From 69c45fc7f1d90d2cf3308acd6b7cc0c47bc4e96e Mon Sep 17 00:00:00 2001 From: Kochetkov S Date: Fri, 25 Sep 2026 16:46:07 +0300 Subject: [PATCH] ++ uralkal apps --- clusters/uralkal/kustomization.yaml | 4 + infrastructure/camunda/uralkal/camunda.yaml | 322 ++++++++++++++++++ .../camunda/uralkal/kustomization.yaml | 6 + .../superset/uralkal/kustomization.yaml | 7 + .../superset/uralkal/superset-namespace.yaml | 6 + infrastructure/superset/uralkal/superset.yaml | 142 ++++++++ .../trino/uralkal/kustomization.yaml | 7 + .../trino/uralkal/trino-namespace.yaml | 6 + infrastructure/trino/uralkal/trino.yaml | 180 ++++++++++ .../zitadel/uralkal/kustomization.yaml | 6 + infrastructure/zitadel/uralkal/zitadel.yaml | 154 +++++++++ 11 files changed, 840 insertions(+) create mode 100644 infrastructure/camunda/uralkal/camunda.yaml create mode 100644 infrastructure/camunda/uralkal/kustomization.yaml create mode 100644 infrastructure/superset/uralkal/kustomization.yaml create mode 100644 infrastructure/superset/uralkal/superset-namespace.yaml create mode 100644 infrastructure/superset/uralkal/superset.yaml create mode 100644 infrastructure/trino/uralkal/kustomization.yaml create mode 100644 infrastructure/trino/uralkal/trino-namespace.yaml create mode 100644 infrastructure/trino/uralkal/trino.yaml create mode 100644 infrastructure/zitadel/uralkal/kustomization.yaml create mode 100644 infrastructure/zitadel/uralkal/zitadel.yaml diff --git a/clusters/uralkal/kustomization.yaml b/clusters/uralkal/kustomization.yaml index e50900e..ba68ba7 100644 --- a/clusters/uralkal/kustomization.yaml +++ b/clusters/uralkal/kustomization.yaml @@ -10,3 +10,7 @@ resources: - ../../infrastructure/istio-gateway/uralkal - ../../infrastructure/rabbitmq/uralkal - ../../infrastructure/kafka/uralkal + - ../../infrastructure/zitadel/uralkal + - ../../infrastructure/camunda/uralkal + - ../../infrastructure/superset/uralkal + - ../../infrastructure/trino/uralkal diff --git a/infrastructure/camunda/uralkal/camunda.yaml b/infrastructure/camunda/uralkal/camunda.yaml new file mode 100644 index 0000000..f647a56 --- /dev/null +++ b/infrastructure/camunda/uralkal/camunda.yaml @@ -0,0 +1,322 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: camunda + namespace: camunda +spec: + dependsOn: [] + interval: 5m + timeout: 15m + postRenderers: + - kustomize: + patches: + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: StatefulSet + namespace: camunda + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: batch + version: v1 + kind: Job + namespace: camunda + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + name: camunda-connectors + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + name: camunda-identity + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + name: camunda-operate + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + name: camunda-optimize + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + name: camunda-tasklist + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: Deployment + namespace: camunda + name: camunda-zeebe-gateway + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - target: + group: apps + version: v1 + kind: StatefulSet + namespace: camunda + name: camunda-zeebe + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + values: + global: + vault: + enabled: true + role: camunda + authPath: auth/kubernetes + secrets: + postgresql: + path: secrets/data/camunda/postgresql + keys: + password: password + postgresPassword: postgres-password + image: + pullSecrets: + - name: regcred + identity: + auth: + publicIssuerUrl: "https://camunda-keycloak.sarex.local.uralkali.com/auth/realms/camunda-platform" + identity: + redirectUrl: "https://camunda-identity.sarex.local.uralkali.com" + operate: + redirectUrl: "https://camunda.sarex.local.uralkali.com" + tasklist: + redirectUrl: "https://camunda-tasklist.sarex.local.uralkali.com" + optimize: + redirectUrl: "https://camunda-optimize.sarex.local.uralkali.com" + identityPostgresql: + enabled: false + auth: + usePasswordFiles: true + primary: + automountServiceAccountToken: true + persistence: + size: 10Gi + storageClass: local-path + identityKeycloak: + externalDatabase: + host: 10.133.0.249 + port: 5432 + user: bn_keycloak + database: bitnami_keycloak + password: "" + existingSecret: "" + existingSecretPasswordKey: password + postgresql: + enabled: false + auth: + usePasswordFiles: true + primary: + automountServiceAccountToken: true + persistence: + size: 10Gi + storageClass: local-path + vaultEnv: + enabled: true + role: camunda + authPath: auth/kubernetes + envFiles: + KEYCLOAK_ADMIN_PASSWORD: + path: secrets/data/camunda/keycloak-admin + key: admin-password + KEYCLOAK_PASSWORD: + path: secrets/data/camunda/keycloak-admin + key: admin-password + KEYCLOAK_DATABASE_PASSWORD: + path: secrets/data/camunda/postgresql + key: keycloak-password + global: + storageClass: local-path + tolerations: [] + elasticsearch: + sysctlImage: + registry: cr.yandex + repository: crp3ccidau046kdj8g9q/contour/camunda/os-shell + tag: 12-debian-12-r32 + pullSecrets: + - regcred + master: + replicaCount: 1 + podAntiAffinityPreset: soft + persistence: + size: 10Gi + storageClass: local-path + tolerations: [] + metrics: + enabled: false + serviceMonitor: + enabled: false + prometheusRule: + enabled: false + tolerations: [] + camundaCanary: + enabled: false + prometheusServiceMonitor: + enabled: false + console: + image: + pullSecrets: + - name: regcred + tolerations: [] + zeebe: + clusterSize: "1" + partitionCount: "1" + replicationFactor: "1" + pvcStorageClassName: local-path + image: + pullSecrets: + - name: regcred + tolerations: [] + zeebeGateway: + replicas: 1 + image: + pullSecrets: + - name: regcred + tolerations: [] + identity: + fullURL: "https://camunda-identity.sarex.local.uralkali.com" + externalDatabase: + enabled: true + host: 10.133.0.249 + port: 5432 + username: identity + database: identity + password: "" + existingSecret: "" + existingSecretPasswordKey: password + image: + pullSecrets: + - name: regcred + tolerations: [] + operate: + image: + pullSecrets: + - name: regcred + serviceAccount: + automountServiceAccountToken: true + tolerations: [] + tasklist: + image: + pullSecrets: + - name: regcred + serviceAccount: + automountServiceAccountToken: true + tolerations: [] + optimize: + image: + pullSecrets: + - name: regcred + serviceAccount: + automountServiceAccountToken: true + tolerations: [] + executionIdentity: + image: + pullSecrets: + - name: regcred + tolerations: [] + webModeler: + image: + pullSecrets: + - name: regcred + restapi: + tolerations: [] + webapp: + tolerations: [] + websockets: + tolerations: [] + connectors: + image: + pullSecrets: + - name: regcred + serviceAccount: + automountServiceAccountToken: true + tolerations: [] diff --git a/infrastructure/camunda/uralkal/kustomization.yaml b/infrastructure/camunda/uralkal/kustomization.yaml new file mode 100644 index 0000000..0c26313 --- /dev/null +++ b/infrastructure/camunda/uralkal/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: camunda.yaml diff --git a/infrastructure/superset/uralkal/kustomization.yaml b/infrastructure/superset/uralkal/kustomization.yaml new file mode 100644 index 0000000..d27edd1 --- /dev/null +++ b/infrastructure/superset/uralkal/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: superset.yaml + - path: superset-namespace.yaml diff --git a/infrastructure/superset/uralkal/superset-namespace.yaml b/infrastructure/superset/uralkal/superset-namespace.yaml new file mode 100644 index 0000000..464d5e9 --- /dev/null +++ b/infrastructure/superset/uralkal/superset-namespace.yaml @@ -0,0 +1,6 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: superset + labels: + istio-injection: disabled diff --git a/infrastructure/superset/uralkal/superset.yaml b/infrastructure/superset/uralkal/superset.yaml new file mode 100644 index 0000000..2ac9dbd --- /dev/null +++ b/infrastructure/superset/uralkal/superset.yaml @@ -0,0 +1,142 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: superset + namespace: superset +spec: + interval: 5m + timeout: 20m + chart: + spec: + chart: superset-contour + version: "0.13.4" + values: + global: + imagePullSecrets: + - regcred + fullnameOverride: superset + serviceAccount: + create: true + serviceAccountName: superset + imagePullSecrets: + - name: regcred + image: + repository: cr.yandex/crp3ccidau046kdj8g9q/contour/superset/superset + tag: 4.1.1 + initImage: + repository: cr.yandex/crp3ccidau046kdj8g9q/contour/superset/superset + tag: dockerize + vault: + enabled: true + role: superset + authPath: auth/kubernetes + kvVersion: 2 + secrets: + - env: SUPERSET_SECRET_KEY + path: secrets/data/vault/apps/superset + key: SUPERSET_SECRET_KEY + - env: DB_PASS + path: secrets/data/apps/superset/postgres + key: password + - env: JWT_SECRET + path: secrets/data/vault/apps/superset + key: JWT_SECRET + stronghold: + enabled: false + extraEnv: + GUNICORN_TIMEOUT: "300" + SERVER_WORKER_AMOUNT: "4" + BABEL_DEFAULT_LOCALE: ru + extraEnvRaw: + - name: ENABLE_PROXY_FIX + value: "true" + supersetNode: + connections: + redis_host: superset-redis-headless + redis_port: "6379" + redis_user: "" + redis_cache_db: "1" + redis_celery_db: "0" + db_host: 10.133.0.249 + db_port: "5432" + db_user: superset + db_name: superset + resources: + requests: + cpu: 500m + memory: 1Gi + limits: + memory: 2Gi + supersetWorker: + resources: + requests: + cpu: 500m + memory: 1Gi + limits: + memory: 2Gi + init: + loadExamples: false + postgresql: + enabled: false + redis: + enabled: true + image: + registry: cr.yandex + repository: crp3ccidau046kdj8g9q/contour/superset/redis + tag: 7.0.10-debian-11-r4 + architecture: standalone + auth: + enabled: false + existingSecret: "" + existingSecretKey: "" + password: "" + master: + persistence: + enabled: false + configOverrides: + feature_flags: | + FEATURE_FLAGS = { + "EMBEDDED_SUPERSET": True, + "ENABLE_TEMPLATE_PROCESSING": True, + } + GUEST_ROLE_NAME = "Gamma" + GUEST_TOKEN_JWT_AUDIENCE = "guest" + GUEST_TOKEN_JWT_SECRET = os.getenv("JWT_SECRET") + GUEST_TOKEN_JWT_EXP_SECONDS = 3600 + iframe_config: | + TALISMAN_ENABLED = True + TALISMAN_CONFIG = { + "frame_options": None, + "content_security_policy": { + "base-uri": ["'self'"], + "default-src": ["'self'"], + "img-src": ["'self'", "blob:", "data:", "https://apachesuperset.gateway.scarf.sh", "https://static.scarf.sh/"], + "worker-src": ["'self'", "blob:"], + "connect-src": ["'self'", "https://api.mapbox.com", "https://events.mapbox.com"], + "object-src": ["'none'"], + "style-src": ["'self'", "'unsafe-inline'"], + "script-src": ["'self'", "'strict-dynamic'"], + "frame-ancestors": ["'self'", "https://sarex.local.uralkali.com", "https://*.sarex.local.uralkali.com", "https://bi.sarex.local.uralkali.com"], + }, + "content_security_policy_nonce_in": ["script-src"], + } + X_FRAME_OPTIONS = None + HTTP_HEADERS = { + "Content-Security-Policy": "frame-ancestors 'self' https://sarex.local.uralkali.com https://*.sarex.local.uralkali.com https://bi.sarex.local.uralkali.com", + } + extend_timeout: | + SQLLAB_ASYNC_TIME_LIMIT_SEC = 300 + SUPERSET_WEBSERVER_TIMEOUT = 300 + SQLLAB_TIMEOUT = 600 + set_locale: | + BABEL_DEFAULT_LOCALE = "ru" + enable_oauth: "" + extraConfigs: + import_datasources.yaml: | + databases: + - database_name: trino + sqlalchemy_uri: trino://superset@trino.trino.svc.cluster.local:8080 + expose_in_sqllab: true + allow_ctas: true + allow_cvas: true + allow_dml: false diff --git a/infrastructure/trino/uralkal/kustomization.yaml b/infrastructure/trino/uralkal/kustomization.yaml new file mode 100644 index 0000000..d99c091 --- /dev/null +++ b/infrastructure/trino/uralkal/kustomization.yaml @@ -0,0 +1,7 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: trino.yaml + - path: trino-namespace.yaml diff --git a/infrastructure/trino/uralkal/trino-namespace.yaml b/infrastructure/trino/uralkal/trino-namespace.yaml new