From f6df384388ebc75254af7640aa6939844adbf28e Mon Sep 17 00:00:00 2001 From: ivan Date: Wed, 23 Sep 2026 23:36:08 +0500 Subject: [PATCH] added asterus --- apps/attachments/asterus/backend.yaml | 139 +++++++ apps/attachments/asterus/kustomization.yaml | 6 + apps/bim/asterus/backend.yaml | 199 ++++++++++ apps/bim/asterus/kustomization.yaml | 6 + apps/checklists/asterus/backend.yaml | 137 +++++++ apps/checklists/asterus/kustomization.yaml | 6 + apps/comparisons/asterus/backend.yaml | 148 ++++++++ apps/comparisons/asterus/frontend.yaml | 88 +++++ apps/comparisons/asterus/kustomization.yaml | 7 + .../asterus/kustomization.yaml | 6 + apps/control-interface/asterus/srx-admin.yaml | 95 +++++ apps/cross-section/asterus/frontend.yaml | 88 +++++ apps/cross-section/asterus/kustomization.yaml | 6 + apps/django/asterus/backend.yaml | 359 ++++++++++++++++++ apps/django/asterus/celery.yaml | 310 +++++++++++++++ apps/django/asterus/django-configmap.yaml | 7 + apps/django/asterus/export-project.yaml | 105 +++++ apps/django/asterus/frontend.yaml | 105 +++++ apps/django/asterus/kafka-cert.yaml | 37 ++ apps/django/asterus/kustomization.yaml | 14 + apps/django/asterus/nginx-configmap.yaml | 112 ++++++ apps/django/asterus/s3-proxy.yaml | 113 ++++++ apps/django/asterus/uwsgi-configmap.yaml | 30 ++ apps/document-link/asterus/frontend.yaml | 88 +++++ apps/document-link/asterus/kustomization.yaml | 6 + apps/documentations/asterus/api.yaml | 294 ++++++++++++++ apps/documentations/asterus/filestream.yaml | 288 ++++++++++++++ apps/documentations/asterus/frontend.yaml | 123 ++++++ apps/documentations/asterus/hasher.yaml | 145 +++++++ .../documentations/asterus/kustomization.yaml | 12 + .../asterus/pdf-markings-amqp.yaml | 171 +++++++++ apps/documentations/asterus/pdf-markings.yaml | 174 +++++++++ apps/documentations/asterus/pdm.yaml | 291 ++++++++++++++ apps/eav/asterus/asset.yaml | 160 ++++++++ apps/eav/asterus/backend.yaml | 221 +++++++++++ apps/eav/asterus/django-configmap.yaml | 145 +++++++ apps/eav/asterus/kafka-cert.yaml | 37 ++ apps/eav/asterus/kustomization.yaml | 11 + apps/eav/asterus/permissions.yaml | 124 ++++++ apps/eav/asterus/schema.yaml | 43 +++ apps/flows/asterus/authentication.yaml | 89 +++++ apps/flows/asterus/backend.yaml | 250 ++++++++++++ apps/flows/asterus/celery.yaml | 227 +++++++++++ apps/flows/asterus/export-reviews.yaml | 132 +++++++ apps/flows/asterus/frontend.yaml | 123 ++++++ apps/flows/asterus/kustomization.yaml | 11 + apps/flows/asterus/notification.yaml | 103 +++++ apps/iam/wb/backend-s3.yaml | 9 - apps/inspections/asterus/backend.yaml | 185 +++++++++ apps/inspections/asterus/frontend.yaml | 123 ++++++ apps/inspections/asterus/kustomization.yaml | 9 + .../asterus/production-configmap.yaml | 71 ++++ apps/inspections/asterus/uwsgi-configmap.yaml | 21 + apps/issues/asterus/issues.yaml | 239 ++++++++++++ apps/issues/asterus/kustomization.yaml | 10 + apps/issues/asterus/production-configmap.yaml | 7 + apps/issues/asterus/static.yaml | 88 +++++ apps/issues/asterus/uwsgi-configmap.yaml | 22 ++ apps/issues/asterus/worker.yaml | 223 +++++++++++ apps/measurements/asterus/backend.yaml | 99 +++++ apps/measurements/asterus/kustomization.yaml | 6 + apps/message-hub/asterus/kafka-cert.yaml | 37 ++ apps/message-hub/asterus/kafka-config.yaml | 66 ++++ apps/message-hub/asterus/kustomization.yaml | 8 + apps/message-hub/asterus/message-hub.yaml | 214 +++++++++++ apps/pm/asterus/backend-configmap.yaml | 29 ++ apps/pm/asterus/backend.yaml | 145 +++++++ apps/pm/asterus/celery.yaml | 133 +++++++ apps/pm/asterus/frontend.yaml | 88 +++++ apps/pm/asterus/kafka-cert.yaml | 37 ++ apps/pm/asterus/kustomization.yaml | 10 + apps/processing/asterus/engine-low.yaml | 327 ++++++++++++++++ apps/processing/asterus/engine.yaml | 342 +++++++++++++++++ apps/processing/asterus/frontend.yaml | 88 +++++ apps/processing/asterus/kustomization.yaml | 9 + apps/processing/asterus/workflows-api.yaml | 132 +++++++ apps/projects/asterus/frontend.yaml | 88 +++++ apps/projects/asterus/kustomization.yaml | 6 + apps/remarks/asterus/frontend.yaml | 116 ++++++ apps/remarks/asterus/kustomization.yaml | 6 + apps/reviews/asterus/frontend.yaml | 123 ++++++ apps/reviews/asterus/kustomization.yaml | 6 + apps/stamp-verification/asterus/frontend.yaml | 88 +++++ .../asterus/kustomization.yaml | 6 + .../asterus/django-configmap.yaml | 7 + apps/subscriptions/asterus/kustomization.yaml | 8 + .../asterus/sarex-subscriptions.yaml | 172 +++++++++ .../asterus/uwsgi-configmap.yaml | 22 ++ apps/system-log/asterus/api.yaml | 169 +++++++++ apps/system-log/asterus/kustomization.yaml | 7 + apps/system-log/asterus/worker.yaml | 139 +++++++ apps/transmittal/asterus/kustomization.yaml | 7 + apps/transmittal/asterus/transmittal.yaml | 331 ++++++++++++++++ apps/transmittal/asterus/worker.yaml | 307 +++++++++++++++ apps/workspaces/asterus/frontend1.yaml | 88 +++++ apps/workspaces/asterus/frontend2.yaml | 88 +++++ apps/workspaces/asterus/kustomization.yaml | 8 + apps/workspaces/asterus/workspaces-api.yaml | 152 ++++++++ clusters/asterus/kustomization.yaml | 25 ++ 99 files changed, 10128 insertions(+), 9 deletions(-) create mode 100644 apps/attachments/asterus/backend.yaml create mode 100644 apps/attachments/asterus/kustomization.yaml create mode 100644 apps/bim/asterus/backend.yaml create mode 100644 apps/bim/asterus/kustomization.yaml create mode 100644 apps/checklists/asterus/backend.yaml create mode 100644 apps/checklists/asterus/kustomization.yaml create mode 100644 apps/comparisons/asterus/backend.yaml create mode 100644 apps/comparisons/asterus/frontend.yaml create mode 100644 apps/comparisons/asterus/kustomization.yaml create mode 100644 apps/control-interface/asterus/kustomization.yaml create mode 100644 apps/control-interface/asterus/srx-admin.yaml create mode 100644 apps/cross-section/asterus/frontend.yaml create mode 100644 apps/cross-section/asterus/kustomization.yaml create mode 100644 apps/django/asterus/backend.yaml create mode 100644 apps/django/asterus/celery.yaml create mode 100644 apps/django/asterus/django-configmap.yaml create mode 100644 apps/django/asterus/export-project.yaml create mode 100644 apps/django/asterus/frontend.yaml create mode 100644 apps/django/asterus/kafka-cert.yaml create mode 100644 apps/django/asterus/kustomization.yaml create mode 100644 apps/django/asterus/nginx-configmap.yaml create mode 100644 apps/django/asterus/s3-proxy.yaml create mode 100644 apps/django/asterus/uwsgi-configmap.yaml create mode 100644 apps/document-link/asterus/frontend.yaml create mode 100644 apps/document-link/asterus/kustomization.yaml create mode 100644 apps/documentations/asterus/api.yaml create mode 100644 apps/documentations/asterus/filestream.yaml create mode 100644 apps/documentations/asterus/frontend.yaml create mode 100644 apps/documentations/asterus/hasher.yaml create mode 100644 apps/documentations/asterus/kustomization.yaml create mode 100644 apps/documentations/asterus/pdf-markings-amqp.yaml create mode 100644 apps/documentations/asterus/pdf-markings.yaml create mode 100644 apps/documentations/asterus/pdm.yaml create mode 100644 apps/eav/asterus/asset.yaml create mode 100644 apps/eav/asterus/backend.yaml create mode 100644 apps/eav/asterus/django-configmap.yaml create mode 100644 apps/eav/asterus/kafka-cert.yaml create mode 100644 apps/eav/asterus/kustomization.yaml create mode 100644 apps/eav/asterus/permissions.yaml create mode 100644 apps/eav/asterus/schema.yaml create mode 100644 apps/flows/asterus/authentication.yaml create mode 100644 apps/flows/asterus/backend.yaml create mode 100644 apps/flows/asterus/celery.yaml create mode 100644 apps/flows/asterus/export-reviews.yaml create mode 100644 apps/flows/asterus/frontend.yaml create mode 100644 apps/flows/asterus/kustomization.yaml create mode 100644 apps/flows/asterus/notification.yaml create mode 100644 apps/inspections/asterus/backend.yaml create mode 100644 apps/inspections/asterus/frontend.yaml create mode 100644 apps/inspections/asterus/kustomization.yaml create mode 100644 apps/inspections/asterus/production-configmap.yaml create mode 100644 apps/inspections/asterus/uwsgi-configmap.yaml create mode 100644 apps/issues/asterus/issues.yaml create mode 100644 apps/issues/asterus/kustomization.yaml create mode 100644 apps/issues/asterus/production-configmap.yaml create mode 100644 apps/issues/asterus/static.yaml create mode 100644 apps/issues/asterus/uwsgi-configmap.yaml create mode 100644 apps/issues/asterus/worker.yaml create mode 100644 apps/measurements/asterus/backend.yaml create mode 100644 apps/measurements/asterus/kustomization.yaml create mode 100644 apps/message-hub/asterus/kafka-cert.yaml create mode 100644 apps/message-hub/asterus/kafka-config.yaml create mode 100644 apps/message-hub/asterus/kustomization.yaml create mode 100644 apps/message-hub/asterus/message-hub.yaml create mode 100644 apps/pm/asterus/backend-configmap.yaml create mode 100644 apps/pm/asterus/backend.yaml create mode 100644 apps/pm/asterus/celery.yaml create mode 100644 apps/pm/asterus/frontend.yaml create mode 100644 apps/pm/asterus/kafka-cert.yaml create mode 100644 apps/pm/asterus/kustomization.yaml create mode 100644 apps/processing/asterus/engine-low.yaml create mode 100644 apps/processing/asterus/engine.yaml create mode 100644 apps/processing/asterus/frontend.yaml create mode 100644 apps/processing/asterus/kustomization.yaml create mode 100644 apps/processing/asterus/workflows-api.yaml create mode 100644 apps/projects/asterus/frontend.yaml create mode 100644 apps/projects/asterus/kustomization.yaml create mode 100644 apps/remarks/asterus/frontend.yaml create mode 100644 apps/remarks/asterus/kustomization.yaml create mode 100644 apps/reviews/asterus/frontend.yaml create mode 100644 apps/reviews/asterus/kustomization.yaml create mode 100644 apps/stamp-verification/asterus/frontend.yaml create mode 100644 apps/stamp-verification/asterus/kustomization.yaml create mode 100644 apps/subscriptions/asterus/django-configmap.yaml create mode 100644 apps/subscriptions/asterus/kustomization.yaml create mode 100644 apps/subscriptions/asterus/sarex-subscriptions.yaml create mode 100644 apps/subscriptions/asterus/uwsgi-configmap.yaml create mode 100644 apps/system-log/asterus/api.yaml create mode 100644 apps/system-log/asterus/kustomization.yaml create mode 100644 apps/system-log/asterus/worker.yaml create mode 100644 apps/transmittal/asterus/kustomization.yaml create mode 100644 apps/transmittal/asterus/transmittal.yaml create mode 100644 apps/transmittal/asterus/worker.yaml create mode 100644 apps/workspaces/asterus/frontend1.yaml create mode 100644 apps/workspaces/asterus/frontend2.yaml create mode 100644 apps/workspaces/asterus/kustomization.yaml create mode 100644 apps/workspaces/asterus/workspaces-api.yaml diff --git a/apps/attachments/asterus/backend.yaml b/apps/attachments/asterus/backend.yaml new file mode 100644 index 0000000..4586a2a --- /dev/null +++ b/apps/attachments/asterus/backend.yaml @@ -0,0 +1,139 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: attachments + namespace: attachments + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + attachments: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/attachments:production_6dbb4dce + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: attachments + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: attachments-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: yc-s3 + mountPath: + _default: /etc/sarex/yc-s3-storage + readOnly: + _default: true + secret: + secretName: + _default: yc-s3 + + envs: + - name: DATABASE_SSL_MODE + value: + _default: disable + - name: POSTGRES_POOL_SIZE + value: + _default: "4" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8000 + - name: YANDEX_S3_ACCOUNT_PATH + value: + _default: /etc/sarex/yc-s3-storage/yc-s3-service-account.json + - name: BUCKET_NAME + value: + _default: attachments + - name: YANDEX_S3_VERIFY + value: + _default: "false" + - name: DATABASE_PORT + value: + _default: "5432" + - name: DATABASE_HOST + value: + _default: postgres-service + + secretEnvs: + - name: DATABASE_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DATABASE_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DATABASE_NAME + secretName: + _default: postgres-secret + secretKey: database + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/attachments/asterus/kustomization.yaml b/apps/attachments/asterus/kustomization.yaml new file mode 100644 index 0000000..8cd3447 --- /dev/null +++ b/apps/attachments/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: attachments +resources: + - backend.yaml diff --git a/apps/bim/asterus/backend.yaml b/apps/bim/asterus/backend.yaml new file mode 100644 index 0000000..4073ae8 --- /dev/null +++ b/apps/bim/asterus/backend.yaml @@ -0,0 +1,199 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: bim + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:97de42bb1e5de1228e04b1caad0530715bf9bc63 + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: LAST_MASTER_BIM + value: + _default: "100000" + - name: LAST_SLAVE_1_BIM + value: + _default: "100000" + - name: LAST_MASTER_BIM_V3 + value: + _default: "100000" + - name: LAST_SLAVE_1_BIM_V3 + value: + _default: "100000" + - name: LAST_SLAVE_1_BIM_V4 + value: + _default: "100000" + - name: LAST_SLAVE_2_BIM + value: + _default: "1000000000" + - name: DB_CERT_PATH_3 + value: + _default: /root/yandex_pg.pem + - name: POSTGRES_ADDRESS_3 + value: + _default: postgres-service + - name: POSTGRES_PORT_3 + value: + _default: "5432" + - name: POSTGRES_DB_3 + value: + _default: bimapidb + - name: DB_CERT_PATH_2 + value: + _default: /root/yandex_pg.pem + - name: POSTGRES_ADDRESS_2 + value: + _default: postgres-service + - name: POSTGRES_ADDRESS_4 + value: + _default: postgres-service + - name: POSTGRES_PORT_2 + value: + _default: "5432" + - name: POSTGRES_PORT_4 + value: + _default: "5432" + - name: POSTGRES_DB_2 + value: + _default: bimapidb + - name: POSTGRES_DB_4 + value: + _default: bimapidb + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: bimapidb + - name: POSTGRES_POOL_SIZE + value: + _default: "30" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8000 + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_SSL + value: + _default: "0" + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: POSTGRES_USER_2 + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD_2 + secretName: + _default: postgres-secret + secretKey: password + - name: POSTGRES_USER_3 + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD_3 + secretName: + _default: postgres-secret + secretKey: password + - name: POSTGRES_USER_4 + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD_4 + secretName: + _default: postgres-secret + secretKey: password + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/bim/asterus/kustomization.yaml b/apps/bim/asterus/kustomization.yaml new file mode 100644 index 0000000..5524cd9 --- /dev/null +++ b/apps/bim/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: bim +resources: + - backend.yaml diff --git a/apps/checklists/asterus/backend.yaml b/apps/checklists/asterus/backend.yaml new file mode 100644 index 0000000..a985e5f --- /dev/null +++ b/apps/checklists/asterus/backend.yaml @@ -0,0 +1,137 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: checklist + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/checklists-backend:preprod_b1980fc6 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: HTTP_APP_HOST + value: + _default: 0.0.0.0 + - name: HTTP_APP_PORT + value: + _default: "8000" + - name: HTTP_APP_ROOT_PATH + value: + _default: /checklists + - name: HTTP_APP_WORKERS + value: + _default: "8" + - name: HTTP_APP_ADMIN_ENABLE + value: + _default: "true" + - name: JWT_AUTH_ENABLE + value: + _default: "true" + - name: DEBUG + value: + _default: "false" + + secretEnvs: + - name: DATABASE_HOST + secretName: + _default: checklists-postgresql-secret + secretKey: hostname + - name: DATABASE_PORT + secretName: + _default: checklists-postgresql-secret + secretKey: port + - name: DATABASE_NAME + secretName: + _default: checklists-postgresql-secret + secretKey: database + - name: DATABASE_USER + secretName: + _default: checklists-postgresql-secret + secretKey: username + - name: DATABASE_PASSWORD + secretName: + _default: checklists-postgresql-secret + secretKey: password + - name: JWT_AUTH_PUBLIC_KEY + secretName: + _default: checklists-public-key + secretKey: key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/checklists/asterus/kustomization.yaml b/apps/checklists/asterus/kustomization.yaml new file mode 100644 index 0000000..c8ca10a --- /dev/null +++ b/apps/checklists/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: checklist +resources: + - backend.yaml diff --git a/apps/comparisons/asterus/backend.yaml b/apps/comparisons/asterus/backend.yaml new file mode 100644 index 0000000..43da4dd --- /dev/null +++ b/apps/comparisons/asterus/backend.yaml @@ -0,0 +1,148 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: comparisons + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/comparisons-backend:964d9d277da96990fd89ddacabcfb2f4d7243635 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: comparisons_db + - name: POSTGRES_POOL_SIZE + value: + _default: "3" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8000 + - name: API_ADDRESS_FILE + value: + _default: 0.0.0.0:8000 + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: DOCUMENTATION_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/ + - name: DOCUMENTATION_FILESTREAM_URL + value: + _default: http://documentations-filestream-service.documentations.svc.cluster.local:80/ + - name: WORKFLOW_URL + value: + _default: http://workflows-api-service.workflow.svc.cluster.local:80/ + - name: WORKSPACE_URL + value: + _default: http://workspaces-service.workspaces.svc.cluster.local:80/ + - name: COMPARISON_URL + value: + _default: http://backend-service.comparisons.svc.cluster.local:8000/ + - name: WORKFLOW_IMAGES_VERSION + value: + _default: master + - name: EXTERNAL_DOCUMENTATION_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/ + - name: BIM_V2_INTERNAL_URL + value: + _default: http://bim-backend-v2-service.bim-api.svc.cluster.local:80/ + - name: ENABLE_SSL + value: + _default: "0" + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/comparisons/asterus/frontend.yaml b/apps/comparisons/asterus/frontend.yaml new file mode 100644 index 0000000..b374704 --- /dev/null +++ b/apps/comparisons/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: comparisons + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/comparisons-frontend:contour_8ce2d431 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/comparisons/asterus/kustomization.yaml b/apps/comparisons/asterus/kustomization.yaml new file mode 100644 index 0000000..5500048 --- /dev/null +++ b/apps/comparisons/asterus/kustomization.yaml @@ -0,0 +1,7 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: comparisons +resources: + - backend.yaml + - frontend.yaml diff --git a/apps/control-interface/asterus/kustomization.yaml b/apps/control-interface/asterus/kustomization.yaml new file mode 100644 index 0000000..1f2b061 --- /dev/null +++ b/apps/control-interface/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: control-interface +resources: + - srx-admin.yaml diff --git a/apps/control-interface/asterus/srx-admin.yaml b/apps/control-interface/asterus/srx-admin.yaml new file mode 100644 index 0000000..5050111 --- /dev/null +++ b/apps/control-interface/asterus/srx-admin.yaml @@ -0,0 +1,95 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: srx-admin + namespace: control-interface + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + srx-admin: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/srx-admin:prod_feb59026 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: srx-admin + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: srx-admin-svc + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 80 + + portName: + _default: http + + volumes: + _default: + - name: tmp-volume + mountPath: + _default: /tmp + emptyDir: {} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cross-section/asterus/frontend.yaml b/apps/cross-section/asterus/frontend.yaml new file mode 100644 index 0000000..bbec8d8 --- /dev/null +++ b/apps/cross-section/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cross-section + namespace: cross-section + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/cross-section-static:377ae058139538a53f3b90d2ee7e5585f9199497 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 8000 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cross-section/asterus/kustomization.yaml b/apps/cross-section/asterus/kustomization.yaml new file mode 100644 index 0000000..2444577 --- /dev/null +++ b/apps/cross-section/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: cross-section +resources: + - frontend.yaml diff --git a/apps/django/asterus/backend.yaml b/apps/django/asterus/backend.yaml new file mode 100644 index 0000000..a5af5d8 --- /dev/null +++ b/apps/django/asterus/backend.yaml @@ -0,0 +1,359 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: django + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_8f05291e + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: django-configmap + mountPath: + _default: /opt/sarex/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: django-configmap + items: + - key: production.py + path: + _default: production.py + + - name: uwsgi-configmap + mountPath: + _default: /opt/sarex/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: uwsgi-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: kafka-cert-volume + mountPath: + _default: /usr/local/share/ca-certificates + readOnly: + _default: true + configMap: + name: + _default: kafka-cert + + envs: + - name: ALLOWED_HOSTS + value: + _default: "*" + - name: SERVER_USE_CHANGELOG + value: + _default: "1" + - name: DJANGO_SETTINGS_MODULE + value: + _default: config.settings.production + - name: GATEWAY_HOST + value: + _default: http://pdm-api.documentations.svc.cluster.local:8080 + - name: CELERY_REDIS_HOST + value: + _default: redis-service + - name: CELERY_REDIS_PORT + value: + _default: "6379" + - name: DJANGO_REDIS_HOST + value: + _default: redis-service + - name: DJANGO_REDIS_PORT + value: + _default: "6379" + - name: SERVER_ZITADEL_ENABLED + value: + _default: "False" + - name: SERVER_KAFKA_ENABLED + value: + _default: "False" + - name: KAFKA_TOPICS + value: + _default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}' + - name: KAFKA_BOOTSTRAP_SERVERS + value: + _default: '["asterus-kafka-kafka-bootstrap.kafka.svc.cluster.local:9093"]' + - name: KAFKA_SECURITY_PROTOCOL + value: + _default: SSL + - name: KAFKA_SASL_MECHANISM + value: + _default: SCRAM-SHA-512 + - name: KAFKA_SSL_CAFILE + value: + _default: /usr/local/share/ca-certificates/kafka.crt + - name: BIMV2_INTERNAL_HOST + value: + _default: http://bim-backend-v2-service.bim-api + - name: BIMV2_TIMEOUT + value: + _default: "60" + - name: JWT_KID + value: + _default: "1" + - name: SERVER_SYNC_KC_ADMIN_HANDLER + value: + _default: "True" + - name: PDM_SYNC + value: + _default: "1" + - name: KC_SYNC_ENABLE + value: + _default: "0" + - name: MEASUREMENTS_HOST + value: + _default: http://measurements-service.measurements.svc.cluster.local:8000/api + - name: MEASUREMENTS_USE_MEASUREMENTS + value: + _default: "1" + - name: SERVER_API_HOST + value: + _default: https://sarex.asterus.ru + - name: SERVER_HOST + value: + _default: https://sarex.asterus.ru + - name: WORKFLOWS_HOST + value: + _default: https://sarex.asterus.ru + - name: WORKFLOWS_BASE_HOST + value: + _default: https://sarex.asterus.ru + - name: SERVER_VERIFY_SSL + value: + _default: "False" + - name: WORKFLOWS_USE + value: + _default: "1" + - name: WORKFLOWS_TAG + value: + _default: stable + - name: SERVER_S3_STREAM_IMPORT + value: + _default: "1" + - name: SERVER_USE_CLICKHOUSE + value: + _default: "0" + - name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK + value: + _default: "0" + - name: SERVER_USE_METASHAPE + value: + _default: "0" + - name: SERVER_CHANGELOG_MODE_SYSTEM_LOG + value: + _default: "0" + - name: SERVER_CHANGELOG_MODE + value: + _default: "1" + - name: ZITADEL_HOST + value: + _default: https://zitadel.asterus.ru + - name: SERVER_DJANGO_URLS + value: + _default: "1" + - name: CHECK_IMPORT_HASH + value: + _default: "1" + - name: EAV_ENABLE + value: + _default: "1" + - name: SERVER_CHECK_IMPORT_HASH + value: + _default: "1" + - name: SERVER_CHUNKED_PATH + value: + _default: /tmp/chunked_uploads/%Y/%m/%d + - name: SERVER_HIDE_USER_SCROLL_PERMISSIONS + value: + _default: "0" + - name: SERVER_USE_WRORKFLOW_STATUS + value: + _default: "1" + - name: GK_ENCRYPTION_KEY + value: + _default: zfDjuszywHSbAhY8KJQbESbpUYN74XTs + - name: SERVER_EXTERNAL_PDF_CONVERTER_HOST + value: + _default: http://export-project-service:8000 + - name: S3_HOST + value: + _default: http://minio-service.minio.svc.cluster.local:9000 + - name: AWS_S3_ENDPOINT_URL + value: + _default: http://minio-service.minio.svc.cluster.local:9000 + - name: WORKFLOWS_TIMEOUT + value: + _default: "120" + - name: SERVER_LOGINGG_BODY_ACTION + value: + _default: "0" + + secretEnvs: + - name: KC_CLIENT_ID + secretName: + _default: gatekeeper-secret + secretKey: client_id + - name: KC_CLIENT_SECRET + secretName: + _default: gatekeeper-secret + secretKey: client_secret + - name: KAFKA_SASL_PLAIN_USERNAME + secretName: + _default: kafka-secret + secretKey: username + - name: KAFKA_SASL_PLAIN_PASSWORD + secretName: + _default: kafka-secret + secretKey: password + - name: ZITADEL_ACCESS_TOKEN + secretName: + _default: zitadel-secret + secretKey: access_token + - name: JWT_PRIVATE_KEY + secretName: + _default: backend-secret + secretKey: ssh_private.key + - name: JWT_PUBLIC_KEY + secretName: + _default: backend-secret + secretKey: ssh_public.key + - name: DJANGO_POSTGRES_DATABASE + secretName: + _default: postgres-secret + secretKey: database + - name: DJANGO_POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DJANGO_POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DJANGO_POSTGRES_HOST + secretName: + _default: postgres-secret + secretKey: host + - name: DJANGO_POSTGRES_PORTS + secretName: + _default: postgres-secret + secretKey: port + - name: S3_LOGIN + secretName: + _default: sarex-media-storage-secret + secretKey: login + - name: S3_PASSWORD + secretName: + _default: sarex-media-storage-secret + secretKey: password + - name: S3_BUCKET + secretName: + _default: sarex-media-storage-secret + secretKey: bucket + - name: CELERY_RABBITMQ_HOST + secretName: + _default: rabbitmq-secret + secretKey: host + - name: CELERY_RABBITMQ_USER + secretName: + _default: rabbitmq-secret + secretKey: username + - name: CELERY_RABBITMQ_PASSWORD + secretName: + _default: rabbitmq-secret + secretKey: password + - name: CELERY_RABBITMQ_VHOST + secretName: + _default: rabbitmq-secret + secretKey: vhost + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/django/asterus/celery.yaml b/apps/django/asterus/celery.yaml new file mode 100644 index 0000000..aef9191 --- /dev/null +++ b/apps/django/asterus/celery.yaml @@ -0,0 +1,310 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: celery + namespace: django + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + celery: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_8f05291e + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: celery + + replicaCount: + _default: 1 + + command: + _default: ["celery", "-A", "config", "worker", "-B", "-l", "info", "-E", "-Q", "default", "-n", "default_worker.%h", "--concurrency=2"] + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + volumes: + _default: + - name: django-configmap + mountPath: + _default: /opt/sarex/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: django-configmap + items: + - key: production.py + path: + _default: production.py + + - name: kafka-cert-volume + mountPath: + _default: /usr/local/share/ca-certificates + readOnly: + _default: true + configMap: + name: + _default: kafka-cert + + envs: + - name: ALLOWED_HOSTS + value: + _default: "*" + - name: SERVER_USE_CHANGELOG + value: + _default: "1" + - name: DJANGO_SETTINGS_MODULE + value: + _default: config.settings.production + - name: CELERY_REDIS_HOST + value: + _default: redis-service + - name: CELERY_REDIS_PORT + value: + _default: "6379" + - name: DJANGO_REDIS_HOST + value: + _default: redis-service + - name: DJANGO_REDIS_PORT + value: + _default: "6379" + - name: BIMV2_INTERNAL_HOST + value: + _default: http://bim-backend-v2-service.bim-api + - name: BIMV2_TIMEOUT + value: + _default: "60" + - name: JWT_KID + value: + _default: "1" + - name: PDM_SYNC + value: + _default: "1" + - name: KC_SYNC_ENABLE + value: + _default: "0" + - name: MEASUREMENTS_HOST + value: + _default: http://measurements-service.measurements.svc.cluster.local:8000/api + - name: MEASUREMENTS_USE_MEASUREMENTS + value: + _default: "1" + - name: SERVER_API_HOST + value: + _default: https://sarex.asterus.ru + - name: SERVER_HOST + value: + _default: https://sarex.asterus.ru + - name: WORKFLOWS_HOST + value: + _default: https://sarex.asterus.ru + - name: WORKFLOWS_BASE_HOST + value: + _default: https://sarex.asterus.ru + - name: WORKFLOWS_USE + value: + _default: "1" + - name: WORKFLOWS_TAG + value: + _default: stable + - name: SERVER_S3_STREAM_IMPORT + value: + _default: "1" + - name: SERVER_USE_CLICKHOUSE + value: + _default: "0" + - name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK + value: + _default: "0" + - name: SERVER_USE_METASHAPE + value: + _default: "0" + - name: SERVER_CHANGELOG_MODE_SYSTEM_LOG + value: + _default: "0" + - name: SERVER_CHANGELOG_MODE + value: + _default: "1" + - name: SERVER_DJANGO_URLS + value: + _default: "1" + - name: CHECK_IMPORT_HASH + value: + _default: "1" + - name: EAV_ENABLE + value: + _default: "1" + - name: SERVER_CHECK_IMPORT_HASH + value: + _default: "1" + - name: SERVER_ZITADEL_ENABLED + value: + _default: "True" + - name: SERVER_KAFKA_ENABLED + value: + _default: "True" + - name: SERVER_CHUNKED_PATH + value: + _default: /tmp/chunked_uploads/%Y/%m/%d + - name: SERVER_HIDE_USER_SCROLL_PERMISSIONS + value: + _default: "0" + - name: KAFKA_TOPICS + value: + _default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}' + - name: KAFKA_BOOTSTRAP_SERVERS + value: + _default: '["asterus-kafka-kafka-bootstrap.kafka.svc.cluster.local:9093"]' + - name: KAFKA_SECURITY_PROTOCOL + value: + _default: SSL + - name: KAFKA_SASL_MECHANISM + value: + _default: SCRAM-SHA-512 + - name: KAFKA_SSL_CAFILE + value: + _default: /usr/local/share/ca-certificates/kafka.crt + - name: SERVER_USE_WRORKFLOW_STATUS + value: + _default: "1" + - name: SERVER_EXTERNAL_PDF_CONVERTER_HOST + value: + _default: http://export-project-service:8000 + - name: S3_HOST + value: + _default: http://minio-service.minio.svc.cluster.local:9000 + - name: AWS_S3_ENDPOINT_URL + value: + _default: http://minio-service.minio.svc.cluster.local:9000 + - name: WORKFLOWS_TIMEOUT + value: + _default: "120" + - name: SERVER_LOGINGG_BODY_ACTION + value: + _default: "0" + + secretEnvs: + - name: KAFKA_SASL_PLAIN_USERNAME + secretName: + _default: kafka-secret + secretKey: username + - name: KAFKA_SASL_PLAIN_PASSWORD + secretName: + _default: kafka-secret + secretKey: password + - name: KC_USERNAME + secretName: + _default: kc-admin + secretKey: username + - name: KC_PASSWORD + secretName: + _default: kc-admin + secretKey: password + - name: JWT_PRIVATE_KEY + secretName: + _default: backend-secret + secretKey: ssh_private.key + - name: JWT_PUBLIC_KEY + secretName: + _default: backend-secret + secretKey: ssh_public.key + - name: DJANGO_POSTGRES_DATABASE + secretName: + _default: postgres-secret + secretKey: database + - name: DJANGO_POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DJANGO_POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DJANGO_POSTGRES_HOST + secretName: + _default: postgres-secret + secretKey: host + - name: DJANGO_POSTGRES_PORTS + secretName: + _default: postgres-secret + secretKey: port + - name: S3_LOGIN + secretName: + _default: sarex-media-storage-secret + secretKey: login + - name: S3_PASSWORD + secretName: + _default: sarex-media-storage-secret + secretKey: password + - name: S3_BUCKET + secretName: + _default: sarex-media-storage-secret + secretKey: bucket + - name: CELERY_RABBITMQ_HOST + secretName: + _default: rabbitmq-secret + secretKey: host + - name: CELERY_RABBITMQ_USER + secretName: + _default: rabbitmq-secret + secretKey: username + - name: CELERY_RABBITMQ_PASSWORD + secretName: + _default: rabbitmq-secret + secretKey: password + - name: CELERY_RABBITMQ_VHOST + secretName: + _default: rabbitmq-secret + secretKey: vhost + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/django/asterus/django-configmap.yaml b/apps/django/asterus/django-configmap.yaml new file mode 100644 index 0000000..8f03699 --- /dev/null +++ b/apps/django/asterus/django-configmap.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +data: + production.py: "import os\nfrom .base import *\nfrom logging.handlers import SysLogHandler\nfrom datetime import timedelta\n\nALLOWED_HOSTS = [\"*\"]\nFILE_UPLOAD_PERMISSIONS = 0o644\nDEBUG = False\nCSRF_COOKIE_SECURE = True\nCSRF_TRUSTED_ORIGINS = [\"sarex.vhdm.ru\", \"sarex.asterus.ru\"]\nSESSION_COOKIE_SECURE = True\nSECURE_SSL_REDIRECT = False\n\n# Uncomment and set the environment variables accordingly\n# STATIC_ROOT = os.environ.get('STATIC_ROOT')\n# MEDIA_ROOT = os.environ.get('MEDIA_ROOT')\n# SECRET_KEY = os.environ.get('SECRET_KEY')\nSECRET_KEY = 't2=9+($2f%7ptsdy4!rby$)mcfl1l%o2e@vs^d(g&(wwi&%k1v'\n\nCORS_ORIGIN_ALLOW_ALL = True\nINSTALLED_APPS = list(INSTALLED_APPS) + ['corsheaders']\n\nCORS_ALLOW_METHODS = (\n 'DELETE',\n 'GET',\n 'OPTIONS',\n 'PATCH',\n 'POST',\n 'PUT',\n)\n\nCORS_ALLOW_HEADERS = (\n 'accept',\n 'accept-encoding',\n 'authorization',\n 'content-type',\n 'user-agent',\n 'x-csrftoken',\n 'x-requested-with',\n 'x-token',\n 'Bearer',\n)\n\nHOST = \"https://sarex.asterus.ru\"\n\nPOSTGRES_DATABASE = os.environ.get('DJANGO_POSTGRES_DATABASE')\nPOSTGRES_USER = os.environ.get('DJANGO_POSTGRES_USER')\nPOSTGRES_PASSWORD = os.environ.get('DJANGO_POSTGRES_PASSWORD')\nPOSTGRES_HOST = os.environ.get('DJANGO_POSTGRES_HOST')\nPOSTGRES_PORTS = os.environ.get('DJANGO_POSTGRES_PORTS', \"5432\")\n\nDATABASES = {\n 'default': {\n 'ENGINE': 'django_prometheus.db.backends.postgresql',\n 'NAME': POSTGRES_DATABASE,\n 'USER': POSTGRES_USER,\n 'PASSWORD': POSTGRES_PASSWORD,\n 'HOST': POSTGRES_HOST,\n 'PORT': POSTGRES_PORTS,\n }\n}\n\nLOGGING = {\n 'version': 1,\n 'disable_existing_loggers': False,\n 'filters': {\n 'require_debug_false': {\n '()': 'django.utils.log.RequireDebugFalse',\n }\n },\n 'formatters': {\n 'verbose': {\n 'format': '[contactor] %(levelname)s %(asctime)s %(message)s',\n },\n },\n 'handlers': {\n 'console': {\n 'level': 'DEBUG',\n 'class': 'logging.StreamHandler',\n },\n 'sentry': {\n 'level': 'ERROR',\n 'filters': ['require_debug_false'],\n 'class': 'logging.StreamHandler',\n },\n },\n 'loggers': {\n '': {\n 'handlers': ['console', 'sentry'],\n 'level': 'INFO',\n 'propagate': False,\n },\n }\n}\n\nCOMPARATOR_JWT = os.environ.get(\"COMPARATOR_JWT\", \"default_jwt\")\nCOMPARATOR_URL = os.environ.get(\"COMPARATOR_URL\", \"https://lk.brusnika.onprem.sarex.io/comparator\")\nCOMPARATOR_SECTION = os.environ.get(\"COMPARATOR_SECTION\", \"sarex-production-storage\")\n\nSIMPLE_JWT = {\n 'ACCESS_TOKEN_LIFETIME': timedelta(hours=1), \n 'REFRESH_TOKEN_LIFETIME': timedelta(days=1),\n 'ROTATE_REFRESH_TOKENS': False,\n 'BLACKLIST_AFTER_ROTATION': True,\n 'UPDATE_LAST_LOGIN': False,\n 'ALGORITHM': 'RS512',\n 'SIGNING_KEY': os.environ.get(\"JWT_PRIVATE_KEY\").replace(\"\\\\n\", \"\\n\"),\n 'VERIFYING_KEY': os.environ.get(\"JWT_PUBLIC_KEY\").replace(\"\\\\n\", \"\\n\"),\n 'AUDIENCE': None,\n 'ISSUER': os.environ.get('SIMPLE_JWT_ISSUER', 'default_issuer'),\n 'AUTH_HEADER_TYPES': ('Bearer',),\n 'AUTH_HEADER_NAME': 'HTTP_AUTHORIZATION',\n 'USER_ID_FIELD': 'id',\n 'USER_ID_CLAIM': 'user_id',\n 'AUTH_TOKEN_CLASSES': ('rest_framework_simplejwt.tokens.AccessToken',),\n 'TOKEN_TYPE_CLAIM': 'token_type',\n 'JTI_CLAIM': 'jti',\n 'SLIDING_TOKEN_REFRESH_EXP_CLAIM': 'refresh_exp',\n 'SLIDING_TOKEN_LIFETIME': timedelta(minutes=5),\n 'SLIDING_TOKEN_REFRESH_LIFETIME': timedelta(days=1),\n}\n\nos.environ[\"DJANGO_ALLOW_ASYNC_UNSAFE\"] = \"true\"\nDEFAULT_FILE_STORAGE = 'sarex.core.storages.CustomS3Boto3Storage'\nDATA_UPLOAD_MAX_MEMORY_SIZE = 268435456\n\nif not os.environ.get('ISOLATED', False):\n import sentry_sdk\n from sentry_sdk.integrations.django import DjangoIntegration\n\n sentry_sdk.init(\n dsn=\"https://3df2f4b8d3d14595a06c92e9d7c562cb@sentry.io/1501541\",\n integrations=[DjangoIntegration()],\n environment=os.environ.get('SENTRY_ENVIRONMENT', 'production'),\n send_default_pii=True,\n )\n\nCOMPARISON_API_URL = f\"{os.environ.get('WORKFLOWSSETTINGS_HOST')}/comparisons\"\nDOCUMENTATION_API_URL = f\"{os.environ.get('WORKFLOWSSETTINGS_HOST')}/documentations\"\nPDM_FILES_API_URL = f\"{os.environ.get('WORKFLOWSSETTINGS_HOST')}/files\"\n\nWORKFLOWS_TASKS = {\n \"update_orthomosaic_data\": {\n \"image\": f\"{os.environ.get('WORKFLOWSSETTINGS_REGISTRY')}/update-orthomosaic-data:dev\",\n \"service_requests\": [\"django-auth\"],\n \"backoff_limit\": 3,\n },\n}\n\nREST_FRAMEWORK = { 'DEFAULT_PAGINATION_CLASS': (\n 'rest_framework.pagination.LimitOffsetPagination' ),\n 'DEFAULT_SCHEMA_CLASS': 'rest_framework.schemas.coreapi.AutoSchema',\n 'PAGE_SIZE': 1000, 'DEFAULT_FILTER_BACKENDS': [\n 'django_filters.rest_framework.DjangoFilterBackend' ],\n 'DEFAULT_AUTHENTICATION_CLASSES': [\n 'rest_framework.authentication.RemoteUserAuthentication',\n 'rest_framework_simplejwt.authentication.JWTAuthentication',\n 'rest_framework.authentication.BasicAuthentication',\n 'rest_framework.authentication.SessionAuthentication',\n 'sarex.authentication.backends.JWTAuthentication' ],\n 'DEFAULT_PERMISSION_CLASSES': [\n 'rest_framework.permissions.IsAuthenticated', ] }\n\nAUTHENTICATION_BACKENDS = [\n 'sarex.authentication.backends.CustomRemoteUserBackend',\n # 'django.contrib.auth.backends.RemoteUserBackend',\n 'django.contrib.auth.backends.ModelBackend',\n 'guardian.backends.ObjectPermissionBackend',\n]\n\nMIDDLEWARE = [\n 'django_prometheus.middleware.PrometheusBeforeMiddleware',\n 'django.middleware.security.SecurityMiddleware',\n 'django.contrib.sessions.middleware.SessionMiddleware',\n 'django.middleware.common.CommonMiddleware',\n 'django.middleware.csrf.CsrfViewMiddleware',\n 'django_keycloak.middlewares.AuthorizationHeaderMiddleware',\n 'django_keycloak.middlewares.KeycloakSessionMiddleware',\n 'django.contrib.auth.middleware.AuthenticationMiddleware',\n 'django.contrib.auth.middleware.RemoteUserMiddleware',\n 'django.contrib.messages.middleware.MessageMiddleware',\n 'django.middleware.clickjacking.XFrameOptionsMiddleware',\n 'django_user_agents.middleware.UserAgentMiddleware',\n 'simple_history.middleware.HistoryRequestMiddleware',\n 'django_prometheus.middleware.PrometheusAfterMiddleware', ]\n\nclass ADSettings(BaseSettings):\n bind_DN: str = \"LDAP_keycloak\"\n ldap_password: str = \"EAjw*U$2\"\n ldap_host: str = \"ldap://vhdmpdc.vhdm.int\"\n sizelimit: int = 5000\n default_company_name: Optional[str] = \"Asterus\"\n base: str = \"\"\n group_prefix: str = 'Group'\n department_prefix: str = 'Department'\n position_prefix: str = 'Position'\n separator: str = '-'\n criteria: str = \"(&(objectCategory=user)(memberOf=CN=KsmgUsersName,OU=Security Groups,DC=vhdm,DC=int))\"\n staff_group_name: Optional[str] = None\n superuser_group_name: Optional[str] = None\n include_staff_data_update: bool = True\n include_superuser_data_update: bool = True\n attributes: Dict[str, str] = {\n \"username\": \"sAMAccountName\",\n \"name\": \"cn\",\n \"last_name\": \"sn\",\n \"first_name\": \"givenName\",\n \"email\": \"mail\",\n \"groups\": \"memberOf\"\n }\n\n class Config:\n env_prefix = \"AD_\"\n\nclass KeyCloakSettings(BaseSettings):\n client_id: str = \"client_id\"\n client_secret: str = \"client_secret\"\n discovery_url: str = \"https://kc.asterus.ru/realms/Sarex/.well-known/openid-configuration\"\n staff: Optional[str] = \"Sarex staff\"\n delete_cookies_logout: bool = True\n superuser: Optional[str] = \"Sarex superusers\"\n username: str = ''\n password: str = ''\n keycloak_pagination_size: int = 10\n base_url: str = 'https://kc.asterus.ru'\n realm: str = 'Sarex'\n realm_name: str = 'Sarex'\n sync_with_django: bool = True\n sync_admin: bool = False\n group_prefix: str = 'Sarex-Role'\n company_prefix: str = 'Sarex-Company'\n department_prefix: str = 'Sarex-Department'\n position_prefix: str = 'Sarex-Position'\n separator: str = '__'\n sync_user_groups: bool = False\n sync_user_positions: bool = False\n sync_user_departments: bool = False\n sync_user_companies: bool = False\n default_group_name: Optional[str] = 'Тест'\n timeout: int = 60\n default_company_name: Optional[str] = 'Asterus'\n trusted_uri: List[str] = ['/api/core/orthophotos/', '/api/token', '/api/token/me']\n trusted_uri: List[str] = []\n \n use_redirect_logout: bool = True\n sso_logout_redirect: bool = True\n logout_redirect_uri: str = \"/\"\n\n class Config:\n env_prefix = \"KC_\"\n\n\nKEYCLOAKSETTINGS = KeyCloakSettings()\n\nREMOTE_USER_DEFAULT_COMPANY_ID = 1\n\nAUTH_SETTINGS = {\n \"refresh_token\": False,\n \"refresh_token_uri\": \"/api/token/me\",\n \"refresh_oauth_token\": False,\n \"refresh_oauth_token_uri\": \"/oauth/token\",\n \"refresh_time\": 240,\n}\nCSRF_TRUSTED_ORIGINS = ['https://sarex.vhdm.ru', 'https://sarex.asterus.ru']\nSAREX_MODULES = [\n #{\n # \"name\": \"Съёмки\",\n # \"uri\": \"/targets\"\n #},\n\n # {\n # \"name\": \"Передача документации\", \n # \"uri\": \"/transmittal\"\n # },\n \n # {\n # \"name\": \"Запросы\",\n # \"uri\": \"/rfi\"\n # },\n\n {\n \"name\": \"Управление проектами\",\n \"uri\": \"/management/projects\",\n },\n {\n \"name\": \"Документация\",\n \"uri\": \"/documentations\",\n },\n {\n \"name\": \"Замечания\",\n \"uri\": \"/remarks\"\n },\n {\n \"name\": \"Замечания V2\",\n \"uri\": \"/issues\"\n },\n {\n \"name\": \"Аналитика\",\n \"uri\": \"/analytics\"\n },\n # {\n # \"name\": \"Инспекции\",\n # \"uri\": \"/inspections\"\n # },\n {\n \"name\": \"Обзор\",\n \"uri\": \"/projects\"\n },\n {\n \"name\": \"Согласование документов\",\n \"uri\": \"/reviews\"\n },\n {\n \"name\": \"Рабочие процессы\",\n \"uri\": \"/processes\"\n },\n # {\n # \"name\": \"Договоры\",\n # \"uri\": \"/contracts\"\n # },\n # {\n # \"name\": \"Предписания\",\n # \"uri\": \"/prescriptions\"\n # },\n # {\n # \"name\": \"Справочники\",\n # \"uri\": \"/assets\"\n # },\n \n ]\n\nWEB_APP_AUTH_MODE='jwt-session-based'\n\n \n\nAD_SETTINGS = ADSettings()\n" +kind: ConfigMap +metadata: + name: django-configmap + namespace: django diff --git a/apps/django/asterus/export-project.yaml b/apps/django/asterus/export-project.yaml new file mode 100644 index 0000000..cd04c28 --- /dev/null +++ b/apps/django/asterus/export-project.yaml @@ -0,0 +1,105 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: export-project + namespace: django + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + export-project: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/export-project:prod_37a48176 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: export-project + + replicaCount: + _default: 1 + + port: + _default: 8000 + + resources: + limits: + cpu: + _default: "2" + memory: + _default: 16Gi + requests: + cpu: + _default: "1" + memory: + _default: 512Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: export-project-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: TIMEOUT + value: + _default: "180" + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/django/asterus/frontend.yaml b/apps/django/asterus/frontend.yaml new file mode 100644 index 0000000..126188b --- /dev/null +++ b/apps/django/asterus/frontend.yaml @@ -0,0 +1,105 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: django + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/sarex-frontend-dev:contour_5.16.3 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + volumes: + _default: + - name: nginx-configmap + mountPath: + _default: /etc/nginx/nginx.conf + subPath: + _default: nginx.conf + readOnly: + _default: true + configMap: + name: + _default: nginx-configmap + items: + - key: nginx.conf + path: + _default: nginx.conf + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/django/asterus/kafka-cert.yaml b/apps/django/asterus/kafka-cert.yaml new file mode 100644 index 0000000..9116fc0 --- /dev/null +++ b/apps/django/asterus/kafka-cert.yaml @@ -0,0 +1,37 @@ +apiVersion: v1 +data: + kafka.crt: | + -----BEGIN CERTIFICATE----- + MIIFLTCCAxWgAwIBAgIUeuNKW4rB4ReiwjDidNIdob7VRokwDQYJKoZIhvcNAQEN + BQAwLTETMBEGA1UECgwKaW8uc3RyaW16aTEWMBQGA1UEAwwNY2x1c3Rlci1jYSB2 + MDAeFw0yNTA4MjYxMDM0NDRaFw0yNjA4MjYxMDM0NDRaMC0xEzARBgNVBAoMCmlv + LnN0cmltemkxFjAUBgNVBAMMDWNsdXN0ZXItY2EgdjAwggIiMA0GCSqGSIb3DQEB + AQUAA4ICDwAwggIKAoICAQCv7lvKnTUpgnDd91YgCMQSYTSVUdkkQITXZENXj2km + UN5k2NhnDIMOeHD4Bu8fjSUvELcilNAgsPqKNWO97CWtU9/phxsQRMgDwywtyr8Q + W3Vc2RYk/7vcpi77M/IjmFoRExXowO9U3mLNd0vACk+yC7WObcNr9veFnVyrmoL3 + iOqLbmzKiZvdIz1f6lwDDOXNuj26Ct6jRatV96HcqKzK50Jj9eS5SvV57JQLvTsZ + LbPnesAxgKzW7sci6N9lB9jrDirBl2h/QJXAmhUyg2yAvrU8wBTTpQWCdQRQ54Pv + LCZV3iXMkTYkxoyCg/GPbb2M7DF1sEe45iWsYkqDsWvdhirfp8BBVp+oni3xmj9J + +8hzB2MZhyA9i6v6Hfua7d0ExKUhuJkUxBcGyFHbXpC2m2m8plaHL2mNBXAuQZDw + wf+aHvHo2QLoNFL2xR8/63IHosnnRgzdKpZX6Z1Ftd8caHf/L+XgI3ET8LwklC55 + y4FmFQwd8rOGiR38Ixg9zhr44tV3foWWrIM+sb/ni4UokeGkX2AymSsdln9pAnIj + usGG9ZuSZUPZ+w5HjtL3hxh9pbGdYja2YcfusCCQK56LBWRJnB8W/IafEOvVxMT/ + gqx6Hee/geY3G2LRlMfsLRAbCvYOIi7kDzOM/LnM+XlbEkJO8uyjnT5wbCFCRnvy + nwIDAQABo0UwQzAdBgNVHQ4EFgQUeNSYqykN5qUxAfLJ7z9Say0XIHAwEgYDVR0T + AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQADggIB + AH82HGTXnJKbBln7q+Wx9chwMUFZc4u43Q0QAvCgGXMRFa5Dl4x/9rtrYYuDpZwh + /GKgOkhZ/SKLeuy9e7bgoHnt2sNR4CqAjK6YQp7o5aBNRGhiQZTkfjoG/P17AV7e + nKP65WXPAirouUxlvC8Kplh2vsuUkGcjzsKRTYQRNR1+yHw+P91qcX+RglrHFyMJ + wWKOldwgR3Mit+tAMbgioqrNTmwIEREDCF0DcJuX3LKTo7/q3I9cMFhz7/kk5CTm + pePoWMcvhgOX/cQcqNA7Q0HAOIV3OioxAod+XyjpaTo42YrTUSjq5Rl2a9U7GNN/ + xazxT+YDs/mHSP0Yt/5jxMSjsifPP4l4KP9YvqiC7UZGrZ9ctzkg3UlQmr87Km9W + FqVLoX6Y1OmNB/c5XCg4S4g2q5VavXM792fn1ow6oR5hgDHXBLNA+TKWFmJ5UXJB + z4l7Hn7rFJB5e9QVEDRIzr8c2QcUZ668kicP3Oh45NywMcSV6GZO4PNDNsNW0kFf + 3txTYwDEvT3n83C0lybw2hgLl3Q//lX+Zn3TMdqGVXkCXR0df45U8p14Wfe7QRtb + Jmg3tvOOpueyc3I+mrpDbyxdYQxr8IZdFoaV+mZUCi+ezMrHBNNNq0Lc/t2ICa+p + bpTSKuKNG91nPGXEd7sFGL8ZYypObQc5HC6wMCeVC3Cx + -----END CERTIFICATE----- +kind: ConfigMap +metadata: + name: kafka-cert + namespace: django diff --git a/apps/django/asterus/kustomization.yaml b/apps/django/asterus/kustomization.yaml new file mode 100644 index 0000000..e285039 --- /dev/null +++ b/apps/django/asterus/kustomization.yaml @@ -0,0 +1,14 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: django +resources: + - django-configmap.yaml + - uwsgi-configmap.yaml + - kafka-cert.yaml + - nginx-configmap.yaml + - backend.yaml + - celery.yaml + - export-project.yaml + - s3-proxy.yaml + - frontend.yaml diff --git a/apps/django/asterus/nginx-configmap.yaml b/apps/django/asterus/nginx-configmap.yaml new file mode 100644 index 0000000..f8f918e --- /dev/null +++ b/apps/django/asterus/nginx-configmap.yaml @@ -0,0 +1,112 @@ +apiVersion: v1 +data: + nginx.conf: | + worker_processes auto; + + pid /var/run/nginx.pid; + + events { + use epoll; + worker_connections 1024; + } + + http { + + # Basic Settings + large_client_header_buffers 8 128k; + sendfile on; + tcp_nopush on; + tcp_nodelay on; + keepalive_timeout 300; + types_hash_max_size 2048; + client_max_body_size 5000M; + client_header_buffer_size 5M; + # server_tokens off; + # server_names_hash_bucket_size 64; + # server_name_in_redirect off; + include /etc/nginx/mime.types; + default_type application/octet-stream; + + # Logging Settings + access_log /var/log/nginx/access.log; + error_log /var/log/nginx/error.log; + + # GZIP Settings + gzip on; + gzip_vary on; + gzip_proxied any; + gzip_comp_level 6; + gzip_buffers 16 8k; + gzip_http_version 1.1; + gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; + + log_format main '$remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + server { + listen 80; + listen [::]:80; + root /opt/react_client/; + + proxy_set_header Host 'sarex.asterus.ru'; + + location ~^/workflows/(.