

@ -0,0 +1,6 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: camunda.yaml

View File

@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: superset.yaml
- path: superset-namespace.yaml

View File

@ -0,0 +1,6 @@
apiVersion: v1
kind: Namespace
metadata:
name: superset
labels:
istio-injection: disabled

View File

@ -0,0 +1,142 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: superset
namespace: superset
spec:
interval: 5m
timeout: 20m
chart:
spec:
chart: superset-contour
version: "0.13.4"
values:
global:
imagePullSecrets:
- regcred
fullnameOverride: superset
serviceAccount:
create: true
serviceAccountName: superset
imagePullSecrets:
- name: regcred
image:
repository: cr.yandex/crp3ccidau046kdj8g9q/contour/superset/superset
tag: 4.1.1
initImage:
repository: cr.yandex/crp3ccidau046kdj8g9q/contour/superset/superset
tag: dockerize
vault:
enabled: true
role: superset
authPath: auth/kubernetes
kvVersion: 2
secrets:
- env: SUPERSET_SECRET_KEY
path: secrets/data/vault/apps/superset
key: SUPERSET_SECRET_KEY
- env: DB_PASS
path: secrets/data/apps/superset/postgres
key: password
- env: JWT_SECRET
path: secrets/data/vault/apps/superset
key: JWT_SECRET
stronghold:
enabled: false
extraEnv:
GUNICORN_TIMEOUT: "300"
SERVER_WORKER_AMOUNT: "4"
BABEL_DEFAULT_LOCALE: ru
extraEnvRaw:
- name: ENABLE_PROXY_FIX
value: "true"
supersetNode:
connections:
redis_host: superset-redis-headless
redis_port: "6379"
redis_user: ""
redis_cache_db: "1"
redis_celery_db: "0"
db_host: 10.133.0.249
db_port: "5432"
db_user: superset
db_name: superset
resources:
requests:
cpu: 500m
memory: 1Gi
limits:
memory: 2Gi
supersetWorker:
resources:
requests:
cpu: 500m
memory: 1Gi
limits:
memory: 2Gi
init:
loadExamples: false
postgresql:
enabled: false
redis:
enabled: true
image:
registry: cr.yandex
repository: crp3ccidau046kdj8g9q/contour/superset/redis
tag: 7.0.10-debian-11-r4
architecture: standalone
auth:
enabled: false
existingSecret: ""
existingSecretKey: ""
password: ""
master:
persistence:
enabled: false
configOverrides:
feature_flags: |
FEATURE_FLAGS = {
"EMBEDDED_SUPERSET": True,
"ENABLE_TEMPLATE_PROCESSING": True,
}
GUEST_ROLE_NAME = "Gamma"
GUEST_TOKEN_JWT_AUDIENCE = "guest"
GUEST_TOKEN_JWT_SECRET = os.getenv("JWT_SECRET")
GUEST_TOKEN_JWT_EXP_SECONDS = 3600
iframe_config: |
TALISMAN_ENABLED = True
TALISMAN_CONFIG = {
"frame_options": None,
"content_security_policy": {
"base-uri": ["'self'"],
"default-src": ["'self'"],
"img-src": ["'self'", "blob:", "data:", "https://apachesuperset.gateway.scarf.sh", "https://static.scarf.sh/"],
"worker-src": ["'self'", "blob:"],
"connect-src": ["'self'", "https://api.mapbox.com", "https://events.mapbox.com"],
"object-src": ["'none'"],
"style-src": ["'self'", "'unsafe-inline'"],
"script-src": ["'self'", "'strict-dynamic'"],
"frame-ancestors": ["'self'", "https://sarex.local.uralkali.com", "https://*.sarex.local.uralkali.com", "https://bi.sarex.local.uralkali.com"],
},
"content_security_policy_nonce_in": ["script-src"],
}
X_FRAME_OPTIONS = None
HTTP_HEADERS = {
"Content-Security-Policy": "frame-ancestors 'self' https://sarex.local.uralkali.com https://*.sarex.local.uralkali.com https://bi.sarex.local.uralkali.com",
}
extend_timeout: |
SQLLAB_ASYNC_TIME_LIMIT_SEC = 300
SUPERSET_WEBSERVER_TIMEOUT = 300
SQLLAB_TIMEOUT = 600
set_locale: |
BABEL_DEFAULT_LOCALE = "ru"
enable_oauth: ""
extraConfigs:
import_datasources.yaml: |
databases:
- database_name: trino
sqlalchemy_uri: trino://superset@trino.trino.svc.cluster.local:8080
expose_in_sqllab: true
allow_ctas: true
allow_cvas: true
allow_dml: false

