This commit is contained in:
ivan 2026-07-31 12:54:49 +05:00
parent 2296dae803
commit c7b749fd09
119 changed files with 5796 additions and 2948 deletions

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: auth-flow
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,108 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: bim
labels:
app: backend
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: bim
vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim
vault.hashicorp.com/agent-inject-template-bim-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/bim" -}}
POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local
POSTGRES_PORT=5432
POSTGRES_PORT_2=5432
POSTGRES_PORT_3=5432
POSTGRES_PORT_4=5432
POSTGRES_DB=bim_db
POSTGRES_DB_2=bim_db
POSTGRES_DB_3=bim_db
POSTGRES_DB_4=bim_db
POSTGRES_USER={{ index .Data.data "username" }}
POSTGRES_USER_2={{ index .Data.data "username" }}
POSTGRES_USER_3={{ index .Data.data "username" }}
POSTGRES_USER_4={{ index .Data.data "username" }}
POSTGRES_PASSWORD={{ index .Data.data "password" }}
POSTGRES_PASSWORD_2={{ index .Data.data "password" }}
POSTGRES_PASSWORD_3={{ index .Data.data "password" }}
POSTGRES_PASSWORD_4={{ index .Data.data "password" }}
{{- end -}}
spec:
serviceAccountName: bim-vault
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql
set +a
exec ./httpserver
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: LAST_MASTER_BIM
value: "100000"
- name: LAST_MASTER_BIM_V3
value: "100000"
- name: DB_CERT_PATH_4
value: /root/yandex_pg.pem
- name: DB_CERT_PATH_3
value: /root/yandex_pg.pem
- name: DB_CERT_PATH_2
value: /root/yandex_pg.pem
- name: LAST_SLAVE_1_BIM
value: "1000000"
- name: POSTGRES_POOL_SIZE
value: "30"
- name: API_ADDRESS
value: 0.0.0.0:8000
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000
- name: ENABLE_SQL_QUERY
value: "0"
- name: ENABLE_SSL
value: "0"
resources:
requests:
cpu: 25m
memory: 100Mi
livenessProbe:
httpGet:
path: /ping
port: 8000
initialDelaySeconds: 10
periodSeconds: 60
failureThreshold: 10
readinessProbe:
httpGet:
path: /ping
port: 8000
initialDelaySeconds: 5
periodSeconds: 5
failureThreshold: 20
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: bim
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

217
apps/bim/base/backend.yaml Normal file
View File

@ -0,0 +1,217 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: bim
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: bim-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql
set +a
exec ./httpserver
resources:
requests:
cpu:
_default: 25m
memory:
_default: 100Mi
probes:
liveness:
enabled:
_default: true
type:
_default: httpGet
httpGet:
path:
_default: /ping
port:
_default: 8000
initialDelaySeconds:
_default: 10
periodSeconds:
_default: 60
failureThreshold:
_default: 10
readiness:
enabled:
_default: true
type:
_default: httpGet
httpGet:
path:
_default: /ping
port:
_default: 8000
initialDelaySeconds:
_default: 5
periodSeconds:
_default: 5
failureThreshold:
_default: 20
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: LAST_MASTER_BIM
value:
_default: "100000"
- name: LAST_MASTER_BIM_V3
value:
_default: "100000"
- name: DB_CERT_PATH_4
value:
_default: "/root/yandex_pg.pem"
- name: DB_CERT_PATH_3
value:
_default: "/root/yandex_pg.pem"
- name: DB_CERT_PATH_2
value:
_default: "/root/yandex_pg.pem"
- name: LAST_SLAVE_1_BIM
value:
_default: "1000000"
- name: POSTGRES_POOL_SIZE
value:
_default: "30"
- name: API_ADDRESS
value:
_default: "0.0.0.0:8000"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: ENABLE_SQL_QUERY
value:
_default: "0"
- name: ENABLE_SSL
value:
_default: "0"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: bim
vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim
vault.hashicorp.com/agent-inject-template-bim-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/bim" -}}
POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local
POSTGRES_PORT=5432
POSTGRES_PORT_2=5432
POSTGRES_PORT_3=5432
POSTGRES_PORT_4=5432
POSTGRES_DB=bim_db
POSTGRES_DB_2=bim_db
POSTGRES_DB_3=bim_db
POSTGRES_DB_4=bim_db
POSTGRES_USER={{ index .Data.data "username" }}
POSTGRES_USER_2={{ index .Data.data "username" }}
POSTGRES_USER_3={{ index .Data.data "username" }}
POSTGRES_USER_4={{ index .Data.data "username" }}
POSTGRES_PASSWORD={{ index .Data.data "password" }}
POSTGRES_PASSWORD_2={{ index .Data.data "password" }}
POSTGRES_PASSWORD_3={{ index .Data.data "password" }}
POSTGRES_PASSWORD_4={{ index .Data.data "password" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,6 +4,4 @@ kind: Kustomization
namespace: bim
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- backend-service.yaml
- backend.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: bim-vault
namespace: bim