+).js { + rewrite /workflows/(.+) /$1 break; + proxy_pass http://frontend-service.workflows.svc.cluster.local:8080; + } + + location = /static/index.bundle.js { + add_header Cache-Control 'no-store no-cache, must-revalidate, proxy-revalidate, max-age=0'; + if_modified_since off; + expires off; + } + + location ~^/api/pm/ { + proxy_pass http://backend-service.pm.svc.cluster.local:8000; + } + + location ~^/(api|admin)/ { + # proxy_set_header Host $host; + # proxy_set_header Referer $http_referer; + proxy_pass http://backend-service:8000; + } + + location @index { + add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0'; + if_modified_since off; + expires off; + try_files /static/index.html =404; + } + + location /service-worker.js { + try_files /static/$uri @index; + } + + location ~ ^/workspaces-v2/(.+)\.wasm$ { + rewrite /workspaces-v2/(.+) /$1 break; + proxy_pass http://workspaces-v2-frontend-static-service.workspaces.svc.cluster.local:80; + + add_header Content-Type application/wasm; + proxy_set_header Accept application/wasm; + + } + + location ~ ^/workspaces-v2/(.+)\.js$ { + rewrite /workspaces-v2/(.+) /$1 break; + proxy_pass http://workspaces-v2-frontend-static-service.workspaces.svc.cluster.local:80; + } + location ~^/comparisons/static/(.+).js { + rewrite /comparisons/static/(.+) /$1 break; + proxy_pass http://frontend-service.comparisons.svc.cluster.local:80; + } + + location / { + try_files $uri @index; + } + } + } +kind: ConfigMap +metadata: + name: nginx-configmap + namespace: django diff --git a/apps/django/asterus/s3-proxy.yaml b/apps/django/asterus/s3-proxy.yaml new file mode 100644 index 0000000..42bfa92 --- /dev/null +++ b/apps/django/asterus/s3-proxy.yaml @@ -0,0 +1,113 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: s3-proxy + namespace: django + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + s3-proxy: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/s3-proxy:stable + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: s3-proxy + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: s3-proxy-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + envs: + - name: AWS_API_ENDPOINT + value: + _default: http://minio-service.minio.svc.cluster.local:9000 + - name: ACCESS_LOG + value: + _default: "true" + - name: CORS_ALLOW_HEADERS + value: + _default: "Content-Type, Accept-Ranges, Content-Range, Content-Encoding" + + secretEnvs: + - name: AWS_ACCESS_KEY_ID + secretName: + _default: sarex-media-storage-secret + secretKey: login + - name: AWS_SECRET_ACCESS_KEY + secretName: + _default: sarex-media-storage-secret + secretKey: password + - name: AWS_S3_BUCKET + secretName: + _default: sarex-media-storage-secret + secretKey: bucket + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/django/asterus/uwsgi-configmap.yaml b/apps/django/asterus/uwsgi-configmap.yaml new file mode 100644 index 0000000..6525e83 --- /dev/null +++ b/apps/django/asterus/uwsgi-configmap.yaml @@ -0,0 +1,30 @@ +apiVersion: v1 +data: + uwsgi.ini: |- + [uwsgi] + module = config.wsgi:application + DJANGO_SETTINGS_MODULE = config.settings.production + DEBUG = True + http = 0.0.0.0:8000 + processes = 8 + master = true + vacuum = true + enable-threads = true + buffer-size = 65535 + stats = :3031 + stats-http = true + memory-report = true + lazy-apps = true + # listen = 1024 + disable-write-exception= 0 + harakiri = 300 + socket-timeout = 300 + chunked-input-timeout = 300 + http-timeout = 300 + worker-reload-mercy = 240 + mule-reload-mercy = 240 + static-map = /api/static=/opt/sarex/static/ +kind: ConfigMap +metadata: + name: uwsgi-configmap + namespace: django diff --git a/apps/document-link/asterus/frontend.yaml b/apps/document-link/asterus/frontend.yaml new file mode 100644 index 0000000..5f72183 --- /dev/null +++ b/apps/document-link/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: document-link + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/document-link-frontend:83a92ae26b0bb38ee297c68c2a7a2c5a00811bfb + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 3000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 3000 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/document-link/asterus/kustomization.yaml b/apps/document-link/asterus/kustomization.yaml new file mode 100644 index 0000000..66c1795 --- /dev/null +++ b/apps/document-link/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: document-link +resources: + - frontend.yaml diff --git a/apps/documentations/asterus/api.yaml b/apps/documentations/asterus/api.yaml new file mode 100644 index 0000000..9c4e441 --- /dev/null +++ b/apps/documentations/asterus/api.yaml @@ -0,0 +1,294 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentations-api + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + documentations-api: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/documentations:prod_ace84de8 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: documentations-api + + replicaCount: + _default: 1 + + port: + _default: 8080 + + resources: + requests: + cpu: + _default: 500m + memory: + _default: 500Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 8080 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 60 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 8080 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 30 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: documentations-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8080 + + portName: + _default: http + + volumes: + _default: + - name: documentations-yc-s3-secret + mountPath: + _default: /etc/sarex/yc-s3-storage + readOnly: + _default: true + secret: + secretName: + _default: documentations-yc-s3 + + envs: + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: documentations_db + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8080 + - name: API_ADDRESS_FILE + value: + _default: 0.0.0.0:8080 + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_SSL + value: + _default: "0" + - name: ENABLE_S3 + value: + _default: "1" + - name: ENVIRONMENT + value: + _default: production + - name: HOST + value: + _default: https://sarex.asterus.ru + - name: VALKEY_PORT + value: + _default: "6379" + - name: VALKEY_HOST + value: + _default: redis + - name: VALKEY_ADDR + value: + _default: redis:6379 + - name: FILE_URL_EXTERNAL + value: + _default: https://sarex.asterus.ru/files + - name: DOCUMENTATION_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/ + - name: WORKFLOW_URL + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000/ + - name: WORKSPACE_URL + value: + _default: http://workspaces-service.workspaces.svc.cluster.local:8080/ + - name: WORKSPACE_V2_EXTERNAL_URL + value: + _default: https://sarex.asterus.ru/workspaces-v2/ + - name: BIM_API_URL + value: + _default: http://backend-service.bim.svc.cluster.local:8000/ + - name: BIM_API_V2_URL + value: + _default: http://backend-service.bim.svc.cluster.local:8000/ + - name: BIM_API_URL_EXTERNAL + value: + _default: https://sarex.asterus.ru/bim + - name: SYSTEM_LOG_URL + value: + _default: http://api-service.system-log.svc.cluster.local:8000/ + - name: MARKS_PROCESSING_URL + value: + _default: http://marks-service.documentations.svc.cluster.local:8000 + - name: WORKSPACE_BUNDLE_VERSION + value: + _default: v1 + - name: PUBLIC_LINK_HOST + value: + _default: https://document-link.asterus.ru + - name: FLOWS_URL + value: + _default: http://backend-service.flows.svc.cluster.local:8000 + - name: AUTOMATION_URL + value: + _default: http://automation-api-service.automation.svc.cluster.local:8000 + - name: DJANGO_HOST + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: NAMESPACE + value: + _default: documentations + - name: DJANGO_ORIGINATOR + value: + _default: docs_prod + - name: WORKFLOW_IMAGES_VERSION + value: + _default: master + - name: WORKFLOWS_IMAGES_VERSION + value: + _default: master + - name: S3_SERVICE_ACCOUNT + value: + _default: /etc/sarex/yc-s3-storage/yc-s3-service-account.json + - name: READ_WRITE_TIMEOUT_FILE_STREAM + value: + _default: 6h + - name: CACHE_DEFAULT_EXPIRATION + value: + _default: 60s + - name: CACHE_CLEANUP_INTERVAL + value: + _default: 60s + - name: USE_CACHE_IN_FILE_STREAMER + value: + _default: "1" + - name: SENTRY_DEBUG + value: + _default: "0" + - name: USE_LEGACY_BIM_FLOW + value: + _default: "true" + - name: DELETE_S3D_AFTER_MESHOPT + value: + _default: "true" + - name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES + value: + _default: "5" + - name: USE_BIMV1_FOR_BIMV2 + value: + _default: "0" + - name: LAST_MASTER_BIM + value: + _default: "36311" + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + - name: DJANGO_BASIC_AUTH_FOR_GET_USER + secretName: + _default: django-auth + secretKey: key + - name: DOCUMENT_PUBLIC_LINK_JWT_SECRET + secretName: + _default: yc-jwt-secret + secretKey: secret + - name: PUBLIC_KEY + secretName: + _default: public-key + secretKey: ssh_public.key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/asterus/filestream.yaml b/apps/documentations/asterus/filestream.yaml new file mode 100644 index 0000000..32ef157 --- /dev/null +++ b/apps/documentations/asterus/filestream.yaml @@ -0,0 +1,288 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentations-filestream + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + documentations-filestream: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/documentations-api-files:prod_5904312b + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: documentations-filestream + + replicaCount: + _default: 1 + + port: + _default: 8080 + + resources: + requests: + cpu: + _default: 150m + memory: + _default: 200Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 8080 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 60 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 8080 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 30 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: documentations-filestream-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8080 + + portName: + _default: http + + volumes: + _default: + - name: documentations-yc-s3-secret + mountPath: + _default: /etc/sarex/yc-s3-storage + readOnly: + _default: true + secret: + secretName: + _default: documentations-yc-s3 + + envs: + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: documentations_db + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8080 + - name: API_ADDRESS_FILE + value: + _default: 0.0.0.0:8080 + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_SSL + value: + _default: "0" + - name: ENABLE_S3 + value: + _default: "1" + - name: ENVIRONMENT + value: + _default: production + - name: HOST + value: + _default: https://sarex.asterus.ru + - name: FILE_URL_EXTERNAL + value: + _default: https://sarex.asterus.ru/files + - name: DOCUMENTATION_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/ + - name: WORKFLOW_URL + value: + _default: http://workflows-api-service.workflow.svc.cluster.local:80/ + - name: WORKSPACE_URL + value: + _default: http://workspaces-service.workspaces.svc.cluster.local:80/ + - name: WORKSPACE_V2_EXTERNAL_URL + value: + _default: https://sarex.asterus.ru/workspaces-v2/ + - name: BIM_API_URL + value: + _default: http://bim-api-service.bim-api.svc.cluster.local:5555/ + - name: BIM_API_V2_URL + value: + _default: http://bim-backend-v2-service.bim-api.svc.cluster.local:80/ + - name: BIM_API_URL_EXTERNAL + value: + _default: https://sarex.asterus.ru/bim + - name: SYSTEM_LOG_URL + value: + _default: http://api-service.system-log.svc.cluster.local:80 + - name: MARKS_PROCESSING_URL + value: + _default: http://marks-service.processing:8000 + - name: WORKSPACE_BUNDLE_VERSION + value: + _default: v1 + - name: PUBLIC_LINK_HOST + value: + _default: https://document-link.asterus.ru + - name: FLOWS_URL + value: + _default: http://backend-service.flows.svc.cluster.local:8000 + - name: AUTOMATION_URL + value: + _default: http://automation-api-service.automation.svc.cluster.local:8000 + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: NAMESPACE + value: + _default: documentations + - name: DJANGO_ORIGINATOR + value: + _default: docs_prod + - name: VALKEY_PORT + value: + _default: "6379" + - name: VALKEY_HOST + value: + _default: redis + - name: VALKEY_ADDR + value: + _default: redis:6379 + - name: WORKFLOW_IMAGES_VERSION + value: + _default: master + - name: WORKFLOWS_IMAGES_VERSION + value: + _default: master + - name: S3_SERVICE_ACCOUNT + value: + _default: /etc/sarex/yc-s3-storage/yc-s3-service-account.json + - name: READ_WRITE_TIMEOUT_FILE_STREAM + value: + _default: 6h + - name: CACHE_DEFAULT_EXPIRATION + value: + _default: 60s + - name: CACHE_CLEANUP_INTERVAL + value: + _default: 60s + - name: USE_CACHE_IN_FILE_STREAMER + value: + _default: "1" + - name: SENTRY_DEBUG + value: + _default: "0" + - name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES + value: + _default: "5" + - name: USE_BIMV1_FOR_BIMV2 + value: + _default: "1" + - name: LAST_MASTER_BIM + value: + _default: "36311" + + secretEnvs: + - name: DJANGO_BASIC_AUTH_FOR_GET_USER + secretName: + _default: django-auth + secretKey: key + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + - name: DOCUMENT_PUBLIC_LINK_JWT_SECRET + secretName: + _default: yc-jwt-secret + secretKey: secret + - name: PUBLIC_KEY + secretName: + _default: public-key + secretKey: ssh_public.key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/asterus/frontend.yaml b/apps/documentations/asterus/frontend.yaml new file mode 100644 index 0000000..e12b563 --- /dev/null +++ b/apps/documentations/asterus/frontend.yaml @@ -0,0 +1,123 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentation-frontend-static + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/documentation-frontend-app:brusnika_5a4e4adc + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: documentation-frontend-static + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 100m + memory: + _default: 100Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 10 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 10 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: documentation-frontend-static + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/asterus/hasher.yaml b/apps/documentations/asterus/hasher.yaml new file mode 100644 index 0000000..7bcb684 --- /dev/null +++ b/apps/documentations/asterus/hasher.yaml @@ -0,0 +1,145 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: hasher + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + hasher: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/hasher:production_3f853d3a + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: normal + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + envs: + - name: HASHER_APP__LOG_LEVEL + value: + _default: INFO + - name: HASHER_APP__NUM_WORKERS + value: + _default: "4" + - name: HASHER_AMQP__ROUTING__TASK_INPUT_QUEUE + value: + _default: hash.compute.normal.tasks + - name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE + value: + _default: hash.compute + - name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE_TYPE + value: + _default: direct + - name: HASHER_AMQP__ROUTING__TASK_INPUT_ROUTING_KEY + value: + _default: hash.compute.normal + - name: HASHER_S3__MAX_POOL_CONNECTIONS + value: + _default: "10" + - name: HASHER_S3__CONNECT_TIMEOUT + value: + _default: "10" + - name: HASHER_S3__READ_TIMEOUT + value: + _default: "30" + - name: HASHER_S3__REGION_NAME + value: + _default: ru-central1 + - name: HASHER_S3__USE_SSL + value: + _default: "true" + - name: HASHER_S3__VERIFY + value: + _default: "true" + + secretEnvs: + - name: HASHER_AMQP__USERNAME + secretName: + _default: hasher-rabbitmq-secret + secretKey: user + - name: HASHER_AMQP__PASSWORD + secretName: + _default: hasher-rabbitmq-secret + secretKey: password + - name: HASHER_AMQP__HOST + secretName: + _default: hasher-rabbitmq-secret + secretKey: host + - name: HASHER_AMQP__PORT + secretName: + _default: hasher-rabbitmq-secret + secretKey: port + - name: HASHER_AMQP__VHOST + secretName: + _default: hasher-rabbitmq-secret + secretKey: vhost + - name: HASHER_S3__ENDPOINT + secretName: + _default: hasher-s3-secret + secretKey: endpoint + - name: HASHER_S3__ACCESS_KEY + secretName: + _default: hasher-s3-secret + secretKey: access_key + - name: HASHER_S3__SECRET_KEY + secretName: + _default: hasher-s3-secret + secretKey: secret_key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/asterus/kustomization.yaml b/apps/documentations/asterus/kustomization.yaml new file mode 100644 index 0000000..ef39561 --- /dev/null +++ b/apps/documentations/asterus/kustomization.yaml @@ -0,0 +1,12 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: documentations +resources: + - frontend.yaml + - api.yaml + - filestream.yaml + - hasher.yaml + - pdf-markings-amqp.yaml + - pdf-markings.yaml + - pdm.yaml diff --git a/apps/documentations/asterus/pdf-markings-amqp.yaml b/apps/documentations/asterus/pdf-markings-amqp.yaml new file mode 100644 index 0000000..4939801 --- /dev/null +++ b/apps/documentations/asterus/pdf-markings-amqp.yaml @@ -0,0 +1,171 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: pdf-markings-amqp + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + pdf-markings-amqp: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pdf-markings-amqp:prod_3ab263be + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: pdf-markings-amqp + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + volumes: + _default: + - name: yc-s3 + mountPath: + _default: /etc/sarex/yc-s3-storage + readOnly: + _default: true + secret: + secretName: + _default: yc-s3 + + envs: + - name: MARKS_APP__LOG_LEVEL + value: + _default: INFO + - name: MARKS_CRYPTO__HASHING_ALGO + value: + _default: md_gost12_256 + - name: MARKS_DOCUMENTS_DB__HOST + value: + _default: postgres-service + - name: MARKS_DOCUMENTS_DB__PORT + value: + _default: "5432" + - name: MARKS_DOCUMENTS_DB__DATABASE + value: + _default: documentations_db + - name: MARKS_DOCUMENTS_DB__SSLMODE + value: + _default: disable + - name: MARKS_QR__REDIRECT_URL + value: + _default: https://stamp-verification.sarex.asterus.ru/ + - name: MARKS_QR__BASE_DOCUMENT_URL + value: + _default: https://sarex.asterus.ru + - name: MARKS_S3__USE_SSL + value: + _default: "false" + - name: MARKS_S3__SSL_VERIFY + value: + _default: "false" + - name: MARKS_S3__REGION + value: + _default: ru-central1 + - name: MARKS_S3__DEFAULT_BUCKET + value: + _default: documentations-stage-1-sarex-new + - name: MARKS_RABBITMQ__ROUTING__INPUT_QUEUE + value: + _default: pdf_markings_input + + secretEnvs: + - name: MARKS_DOCUMENTS_DB__USERNAME + secretName: + _default: postgres-secret + secretKey: username + - name: MARKS_DOCUMENTS_DB__PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: MARKS_S3__URL + secretName: + _default: yc-s3 + secretKey: endpoint_url + - name: MARKS_S3__ACCESS_KEY + secretName: + _default: yc-s3 + secretKey: key_id + - name: MARKS_S3__SECRET_KEY + secretName: + _default: yc-s3 + secretKey: access_key + - name: MARKS_RABBITMQ__HOST + secretName: + _default: rabbitmq + secretKey: host + - name: MARKS_RABBITMQ__PORT + secretName: + _default: rabbitmq + secretKey: port + - name: MARKS_RABBITMQ__USERNAME + secretName: + _default: rabbitmq + secretKey: username + - name: MARKS_RABBITMQ__PASSWORD + secretName: + _default: rabbitmq + secretKey: password + - name: MARKS_RABBITMQ__VHOST + secretName: + _default: rabbitmq + secretKey: vhost + - name: MARKS_RABBITMQ__HEARTBEAT_SECONDS + secretName: + _default: rabbitmq + secretKey: heartbeat + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/asterus/pdf-markings.yaml b/apps/documentations/asterus/pdf-markings.yaml new file mode 100644 index 0000000..0be5fba --- /dev/null +++ b/apps/documentations/asterus/pdf-markings.yaml @@ -0,0 +1,174 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: pdf-markings + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + pdf-markings: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/process-pdf-marks-service:0.3.3 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: pdf-markings + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: marks-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: yc-s3 + mountPath: + _default: /etc/sarex/yc-s3-storage + readOnly: + _default: true + secret: + secretName: + _default: documentations-yc-s3 + + envs: + - name: APP_NAME + value: + _default: pdm_v2 + - name: VERIFY + value: + _default: "False" + - name: APP_VERSION + value: + _default: 0.0.1 + - name: LOG_LEVEL + value: + _default: INFO + - name: HTTP_PORT + value: + _default: "8000" + - name: DOC_POSTGRES_HOST + value: + _default: postgres-service + - name: DOC_POSTGRES_PORT + value: + _default: "5432" + - name: DOC_POSTGRES_DB + value: + _default: documentations_db + - name: DOC_POSTGRES_POOL_SIZE + value: + _default: "10" + - name: DOC_POSTGRES_SSL_MODE + value: + _default: disable + - name: API_ADDRESS + value: + _default: 0.0.0.0:8000 + - name: DATABASE_SSL_MODE + value: + _default: disable + - name: YANDEX_S3_USE_SSL + value: + _default: "0" + - name: ENVIRONMENT + value: + _default: production + - name: YANDEX_S3_ACCOUNT_PATH + value: + _default: /etc/sarex/yc-s3-storage/yc-s3-service-account.json + - name: REDIRECT_URL_QR + value: + _default: https://stamp-verification.asterus.ru/ + - name: BASE_DOCUMENT_URL + value: + _default: https://sarex.asterus.ru + + secretEnvs: + - name: DOC_POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DOC_POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: YANDEX_S3_ENDPOINT_URL + secretName: + _default: yc-s3 + secretKey: endpoint_url + - name: YANDEX_S3_SECRET_ACCESS_KEY + secretName: + _default: yc-s3 + secretKey: access_key + - name: YANDEX_S3_ACCESS_KEY_ID + secretName: + _default: yc-s3 + secretKey: key_id + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/asterus/pdm.yaml b/apps/documentations/asterus/pdm.yaml new file mode 100644 index 0000000..93f625a --- /dev/null +++ b/apps/documentations/asterus/pdm.yaml @@ -0,0 +1,291 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: pdm-api + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + pdm-api: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pdmv2:prod_9507c2d5 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: pdm-api + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: pdm-api + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 8080 + + portName: + _default: http + + volumes: + _default: + - name: documentations-yc-s3-secret + mountPath: + _default: /etc/sarex/yc-s3-storage + readOnly: + _default: true + secret: + secretName: + _default: documentations-yc-s3-pdm + + envs: + - name: BIM_V2_HOST + value: + _default: "" + - name: DRAWINGS_INTERNAL_URL + value: + _default: "" + - name: ENABLE_PERMISSIONS_FILTER + value: + _default: "1" + - name: PERMISSIONS_FILTER_COMPANIES + value: + _default: "[1]" + - name: S3_SERVICE_ACCOUNT + value: + _default: /etc/sarex/yc-s3-storage/yc-s3-service-account.json + - name: APP_NAME + value: + _default: pdm_v2 + - name: APP_VERSION + value: + _default: 0.0.1 + - name: LOG_LEVEL + value: + _default: INFO + - name: HTTP_PORT + value: + _default: "8080" + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: documentations_db + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8080 + - name: API_ADDRESS_FILE + value: + _default: 0.0.0.0:8080 + - name: ENABLE_OBSERVABILITY + value: + _default: "1" + - name: ENABLE_SSL + value: + _default: "0" + - name: ENABLE_S3 + value: + _default: "1" + - name: FILE_URL_EXTERNAL + value: + _default: https://sarex.asterus.ru/files + - name: DOCUMENTATION_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/ + - name: WORKFLOW_URL + value: + _default: http://workflows-api-service.workflow.svc.cluster.local:80/ + - name: WORKSPACE_URL + value: + _default: http://workspaces-service.workspaces.svc.cluster.local:8080 + - name: BIM_API_URL + value: + _default: http://bim-api-service.bim-api.svc.cluster.local:5555/ + - name: BIM_API_V2_URL + value: + _default: http://bim-backend-v2-service.bim-api.svc.cluster.local:80/ + - name: BIM_API_URL_EXTERNAL + value: + _default: https://docs.dogma.ru/bim + - name: WORKSPACE_BUNDLE_VERSION + value: + _default: v1 + - name: DJANGO_HOST + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: NAMESPACE + value: + _default: documentations + - name: DJANGO_ORIGINATOR + value: + _default: docs_prod + - name: FLOWS_URL + value: + _default: http://backend-service.flows.svc.cluster.local:8000 + - name: NOTES_URL + value: + _default: https://sarex.asterus.ru/notes + - name: RESOURCES_URL + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: REMARKS_URL + value: + _default: https://sarex.asterus.ru/remarks + - name: WORKFLOW_IMAGES_VERSION + value: + _default: master + - name: WORKFLOWS_IMAGES_VERSION + value: + _default: master + - name: ATTACHMENTS_URL + value: + _default: http://attachments-service.attachments.svc.cluster.local:80 + - name: STATES_URL + value: + _default: http://workspaces-service.workspaces.svc.cluster.local:8080 + - name: INSPECTIONS_URL + value: + _default: http://inspections-service.inspections.svc.cluster.local:8000 + - name: WIDTH_THUMB_STATES + value: + _default: "120" + - name: HEIGHT_THUMB_STATES + value: + _default: "73" + - name: WIDTH_THUMB_ATTACHMENTS + value: + _default: "300" + - name: HEIGHT_THUMB_ATTACHMENTS + value: + _default: "300" + - name: SUBSCRIPTIONS_URL + value: + _default: http://sarex-subscriptions-service.subscriptions.svc.cluster.local:80 + - name: EAV_URL + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: SYSTEM_LOG_URL + value: + _default: http://api-service.system-log.svc.cluster.local:8000 + - name: API_HOST_PREFIX + value: + _default: /gateway + - name: TRANSMITTALS_BASE_URL + value: + _default: "" + - name: TRANSMITTALS_ENABLE + value: + _default: "false" + - name: TARGET_URL + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: RELEASES_URL + value: + _default: https://gitlab.com + - name: READ_WRITE_TIMEOUT_FILE_STREAM + value: + _default: 6h + - name: CACHE_DEFAULT_EXPIRATION + value: + _default: 60s + - name: CACHE_CLEANUP_INTERVAL + value: + _default: 60s + - name: USE_CACHE_IN_FILE_STREAMER + value: + _default: "1" + - name: SENTRY_DEBUG + value: + _default: "0" + - name: ENVIRONMENT + value: + _default: prod + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + - name: PUBLIC_KEY + secretName: + _default: public-key + secretKey: ssh_public.key + - name: RELEASES_TOKEN + secretName: + _default: releases-token + secretKey: key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/eav/asterus/asset.yaml b/apps/eav/asterus/asset.yaml new file mode 100644 index 0000000..39659b7 --- /dev/null +++ b/apps/eav/asterus/asset.yaml @@ -0,0 +1,160 @@ +apiVersion: v1 +data: + asset.py: | + from typing import List + + from django.conf import settings + from django.http import HttpResponseBadRequest + from django_filters import rest_framework as django_filters + from rest_framework import status + from rest_framework.decorators import action + from rest_framework.response import Response + from rest_framework import filters + + from rest_framework.viewsets import ModelViewSet + + from assets.api.v0.filters.asset import AssetFilter + from assets.models import Asset + from assets.serializers import ( + AssetSerializer, + AssetSearchSerializer, + # AssetCopySerializer, + AssetCopyRequestSerializer, + ) + from core.permissions import CompanyIdTokenBasedPermission + + + class AssetViewSet(ModelViewSet): + + queryset = Asset.objects.all() + + filterset_class = AssetFilter + filter_backends = (django_filters.DjangoFilterBackend, filters.OrderingFilter, ) + + serializer_class = AssetSerializer + topic = settings.ASSETS_TOPIC + permission_classes = [CompanyIdTokenBasedPermission, ] + + ordering_fields = ['created_at', 'name'] + ordering = ['-created_at'] + + def get_queryset(self): + validated_token = self.request.auth + print(self.request.auth) + #user_company_ids = validated_token.get("company_ids") + is_superuser = True + if is_superuser: + return Asset.objects.all() + return Asset.objects.filter( + tenant_id__in=1, + ) + + def get_serializer(self, *args, **kwargs): + if isinstance(kwargs.get("data", {}), list): + kwargs["many"] = True + return super().get_serializer(*args, **kwargs) + + def list_update(self, request, *args, **kwargs): + instances = self.get_queryset().filter(id__in=[item.get('id') for item in request.data]) + serializer = self.serializer_class(instances, data=request.data, many=True) + serializer.is_valid(raise_exception=True) + serializer.save() + return Response(serializer.data, status=status.HTTP_200_OK) + + def list_partial_update(self, request, *args, **kwargs): + instances = self.get_queryset().filter(id__in=[item.get('id') for item in request.data]) + serializer = self.serializer_class(instances, data=request.data, many=True, partial=True) + serializer.is_valid(raise_exception=True) + serializer.save() + return Response(serializer.data, status=status.HTTP_200_OK) + + def destroy(self, request, *args, **kwargs): + serializer = self.get_serializer() + parent = self.get_object() + instances = self.queryset.filter(path__icontains=parent.id) + for i in instances: + serializer.destroy(i) + return Response(None, status=status.HTTP_200_OK) + + @action(detail=True, methods=['post']) + def copy(self, request, *args, **kwargs): + serializer = self.get_serializer() + request_serializer = AssetCopyRequestSerializer(data=request.data) + source = self.get_object() + + if source.parent_id: + return HttpResponseBadRequest("Only root assets are allowed") + + request_serializer.is_valid(raise_exception=True) + if request_serializer.validated_data["recursive"]: + name = request_serializer.validated_data["destination"]["name"] if \ + request_serializer.validated_data["destination"]["name"] else source.name + destination = self.copy_recursive(source.id, name, + request_serializer.validated_data["destination"]["resource_id"]) + else: + destination = serializer.copy(source, request_serializer.validated_data["destination"]) + return Response(AssetSerializer(destination).data, status=status.HTTP_201_CREATED) + + def copy_recursive(self, root_id: int, root_name: str, resource_id: str) -> Asset: + root_copy = None + serializer = self.get_serializer() + copies_map = {} + + # Мы должны гарантировать, что дочерние ноды будут созданы в базе не раньше родительских + sorted_nodes = self.sort_nodes(root_id) + + for source in sorted_nodes: + # Установить имя копии как у оригинала, но в случае рута - целевое имя + if source.parent_id: + copy_data = { + "name": source.name, + "parent_id": copies_map[source.parent_id], + "resource_id": resource_id + } + destination = serializer.copy(source, copy_data) + else: + copy_data = { + "name": root_name, + "parent_id": None, + "resource_id": resource_id + } + destination = serializer.copy(source, copy_data) + root_copy = destination + + copies_map[source.id] = destination.id + return root_copy + + def sort_nodes(self, root_id: int) -> List[Asset]: + nodes_instances = self.queryset.filter(path__icontains=root_id) + sort_dict = {} + sorted_nodes = [] + + for node in nodes_instances: + # Так как копировать можно только руты, уровень вложенности можно посчитать по количеству точек в пути + node_level = node.path.count('.') + if node_level not in sort_dict: + sort_dict[node_level] = [] + sort_dict[node_level].append(node) + + current_level = 0 + while current_level in sort_dict: + sorted_nodes.extend(sort_dict[current_level]) + current_level += 1 + + return sorted_nodes + + @action(detail=False, methods=["POST"]) + def search(self, request, *args, **kwargs): + request_serializer = AssetSearchSerializer(data=request.data) + request_serializer.is_valid(raise_exception=True) + + instances = self.get_queryset() + if request_serializer.data["id"]: + instances = instances.filter(id__in=request_serializer.data["id"]) + + serializer = self.serializer_class(instances, many=True) + return Response(serializer.data, status=status.HTTP_200_OK) +kind: ConfigMap +metadata: + name: asset + namespace: eav diff --git a/apps/eav/asterus/backend.yaml b/apps/eav/asterus/backend.yaml new file mode 100644 index 0000000..6489a1c --- /dev/null +++ b/apps/eav/asterus/backend.yaml @@ -0,0 +1,221 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: eav + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/eav:prod_2460295f + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: eav-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: django-configmap + mountPath: + _default: /server/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: django-configmap + items: + - key: production.py + path: + _default: production.py + + - name: asset + mountPath: + _default: /server/assets/api/v0/views/asset.py + subPath: + _default: asset.py + readOnly: + _default: true + configMap: + name: + _default: asset + items: + - key: asset.py + path: + _default: asset.py + + - name: schema + mountPath: + _default: /server/main/api/v4/views/schema.py + subPath: + _default: schema.py + readOnly: + _default: true + configMap: + name: + _default: schema + items: + - key: schema.py + path: + _default: schema.py + + - name: permissions + mountPath: + _default: /server/core/permissions.py + subPath: + _default: permissions.py + readOnly: + _default: true + configMap: + name: + _default: permissions + items: + - key: permissions.py + path: + _default: permissions.py + + - name: kafka-cert-volume + mountPath: + _default: /usr/local/share/ca-certificates + readOnly: + _default: true + configMap: + name: + _default: kafka-cert + + envs: + - name: KAFKA_USERNAME + value: + _default: sarex + - name: KAFKA_SSL_CAFILE + value: + _default: /usr/local/share/ca-certificates/kafka.crt + - name: KAFKA_HOST + value: + _default: asterus-kafka-kafka-bootstrap.kafka.svc.cluster.local:9093 + - name: ASSETS_TOPIC + value: + _default: assets-broadcast + - name: DJANGO_SETTINGS_MODULE + value: + _default: config.settings.production + - name: KAFKA_ENABLED + value: + _default: "False" + - name: DJANGO_POSTGRES_HOST + value: + _default: postgres-service + - name: DJANGO_POSTGRES_DATABASE + value: + _default: eav_db + - name: YC_S3_ENDPOINT_URL + value: + _default: http://minio-service.minio.svc.cluster.local:9000 + - name: YC_S3_BUCKET_NAME + value: + _default: eav + + secretEnvs: + - name: KAFKA_PASSWORD + secretName: + _default: kafka-cred + secretKey: password + - name: DJANGO_POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DJANGO_POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: JWT_PRIVATE_KEY + secretName: + _default: backend-secret + secretKey: ssh_private.key + - name: JWT_PUBLIC_KEY + secretName: + _default: backend-secret + secretKey: ssh_public.key + - name: YC_S3_ACCESS_KEY_ID + secretName: + _default: s3-secret + secretKey: login + - name: YC_S3_SECRET_ACCESS_KEY + secretName: + _default: s3-secret + secretKey: password + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/eav/asterus/django-configmap.yaml b/apps/eav/asterus/django-configmap.yaml new file mode 100644 index 0000000..834a5fe --- /dev/null +++ b/apps/eav/asterus/django-configmap.yaml @@ -0,0 +1,145 @@ +apiVersion: v1 +data: + production.py: | + # production.py + + from .base import * + from datetime import timedelta + import os + from django.core.exceptions import ImproperlyConfigured + + INSTALLED_APPS.append("corsheaders") + MIDDLEWARE = ["corsheaders.middleware.CorsMiddleware"] + MIDDLEWARE + + # DEBUG SETTINGS START + # --------------------------------------------------------------------------------------------------------------------- + DEBUG = True + ALLOWED_HOSTS = ['*'] + # --------------------------------------------------------------------------------------------------------------------- + # DEBUG SETTINGS END + + # DATABASE SETTINGS START + # --------------------------------------------------------------------------------------------------------------------- + DATABASES = { + "default": { + "ENGINE": "django.db.backends.postgresql", + "NAME": os.getenv("DJANGO_POSTGRES_DATABASE"), + "USER": os.getenv("DJANGO_POSTGRES_USER"), + "PASSWORD": os.getenv("DJANGO_POSTGRES_PASSWORD"), + "HOST": os.getenv("DJANGO_POSTGRES_HOST"), + "PORT": "5432", + } + } + # --------------------------------------------------------------------------------------------------------------------- + # DATABASE SETTINGS END + + # RESPONSE HEADERS START + # --------------------------------------------------------------------------------------------------------------------- + CORS_ORIGIN_ALLOW_ALL = True + + CORS_ALLOWED_ORIGINS = [ + "https://sarex.asterus.ru", + ] + + CORS_TRUSTED_ORIGINS = [ + "https://sarex.asterus.ru", + ] + + CSRF_TRUSTED_ORIGINS = [ + "https://sarex.asterus.ru", + ] + + CORS_ALLOW_METHODS = ( + 'DELETE', + 'GET', + 'OPTIONS', + 'PATCH', + 'POST', + 'PUT', + ) + + CORS_ALLOW_HEADERS = ( + 'accept', + 'accept-encoding', + 'authorization', + 'content-type', + 'user-agent', + 'x-csrftoken', + 'x-requested-with', + 'x-token', + 'Bearer' + ) + # --------------------------------------------------------------------------------------------------------------------- + # RESPONSE HEADERS END + + REST_FRAMEWORK = { + "DEFAULT_PAGINATION_CLASS": ( + "rest_framework.pagination.LimitOffsetPagination" + ), + "DEFAULT_SCHEMA_CLASS": "rest_framework.schemas.coreapi.AutoSchema", + "PAGE_SIZE": 10000, + "DEFAULT_FILTER_BACKENDS": [ + "django_filters.rest_framework.DjangoFilterBackend" + ], + "DEFAULT_AUTHENTICATION_CLASSES": [ + # "rest_framework_simplejwt.authentication.JWTAuthentication", + "rest_framework.authentication.SessionAuthentication", + "rest_framework.authentication.BasicAuthentication", + ], + "DEFAULT_PERMISSION_CLASSES": [ + "rest_framework.permissions.AllowAny", + ] + } + + # JWT SETTINGS START + # --------------------------------------------------------------------------------------------------------------------- + def get_env_variable(var_name, default=None): + try: + return os.getenv(var_name, default) + except KeyError: + error_msg = f"Set the {var_name} environment variable" + if default: + return default + raise ImproperlyConfigured(error_msg) + + SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="django") + + SIMPLE_JWT = { + "ACCESS_TOKEN_LIFETIME": timedelta(minutes=5), + "REFRESH_TOKEN_LIFETIME": timedelta(days=1), + "ROTATE_REFRESH_TOKENS": False, + "UPDATE_LAST_LOGIN": False, + + "ALGORITHM": "RS512", + "SIGNING_KEY": get_env_variable("JWT_PRIVATE_KEY").replace("\\\n", "\n"), + "VERIFYING_KEY": get_env_variable("JWT_PUBLIC_KEY").replace("\\\n", "\n"), + "AUDIENCE": None, + "ISSUER": SIMPLE_JWT_ISSUER, + + "AUTH_HEADER_TYPES": ("Bearer",), + "AUTH_HEADER_NAME": "HTTP_AUTHORIZATION", + "USER_ID_FIELD": "id", + "USER_ID_CLAIM": "user_id", + + "AUTH_TOKEN_CLASSES": ("rest_framework_simplejwt.tokens.AccessToken",), + "TOKEN_TYPE_CLAIM": "token_type", + + "JTI_CLAIM": "jti", + + "SLIDING_TOKEN_REFRESH_EXP_CLAIM": "refresh_exp", + "SLIDING_TOKEN_LIFETIME": timedelta(minutes=5), + "SLIDING_TOKEN_REFRESH_LIFETIME": timedelta(days=1), + } + # --------------------------------------------------------------------------------------------------------------------- + # JWT SETTINGS END + + STATIC_ROOT = '/static/' + STATIC_URL = '/static/' + STATICFILES_STORAGE = 'django.contrib.staticfiles.storage.StaticFilesStorage' + + SESSION_COOKIE_NAME = 'eav-sessionid' + CSRF_COOKIE_NAME = 'eav-csrftoken' +kind: ConfigMap +metadata: + name: django-configmap + namespace: eav diff --git a/apps/eav/asterus/kafka-cert.yaml b/apps/eav/asterus/kafka-cert.yaml new file mode 100644 index 0000000..5f078bd --- /dev/null +++ b/apps/eav/asterus/kafka-cert.yaml @@ -0,0 +1,37 @@ +apiVersion: v1 +data: + kafka.crt: | + -----BEGIN CERTIFICATE----- + MIIFLTCCAxWgAwIBAgIUeuNKW4rB4ReiwjDidNIdob7VRokwDQYJKoZIhvcNAQEN + BQAwLTETMBEGA1UECgwKaW8uc3RyaW16aTEWMBQGA1UEAwwNY2x1c3Rlci1jYSB2 + MDAeFw0yNTA4MjYxMDM0NDRaFw0yNjA4MjYxMDM0NDRaMC0xEzARBgNVBAoMCmlv + LnN0cmltemkxFjAUBgNVBAMMDWNsdXN0ZXItY2EgdjAwggIiMA0GCSqGSIb3DQEB + AQUAA4ICDwAwggIKAoICAQCv7lvKnTUpgnDd91YgCMQSYTSVUdkkQITXZENXj2km + UN5k2NhnDIMOeHD4Bu8fjSUvELcilNAgsPqKNWO97CWtU9/phxsQRMgDwywtyr8Q + W3Vc2RYk/7vcpi77M/IjmFoRExXowO9U3mLNd0vACk+yC7WObcNr9veFnVyrmoL3 + iOqLbmzKiZvdIz1f6lwDDOXNuj26Ct6jRatV96HcqKzK50Jj9eS5SvV57JQLvTsZ + LbPnesAxgKzW7sci6N9lB9jrDirBl2h/QJXAmhUyg2yAvrU8wBTTpQWCdQRQ54Pv + LCZV3iXMkTYkxoyCg/GPbb2M7DF1sEe45iWsYkqDsWvdhirfp8BBVp+oni3xmj9J + +8hzB2MZhyA9i6v6Hfua7d0ExKUhuJkUxBcGyFHbXpC2m2m8plaHL2mNBXAuQZDw + wf+aHvHo2QLoNFL2xR8/63IHosnnRgzdKpZX6Z1Ftd8caHf/L+XgI3ET8LwklC55 + y4FmFQwd8rOGiR38Ixg9zhr44tV3foWWrIM+sb/ni4UokeGkX2AymSsdln9pAnIj + usGG9ZuSZUPZ+w5HjtL3hxh9pbGdYja2YcfusCCQK56LBWRJnB8W/IafEOvVxMT/ + gqx6Hee/geY3G2LRlMfsLRAbCvYOIi7kDzOM/LnM+XlbEkJO8uyjnT5wbCFCRnvy + nwIDAQABo0UwQzAdBgNVHQ4EFgQUeNSYqykN5qUxAfLJ7z9Say0XIHAwEgYDVR0T + AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQADggIB + AH82HGTXnJKbBln7q+Wx9chwMUFZc4u43Q0QAvCgGXMRFa5Dl4x/9rtrYYuDpZwh + /GKgOkhZ/SKLeuy9e7bgoHnt2sNR4CqAjK6YQp7o5aBNRGhiQZTkfjoG/P17AV7e + nKP65WXPAirouUxlvC8Kplh2vsuUkGcjzsKRTYQRNR1+yHw+P91qcX+RglrHFyMJ + wWKOldwgR3Mit+tAMbgioqrNTmwIEREDCF0DcJuX3LKTo7/q3I9cMFhz7/kk5CTm + pePoWMcvhgOX/cQcqNA7Q0HAOIV3OioxAod+XyjpaTo42YrTUSjq5Rl2a9U7GNN/ + xazxT+YDs/mHSP0Yt/5jxMSjsifPP4l4KP9YvqiC7UZGrZ9ctzkg3UlQmr87Km9W + FqVLoX6Y1OmNB/c5XCg4S4g2q5VavXM792fn1ow6oR5hgDHXBLNA+TKWFmJ5UXJB + z4l7Hn7rFJB5e9QVEDRIzr8c2QcUZ668kicP3Oh45NywMcSV6GZO4PNDNsNW0kFf + 3txTYwDEvT3n83C0lybw2hgLl3Q//lX+Zn3TMdqGVXkCXR0df45U8p14Wfe7QRtb + Jmg3tvOOpueyc3I+mrpDbyxdYQxr8IZdFoaV+mZUCi+ezMrHBNNNq0Lc/t2ICa+p + bpTSKuKNG91nPGXEd7sFGL8ZYypObQc5HC6wMCeVC3Cx + -----END CERTIFICATE----- +kind: ConfigMap +metadata: + name: kafka-cert + namespace: eav diff --git a/apps/eav/asterus/kustomization.yaml b/apps/eav/asterus/kustomization.yaml new file mode 100644 index 0000000..f4f98e1 --- /dev/null +++ b/apps/eav/asterus/kustomization.yaml @@ -0,0 +1,11 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: eav +resources: + - django-configmap.yaml + - asset.yaml + - schema.yaml + - permissions.yaml + - kafka-cert.yaml + - backend.yaml diff --git a/apps/eav/asterus/permissions.yaml b/apps/eav/asterus/permissions.yaml new file mode 100644 index 0000000..d682d81 --- /dev/null +++ b/apps/eav/asterus/permissions.yaml @@ -0,0 +1,124 @@ +apiVersion: v1 +data: + permissions.py: | + import re + + from rest_framework.permissions import BasePermission + from rest_framework.request import Request + + class CompanyIdTokenBasedPermission(BasePermission): + + def has_permission_to_retrieve(self, request: Request, view) -> bool: + validated_token = request.auth + user_company_ids = validated_token.get('company_ids', []) + company_id = request.query_params.get('company_id') + + if company_id is None: + company_id = request.query_params.get('tenant_id') + if company_id is None: + company_id = request.query_params.get('tenant_identifier') + if not company_id: + return True + + return True + + + class CompanyAttributeIdTokenBasedPermission(CompanyIdTokenBasedPermission): + + def has_permission_to_update(self, request: Request, view) -> bool: + validated_token = request.auth + user_company_ids = set(validated_token.get('company_ids', [])) + + if isinstance(request.data, list): + objects_ids = [obj.get("id") for obj in request.data] + else: + objects_ids = [request.data.get("id")] + + # Проверка, что множество компаний Пользователя включает множество затрагиваемых в БД + objects = view.queryset.filter(id__in=objects_ids) + affected_tenants = set(int(obj.tenant_identifier) for obj in objects) + return affected_tenants.issubset(user_company_ids) + + + + class CompanyIdTokenBasedPermission(BasePermission): + + def has_permission_to_retrieve(self, request: Request, view) -> bool: + validated_token = request.auth + print(request.auth, "########################") + user_company_ids = validated_token.get('company_ids', []) + company_id = request.query_params.get('company_id') + + if company_id is None: + company_id = request.query_params.get('tenant_id') + if company_id is None: + company_id = request.query_params.get('tenant_identifier') + if not company_id: + return True + + return int(company_id) in user_company_ids + + def has_permission_to_create(self, request: Request, view) -> bool: + validated_token = request.auth + affected_tenants = set() + user_company_ids = set(validated_token.get('company_ids', [])) + + if isinstance(request.data, list): + for obj in request.data: + affected_tenants.add(obj.get("tenant_id")) + else: + affected_tenants.add(request.data.get("tenant_id")) + # Проверка, что множество компаний Пользователя включает множество затрагиваемых полностью + return affected_tenants.issubset(user_company_ids) + + def has_permission_to_update(self, request: Request, view) -> bool: + validated_token = request.auth + user_company_ids = set(validated_token.get('company_ids', [])) + + if isinstance(request.data, list): + objects_ids = [obj.get("id") for obj in request.data] + else: + objects_ids = [request.data.get("id")] + + # Проверка, что множество компаний Пользователя включает множество затрагиваемых в БД + objects = view.queryset.filter(id__in=objects_ids) + affected_tenants = set(int(obj.tenant_id) for obj in objects) + return affected_tenants.issubset(user_company_ids) + + def has_object_permission(self, request, view, obj): + validated_token = request.auth + + user_company_ids = { + int(value) + for value in + validated_token.get("company_ids", []) + } + + if hasattr(obj, "tenant_id"): + tenant_id = int(getattr(obj, "tenant_id")) + return tenant_id in user_company_ids + + return True + + def has_permission(self, request, view) -> bool: + if request.auth is None: + if request.user is None: + return False + elif request.user.is_superuser: + return True + + if request.method == "GET": + #return self.has_permission_to_retrieve(request, view) + return True + elif request.method == "POST": + if re.fullmatch(".*/*/copy/", request.path): + return True # Проверка прав перекладывается на has_object_permission() + if re.fullmatch(".