View File

@ -0,0 +1,7 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: trino.yaml
- path: trino-namespace.yaml

View File

@ -0,0 +1,6 @@
apiVersion: v1
kind: Namespace
metadata:
name: trino
labels:
istio-injection: disabled

View File

@ -0,0 +1,180 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: trino
namespace: trino
spec:
interval: 5m
timeout: 20m
chart:
spec:
chart: trino-contour
version: "0.33.1"
postRenderers:
- kustomize:
patches:
- target:
group: apps
version: v1
kind: Deployment
name: trino-worker
patch: |
- op: replace
path: /spec/template/spec/nodeSelector
value:
kubernetes.io/hostname: proc1
- op: add
path: /spec/template/spec/tolerations
value:
- key: dedicated.processing
operator: Equal
value: processing
effect: NoExecute
values:
nameOverride: trino
coordinatorNameOverride: trino-coordinator
workerNameOverride: trino-worker
imagePullSecrets:
- name: regcred
image:
registry: cr.yandex
repository: crp3ccidau046kdj8g9q/contour/trino/trino
tag: "432"
serviceAccount:
create: true
name: trino
gateway:
enabled: false
virtualService:
enabled: false
vault:
enabled: true
role: trino
authPath: auth/kubernetes
kvVersion: 2
secrets:
- env: TRINO_POSTGRES_USER
path: secrets/data/apps/trino/postgres
key: username
- env: TRINO_POSTGRES_PASSWORD
path: secrets/data/apps/trino/postgres
key: password
- env: TRINO_INTERNAL_SHARED_SECRET
path: secrets/data/vault/apps/trino
key: TRINO_INTERNAL_SHARED_SECRET
stronghold:
enabled: false
server:
workers: 1
log:
trino:
level: INFO
config:
authenticationType: ""
query:
maxMemory: 20GB
autoscaling:
enabled: false
additionalLogProperties: []
auth:
passwordAuthSecret: ""
env:
- name: TRINO_POSTGRES_HOST
value: "10.133.0.249"
- name: TRINO_POSTGRES_PORT
value: "5432"
envFrom: []
catalogs:
sarex_db: null
resources_db: null
django_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/django_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
flows_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/flows_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
issues_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/issues_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
workspaces_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/workspaces_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
pm_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/pm_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
eav_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/eav_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
inspections_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/inspections_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
documentations_db: |
connector.name=postgresql
connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/documentations_db?sslmode=disable
connection-user=${ENV:TRINO_POSTGRES_USER}
connection-password=${ENV:TRINO_POSTGRES_PASSWORD}
postgresql.array-mapping=AS_JSON
clickhouse_db: |
connector.name=tpch
tpch.splits-per-node=4
hive: |
connector.name=tpch
tpch.splits-per-node=4
coordinator:
jvm:
maxHeapSize: 6G
config:
memory:
heapHeadroomPerNode: 1GB
query:
maxMemoryPerNode: 4GB
resources:
requests:
cpu: 500m
memory: 6Gi
limits:
memory: 8Gi
nodeSelector: null
tolerations: []
worker:
jvm:
maxHeapSize: 24G
config:
memory:
heapHeadroomPerNode: 4GB
query:
maxMemoryPerNode: 20GB
resources:
requests:
cpu: 500m
memory: 24Gi
limits:
memory: 32Gi
nodeSelector:
kubernetes.io/hostname: proc1
tolerations:
- key: dedicated.processing
operator: Equal
value: processing
effect: NoExecute