file mode 100644 index 0000000..5584d59 --- /dev/null +++ b/infrastructure/trino/uralkal/trino-namespace.yaml @@ -0,0 +1,6 @@ +apiVersion: v1 +kind: Namespace +metadata: + name: trino + labels: + istio-injection: disabled diff --git a/infrastructure/trino/uralkal/trino.yaml b/infrastructure/trino/uralkal/trino.yaml new file mode 100644 index 0000000..bc92d79 --- /dev/null +++ b/infrastructure/trino/uralkal/trino.yaml @@ -0,0 +1,180 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: trino + namespace: trino +spec: + interval: 5m + timeout: 20m + chart: + spec: + chart: trino-contour + version: "0.33.1" + postRenderers: + - kustomize: + patches: + - target: + group: apps + version: v1 + kind: Deployment + name: trino-worker + patch: | + - op: replace + path: /spec/template/spec/nodeSelector + value: + kubernetes.io/hostname: proc1 + - op: add + path: /spec/template/spec/tolerations + value: + - key: dedicated.processing + operator: Equal + value: processing + effect: NoExecute + values: + nameOverride: trino + coordinatorNameOverride: trino-coordinator + workerNameOverride: trino-worker + imagePullSecrets: + - name: regcred + image: + registry: cr.yandex + repository: crp3ccidau046kdj8g9q/contour/trino/trino + tag: "432" + serviceAccount: + create: true + name: trino + gateway: + enabled: false + virtualService: + enabled: false + vault: + enabled: true + role: trino + authPath: auth/kubernetes + kvVersion: 2 + secrets: + - env: TRINO_POSTGRES_USER + path: secrets/data/apps/trino/postgres + key: username + - env: TRINO_POSTGRES_PASSWORD + path: secrets/data/apps/trino/postgres + key: password + - env: TRINO_INTERNAL_SHARED_SECRET + path: secrets/data/vault/apps/trino + key: TRINO_INTERNAL_SHARED_SECRET + stronghold: + enabled: false + server: + workers: 1 + log: + trino: + level: INFO + config: + authenticationType: "" + query: + maxMemory: 20GB + autoscaling: + enabled: false + additionalLogProperties: [] + auth: + passwordAuthSecret: "" + env: + - name: TRINO_POSTGRES_HOST + value: "10.133.0.249" + - name: TRINO_POSTGRES_PORT + value: "5432" + envFrom: [] + catalogs: + sarex_db: null + resources_db: null + django_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/django_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + flows_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/flows_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + issues_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/issues_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + workspaces_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/workspaces_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + pm_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/pm_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + eav_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/eav_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + inspections_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/inspections_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + documentations_db: | + connector.name=postgresql + connection-url=jdbc:postgresql://${ENV:TRINO_POSTGRES_HOST}:${ENV:TRINO_POSTGRES_PORT}/documentations_db?sslmode=disable + connection-user=${ENV:TRINO_POSTGRES_USER} + connection-password=${ENV:TRINO_POSTGRES_PASSWORD} + postgresql.array-mapping=AS_JSON + clickhouse_db: | + connector.name=tpch + tpch.splits-per-node=4 + hive: | + connector.name=tpch + tpch.splits-per-node=4 + coordinator: + jvm: + maxHeapSize: 6G + config: + memory: + heapHeadroomPerNode: 1GB + query: + maxMemoryPerNode: 4GB + resources: + requests: + cpu: 500m + memory: 6Gi + limits: + memory: 8Gi + nodeSelector: null + tolerations: [] + worker: + jvm: + maxHeapSize: 24G + config: + memory: + heapHeadroomPerNode: 4GB + query: + maxMemoryPerNode: 20GB + resources: + requests: + cpu: 500m + memory: 24Gi + limits: + memory: 32Gi + nodeSelector: + kubernetes.io/hostname: proc1 + tolerations: + - key: dedicated.processing + operator: Equal + value: processing + effect: NoExecute diff --git a/infrastructure/zitadel/uralkal/kustomization.yaml b/infrastructure/zitadel/uralkal/kustomization.yaml new file mode 100644 index 0000000..17fee7c --- /dev/null +++ b/infrastructure/zitadel/uralkal/kustomization.yaml @@ -0,0 +1,6 @@ +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: zitadel.yaml diff --git a/infrastructure/zitadel/uralkal/zitadel.yaml b/infrastructure/zitadel/uralkal/zitadel.yaml new file mode 100644 index 0000000..8627dda --- /dev/null +++ b/infrastructure/zitadel/uralkal/zitadel.yaml @@ -0,0 +1,154 @@ +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: zitadel + namespace: zitadel +spec: + interval: 5m + timeout: 10m + postRenderers: + - kustomize: + patches: + - target: + group: apps + version: v1 + kind: Deployment + name: zitadel-idp-contour + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - op: replace + path: /spec/template/metadata/annotations/vault.hashicorp.com~1agent-inject-template-zitadel-vault-config.yaml + value: |- + {{- with secret "secrets/data/zitadel/postgresql" -}} + Database: + postgres: + User: + Password: |- + {{ index .Data.data "password" }} + Admin: + Password: |- + {{ index .Data.data "password" }} + FirstInstance: + Org: + Human: + Password: |- + {{ index .Data.data "humanPassword" }} + {{- end -}} + - target: + group: batch + version: v1 + kind: Job + name: zitadel-idp-contour-init + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - op: replace + path: /spec/template/metadata/annotations/vault.hashicorp.com~1agent-inject-template-zitadel-vault-config.yaml + value: |- + {{- with secret "secrets/data/zitadel/postgresql" -}} + Database: + postgres: + User: + Password: |- + {{ index .Data.data "password" }} + Admin: + Password: |- + {{ index .Data.data "password" }} + FirstInstance: + Org: + Human: + Password: |- + {{ index .Data.data "humanPassword" }} + {{- end -}} + - target: + group: batch + version: v1 + kind: Job + name: zitadel-idp-contour-setup + patch: |- + - op: add + path: /spec/template/spec/nodeSelector + value: + dedicated: generic + - op: add + path: /spec/template/spec/tolerations + value: [] + - op: replace + path: /spec/template/metadata/annotations/vault.hashicorp.com~1agent-inject-template-zitadel-vault-config.yaml + value: |- + {{- with secret "secrets/data/zitadel/postgresql" -}} + Database: + postgres: + User: + Password: |- + {{ index .Data.data "password" }} + Admin: + Password: |- + {{ index .Data.data "password" }} + FirstInstance: + Org: + Human: + Password: |- + {{ index .Data.data "humanPassword" }} + {{- end -}} + values: + zitadel: + configmapConfig: + ExternalDomain: login.sarex.local.uralkali.com + ExternalSecure: true + debug: + enabled: false + postgresqlSecret: + create: false + vault: + enabled: true + role: zitadel + authPath: auth/kubernetes + secretPath: secrets/data/zitadel/postgresql + secretKey: password + kvVersion: 2 + fileName: zitadel-vault-config.yaml + serviceAccount: + create: true + name: zitadel + replicaCount: 1 + pdb: + enabled: false + env: + - name: ZITADEL_DEFAULTINSTANCE_FEATURES_LOGINV2_REQUIRED + value: "false" + - name: ZITADEL_SYSTEMDEFAULTS_PASSWORDHASHER_VERIFIERS + value: "bcrypt,pbkdf2" + - name: ZITADEL_MACHINE_IDENTIFICATION_HOSTNAME_ENABLED + value: "true" + - name: ZITADEL_DATABASE_POSTGRES_HOST + value: "10.133.0.249" + - name: ZITADEL_DATABASE_POSTGRES_PORT + value: "5432" + - name: ZITADEL_DATABASE_POSTGRES_USER_USERNAME + value: "zitadel" + - name: ZITADEL_DATABASE_POSTGRES_ADMIN_EXISTINGDATABASE + value: "zitadel" + - name: ZITADEL_DATABASE_POSTGRES_ADMIN_USERNAME + value: "zitadel" + - name: ZITADEL_DATABASE_POSTGRES_DATABASE + value: "zitadel" + - name: ZITADEL_DATABASE_POSTGRES_USER_SSL_MODE + value: "disable" + - name: ZITADEL_DATABASE_POSTGRES_ADMIN_SSL_MODE + value: "disable" + - name: ZITADEL_DEFAULTINSTANCE_ORG_HUMAN_USERNAME + value: "zitadel-admin" + - name: ZITADEL_DEFAULTINSTANCE_ORG_NAME + value: "Sarex"