*/*/search/", request.path): + return True + return self.has_permission_to_create(request, view) + else: + return self.has_permission_to_update(request, view) +kind: ConfigMap +metadata: + name: permissions + namespace: eav diff --git a/apps/eav/asterus/schema.yaml b/apps/eav/asterus/schema.yaml new file mode 100644 index 0000000..569eeac --- /dev/null +++ b/apps/eav/asterus/schema.yaml @@ -0,0 +1,43 @@ +apiVersion: v1 +data: + schema.py: | + from rest_framework.viewsets import ModelViewSet + from rest_framework.permissions import IsAuthenticated + + from core.permissions import CompanyIdTokenBasedPermission + from main.models import AttributeSchema + from main.api.v0.filters import AttributeSchemaFilterSet + from main.serializers import ( + AttributeSchemaCreateSerializer, + AttributeSchemaRetrieveSerializer, + ) + + + class AttributeSchemaViewSet(ModelViewSet): + + queryset = AttributeSchema.public.all() + create_serializer_class = AttributeSchemaCreateSerializer + retrieve_serializer_class = AttributeSchemaRetrieveSerializer + filterset_class = AttributeSchemaFilterSet + #permission_classes = [IsAuthenticated, CompanyIdTokenBasedPermission] + + filterset_fields = [ + "model_name", + "type_identifier", + "service_name", + ] + + def get_serializer_class(self): + if self.action in ("retrieve", "list",): + return self.retrieve_serializer_class + return self.create_serializer_class + + def filter_queryset(self, queryset, *args, **kwargs): + qs = super().filter_queryset(queryset) + qs = qs.filter(published=True) + qs = qs.order_by("tenant_identifier") + return qs +kind: ConfigMap +metadata: + name: schema + namespace: eav diff --git a/apps/flows/asterus/authentication.yaml b/apps/flows/asterus/authentication.yaml new file mode 100644 index 0000000..4323429 --- /dev/null +++ b/apps/flows/asterus/authentication.yaml @@ -0,0 +1,89 @@ +apiVersion: v1 +data: + authentication.py: | + import httpx + + from fastapi import Request, status + from itsdangerous import URLSafeTimedSerializer, BadData as BadDataError + from sqladmin.authentication import AuthenticationBackend + + from flow.config import settings + + + class AdminAuthentication(AuthenticationBackend): + def get_serializer(self) -> URLSafeTimedSerializer: + return URLSafeTimedSerializer( + secret_key=settings.admin_panel.secret_key, + ) + + async def login(self, request: Request) -> bool: + form = await request.form() + username, password = form["username"], form["password"] + + # получаем данные о юзере + if settings.django.use: + print("OK"*30) + client: httpx.AsyncClient = settings.django.get_async_session(token=settings.django.token) + async with client as session: + auth_response = await session.post(url='/login/', json={ + 'username': username, + 'password': password, + }, follow_redirects=False) + print("*"*30, auth_response.status_code ,settings.django.host, username, password,"*"*30) + # if auth_response.status_code != status.HTTP_200_OK: + # return False + + # django_response = await session.get(url='/client/settings/') + # print("$"*30, django_response.status_code, "$"*30) + # if django_response.status_code != status.HTTP_200_OK: + # return False + if username == "sarex_test" and password == "9293213v": + #user = django_response.json() + has_access = True + if not has_access: + return False + + user_id = 209 + + token_payload = { + 'is_django_user': True, + 'user_id': user_id, + } + else: + token_payload = { + 'is_django_user': False, + 'user_id': None, + } + + token = self.get_serializer().dumps(token_payload) + + request.session.update({"token": token}) + return True + + async def logout(self, request: Request) -> bool: + request.session.clear() + return True + + async def authenticate(self, request: Request) -> bool: + token = request.session.get("token") + + if not token: + return False + + try: + payload = self.get_serializer().loads(token, max_age=settings.admin_panel.token_max_age) + except (BadDataError, KeyError): + return False + + is_django_user = payload.get('is_django_user') + if settings.django.use != is_django_user: + return False + + return True + + + authentication_backend = AdminAuthentication(secret_key=settings.admin_panel.secret_key) +kind: ConfigMap +metadata: + name: authentication + namespace: flows diff --git a/apps/flows/asterus/backend.yaml b/apps/flows/asterus/backend.yaml new file mode 100644 index 0000000..472b013 --- /dev/null +++ b/apps/flows/asterus/backend.yaml @@ -0,0 +1,250 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_6671091d + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 4 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: authentication + mountPath: + _default: /opt/src/flow/admin/authentication.py + subPath: + _default: authentication.py + readOnly: + _default: true + configMap: + name: + _default: authentication + items: + - key: authentication.py + path: + _default: authentication.py + + envs: + - name: LOG_LEVEL + value: + _default: DEBUG + - name: BASE_HOST + value: + _default: https://sarex.asterus.ru + - name: CELERY_QUEUE + value: + _default: flow + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000/api + - name: DOCUMENTATION_HOST + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/internal/v1 + - name: DOCUMENTATION_EXTERNAL_HOST + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/api/v1 + - name: ENABLE_ANALYTICS + value: + _default: "1" + - name: ENABLE_CELERY + value: + _default: "1" + - name: PROXY_PATH_PREFIX + value: + _default: /flows + - name: ENABLE_MAILGUN + value: + _default: "0" + - name: EAV_HOST + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: ENABLE_METRICS + value: + _default: "0" + - name: SMTP_HOST + value: + _default: mail.vhdm.ru + - name: SMTP_PORT + value: + _default: "587" + - name: GATEWAY_URL + value: + _default: http://pdm-api.documentations.svc.cluster.local:8080 + - name: PG_HOST + value: + _default: postgres-service + - name: PG_PORT + value: + _default: "5432" + - name: DOCUMENTATION_PG_PORT + value: + _default: "5432" + - name: DOCUMENTATION_PG_DATABASE + value: + _default: documentations_db + - name: DOCUMENTATION_PG_HOST + value: + _default: postgres-service.documentations.svc.cluster.local + - name: RABBITMQ_HOST + value: + _default: rabbitmq-service + - name: RABBITMQ_PORT + value: + _default: "5672" + - name: RESOURCE_URL + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: SERVICE_HOST + value: + _default: https://sarex.asterus.ru/flows/api/v1 + - name: SYNC_RESOURCE_ID + value: + _default: "1" + - name: TIMEOUT + value: + _default: "120" + - name: WORKFLOWS_HOST + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000/api/v1 + - name: WORKFLOWS_TIMEOUT + value: + _default: "120" + - name: FROM_EMAIL + value: + _default: sarex@asterus-development.com + - name: DOCUMENTATION_TIMEOUT + value: + _default: "320" + - name: PLANNING_HOST + value: + _default: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp + + secretEnvs: + - name: JWT_PUBLIC_KEY + secretName: + _default: backend-secret + secretKey: ssh_public.key + - name: ADMIN_PANEL_SECRET_KEY + secretName: + _default: admin-secret + secretKey: key + - name: DOCUMENTATION_PG_USERNAME + secretName: + _default: postgres-secret-documentations + secretKey: username + - name: DOCUMENTATION_PG_PASSWORD + secretName: + _default: postgres-secret-documentations + secretKey: password + - name: DJANGO_TOKEN + secretName: + _default: django-secret + secretKey: token + - name: PG_DB + secretName: + _default: postgres-secret + secretKey: database + - name: PG_LOGIN + secretName: + _default: postgres-secret + secretKey: username + - name: PG_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: RABBITMQ_USERNAME + secretName: + _default: rabbitmq-secret + secretKey: username + - name: RABBITMQ_PASSWORD + secretName: + _default: rabbitmq-secret + secretKey: password + - name: RABBITMQ_VHOST + secretName: + _default: rabbitmq-secret + secretKey: vhost + - name: MAILGUN_API_KEY + secretName: + _default: mailgun-secret + secretKey: token + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/flows/asterus/celery.yaml b/apps/flows/asterus/celery.yaml new file mode 100644 index 0000000..15a1aac --- /dev/null +++ b/apps/flows/asterus/celery.yaml @@ -0,0 +1,227 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: celery + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + celery: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_42cf0e6e + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: celery + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + envs: + - name: FLOWS_HOST + value: + _default: http://backend-service.flows.svc.cluster.local:8000 + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000/api + - name: DJANGO_BASE_HOST + value: + _default: https://sarex.asterus.ru + - name: RESOURCES_HOST + value: + _default: http://resources.resources.svc.cluster.local:8000 + - name: BASE_HOST + value: + _default: https://sarex.asterus.ru + - name: CELERY_QUEUE + value: + _default: flow + - name: DOCUMENTATION_TIMEOUT + value: + _default: "320" + - name: DOCUMENTATION_HOST + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/internal/v1 + - name: ENABLE_ANALYTICS + value: + _default: "1" + - name: ENABLE_CELERY + value: + _default: "1" + - name: ENABLE_MAILGUN + value: + _default: "0" + - name: ENABLE_METRICS + value: + _default: "0" + - name: PLANNING_HOST + value: + _default: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp + - name: FROM_EMAIL + value: + _default: sarex@dogma.ru + - name: GATEWAY_URL + value: + _default: http://pdm-api.documentations.svc.cluster.local:8080 + - name: PG_HOST + value: + _default: postgres-service + - name: PG_PORT + value: + _default: "5432" + - name: FLOWS_DB_HOST + value: + _default: postgres-service + - name: FLOWS_DB_PORT + value: + _default: "5432" + - name: RABBITMQ_HOST + value: + _default: rabbitmq-service + - name: ISSUES_DB_HOST + value: + _default: postgres-service.issues.svc.cluster.local + - name: ISSUES_DB_PORT + value: + _default: "5432" + - name: RABBITMQ_PORT + value: + _default: "5672" + - name: RESOURCE_URL + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: SERVICE_HOST + value: + _default: https://sarex.asterus.ru/flows/api/v1 + - name: SMTP_HOST + value: + _default: sarex.asterus.ru + - name: SMTP_PORT + value: + _default: "3434" + - name: SYNC_RESOURCE_ID + value: + _default: "1" + - name: TIMEOUT + value: + _default: "320" + - name: WORKFLOWS_HOST + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000/api/v1 + + secretEnvs: + - name: DJANGO_AUTH + secretName: + _default: django-secret + secretKey: token + - name: ADMIN_PANEL_SECRET_KEY + secretName: + _default: admin-secret + secretKey: key + - name: MAILGUN_API_KEY + secretName: + _default: mailgun-secret + secretKey: token + - name: FLOWS_DB_DB + secretName: + _default: postgres-secret + secretKey: database + - name: FLOWS_DB_USERNAME + secretName: + _default: postgres-secret + secretKey: username + - name: FLOWS_DB_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: PG_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: ISSUES_DB_DB + secretName: + _default: issues-postgres-secret + secretKey: database + - name: ISSUES_DB_LOGIN + secretName: + _default: issues-postgres-secret + secretKey: username + - name: ISSUES_DB_PASSWORD + secretName: + _default: issues-postgres-secret + secretKey: password + - name: PG_DB + secretName: + _default: postgres-secret + secretKey: database + - name: PG_LOGIN + secretName: + _default: postgres-secret + secretKey: username + - name: RABBITMQ_USERNAME + secretName: + _default: rabbitmq-secret + secretKey: username + - name: RABBITMQ_PASSWORD + secretName: + _default: rabbitmq-secret + secretKey: password + - name: RABBITMQ_VHOST + secretName: + _default: rabbitmq-secret + secretKey: vhost + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/flows/asterus/export-reviews.yaml b/apps/flows/asterus/export-reviews.yaml new file mode 100644 index 0000000..b84b55d --- /dev/null +++ b/apps/flows/asterus/export-reviews.yaml @@ -0,0 +1,132 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: export-reviews + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + export-reviews: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/export-reviews:preprod_3cad3d5e + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: export-reviews + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: export-reviews + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: BASE_HOST + value: + _default: https://sarex.asterus.ru + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: REVIEWS_HOST + value: + _default: http://backend-service.flows.svc.cluster.local:8000 + - name: GATEWAY_HOST + value: + _default: http://pdm-api.documentations.svc.cluster.local:8080 + - name: DJANGO_TIMEOUT + value: + _default: "180" + - name: REVIEWS_TIMEOUT + value: + _default: "180" + - name: GATEWAY_TIMEOUT + value: + _default: "180" + - name: DOCUMENTATIONS_HOST + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: DOCUMENTATIONS_TIMEOUT + value: + _default: "180" + - name: EAV_HOST + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: TIMEOUT + value: + _default: "180" + - name: VERIFY_HTTPS + value: + _default: "false" + - name: DOCUMENTATIONS_INTERNAL_HOST + value: + _default: http://documentations-service.documentations.svc.cluster.local:80/internal/v1 + - name: TRANSMITTALS_INTERNAL_HOST + value: + _default: http://transmittal-service.transmittal.svc.cluster.local:80/internal/v1 + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/flows/asterus/frontend.yaml b/apps/flows/asterus/frontend.yaml new file mode 100644 index 0000000..00911f8 --- /dev/null +++ b/apps/flows/asterus/frontend.yaml @@ -0,0 +1,123 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_55af772e + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 100m + memory: + _default: 100Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 60 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 30 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/flows/asterus/kustomization.yaml b/apps/flows/asterus/kustomization.yaml new file mode 100644 index 0000000..5f27d38 --- /dev/null +++ b/apps/flows/asterus/kustomization.yaml @@ -0,0 +1,11 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: flows +resources: + - authentication.yaml + - backend.yaml + - celery.yaml + - export-reviews.yaml + - frontend.yaml + - notification.yaml diff --git a/apps/flows/asterus/notification.yaml b/apps/flows/asterus/notification.yaml new file mode 100644 index 0000000..75e4a09 --- /dev/null +++ b/apps/flows/asterus/notification.yaml @@ -0,0 +1,103 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: notification + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + notification: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/notification_server:0.0.1 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: notification + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: notification-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: MAILGUN_ENABLE + value: + _default: "1" + + secretEnvs: + - name: MAILGUN_URL + secretName: + _default: mailgun-secret-faas + secretKey: url + - name: MAILGUN_API_KEY + secretName: + _default: mailgun-secret-faas + secretKey: api_key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/iam/wb/backend-s3.yaml b/apps/iam/wb/backend-s3.yaml index 8eda614..4a99fd8 100644 --- a/apps/iam/wb/backend-s3.yaml +++ b/apps/iam/wb/backend-s3.yaml @@ -1,13 +1,4 @@ --- -# В base S3_ENDPOINT_URL смотрит на storage.yandexcloud.net (Яндекс.Облако) — -# в wb используется собственный self-hosted MinIO. -# ZITADEL_HOST в base (sarex-login.uralmine.com) не трогаем: это общий -# платформенный SSO для iam, не переопределяется ни в одном клиентском контуре. -# -# TODO: для iam в vault wb (1.yaml) ещё не заведён infrastructure.minio.apps.iam -# (нет реального client.endpoint/bucket, в отличие от attachments/django/...) — -# 10.49.10.90:9000 здесь взят по аналогии с остальными приложениями wb. -# Проверить/поправить, когда в vault появится бакет для iam. apiVersion: helm.toolkit.fluxcd.io/v2 kind: HelmRelease metadata: diff --git a/apps/inspections/asterus/backend.yaml b/apps/inspections/asterus/backend.yaml new file mode 100644 index 0000000..4e705b5 --- /dev/null +++ b/apps/inspections/asterus/backend.yaml @@ -0,0 +1,185 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: inspections + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: inspections-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: uwsgi-configmap + mountPath: + _default: /opt/server/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: uwsgi-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: production-configmap + mountPath: + _default: /server/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: production-configmap + items: + - key: production.py + path: + _default: production.py + + envs: + - name: ENVIRONMENT + value: + _default: production + - name: WRITE_SYSTEM_LOG + value: + _default: "0" + - name: NOTIFY_VIA_EMAIL + value: + _default: "1" + - name: SERVICE_URL + value: + _default: https://sarex.asterus.ru + - name: WORKFLOWS_URL + value: + _default: http://workflows-api-service.workflow.svc.cluster.local:80 + - name: EMAIL_DOCKER_IMAGE + value: + _default: cr.yandex/crp3ccidau046kdj8g9q/notification:email + - name: EMAIL_FROM + value: + _default: hello@sarex.io + - name: DATABASE_HOST + value: + _default: postgres-service + - name: DATABASE_PORT + value: + _default: "5432" + - name: DATABASE_NAME + value: + _default: inspections_db + - name: API_ADDRESS + value: + _default: "8000" + + secretEnvs: + - name: DATABASE_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DATABASE_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: YC_S3_ACCESS_KEY_ID + secretName: + _default: yc-s3-secret + secretKey: key_id + - name: YC_S3_SECRET_ACCESS_KEY + secretName: + _default: yc-s3-secret + secretKey: access_key + - name: YC_S3_BUCKET_NAME + secretName: + _default: yc-s3-secret + secretKey: storage_bucket_name + - name: YC_S3_ENDPOINT_URL + secretName: + _default: yc-s3-secret + secretKey: endpoint_url + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/inspections/asterus/frontend.yaml b/apps/inspections/asterus/frontend.yaml new file mode 100644 index 0000000..0fea645 --- /dev/null +++ b/apps/inspections/asterus/frontend.yaml @@ -0,0 +1,123 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: inspections + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/inspections-frontend:contour_707faa44 + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 100m + memory: + _default: 100Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 60 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 30 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/inspections/asterus/kustomization.yaml b/apps/inspections/asterus/kustomization.yaml new file mode 100644 index 0000000..7854bd4 --- /dev/null +++ b/apps/inspections/asterus/kustomization.yaml @@ -0,0 +1,9 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: inspections +resources: + - uwsgi-configmap.yaml + - production-configmap.yaml + - backend.yaml + - frontend.yaml diff --git a/apps/inspections/asterus/production-configmap.yaml b/apps/inspections/asterus/production-configmap.yaml new file mode 100644 index 0000000..d32f91c --- /dev/null +++ b/apps/inspections/asterus/production-configmap.yaml @@ -0,0 +1,71 @@ +apiVersion: v1 +data: + production.py: |- + import os + + from .base import * # noqa: F401, F403 + + # Base settings + DEBUG = True + ALLOWED_HOSTS = [ + "*", + ] + + + # REST framework settings + REST_FRAMEWORK = { + "DEFAULT_FILTER_BACKENDS": [ + "django_filters.rest_framework.DjangoFilterBackend", + ], + "DEFAULT_RENDERER_CLASSES": [ + "rest_framework.renderers.JSONRenderer", + ], + "DEFAULT_PAGINATION_CLASS": "rest_framework.pagination.LimitOffsetPagination", + "PAGE_SIZE": 100, + } + + + # Database settings + DATABASES = { + "default": { + "ENGINE": "core.db.backends.postgis", + "NAME": os.getenv("POSTGRES_DB") or "postgres", + "HOST": os.getenv("POSTGRES_HOST") or "postgres", + "PORT": os.getenv("POSTGRES_PORT") or "5432", + "USER": os.getenv("POSTGRES_USER") or "postgres", + "PASSWORD": os.getenv("POSTGRES_PASSWORD") or "postgres", + } + } + + + # CORS settings + CORS_ALLOWED_ORIGINS = [ + "https://localhost.8000", + "https://localhost.8080", + "https://cde.brusnika.ru" + ] + CORS_ALLOW_ALL_ORIGINS = True + CORS_ALLOW_METHODS = [ + "GET", + "OPTIONS", + "POST", + "PUT", + "PATCH", + "DELETE", + ] + + + # S3 settings + AWS_S3_ENDPOINT_URL = os.getenv("YC_S3_ENDPOINT_URL") + AWS_STORAGE_BUCKET_NAME = os.getenv("YC_S3_BUCKET_NAME") + AWS_ACCESS_KEY_ID = os.getenv("YC_S3_ACCESS_KEY_ID") + AWS_SECRET_ACCESS_KEY = os.getenv("YC_S3_SECRET_ACCESS_KEY") + AWS_DEFAULT_ACL = "public-read" + + if AWS_S3_ENDPOINT_URL and AWS_STORAGE_BUCKET_NAME and AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY: + STATICFILES_STORAGE = "storages.backends.s3boto3.S3Boto3Storage" + DEFAULT_FILE_STORAGE = "storages.backends.s3boto3.S3Boto3Storage" +kind: ConfigMap +metadata: + name: production-configmap + namespace: inspections diff --git a/apps/inspections/asterus/uwsgi-configmap.yaml b/apps/inspections/asterus/uwsgi-configmap.yaml new file mode 100644 index 0000000..730bc95 --- /dev/null +++ b/apps/inspections/asterus/uwsgi-configmap.yaml @@ -0,0 +1,21 @@ +apiVersion: v1 +data: + uwsgi.ini: | + [uwsgi] + chdir = /server + module = config.wsgi:application + master = true + master-fifo = /opt/server/uwsgi-backend-server.fifo + processes = 8 + http = 0.0.0.0:8000 + chmod-socket = 666 + vacuum = true + harakiri = 6000 + buffer-size = 32768 + + static-map = /static=/opt/server/static/ + static-map = /media=/opt/server/media/ +kind: ConfigMap +metadata: + name: uwsgi-configmap + namespace: inspections diff --git a/apps/issues/asterus/issues.yaml b/apps/issues/asterus/issues.yaml new file mode 100644 index 0000000..1542be5 --- /dev/null +++ b/apps/issues/asterus/issues.yaml @@ -0,0 +1,239 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: issues + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + issues: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_f1b6c05c + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: issues + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: issues-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: uwsgi-configmap + mountPath: + _default: /opt/server/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: uwsgi-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: production-configmap + mountPath: + _default: /src/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: production-configmap + items: + - key: production.py + path: + _default: production.py + + envs: + - name: REDIS_HOST + value: + _default: redis-service + - name: ENVIRONMENT + value: + _default: production + - name: AERO_PUBLIC_HOST + value: + _default: https://sarex.asterus.ru + - name: AERO_HOST + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: BASE_AERO_URL + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: BASE_AUTH_URL + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: WORKFLOWS_HOST + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000 + - name: WORKFLOWS_URL + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000 + - name: RESOURCES_API_HOST + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: EAV_HOST + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: SAREX_API + value: + _default: https://sarex.asterus.ru + - name: DOCUMENTATIONS_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: DJANGO_SETTINGS_MODULE + value: + _default: config.settings.production + - name: DATABASE_HOST + value: + _default: postgres-service + - name: DATABASE_PORT + value: + _default: "5432" + - name: API_ADDRESS + value: + _default: "8000" + - name: RABBITMQ_HOSTNAME + value: + _default: rabbitmq-service:5672 + + secretEnvs: + - name: YC_S3_ACCESS_KEY_ID + secretName: + _default: yc-s3-secret + secretKey: key_id + - name: YC_S3_SECRET_ACCESS_KEY + secretName: + _default: yc-s3-secret + secretKey: access_key + - name: YC_S3_BUCKET_NAME + secretName: + _default: yc-s3-secret + secretKey: storage_bucket_name + - name: YC_S3_ENDPOINT_URL + secretName: + _default: yc-s3-secret + secretKey: endpoint_url + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + - name: DJANGO_TOKEN + secretName: + _default: django-auth + secretKey: key + - name: SAREX_USERNAME + secretName: + _default: sarex-auth + secretKey: username + - name: SAREX_PASSWORD + secretName: + _default: sarex-auth + secretKey: password + - name: DATABASE_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DATABASE_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DATABASE_NAME + secretName: + _default: postgres-secret + secretKey: database + - name: RABBITMQ_VHOST + secretName: + _default: rabbitmq-secret + secretKey: vhost + - name: RABBITMQ_USERNAME + secretName: + _default: rabbitmq-secret + secretKey: username + - name: RABBITMQ_PASSWORD + secretName: + _default: rabbitmq-secret + secretKey: password + - name: JWT_PRIVATE_KEY + secretName: + _default: backend-secret + secretKey: ssh_private.key + - name: JWT_PUBLIC_KEY + secretName: + _default: backend-secret + secretKey: ssh_public.key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/issues/asterus/kustomization.yaml b/apps/issues/asterus/kustomization.yaml new file mode 100644 index 0000000..9453eb0 --- /dev/null +++ b/apps/issues/asterus/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: issues +resources: + - uwsgi-configmap.yaml + - production-configmap.yaml + - issues.yaml + - worker.yaml + - static.yaml diff --git a/apps/issues/asterus/production-configmap.yaml b/apps/issues/asterus/production-configmap.yaml new file mode 100644 index 0000000..abcc844 --- /dev/null +++ b/apps/issues/asterus/production-configmap.