View File

@ -0,0 +1,6 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: zitadel.yaml

View File

@ -0,0 +1,154 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: zitadel
namespace: zitadel
spec:
interval: 5m
timeout: 10m
postRenderers:
- kustomize:
patches:
- target:
group: apps
version: v1
kind: Deployment
name: zitadel-idp-contour
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- op: replace
path: /spec/template/metadata/annotations/vault.hashicorp.com~1agent-inject-template-zitadel-vault-config.yaml
value: |-
{{- with secret "secrets/data/zitadel/postgresql" -}}
Database:
postgres:
User:
Password: |-
{{ index .Data.data "password" }}
Admin:
Password: |-
{{ index .Data.data "password" }}
FirstInstance:
Org:
Human:
Password: |-
{{ index .Data.data "humanPassword" }}
{{- end -}}
- target:
group: batch
version: v1
kind: Job
name: zitadel-idp-contour-init
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- op: replace
path: /spec/template/metadata/annotations/vault.hashicorp.com~1agent-inject-template-zitadel-vault-config.yaml
value: |-
{{- with secret "secrets/data/zitadel/postgresql" -}}
Database:
postgres:
User:
Password: |-
{{ index .Data.data "password" }}
Admin:
Password: |-
{{ index .Data.data "password" }}
FirstInstance:
Org:
Human:
Password: |-
{{ index .Data.data "humanPassword" }}
{{- end -}}
- target:
group: batch
version: v1
kind: Job
name: zitadel-idp-contour-setup
patch: |-
- op: add
path: /spec/template/spec/nodeSelector
value:
dedicated: generic
- op: add
path: /spec/template/spec/tolerations
value: []
- op: replace
path: /spec/template/metadata/annotations/vault.hashicorp.com~1agent-inject-template-zitadel-vault-config.yaml
value: |-
{{- with secret "secrets/data/zitadel/postgresql" -}}
Database:
postgres:
User:
Password: |-
{{ index .Data.data "password" }}
Admin:
Password: |-
{{ index .Data.data "password" }}
FirstInstance:
Org:
Human:
Password: |-
{{ index .Data.data "humanPassword" }}
{{- end -}}
values:
zitadel:
configmapConfig:
ExternalDomain: login.sarex.local.uralkali.com
ExternalSecure: true
debug:
enabled: false
postgresqlSecret:
create: false
vault:
enabled: true
role: zitadel
authPath: auth/kubernetes
secretPath: secrets/data/zitadel/postgresql
secretKey: password
kvVersion: 2
fileName: zitadel-vault-config.yaml
serviceAccount:
create: true
name: zitadel
replicaCount: 1
pdb:
enabled: false
env:
- name: ZITADEL_DEFAULTINSTANCE_FEATURES_LOGINV2_REQUIRED
value: "false"
- name: ZITADEL_SYSTEMDEFAULTS_PASSWORDHASHER_VERIFIERS
value: "bcrypt,pbkdf2"
- name: ZITADEL_MACHINE_IDENTIFICATION_HOSTNAME_ENABLED
value: "true"
- name: ZITADEL_DATABASE_POSTGRES_HOST
value: "10.133.0.249"
- name: ZITADEL_DATABASE_POSTGRES_PORT
value: "5432"
- name: ZITADEL_DATABASE_POSTGRES_USER_USERNAME
value: "zitadel"
- name: ZITADEL_DATABASE_POSTGRES_ADMIN_EXISTINGDATABASE
value: "zitadel"
- name: ZITADEL_DATABASE_POSTGRES_ADMIN_USERNAME
value: "zitadel"
- name: ZITADEL_DATABASE_POSTGRES_DATABASE
value: "zitadel"
- name: ZITADEL_DATABASE_POSTGRES_USER_SSL_MODE
value: "disable"
- name: ZITADEL_DATABASE_POSTGRES_ADMIN_SSL_MODE
value: "disable"
- name: ZITADEL_DEFAULTINSTANCE_ORG_HUMAN_USERNAME
value: "zitadel-admin"
- name: ZITADEL_DEFAULTINSTANCE_ORG_NAME
value: "Sarex"