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +data: + production.py: "from datetime import timedelta\nimport os\nfrom .base import *\n\n# DEBUG SETTINGS START\n# -----------------------------------------------------------------------------\nDEBUG = True\nAWS_S3_VERIFY=False\n# -----------------------------------------------------------------------------\n\nTEST_MODE = False\n\n# SECRETS SETTINGS START\n# -----------------------------------------------------------------------------\nSECRET_KEY = \"FromToMuchLoveOfLiving\" # Delete after Test\n# -----------------------------------------------------------------------------\n\n# ALLOWED HOSTS START\n# -----------------------------------------------------------------------------\nALLOWED_HOSTS = [\"*\"]\n# -----------------------------------------------------------------------------\n\n# APPS SETTINGS START\n# -----------------------------------------------------------------------------\n# INSTALLED_APPS += [\n# \"django_extensions\",\n# ]\n# -----------------------------------------------------------------------------\n\n# DEBUG SETTINGS START\n# -----------------------------------------------------------------------------\nDEBUG = True\n# -----------------------------------------------------------------------------\n\nREVIEW_HOST='http://backend-service.flows.svc.cluster.local:8000'\n# -----------------------------------------------------------------------------\n# EXTERNAL SERVICES END\n\nWORKFLOWS_HOST = \"http://workflows-service.workflow.svc.cluster:8000\"\nWORKFLOWS_URL = \"http://workflows-service.workflow.svc.cluster:8000\"\nDOCUMENTATIONS_URL = \"http://documentations-api.documentations.svc.cluster.local:8080\"\nRESOURCES_API_HOST = os.getenv(\"RESOURCES_API_HOST\", default=\"http://resources-service.resources.svc.cluster:8000\")\nKAFKA_HOST = \"brusnika-stage-kafka-bootstrap.kafka.svc.cluster.local:9093\" \nKAFKA_USERNAME = \"sarex\" \nKAFKA_PASSWORD = \"nK36sasvSfoItJnXQ4qxav2OUWIPX5ZC\"\nKAFKA_SSL_CAFILE = os.getenv(\"KAFKA_SSL_CAFILE\", \"/usr/local/share/ca-certificates/kafka.crt\")\nKAFKA_EAV_ASSETS_TOPIC = os.getenv(\"KAFKA_EAV_ASSETS_TOPIC\", \"sarex\")\nKAFKA_ISSUES_TOPIC = os.getenv(\"KAFKA_ISSUES_TOPIC\", \"sarex-issues\")\n\n\nUSE_ASYNC_FUNCTIONS = False\nUSE_NOTIFICATIONS = False\n\n# JWT SETTINGS START\n# ---------------------------------------------------------------------------------------------------------------------\nSIMPLE_JWT_ISSUER = os.getenv(\"SIMPLE_JWT_ISSUER\", default=\"default_issuer\")\n\nSIMPLE_JWT = {\n \"ACCESS_TOKEN_LIFETIME\": timedelta(minutes=5),\n \"REFRESH_TOKEN_LIFETIME\": timedelta(days=1),\n \"ROTATE_REFRESH_TOKENS\": False,\n \"UPDATE_LAST_LOGIN\": False,\n\n \"ALGORITHM\": \"RS512\",\n \"SIGNING_KEY\": os.getenv(\"JWT_PRIVATE_KEY\", default=\"\").replace(\"\\\\n\", \"\\n\"),\n \"VERIFYING_KEY\": os.getenv(\"JWT_PUBLIC_KEY\").replace(\"\\\\n\", \"\\n\"),\n \"AUDIENCE\": None,\n \"ISSUER\": SIMPLE_JWT_ISSUER,\n\n \"AUTH_HEADER_TYPES\": (\"Bearer\",),\n \"AUTH_HEADER_NAME\": \"HTTP_AUTHORIZATION\",\n \"USER_ID_FIELD\": \"id\",\n \"USER_ID_CLAIM\": \"user_id\",\n\n \"AUTH_TOKEN_CLASSES\": (\"rest_framework_simplejwt.tokens.AccessToken\",),\n \"TOKEN_TYPE_CLAIM\": \"token_type\",\n\n \"JTI_CLAIM\": \"jti\",\n\n \"SLIDING_TOKEN_REFRESH_EXP_CLAIM\": \"refresh_exp\",\n \"SLIDING_TOKEN_LIFETIME\": timedelta(minutes=5),\n \"SLIDING_TOKEN_REFRESH_LIFETIME\": timedelta(days=1),\n}\n# ---------------------------------------------------------------------------------------------------------------------\n\nCORS_ALLOWED_ORIGINS = [\n \"https://sarex.asterus.ru\",\n]\n\nCORS_TRUSTED_ORIGINS = [\n \"https://sarex.asterus.ru\",\n]\n\nCSRF_TRUSTED_ORIGINS = [\n \"https://sarex.asterus.ru\",\n]\n\nCORS_ALLOW_ALL_ORIGINS = True\n\nCORS_ALLOW_METHODS = [\n \"DELETE\",\n \"GET\",\n \"OPTIONS\",\n \"PATCH\",\n \"POST\",\n \"PUT\",\n]\n\nSAREX_API = \"http://backend.django.svc.cluster.local:8000\"\n\nAERO_PUBLIC_HOST = os.getenv(\"AERO_PUBLIC_HOST\", default=SAREX_API)\n\nBASE_AERO_URL = \"http://backend.django.svc.cluster.local:8000\"\n\nENVIRONMENT = \"production\"\n\nSESSION_COOKIE_NAME = \"issues-sessionid\"\nCSRF_COOKIE_NAME = \"issues-csrftoken\"\nSTATIC_URL = \"/static/\"\nSTORAGES = {\n 'default': {\n 'BACKEND': \"storages.backends.s3boto3.S3Boto3Storage\",\n },\n 'staticfiles': {\n # Leave whatever setting you already have here, e.g.:\n 'BACKEND': \"storages.backends.s3boto3.S3Boto3Storage\",\n }\n}\n" +kind: ConfigMap +metadata: + name: production-configmap + namespace: issues diff --git a/apps/issues/asterus/static.yaml b/apps/issues/asterus/static.yaml new file mode 100644 index 0000000..fad0070 --- /dev/null +++ b/apps/issues/asterus/static.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: static + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + static: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:893c9953 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: static + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: static-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/issues/asterus/uwsgi-configmap.yaml b/apps/issues/asterus/uwsgi-configmap.yaml new file mode 100644 index 0000000..9838503 --- /dev/null +++ b/apps/issues/asterus/uwsgi-configmap.yaml @@ -0,0 +1,22 @@ +apiVersion: v1 +data: + uwsgi.ini: |- + [uwsgi] + plugins-dir = /usr/lib/uwsgi/plugins + + chdir = /src + module = config.wsgi:application + master = true + processes = 4 + http = 0.0.0.0:8000 + chmod-socket = 666 + vacuum = true + harakiri = 6000 + buffer-size = 32768 + + static-map = /static=/opt/src/static/ + static-map = /media=/opt/src/media/ +kind: ConfigMap +metadata: + name: uwsgi-configmap + namespace: issues diff --git a/apps/issues/asterus/worker.yaml b/apps/issues/asterus/worker.yaml new file mode 100644 index 0000000..4e34685 --- /dev/null +++ b/apps/issues/asterus/worker.yaml @@ -0,0 +1,223 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: worker + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + worker: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_f1b6c05c + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: worker + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["celery", "-A", "config", "worker", "-l", "info", "-E", "--concurrency=2"] + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + volumes: + _default: + - name: uwsgi-configmap + mountPath: + _default: /opt/server/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: uwsgi-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: production-configmap + mountPath: + _default: /src/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: production-configmap + items: + - key: production.py + path: + _default: production.py + + envs: + - name: ENVIRONMENT + value: + _default: production + - name: AERO_PUBLIC_HOST + value: + _default: https://sarex.asterus.ru + - name: AERO_HOST + value: + _default: "http://backend-service.django.svc.cluster.local:8000" + - name: BASE_AERO_URL + value: + _default: "http://backend-service.django.svc.cluster.local:8000" + - name: BASE_AUTH_URL + value: + _default: "http://backend-service.django.svc.cluster.local:8000" + - name: WORKFLOWS_HOST + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000 + - name: WORKFLOWS_URL + value: + _default: http://workflows-api-service.workflows.svc.cluster.local:8000 + - name: RESOURCES_API_HOST + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: EAV_HOST + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: SAREX_API + value: + _default: https://sarex.asterus.ru + - name: DOCUMENTATIONS_URL + value: + _default: http://documentations-api.documentations.svc.cluster.local:8080 + - name: DJANGO_SETTINGS_MODULE + value: + _default: config.settings.production + - name: DATABASE_HOST + value: + _default: postgres-service + - name: DATABASE_PORT + value: + _default: "5432" + - name: API_ADDRESS + value: + _default: "8000" + - name: REDIS_HOST + value: + _default: redis-service + - name: RABBITMQ_HOSTNAME + value: + _default: rabbitmq-service:5672 + + secretEnvs: + - name: YC_S3_ACCESS_KEY_ID + secretName: + _default: yc-s3-secret + secretKey: key_id + - name: YC_S3_SECRET_ACCESS_KEY + secretName: + _default: yc-s3-secret + secretKey: access_key + - name: YC_S3_BUCKET_NAME + secretName: + _default: yc-s3-secret + secretKey: storage_bucket_name + - name: YC_S3_ENDPOINT_URL + secretName: + _default: yc-s3-secret + secretKey: endpoint_url + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + - name: SAREX_USERNAME + secretName: + _default: sarex-auth + secretKey: username + - name: SAREX_PASSWORD + secretName: + _default: sarex-auth + secretKey: password + - name: DATABASE_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DATABASE_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DATABASE_NAME + secretName: + _default: postgres-secret + secretKey: database + - name: RABBITMQ_VHOST + secretName: + _default: rabbitmq-secret + secretKey: vhost + - name: RABBITMQ_USERNAME + secretName: + _default: rabbitmq-secret + secretKey: username + - name: RABBITMQ_PASSWORD + secretName: + _default: rabbitmq-secret + secretKey: password + - name: JWT_PRIVATE_KEY + secretName: + _default: backend-secret + secretKey: ssh_private.key + - name: JWT_PUBLIC_KEY + secretName: + _default: backend-secret + secretKey: ssh_public.key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/measurements/asterus/backend.yaml b/apps/measurements/asterus/backend.yaml new file mode 100644 index 0000000..8bdf328 --- /dev/null +++ b/apps/measurements/asterus/backend.yaml @@ -0,0 +1,99 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: measurements + namespace: measurements + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + measurements: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/measurements:0.4.7 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: measurements + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: measurement-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: CLASSIC_MODE + value: + _default: "0" + + secretEnvs: + - name: S3_JSON_SETTINGS + secretName: + _default: s3-json + secretKey: S3_JSON_SETTINGS + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/measurements/asterus/kustomization.yaml b/apps/measurements/asterus/kustomization.yaml new file mode 100644 index 0000000..ab86f1d --- /dev/null +++ b/apps/measurements/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: measurements +resources: + - backend.yaml diff --git a/apps/message-hub/asterus/kafka-cert.yaml b/apps/message-hub/asterus/kafka-cert.yaml new file mode 100644 index 0000000..39e65b1 --- /dev/null +++ b/apps/message-hub/asterus/kafka-cert.yaml @@ -0,0 +1,37 @@ +apiVersion: v1 +data: + kafka.crt: | + -----BEGIN CERTIFICATE----- + MIIFLTCCAxWgAwIBAgIUeuNKW4rB4ReiwjDidNIdob7VRokwDQYJKoZIhvcNAQEN + BQAwLTETMBEGA1UECgwKaW8uc3RyaW16aTEWMBQGA1UEAwwNY2x1c3Rlci1jYSB2 + MDAeFw0yNTA4MjYxMDM0NDRaFw0yNjA4MjYxMDM0NDRaMC0xEzARBgNVBAoMCmlv + LnN0cmltemkxFjAUBgNVBAMMDWNsdXN0ZXItY2EgdjAwggIiMA0GCSqGSIb3DQEB + AQUAA4ICDwAwggIKAoICAQCv7lvKnTUpgnDd91YgCMQSYTSVUdkkQITXZENXj2km + UN5k2NhnDIMOeHD4Bu8fjSUvELcilNAgsPqKNWO97CWtU9/phxsQRMgDwywtyr8Q + W3Vc2RYk/7vcpi77M/IjmFoRExXowO9U3mLNd0vACk+yC7WObcNr9veFnVyrmoL3 + iOqLbmzKiZvdIz1f6lwDDOXNuj26Ct6jRatV96HcqKzK50Jj9eS5SvV57JQLvTsZ + LbPnesAxgKzW7sci6N9lB9jrDirBl2h/QJXAmhUyg2yAvrU8wBTTpQWCdQRQ54Pv + LCZV3iXMkTYkxoyCg/GPbb2M7DF1sEe45iWsYkqDsWvdhirfp8BBVp+oni3xmj9J + +8hzB2MZhyA9i6v6Hfua7d0ExKUhuJkUxBcGyFHbXpC2m2m8plaHL2mNBXAuQZDw + wf+aHvHo2QLoNFL2xR8/63IHosnnRgzdKpZX6Z1Ftd8caHf/L+XgI3ET8LwklC55 + y4FmFQwd8rOGiR38Ixg9zhr44tV3foWWrIM+sb/ni4UokeGkX2AymSsdln9pAnIj + usGG9ZuSZUPZ+w5HjtL3hxh9pbGdYja2YcfusCCQK56LBWRJnB8W/IafEOvVxMT/ + gqx6Hee/geY3G2LRlMfsLRAbCvYOIi7kDzOM/LnM+XlbEkJO8uyjnT5wbCFCRnvy + nwIDAQABo0UwQzAdBgNVHQ4EFgQUeNSYqykN5qUxAfLJ7z9Say0XIHAwEgYDVR0T + AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQADggIB + AH82HGTXnJKbBln7q+Wx9chwMUFZc4u43Q0QAvCgGXMRFa5Dl4x/9rtrYYuDpZwh + /GKgOkhZ/SKLeuy9e7bgoHnt2sNR4CqAjK6YQp7o5aBNRGhiQZTkfjoG/P17AV7e + nKP65WXPAirouUxlvC8Kplh2vsuUkGcjzsKRTYQRNR1+yHw+P91qcX+RglrHFyMJ + wWKOldwgR3Mit+tAMbgioqrNTmwIEREDCF0DcJuX3LKTo7/q3I9cMFhz7/kk5CTm + pePoWMcvhgOX/cQcqNA7Q0HAOIV3OioxAod+XyjpaTo42YrTUSjq5Rl2a9U7GNN/ + xazxT+YDs/mHSP0Yt/5jxMSjsifPP4l4KP9YvqiC7UZGrZ9ctzkg3UlQmr87Km9W + FqVLoX6Y1OmNB/c5XCg4S4g2q5VavXM792fn1ow6oR5hgDHXBLNA+TKWFmJ5UXJB + z4l7Hn7rFJB5e9QVEDRIzr8c2QcUZ668kicP3Oh45NywMcSV6GZO4PNDNsNW0kFf + 3txTYwDEvT3n83C0lybw2hgLl3Q//lX+Zn3TMdqGVXkCXR0df45U8p14Wfe7QRtb + Jmg3tvOOpueyc3I+mrpDbyxdYQxr8IZdFoaV+mZUCi+ezMrHBNNNq0Lc/t2ICa+p + bpTSKuKNG91nPGXEd7sFGL8ZYypObQc5HC6wMCeVC3Cx + -----END CERTIFICATE----- +kind: ConfigMap +metadata: + name: kafka-cert + namespace: message-hub diff --git a/apps/message-hub/asterus/kafka-config.yaml b/apps/message-hub/asterus/kafka-config.yaml new file mode 100644 index 0000000..c336213 --- /dev/null +++ b/apps/message-hub/asterus/kafka-config.yaml @@ -0,0 +1,66 @@ +apiVersion: v1 +data: + kafka.py: | + from ssl import SSLContext + + import ssl + + from aiokafka.helpers import create_ssl_context + from faststream.kafka import KafkaBroker + from faststream.security import BaseSecurity, SASLPlaintext, SASLScram512 + from pydantic_settings import BaseSettings, SettingsConfigDict + + + class KafkaSettings(BaseSettings): + HOST: str = 'localhost' + PORT: int = 9092 + USERNAME: str | None = None + PASSWORD: str | None = None + SECURITY_PROTOCOL: str = 'PLAINTEXT' + SASL_MECHANISM: str | None = None + SSL_CAFILE: str | None = None + + model_config = SettingsConfigDict(env_prefix='KAFKA_', env_file='.env', extra='ignore') + + @property + def bootstrap_servers(self) -> list[str]: + return [f'{self.HOST}:{str(self.PORT)}'] + + def get_ssl_context(self) -> SSLContext: + context = create_ssl_context(cafile=self.SSL_CAFILE) + context.check_hostname = False + context.verify_mode = ssl.CERT_NONE + return context + + def get_security(self) -> BaseSecurity | None: + use_ssl = self.SECURITY_PROTOCOL in ('SSL', 'SASL_SSL') + ssl_context = self.get_ssl_context() if use_ssl else None + if self.SASL_MECHANISM == 'PLAINTEXT': + return SASLPlaintext( + username=self.USERNAME or '', + password=self.PASSWORD or '', + ssl_context=ssl_context, + use_ssl=use_ssl, + ) + if self.SASL_MECHANISM == 'SCRAM-SHA-512': + return SASLScram512( + username=self.USERNAME or '', + password=self.PASSWORD or '', + ssl_context=ssl_context, + use_ssl=use_ssl, + ) + if use_ssl: + return BaseSecurity(ssl_context=ssl_context) + return None + + @property + def broker(self) -> KafkaBroker: + return KafkaBroker( + bootstrap_servers=self.bootstrap_servers, + security=self.get_security(), + logger=None, + ) +kind: ConfigMap +metadata: + name: kafka-config + namespace: message-hub diff --git a/apps/message-hub/asterus/kustomization.yaml b/apps/message-hub/asterus/kustomization.yaml new file mode 100644 index 0000000..fb5476d --- /dev/null +++ b/apps/message-hub/asterus/kustomization.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: message-hub +resources: + - kafka-cert.yaml + - kafka-config.yaml + - message-hub.yaml diff --git a/apps/message-hub/asterus/message-hub.yaml b/apps/message-hub/asterus/message-hub.yaml new file mode 100644 index 0000000..5c0cfaa --- /dev/null +++ b/apps/message-hub/asterus/message-hub.yaml @@ -0,0 +1,214 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: message-hub + namespace: message-hub + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + message-hub: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_d11aa910 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: message-hub-message-hub + + replicaCount: + _default: 1 + + port: + _default: 8000 + + resources: + requests: + cpu: + _default: 100m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: message-hub-message-hub + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: kafka-cert-volume + mountPath: + _default: /usr/local/share/ca-certificates + readOnly: + _default: true + configMap: + name: + _default: kafka-cert + + - name: kafka-config-volume + mountPath: + _default: /opt/src/config/kafka.py + subPath: + _default: kafka.py + readOnly: + _default: true + configMap: + name: + _default: kafka-config + items: + - key: kafka.py + path: + _default: kafka.py + + envs: + - name: WORKER_TIMEOUT + value: + _default: "60" + - name: PYTHONPATH + value: + _default: src + - name: SETTINGS_MAX_RETRIES + value: + _default: "1" + - name: SETTINGS_TOPICS + value: + _default: '{"planning": "pm", "assets":"assets_broadcast", "issues": "issues_broadcast_prod"}' + - name: PDF_CONVERTER_HOST + value: + _default: http://export-project-service.django.svc.cluster.local:8000 + - name: SAREX_BASE_HOST + value: + _default: http://backend-service.pm.svc.cluster.local:8000 + - name: PM_HOST + value: + _default: http://backend-service.pm.svc.cluster.local:8000 + - name: DB_HOST + value: + _default: postgres-service.pm.svc.cluster.local + - name: DB_PORT + value: + _default: "5432" + - name: DB_DATABASE + value: + _default: pm_db + - name: CACHE_HOST + value: + _default: redis.pm.svc.cluster.local + - name: CACHE_PORT + value: + _default: "6379" + - name: CACHE_SSL + value: + _default: "0" + - name: CACHE_SSL_CA_CERTS + value: + _default: /usr/local/share/ca-certificates/kafka.crt + - name: KAFKA_HOST + value: + _default: asterus-kafka-kafka-bootstrap.kafka.svc.cluster.local + - name: KAFKA_PORT + value: + _default: "9093" + - name: KAFKA_SECURITY_PROTOCOL + value: + _default: SSL + - name: KAFKA_SASL_MECHANISM + value: + _default: PLAIN + - name: KAFKA_SSL_CAFILE + value: + _default: /usr/local/share/ca-certificates/kafka.crt + + secretEnvs: + - name: KAFKA_USERNAME + secretName: + _default: kafka-secret + secretKey: username + - name: KAFKA_PASSWORD + secretName: + _default: kafka-secret + secretKey: password + - name: DB_USERNAME + secretName: + _default: postgres-pm-secret + secretKey: username + - name: DB_PASSWORD + secretName: + _default: postgres-pm-secret + secretKey: password + - name: S3_LOGIN + secretName: + _default: s3-secret + secretKey: username + - name: S3_PASSWORD + secretName: + _default: s3-secret + secretKey: password + - name: S3_BUCKET + secretName: + _default: s3-secret + secretKey: bucket + - name: S3_HOST + secretName: + _default: s3-secret + secretKey: host + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/pm/asterus/backend-configmap.yaml b/apps/pm/asterus/backend-configmap.yaml new file mode 100644 index 0000000..bdfed44 --- /dev/null +++ b/apps/pm/asterus/backend-configmap.yaml @@ -0,0 +1,29 @@ +apiVersion: v1 +data: + uwsgi.ini: | + [uwsgi] + log-format = {"time": "%(time)", "method": "%(method)", "uri": "%(uri)", "status": "%(status)", "size": "%(size)", "addr": "%(addr)", "user": "%(user)", "proto": "%(proto)", "user_agent": "%(uagent)", "referer": "%(referer)", "trace_id": "%(trace_id)", "span_id": "%(span_id)"} + module = config.wsgi:application + DJANGO_SETTINGS_MODULE = config.settings.base + http = 0.0.0.0:8000 + processes = 8 + master = true + vacuum = true + enable-threads = true + buffer-size = 65535 + stats = :3031 + stats-http = true + memory-report = true + lazy-apps = true + listen = 1024 + disable-write-exception= 0 + harakiri = 300 + socket-timeout = 300 + chunked-input-timeout = 300 + http-timeout = 300 + worker-reload-mercy = 240 + mule-reload-mercy = 240 +kind: ConfigMap +metadata: + name: backend-configmap + namespace: pm diff --git a/apps/pm/asterus/backend.yaml b/apps/pm/asterus/backend.yaml new file mode 100644 index 0000000..377b26f --- /dev/null +++ b/apps/pm/asterus/backend.yaml @@ -0,0 +1,145 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: pm + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_8b930b70 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: uwsgi-configmap + mountPath: + _default: /opt/sarex/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: backend-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: env-file + mountPath: + _default: /opt/sarex/.env + subPath: + _default: .env + readOnly: + _default: true + secret: + secretName: + _default: sarex-env + + - name: kafka-cert-volume + mountPath: + _default: /usr/local/share/ca-certificates + readOnly: + _default: true + configMap: + name: + _default: kafka-cert + + envs: + - name: USERS_INTERNAL_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: RESOURCES_INTERNAL_HOST + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: EAV_HOST + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: EAV_API_PREFIX + value: + _default: /api/v0 + - name: EAV_API_PREFIX_V1 + value: + _default: /api/v1 + - name: USERS_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/pm/asterus/celery.yaml b/apps/pm/asterus/celery.yaml new file mode 100644 index 0000000..957b665 --- /dev/null +++ b/apps/pm/asterus/celery.yaml @@ -0,0 +1,133 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: celery + namespace: pm + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + celery: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_8b930b70 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: celery + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["celery", "-A", "config", "worker", "-B", "-l", "info", "-E", "-Q", "pm", "-n", "default_worker.%h", "--concurrency=2"] + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + volumes: + _default: + - name: uwsgi-configmap + mountPath: + _default: /opt/sarex/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: backend-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: env-file + mountPath: + _default: /opt/sarex/.env + subPath: + _default: .env + readOnly: + _default: true + secret: + secretName: + _default: sarex-env + + - name: kafka-cert-volume + mountPath: + _default: /usr/local/share/ca-certificates + readOnly: + _default: true + configMap: + name: + _default: kafka-cert + + envs: + - name: USERS_INTERNAL_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: RESOURCES_INTERNAL_HOST + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: EAV_HOST + value: + _default: http://eav-service.eav.svc.cluster.local:8000 + - name: USERS_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: EAV_API_PREFIX + value: + _default: /api/v0 + - name: EAV_API_PREFIX_V1 + value: + _default: /api/v1 + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/pm/asterus/frontend.yaml b/apps/pm/asterus/frontend.yaml new file mode 100644 index 0000000..3e7668d --- /dev/null +++ b/apps/pm/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: pm + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-frontend:contour_7f125269 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/pm/asterus/kafka-cert.yaml b/apps/pm/asterus/kafka-cert.yaml new file mode 100644 index 0000000..f8975fb --- /dev/null +++ b/apps/pm/asterus/kafka-cert.yaml @@ -0,0 +1,37 @@ +apiVersion: v1 +data: + kafka.crt: | + -----BEGIN CERTIFICATE----- + MIIFLTCCAxWgAwIBAgIUeuNKW4rB4ReiwjDidNIdob7VRokwDQYJKoZIhvcNAQEN + BQAwLTETMBEGA1UECgwKaW8uc3RyaW16aTEWMBQGA1UEAwwNY2x1c3Rlci1jYSB2 + MDAeFw0yNTA4MjYxMDM0NDRaFw0yNjA4MjYxMDM0NDRaMC0xEzARBgNVBAoMCmlv + LnN0cmltemkxFjAUBgNVBAMMDWNsdXN0ZXItY2EgdjAwggIiMA0GCSqGSIb3DQEB + AQUAA4ICDwAwggIKAoICAQCv7lvKnTUpgnDd91YgCMQSYTSVUdkkQITXZENXj2km + UN5k2NhnDIMOeHD4Bu8fjSUvELcilNAgsPqKNWO97CWtU9/phxsQRMgDwywtyr8Q + W3Vc2RYk/7vcpi77M/IjmFoRExXowO9U3mLNd0vACk+yC7WObcNr9veFnVyrmoL3 + iOqLbmzKiZvdIz1f6lwDDOXNuj26Ct6jRatV96HcqKzK50Jj9eS5SvV57JQLvTsZ + LbPnesAxgKzW7sci6N9lB9jrDirBl2h/QJXAmhUyg2yAvrU8wBTTpQWCdQRQ54Pv + LCZV3iXMkTYkxoyCg/GPbb2M7DF1sEe45iWsYkqDsWvdhirfp8BBVp+oni3xmj9J + +8hzB2MZhyA9i6v6Hfua7d0ExKUhuJkUxBcGyFHbXpC2m2m8plaHL2mNBXAuQZDw + wf+aHvHo2QLoNFL2xR8/63IHosnnRgzdKpZX6Z1Ftd8caHf/L+XgI3ET8LwklC55 + y4FmFQwd8rOGiR38Ixg9zhr44tV3foWWrIM+sb/ni4UokeGkX2AymSsdln9pAnIj + usGG9ZuSZUPZ+w5HjtL3hxh9pbGdYja2YcfusCCQK56LBWRJnB8W/IafEOvVxMT/ + gqx6Hee/geY3G2LRlMfsLRAbCvYOIi7kDzOM/LnM+XlbEkJO8uyjnT5wbCFCRnvy + nwIDAQABo0UwQzAdBgNVHQ4EFgQUeNSYqykN5qUxAfLJ7z9Say0XIHAwEgYDVR0T + AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQADggIB + AH82HGTXnJKbBln7q+Wx9chwMUFZc4u43Q0QAvCgGXMRFa5Dl4x/9rtrYYuDpZwh + /GKgOkhZ/SKLeuy9e7bgoHnt2sNR4CqAjK6YQp7o5aBNRGhiQZTkfjoG/P17AV7e + nKP65WXPAirouUxlvC8Kplh2vsuUkGcjzsKRTYQRNR1+yHw+P91qcX+RglrHFyMJ + wWKOldwgR3Mit+tAMbgioqrNTmwIEREDCF0DcJuX3LKTo7/q3I9cMFhz7/kk5CTm + pePoWMcvhgOX/cQcqNA7Q0HAOIV3OioxAod+XyjpaTo42YrTUSjq5Rl2a9U7GNN/ + xazxT+YDs/mHSP0Yt/5jxMSjsifPP4l4KP9YvqiC7UZGrZ9ctzkg3UlQmr87Km9W + FqVLoX6Y1OmNB/c5XCg4S4g2q5VavXM792fn1ow6oR5hgDHXBLNA+TKWFmJ5UXJB + z4l7Hn7rFJB5e9QVEDRIzr8c2QcUZ668kicP3Oh45NywMcSV6GZO4PNDNsNW0kFf + 3txTYwDEvT3n83C0lybw2hgLl3Q//lX+Zn3TMdqGVXkCXR0df45U8p14Wfe7QRtb + Jmg3tvOOpueyc3I+mrpDbyxdYQxr8IZdFoaV+mZUCi+ezMrHBNNNq0Lc/t2ICa+p + bpTSKuKNG91nPGXEd7sFGL8ZYypObQc5HC6wMCeVC3Cx + -----END CERTIFICATE----- +kind: ConfigMap +metadata: + name: kafka-cert + namespace: pm diff --git a/apps/pm/asterus/kustomization.yaml b/apps/pm/asterus/kustomization.yaml new file mode 100644 index 0000000..af2e5e5 --- /dev/null +++ b/apps/pm/asterus/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: pm +resources: + - backend-configmap.yaml + - kafka-cert.yaml + - backend.yaml + - celery.yaml + - frontend.yaml diff --git a/apps/processing/asterus/engine-low.yaml b/apps/processing/asterus/engine-low.yaml new file mode 100644 index 0000000..19fa363 --- /dev/null +++ b/apps/processing/asterus/engine-low.yaml @@ -0,0 +1,327 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend-low + namespace: workflows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + postRenderers: + - kustomize: + patches: + - target: + kind: Deployment + name: backend-low + patch: |- + - op: add + path: /spec/template/spec/serviceAccountName + value: workflows-backend-sa + - op: add + path: /spec/template/spec/automountServiceAccountToken + value: true + + values: + global: + env: _default + + services: + backend-low: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workflows-engine:prod_b6e15fda + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend-low + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + envs: + - name: RABBITMQ_HOST + value: + _default: rabbitmq-service.workflows.svc.cluster.local + - name: RABBITMQ_PORT + value: + _default: "5672/api" + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: ENVIRONMENT + value: + _default: prod + - name: DEFAULT_TOLERATION_KEY + value: + _default: dedicated + - name: DEFAULT_TOLERATION_VALUE + value: + _default: processing + - name: WORKFLOWS_SENTRY_DEBUG + value: + _default: "0" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8000 + - name: DJANGO_HOST + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: WORKFLOW_PRIORITY + value: + _default: low + - name: S3_SERVICE_ACCOUNT + value: + _default: /etc/sarex/yc-s3/yc-s3-service-account.json + - name: BIM_API_V2_DB + value: + _default: /etc/sarex/bim-api-v2-db-prod.json + - name: PDM_API_DB + value: + _default: /etc/pdm/pdm-api-db-prod.json + - name: WORKSPACE_API_DB + value: + _default: /etc/ws/ws-api-db-prod.json + - name: ISSUE_API_DB + value: + _default: /etc/issues/issue-api-db-prod.json + - name: MAILGUN + value: + _default: /etc/mailgun-secret/env.json + - name: INTERNAL_PDM_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: INTERNAL_FILESTREAM_URL + value: + _default: http://documentations-filestream-service.documentations.svc.cluster.local:80 + - name: EXTERNAL_PDM_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: EXTERNAL_FILESTREAM_URL + value: + _default: http://documentations-filestream-service.documentations.svc.cluster.local:80 + - name: RESOURCES_API_INTERNAL_HOST + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_S3_STORAGE + value: + _default: "1" + - name: ENABLE_S3V2_STORAGE + value: + _default: "1" + - name: ENABLE_PDM_STORAGE + value: + _default: "1" + - name: ENABLE_URL_STORAGE + value: + _default: "1" + - name: ENABLE_SRX_TMP + value: + _default: "1" + - name: ENABLE_BIM_API_V2_DB + value: + _default: "1" + - name: ENABLE_WORKSPACE_API_DB + value: + _default: "1" + - name: ENABLE_ISSUE_API_DB + value: + _default: "1" + - name: ENABLE_RESOURCES_API + value: + _default: "1" + - name: ENABLE_PDM_API_DB + value: + _default: "1" + - name: ENABLE_COMPARISONS_API_DB + value: + _default: "1" + - name: ENABLE_MAIL_GUN + value: + _default: "1" + - name: ENABLE_AMQP_EXECUTOR + value: + _default: "1" + - name: ENABLE_KUBERNETES_EXECUTOR + value: + _default: "1" + - name: MAX_WORKFLOWS_LIMIT + value: + _default: "30" + - name: CPU_COUNT + value: + _default: "1" + - name: MEMORY_GI + value: + _default: "4" + - name: CPU_COUNT_LOW_RESOURCES + value: + _default: "1" + - name: MEMORY_GI_LOW_RESOURCES + value: + _default: "1" + - name: CPU_COUNT_HIGH_MEM + value: + _default: "1" + - name: MEMORY_GI_HIGH_MEM + value: + _default: "4" + - name: ENABLE_TOLERATION + value: + _default: "1" + - name: COUNT_RUNNING_WORKERS + value: + _default: "1" + - name: COUNT_CANCELING_WORKERS + value: + _default: "1" + - name: COUNT_HANDLE_JOB_WORKERS + value: + _default: "1" + - name: BIM_API_DEBUG + value: + _default: "0" + - name: BIM_API_V2_DEBUG + value: + _default: "0" + - name: PDM_API_DEBUG + value: + _default: "0" + - name: COMPARISONS_API_DEBUG + value: + _default: "0" + - name: WORKSPACE_API_DEBUG + value: + _default: "0" + - name: JOBS_NAMESPACE + value: + _default: workflows + - name: ISSUE_API_DEBUG + value: + _default: "0" + - name: TOLERATION_KEY + value: + _default: dedicated + - name: TOLERATION_VALUE + value: + _default: processing + - name: TOLERATION_KEY_HIGH_MEM + value: + _default: dedicated + - name: TOLERATION_VALUE_HIGH_MEM + value: + _default: processing + - name: TOLERATION_KEY_PERSISTENT + value: + _default: dedicated + - name: TOLERATION_VALUE_PERSISTENT + value: + _default: processing + - name: RABBITMQ_CREATE_EXCHANGE + value: + _default: autodesk.inputMessage + - name: RABBITMQ_CANCEL_EXCHANGE + value: + _default: autodesk.cancelMessage + - name: RABBITMQ_CREATE_ROUTING_KEY + value: + _default: converting + - name: RABBITMQ_CANCEL_TOPIC + value: + _default: cancel + - name: RABBITMQ_COMPLETENESS_EXCHANGE + value: + _default: autodesk.outputMessage + - name: RABBITMQ_COMPLETENESS_TOPIC + value: + _default: output_navis + - name: CONTROL_PLANE_PERIOD + value: + _default: 10s + - name: DEFAULT_NODE_SELECTOR_KEY + value: + _default: dedicated + - name: DEFAULT_NODE_SELECTOR_VALUE + value: + _default: processing + - name: LOW_PRIORITY + value: + _default: "1" + + secretEnvs: + - name: RABBITMQ_USER + secretName: + _default: rabbitmq-secret + secretKey: username + - name: RABBITMQ_PASS + secretName: + _default: rabbitmq-secret + secretKey: password + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: POSTGRES_DB + secretName: + _default: postgres-secret + secretKey: database + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/processing/asterus/engine.yaml b/apps/processing/asterus/engine.yaml new file mode 100644 index 0000000..7db7f32 --- /dev/null +++ b/apps/processing/asterus/engine.yaml @@ -0,0 +1,342 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: workflows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + postRenderers: + - kustomize: + patches: + - target: + kind: Deployment + name: backend + patch: |- + - op: add + path: /spec/template/spec/serviceAccountName + value: workflows-backend-sa + - op: add + path: /spec/template/spec/automountServiceAccountToken + value: true + + values: + global: + env: _default + + services: + backend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workflows-engine:prod_b6e15fda + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-service + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 8080 + + portName: + _default: http + + envs: + - name: RABBITMQ_HOST + value: + _default: rabbitmq-service.workflows.svc.cluster.local + - name: RABBITMQ_PORT + value: + _default: "5672/api" + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: ENVIRONMENT + value: + _default: prod + - name: WORKFLOWS_SENTRY_DEBUG + value: + _default: "0" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8000 + - name: DJANGO_HOST + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: S3_SERVICE_ACCOUNT + value: + _default: /etc/sarex/yc-s3/yc-s3-service-account.json + - name: BIM_API_V2_DB + value: + _default: /etc/sarex/bim-api-v2-db-prod.json + - name: PDM_API_DB + value: + _default: /etc/pdm/pdm-api-db-prod.json + - name: WORKSPACE_API_DB + value: + _default: /etc/ws/ws-api-db-prod.json + - name: ISSUE_API_DB + value: + _default: /etc/issues/issue-api-db-prod.json + - name: MAILGUN + value: + _default: /etc/mailgun-secret/env.json + - name: INTERNAL_PDM_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: INTERNAL_FILESTREAM_URL + value: + _default: http://documentations-filestream-service.documentations.svc.cluster.local:80 + - name: EXTERNAL_PDM_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: EXTERNAL_FILESTREAM_URL + value: + _default: http://documentations-filestream-service.documentations.svc.cluster.local:80 + - name: RESOURCES_API_INTERNAL_HOST + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_S3_STORAGE + value: + _default: "1" + - name: ENABLE_S3V2_STORAGE + value: + _default: "1" + - name: ENABLE_PDM_STORAGE + value: + _default: "1" + - name: ENABLE_URL_STORAGE + value: + _default: "1" + - name: ENABLE_SRX_TMP + value: + _default: "1" + - name: ENABLE_BIM_API_V2_DB + value: + _default: "1" + - name: ENABLE_WORKSPACE_API_DB + value: + _default: "1" + - name: ENABLE_ISSUE_API_DB + value: + _default: "1" + - name: ENABLE_RESOURCES_API + value: + _default: "1" + - name: ENABLE_PDM_API_DB + value: + _default: "1" + - name: ENABLE_COMPARISONS_API_DB + value: + _default: "1" + - name: ENABLE_MAIL_GUN + value: + _default: "1" + - name: ENABLE_AMQP_EXECUTOR + value: + _default: "1" + - name: ENABLE_KUBERNETES_EXECUTOR + value: + _default: "1" + - name: WORKFLOW_PRIORITY + value: + _default: high + - name: MAX_WORKFLOWS_LIMIT + value: + _default: "30" + - name: CPU_COUNT + value: + _default: "1" + - name: MEMORY_GI + value: + _default: "4" + - name: CPU_COUNT_LOW_RESOURCES + value: + _default: "1" + - name: MEMORY_GI_LOW_RESOURCES + value: + _default: "1" + - name: CPU_COUNT_HIGH_MEM + value: + _default: "1" + - name: MEMORY_GI_HIGH_MEM + value: + _default: "4" + - name: ENABLE_TOLERATION + value: + _default: "1" + - name: COUNT_RUNNING_WORKERS + value: + _default: "1" + - name: COUNT_CANCELING_WORKERS + value: + _default: "1" + - name: COUNT_HANDLE_JOB_WORKERS + value: + _default: "1" + - name: BIM_API_DEBUG + value: + _default: "0" + - name: BIM_API_V2_DEBUG + value: + _default: "0" + - name: PDM_API_DEBUG + value: + _default: "0" + - name: COMPARISONS_API_DEBUG + value: + _default: "0" + - name: WORKSPACE_API_DEBUG + value: + _default: "0" + - name: JOBS_NAMESPACE + value: + _default: workflows + - name: ISSUE_API_DEBUG + value: + _default: "0" + - name: LOW_PRIORITY + value: + _default: "0" + - name: DEFAULT_TOLERATION_KEY + value: + _default: dedicated + - name: DEFAULT_TOLERATION_VALUE + value: + _default: processing + - name: TOLERATION_KEY + value: + _default: dedicated + - name: TOLERATION_VALUE + value: + _default: processing + - name: TOLERATION_KEY_HIGH_MEM + value: + _default: dedicated + - name: TOLERATION_VALUE_HIGH_MEM + value: + _default: processing + - name: TOLERATION_KEY_PERSISTENT + value: + _default: dedicated + - name: TOLERATION_VALUE_PERSISTENT + value: + _default: processing + - name: RABBITMQ_CREATE_EXCHANGE + value: + _default: autodesk.inputMessage + - name: RABBITMQ_CANCEL_EXCHANGE + value: + _default: autodesk.cancelMessage + - name: RABBITMQ_CREATE_ROUTING_KEY + value: + _default: converting + - name: RABBITMQ_CANCEL_TOPIC + value: + _default: cancel + - name: RABBITMQ_COMPLETENESS_EXCHANGE + value: + _default: autodesk.outputMessage + - name: RABBITMQ_COMPLETENESS_TOPIC + value: + _default: output_navis + - name: CONTROL_PLANE_PERIOD + value: + _default: 10s + - name: DEFAULT_NODE_SELECTOR_KEY + value: + _default: dedicated + - name: DEFAULT_NODE_SELECTOR_VALUE + value: + _default: processing + + secretEnvs: + - name: RABBITMQ_USER + secretName: + _default: rabbitmq-secret + secretKey: username + - name: RABBITMQ_PASS + secretName: + _default: rabbitmq-secret + secretKey: password + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: POSTGRES_DB + secretName: + _default: postgres-secret + secretKey: database + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/processing/asterus/frontend.yaml b/apps/processing/asterus/frontend.yaml new file mode 100644 index 0000000..1250b10 --- /dev/null +++ b/apps/processing/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: workflows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workflows-frontend:05cd261953c6265bcdb7d48d6752c5ddf5539489 + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 8080 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/processing/asterus/kustomization.yaml b/apps/processing/asterus/kustomization.yaml new file mode 100644 index 0000000..e7be142 --- /dev/null +++ b/apps/processing/asterus/kustomization.yaml @@ -0,0 +1,9 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: workflows +resources: + - engine.yaml + - engine-low.yaml + - workflows-api.yaml + - frontend.yaml diff --git a/apps/processing/asterus/workflows-api.yaml b/apps/processing/asterus/workflows-api.yaml new file mode 100644 index 0000000..36f7926 --- /dev/null +++ b/apps/processing/asterus/workflows-api.yaml @@ -0,0 +1,132 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: workflows-api + namespace: workflows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + workflows-api: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workflows-api:prod_eeceb0bf + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: workflows-api + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: workflows-api-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8080 + + portName: + _default: http + + envs: + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_POOL_SIZE + value: + _default: "3" + - name: HTTP_HOST + value: + _default: 0.0.0.0:8080 + - name: DJANGO_HOST + value: + _default: http://backend-service.django.svc.cluster.local:8000 + - name: S3_SERVICE_ACCOUNT + value: + _default: /etc/sarex/yc-s3/yc-s3-service-account.json + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: POSTGRES_SSL_USE + value: + _default: "0" + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: POSTGRES_DB + secretName: + _default: postgres-secret + secretKey: database + - name: PUBLIC_KEY + secretName: + _default: public-key + secretKey: key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/projects/asterus/frontend.yaml b/apps/projects/asterus/frontend.yaml new file mode 100644 index 0000000..a57e030 --- /dev/null +++ b/apps/projects/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: projects + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/project-frontend-app:asterus_961300de + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-service + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/projects/asterus/kustomization.yaml b/apps/projects/asterus/kustomization.yaml new file mode 100644 index 0000000..f339513 --- /dev/null +++ b/apps/projects/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: projects +resources: + - frontend.yaml diff --git a/apps/remarks/asterus/frontend.yaml b/apps/remarks/asterus/frontend.yaml new file mode 100644 index 0000000..65ec091 --- /dev/null +++ b/apps/remarks/asterus/frontend.yaml @@ -0,0 +1,116 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: remarks-static + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/remarks-frontend:brusnika_8e76d55b + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: remarks-static + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 10 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 10 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: remarks-static-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/remarks/asterus/kustomization.yaml b/apps/remarks/asterus/kustomization.yaml new file mode 100644 index 0000000..0a7d921 --- /dev/null +++ b/apps/remarks/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: issues +resources: + - frontend.yaml diff --git a/apps/reviews/asterus/frontend.yaml b/apps/reviews/asterus/frontend.yaml new file mode 100644 index 0000000..4113426 --- /dev/null +++ b/apps/reviews/asterus/frontend.yaml @@ -0,0 +1,123 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: reviews-frontend + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/reviews-frontend:contour_9428727f + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: reviews-frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 100m + memory: + _default: 100Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 60 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 80 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 30 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: reviews-frontend-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/reviews/asterus/kustomization.yaml b/apps/reviews/asterus/kustomization.yaml new file mode 100644 index 0000000..3bffbf6 --- /dev/null +++ b/apps/reviews/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: flows +resources: + - frontend.yaml diff --git a/apps/stamp-verification/asterus/frontend.yaml b/apps/stamp-verification/asterus/frontend.yaml new file mode 100644 index 0000000..b5f8e51 --- /dev/null +++ b/apps/stamp-verification/asterus/frontend.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: stamp-verification + namespace: documentations + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/stamp-verification-frontend:893df2712ee7f1e539bc28721da6ee9674495a5a + pullPolicy: + _default: Always + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: stamp-verification-frontend + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: stamp-verification-frontend-service + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 8080 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/stamp-verification/asterus/kustomization.yaml b/apps/stamp-verification/asterus/kustomization.yaml new file mode 100644 index 0000000..027b611 --- /dev/null +++ b/apps/stamp-verification/asterus/kustomization.yaml @@ -0,0 +1,6 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: documentations +resources: + - frontend.yaml diff --git a/apps/subscriptions/asterus/django-configmap.yaml b/apps/subscriptions/asterus/django-configmap.yaml new file mode 100644 index 0000000..ab68d8a --- /dev/null +++ b/apps/subscriptions/asterus/django-configmap.yaml @@ -0,0 +1,7 @@ +apiVersion: v1 +data: + production.py: "import os\n\nfrom .base import *\n\n# DEBUG SETTINGS START\n# -----------------------------------------------------------------------------\nDEBUG = True\n# -----------------------------------------------------------------------------\n# DEBUG SETTINGS END\n\n\n# ALLOWED HOSTS START\n# -----------------------------------------------------------------------------\nALLOWED_HOSTS = [\"*\"]\n# -----------------------------------------------------------------------------\n# ALLOWED HOSTS END\n\n# DATABASE CONFIGURATION START\n# ------------------------------------------------------------------------------\nPOSTGRES_DATABASE = os.getenv(\"DATABASE_NAME\")\nPOSTGRES_USER = os.getenv(\"DATABASE_USER\")\nPOSTGRES_PASSWORD = os.getenv(\"DATABASE_PASSWORD\")\nPOSTGRES_HOST = os.getenv(\"DATABASE_HOST\")\nPOSTGRES_PORT = os.getenv(\"DATABASE_PORT\")\nIS_MAILGUN_USE = 1\n\nDATABASES = {\n \"default\": {\n \"ENGINE\": \"core.db.backends.postgis\",\n \"NAME\": POSTGRES_DATABASE,\n \"USER\": POSTGRES_USER,\n \"PASSWORD\": POSTGRES_PASSWORD,\n \"HOST\": POSTGRES_HOST,\n \"PORT\": POSTGRES_PORT,\n }\n}\n# DATABASE CONFIGURATION END\n# ------------------------------------------------------------------------------\n\n\nCORS_ALLOWED_ORIGINS = [\n \"https://sarex.asterus.ru\"\n]\n\nCORS_ALLOW_ALL_ORIGINS = True\n\nCORS_ALLOW_METHODS = [\n \"DELETE\",\n \"GET\",\n \"OPTIONS\",\n \"PATCH\",\n \"POST\",\n \"PUT\",\n]\n\n# MAILGUN START\n# ------------------------------------------------------------------------------\nMAILGUN_BASE_URL = os.getenv(\"MAILGUN_BASE_URL\", default=\"\")\nMAILGUN_API_KEY = os.getenv(\"MAILGUN_API_KEY\", default=\"\")\n# ------------------------------------------------------------------------------\nALLOWED_HOST_EMAIL = \"https://sarex.asterus.ru\"\n\n# SYSTEM_LOG SERVICE SETTINGS START\n# -----------------------------------------------------------------------------\nSYSTEM_LOG_HOST = os.getenv(\"SYSTEM_LOG_HOST\")\n# -----------------------------------------------------------------------------\n# SYSTEM_LOG SERVICE SETTINGS END\n\n\n# TELEGRAM SETTINGS START\n# -----------------------------------------------------------------------------\nIS_USE_TELEGRAM = os.getenv(\"IS_USE_TELEGRAM\", default=False)\nTELEGRAM_BOT_TOKEN = os.getenv(\"TELEGRAM_BOT_TOKEN\", default=\"6174421650:AAGEicmX0fvDX2683LXiGweWfn1U9UTQHFY\") \n# -----------------------------------------------------------------------------\n# TELEGRAM SETTINGS END\n\n# USER SERVICE SETTINGS START\n# -----------------------------------------------------------------------------\nUSER_SERVICE_HOST = os.getenv(\"USER_SERVICE_HOST\")\nUSER_SERVICE_LOGIN = \"sarex\"\nUSER_SERVICE_PASSWORD = \"ihp9H2CDRldiJi2smUGNCQzx8BR2OrUG\"\n# -----------------------------------------------------------------------------\n# USER SERVICE SETTINGS END\n" +kind: ConfigMap +metadata: + name: django-configmap + namespace: subscriptions diff --git a/apps/subscriptions/asterus/kustomization.yaml b/apps/subscriptions/asterus/kustomization.yaml new file mode 100644 index 0000000..c7f0111 --- /dev/null +++ b/apps/subscriptions/asterus/kustomization.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: subscriptions +resources: + - django-configmap.yaml + - uwsgi-configmap.yaml + - sarex-subscriptions.yaml diff --git a/apps/subscriptions/asterus/sarex-subscriptions.yaml b/apps/subscriptions/asterus/sarex-subscriptions.yaml new file mode 100644 index 0000000..4eb5b23 --- /dev/null +++ b/apps/subscriptions/asterus/sarex-subscriptions.yaml @@ -0,0 +1,172 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: sarex-subscriptions + namespace: subscriptions + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + sarex-subscriptions: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/sarex-subscriptions:prod_8a25513b + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: sarex-subscriptions + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: sarex-subscriptions-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + volumes: + _default: + - name: uwsgi-configmap + mountPath: + _default: /opt/server/uwsgi.ini + subPath: + _default: uwsgi.ini + readOnly: + _default: true + configMap: + name: + _default: uwsgi-configmap + items: + - key: uwsgi.ini + path: + _default: uwsgi.ini + + - name: django-configmap + mountPath: + _default: /server/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: django-configmap + items: + - key: production.py + path: + _default: production.py + + envs: + - name: ALLOWED_HOST_EMAIL + value: + _default: https://sarex.asterus.ru + - name: DATABASE_HOST + value: + _default: postgres-service + - name: DATABASE_PORT + value: + _default: "5432" + - name: DATABASE_NAME + value: + _default: subscriptions_db + - name: API_ADDRESS + value: + _default: "8000" + - name: SYSTEM_LOG_HOST + value: + _default: http://api-service.system-log + - name: USER_SERVICE_HOST + value: + _default: https://sarex.asterus.ru + - name: IS_USE_TELEGRAM + value: + _default: "true" + + secretEnvs: + - name: DATABASE_USER + secretName: + _default: postgres-secret + secretKey: username + - name: DATABASE_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: YC_S3_ACCESS_KEY_ID + secretName: + _default: yc-s3-secret + secretKey: key_id + - name: YC_S3_SECRET_ACCESS_KEY + secretName: + _default: yc-s3-secret + secretKey: access_key + - name: YC_S3_BUCKET_NAME + secretName: + _default: yc-s3-secret + secretKey: storage_bucket_name + - name: YC_S3_ENDPOINT_URL + secretName: + _default: yc-s3-secret + secretKey: endpoint_url + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/subscriptions/asterus/uwsgi-configmap.yaml b/apps/subscriptions/asterus/uwsgi-configmap.yaml new file mode 100644 index 0000000..5188507 --- /dev/null +++ b/apps/subscriptions/asterus/uwsgi-configmap.yaml @@ -0,0 +1,22 @@ +apiVersion: v1 +data: + uwsgi.ini: | + [uwsgi] + + chdir = /server + module = config.wsgi:application + master = true + master-fifo = /opt/server/uwsgi-backend-server.fifo + processes = 8 + http = 0.0.0.0:8000 + chmod-socket = 666 + vacuum = true + harakiri = 6000 + buffer-size = 32768 + + static-map = /static=/opt/server/static/ + static-map = /media=/opt/server/media/ +kind: ConfigMap +metadata: + name: uwsgi-configmap + namespace: subscriptions diff --git a/apps/system-log/asterus/api.yaml b/apps/system-log/asterus/api.yaml new file mode 100644 index 0000000..8feecc7 --- /dev/null +++ b/apps/system-log/asterus/api.yaml @@ -0,0 +1,169 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: api + namespace: system-log + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + api: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/system_log:37de9371be6550b3e5953dc7ce2ad5c41b2cd1e7 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: api + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: api-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: KAFKA_ENABLE + value: + _default: "0" + - name: KAFKA_BROKERS + value: + _default: rc1d-s0a1ujcbj6fdk26b.mdb.yandexcloud.net:9091 + - name: KAFKA_GROUP + value: + _default: system-log-prod + - name: KAFKA_CLIENT_ID + value: + _default: system-log-prod + - name: KAFKA_USE_SSL + value: + _default: "0" + - name: KAFKA_ENABLE_LOGGING + value: + _default: "0" + - name: KAFKA_TOPIC + value: + _default: bru.cde.folders.prod + - name: APP_NAME + value: + _default: system_log + - name: APP_VERSION + value: + _default: 0.0.1 + - name: LOG_LEVEL + value: + _default: INFO + - name: HTTP_HOST + value: + _default: 0.0.0.0 + - name: HTTP_PORT + value: + _default: "8000" + - name: NAMESPACE + value: + _default: system-log + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: system_log_db + - name: POSTGRES_POOL_SIZE + value: + _default: "3" + - name: ENABLE_SSL + value: + _default: "0" + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: KAFKA_USERNAME + secretName: + _default: ya-kafka-secret + secretKey: username + - name: KAFKA_PASSWORD + secretName: + _default: ya-kafka-secret + secretKey: password + - name: KAFKA_PEM_CERT + secretName: + _default: yc-kafka-certificate + secretKey: KAFKA_PEM_CERT + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/system-log/asterus/kustomization.yaml b/apps/system-log/asterus/kustomization.yaml new file mode 100644 index 0000000..4cacc11 --- /dev/null +++ b/apps/system-log/asterus/kustomization.yaml @@ -0,0 +1,7 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: system-log +resources: + - api.yaml + - worker.yaml diff --git a/apps/system-log/asterus/worker.yaml b/apps/system-log/asterus/worker.yaml new file mode 100644 index 0000000..158212f --- /dev/null +++ b/apps/system-log/asterus/worker.yaml @@ -0,0 +1,139 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: worker + namespace: system-log + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + worker: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/system_log_worker:c32c2f279673d1b5baa872b9d27872b0f3cc71cf + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: worker + + replicaCount: + _default: 1 + + port: + _default: 8000 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: worker-service + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: APP_NAME + value: + _default: system_log + - name: APP_VERSION + value: + _default: 0.0.1 + - name: LOG_LEVEL + value: + _default: INFO + - name: HTTP_HOST + value: + _default: 0.0.0.0 + - name: HTTP_PORT + value: + _default: "8000" + - name: NAMESPACE + value: + _default: sarex-system-log + - name: DOCUMENTATIONS_URL + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: system_log_db + - name: POSTGRES_POOL_SIZE + value: + _default: "3" + - name: ENABLE_SSL + value: + _default: "0" + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/transmittal/asterus/kustomization.yaml b/apps/transmittal/asterus/kustomization.yaml new file mode 100644 index 0000000..851b810 --- /dev/null +++ b/apps/transmittal/asterus/kustomization.yaml @@ -0,0 +1,7 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: transmittal +resources: + - transmittal.yaml + - worker.yaml diff --git a/apps/transmittal/asterus/transmittal.yaml b/apps/transmittal/asterus/transmittal.yaml new file mode 100644 index 0000000..3f839fe --- /dev/null +++ b/apps/transmittal/asterus/transmittal.yaml @@ -0,0 +1,331 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: transmittal + namespace: transmittal + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + transmittal: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_f285cf2e + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: transmittal + + replicaCount: + _default: 1 + + port: + _default: 8000 + + resources: + requests: + cpu: + _default: "1" + memory: + _default: 1Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: transmittal-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + envs: + - name: TRANSMITTAL_SERVICE_APP__NAME + value: + _default: Transmittal Service + - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL + value: + _default: ERROR + - name: TRANSMITTAL_SERVICE_APP__HOST + value: + _default: https://lk.srx.wb.ru:30443/transmittal + - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT + value: + _default: prod + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS + value: + _default: '["*"]' + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS + value: + _default: '["*"]' + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS + value: + _default: '["*"]' + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS + value: + _default: "true" + - name: TRANSMITTAL_SERVICE_UVICORN__HOST + value: + _default: 0.0.0.0 + - name: TRANSMITTAL_SERVICE_UVICORN__PORT + value: + _default: "8000" + - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_OTEL__ENABLE + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_OTEL__HOST + value: + _default: http://signoz-otel-collector-external.signoz.svc.cluster.local:4317 + - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME + value: + _default: backend.transmittals-prod + - name: TRANSMITTAL_SERVICE_OTEL__INSECURE + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE + value: + _default: verify-full + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH + value: + _default: /opt/.postgresql/root.crt + - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL + value: + _default: info + - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS + value: + _default: "2" + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT + value: + _default: "30" + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL + value: + _default: http://backend-service.flows.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH + value: + _default: "" + - name: TRANSMITTAL_SERVICE_DATABASE__HOST + value: + _default: postgres-service + - name: TRANSMITTAL_SERVICE_DATABASE__PORT + value: + _default: "5432" + - name: TRANSMITTAL_SERVICE_DATABASE__NAME + value: + _default: transmittal_db + - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_RABBITMQ__VHOST + value: + _default: api + - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST + value: + _default: rabbitmq-service + - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT + value: + _default: "5672" + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL + value: + _default: http://documentations-api.documentations.svc.cluster.local:8080 + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT + value: + _default: "50" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME + value: + _default: ru-central1 + - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY + value: + _default: "true" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET + value: + _default: transmittal-storage + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT + value: + _default: "10.49.10.90:9000" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL + value: + _default: http://export-project-service.django.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT + value: + _default: "50" + - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL + value: + _default: http://marks-service.documentations.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT + value: + _default: "50" + - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL + value: + _default: https://api.mailgun.net/v3/mg.sarex.io + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL + value: + _default: hello@wb.io + + secretEnvs: + - name: TRANSMITTAL_SERVICE_DATABASE__USER + secretName: + _default: postgres-secret + secretKey: username + - name: TRANSMITTAL_SERVICE_DATABASE__PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: YC-PG-CERTIFICATE + secretName: + _default: postgres-secret + secretKey: certificate + - name: TRANSMITTAL_SERVICE_AUTH__PUBLIC_KEY + secretName: + _default: public-key + secretKey: key + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASIC_AUTH_ENCODED + secretName: + _default: django-auth + secretKey: key + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ACCESS_KEY + secretName: + _default: s3-secret + secretKey: access_key + - name: TRANSMITTAL_SERVICE_S3_CLIENT__SECRET_KEY + secretName: + _default: s3-secret + secretKey: secret_key + - name: TRANSMITTAL_SERVICE_RABBITMQ__USER + secretName: + _default: rabbitmq-cred + secretKey: username + - name: TRANSMITTAL_SERVICE_RABBITMQ__PASSWORD + secretName: + _default: rabbitmq-cred + secretKey: password + - name: TRANSMITTAL_SERVICE_MAILGUN__API_KEY + secretName: + _default: mailgun-cred + secretKey: api_key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/transmittal/asterus/worker.yaml b/apps/transmittal/asterus/worker.yaml new file mode 100644 index 0000000..d298439 --- /dev/null +++ b/apps/transmittal/asterus/worker.yaml @@ -0,0 +1,307 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: worker + namespace: transmittal + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + worker: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_d94cce67 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: worker + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["taskiq", "worker", "--no-parse", "transmittal_service.tasks.broker:broker", "transmittal_service.tasks.transmittal.tasks", "transmittal_service.tasks.email.tasks"] + + resources: + requests: + cpu: + _default: "1" + memory: + _default: 1Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + envs: + - name: TRANSMITTAL_SERVICE_APP__NAME + value: + _default: Transmittal Service + - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL + value: + _default: ERROR + - name: TRANSMITTAL_SERVICE_APP__HOST + value: + _default: https://lk.srx.wb.ru:30443/transmittal + - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT + value: + _default: prod + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS + value: + _default: '["*"]' + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS + value: + _default: '["*"]' + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS + value: + _default: '["*"]' + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS + value: + _default: "true" + - name: TRANSMITTAL_SERVICE_UVICORN__HOST + value: + _default: 0.0.0.0 + - name: TRANSMITTAL_SERVICE_UVICORN__PORT + value: + _default: "8000" + - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_OTEL__ENABLE + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_OTEL__HOST + value: + _default: http://signoz-otel-collector-external.signoz.svc.cluster.local:4317 + - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME + value: + _default: backend.transmittals-prod + - name: TRANSMITTAL_SERVICE_OTEL__INSECURE + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE + value: + _default: verify-full + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH + value: + _default: /opt/.postgresql/root.crt + - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL + value: + _default: info + - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS + value: + _default: "2" + - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH + value: + _default: "" + - name: TRANSMITTAL_SERVICE_DATABASE__HOST + value: + _default: postgres-service + - name: TRANSMITTAL_SERVICE_DATABASE__PORT + value: + _default: "5432" + - name: TRANSMITTAL_SERVICE_DATABASE__NAME + value: + _default: transmittal_db + - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_RABBITMQ__VHOST + value: + _default: api + - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST + value: + _default: rabbitmq-service + - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT + value: + _default: "5672" + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL + value: + _default: http://resources-service.resources.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL + value: + _default: http://documentations-api.documentations.svc.cluster.local:8080 + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT + value: + _default: "50" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME + value: + _default: ru-central1 + - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY + value: + _default: "true" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET + value: + _default: transmittal-storage + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT + value: + _default: "10.49.10.90:9000" + - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL + value: + _default: "false" + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL + value: + _default: http://export-project-service.django.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT + value: + _default: "50" + - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL + value: + _default: http://marks-service.documentations.svc.cluster.local:8000 + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT + value: + _default: "50" + - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL + value: + _default: https://api.mailgun.net/v3/mg.sarex.io + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS + value: + _default: "10" + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT + value: + _default: "15" + - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL + value: + _default: hello@wb.io + + secretEnvs: + - name: TRANSMITTAL_SERVICE_DATABASE__USER + secretName: + _default: postgres-secret + secretKey: username + - name: TRANSMITTAL_SERVICE_DATABASE__PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: YC-PG-CERTIFICATE + secretName: + _default: postgres-secret + secretKey: certificate + - name: TRANSMITTAL_SERVICE_AUTH__PUBLIC_KEY + secretName: + _default: public-key + secretKey: key + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASIC_AUTH_ENCODED + secretName: + _default: django-auth + secretKey: key + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ACCESS_KEY + secretName: + _default: s3-secret + secretKey: access_key + - name: TRANSMITTAL_SERVICE_S3_CLIENT__SECRET_KEY + secretName: + _default: s3-secret + secretKey: secret_key + - name: TRANSMITTAL_SERVICE_RABBITMQ__USER + secretName: + _default: rabbitmq-cred + secretKey: username + - name: TRANSMITTAL_SERVICE_RABBITMQ__PASSWORD + secretName: + _default: rabbitmq-cred + secretKey: password + - name: TRANSMITTAL_SERVICE_MAILGUN__API_KEY + secretName: + _default: mailgun-cred + secretKey: api_key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/workspaces/asterus/frontend1.yaml b/apps/workspaces/asterus/frontend1.yaml new file mode 100644 index 0000000..62d9fd9 --- /dev/null +++ b/apps/workspaces/asterus/frontend1.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend1 + namespace: workspaces + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend1: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workspaces-frontend-static:62c550704fb8138610e8f32860cd96d710374814 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend1 + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: workspaces-frontend-static-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/workspaces/asterus/frontend2.yaml b/apps/workspaces/asterus/frontend2.yaml new file mode 100644 index 0000000..ff9d2a0 --- /dev/null +++ b/apps/workspaces/asterus/frontend2.yaml @@ -0,0 +1,88 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend2 + namespace: workspaces + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend2: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workspaces-v2-frontend:contour_8b87e5b0 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: frontend2 + + replicaCount: + _default: 1 + + port: + _default: 80 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: workspaces-v2-frontend-static-service + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/workspaces/asterus/kustomization.yaml b/apps/workspaces/asterus/kustomization.yaml new file mode 100644 index 0000000..74f025d --- /dev/null +++ b/apps/workspaces/asterus/kustomization.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +namespace: workspaces +resources: + - workspaces-api.yaml + - frontend1.yaml + - frontend2.yaml diff --git a/apps/workspaces/asterus/workspaces-api.yaml b/apps/workspaces/asterus/workspaces-api.yaml new file mode 100644 index 0000000..c7eacb7 --- /dev/null +++ b/apps/workspaces/asterus/workspaces-api.yaml @@ -0,0 +1,152 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: workspaces-api + namespace: workspaces + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + workspaces-api: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/workspaces:production_bfd943b2 + pullPolicy: + _default: IfNotPresent + + imagePullSecrets: + enabled: + _default: true + name: + _default: dockerhub + + deployment: + enabled: true + + name: + _default: workspaces-api + + replicaCount: + _default: 1 + + port: + _default: 8080 + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: workspaces-service + + type: + _default: ClusterIP + + port: + _default: 8080 + + targetPort: + _default: 8080 + + portName: + _default: http + + envs: + - name: POSTGRES_ADDRESS + value: + _default: postgres-service + - name: POSTGRES_PORT + value: + _default: "5432" + - name: POSTGRES_DB + value: + _default: workspaces_db + - name: POSTGRES_POOL_SIZE + value: + _default: "3" + - name: BUNDLES_RETRY_COUNT + value: + _default: "5" + - name: BUNDLES_NJOBS + value: + _default: "5" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8080 + - name: NAMESPACE + value: + _default: sarex-workspaces + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_SSL + value: + _default: "0" + - name: DOCUMENTATION_HOST + value: + _default: http://documentations-service.documentations.svc.cluster.local:80 + - name: DOCUMENTATION_LOGGER_FEATURE + value: + _default: "0" + - name: DOCUMENTATION_ORIGINATOR + value: + _default: prod_ws + - name: ENVIRONMENT + value: + _default: prod + - name: DJANGO_HOST + value: + _default: http://backend.django.svc.cluster.local:8000 + - name: DJANGO_ORIGINATOR + value: + _default: docs_prod + + secretEnvs: + - name: POSTGRES_USER + secretName: + _default: postgres-secret + secretKey: username + - name: POSTGRES_PASSWORD + secretName: + _default: postgres-secret + secretKey: password + - name: DJANGO_BASIC_AUTH + secretName: + _default: django-auth + secretKey: key + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/clusters/asterus/kustomization.yaml b/clusters/asterus/kustomization.yaml index c8977a7..c9b5c84 100644 --- a/clusters/asterus/kustomization.yaml +++ b/clusters/asterus/kustomization.yaml @@ -5,3 +5,28 @@ resources: - ./helm-repositories.yaml - ../../apps/auth-flow/asterus + # - ../../apps/attachments/asterus + # - ../../apps/bim/asterus + # - ../../apps/checklists/asterus + # - ../../apps/comparisons/asterus + # - ../../apps/control-interface/asterus + # - ../../apps/cross-section/asterus + # - ../../apps/django/asterus + # - ../../apps/document-link/asterus + # - ../../apps/eav/asterus + # - ../../apps/measurements/asterus + # - ../../apps/message-hub/asterus + # - ../../apps/projects/asterus + # - ../../apps/documentations/asterus + # - ../../apps/stamp-verification/asterus + # - ../../apps/inspections/asterus + # - ../../apps/subscriptions/asterus + # - ../../apps/system-log/asterus + # - ../../apps/transmittal/asterus + # - ../../apps/flows/asterus + # - ../../apps/reviews/asterus + # - ../../apps/issues/asterus + # - ../../apps/remarks/asterus + # - ../../apps/pm/asterus + # - ../../apps/processing/asterus + # - ../../apps/workspaces/asterus