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: bim

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: bim
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,53 +1,98 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: bim
spec:
template:
spec:
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc
env:
- name: LAST_MASTER_BIM
value: '100000'
- name: LAST_SLAVE_1_BIM
value: '94015'
- name: LAST_MASTER_BIM_V3
value: '100000'
- name: LAST_SLAVE_1_BIM_V3
value: '0'
- name: DB_CERT_PATH_3
value: /root/yandex_pg.pem
- name: POSTGRES_ADDRESS_3
value: postgres-service
- name: POSTGRES_PORT_3
value: '5432'
- name: POSTGRES_DB_3
value: bimapidb
- name: DB_CERT_PATH_2
value: /root/yandex_pg.pem
- name: POSTGRES_ADDRESS_2
value: postgres-service
- name: POSTGRES_PORT_2
value: '5432'
- name: POSTGRES_DB_2
value: bimapidb
- name: POSTGRES_ADDRESS
value: postgres-service
- name: POSTGRES_PORT
value: '5432'
- name: POSTGRES_DB
value: bimapidb
- name: POSTGRES_POOL_SIZE
value: '30'
- name: API_ADDRESS
value: 0.0.0.0:8000
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000
- name: ENABLE_SQL_QUERY
value: '0'
- name: ENABLE_SSL
value: '0'
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc
envs:
- name: LAST_MASTER_BIM
value:
_default: "100000"
- name: LAST_SLAVE_1_BIM
value:
_default: "94015"
- name: LAST_MASTER_BIM_V3
value:
_default: "100000"
- name: LAST_SLAVE_1_BIM_V3
value:
_default: "0"
- name: DB_CERT_PATH_3
value:
_default: "/root/yandex_pg.pem"
- name: POSTGRES_ADDRESS_3
value:
_default: "postgres-service"
- name: POSTGRES_PORT_3
value:
_default: "5432"
- name: POSTGRES_DB_3
value:
_default: "bimapidb"
- name: DB_CERT_PATH_2
value:
_default: "/root/yandex_pg.pem"
- name: POSTGRES_ADDRESS_2
value:
_default: "postgres-service"
- name: POSTGRES_PORT_2
value:
_default: "5432"
- name: POSTGRES_DB_2
value:
_default: "bimapidb"
- name: POSTGRES_ADDRESS
value:
_default: "postgres-service"
- name: POSTGRES_PORT
value:
_default: "5432"
- name: POSTGRES_DB
value:
_default: "bimapidb"
- name: POSTGRES_POOL_SIZE
value:
_default: "30"
- name: API_ADDRESS
value:
_default: "0.0.0.0:8000"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: ENABLE_SQL_QUERY
value:
_default: "0"
- name: ENABLE_SSL
value:
_default: "0"
- name: DB_CERT_PATH_4
value:
_default: "/root/yandex_pg.pem"

View File

@ -9,5 +9,5 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend

View File

@ -7,5 +7,5 @@ resources:
patches:
- path: replicas.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend

View File

@ -1,8 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: bim
spec:
replicas: 1
values:
services:
backend:
deployment:
replicaCount:
_default: 1

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: cde-svc
namespace: faas
spec:
type: ClusterIP
selector:
app: cde
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-flowscallback
namespace: cde
labels:
app: cde-flowscallback
service: cde-flowscallback
spec:
replicas: 1
selector:
matchLabels:
app: cde-flowscallback
template:
metadata:
labels:
app: cde-flowscallback
service: cde-flowscallback
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-flowscallback
image: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-flowscallback:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-flowscallback
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-splitpdf
namespace: cde
labels:
app: cde-splitpdf
service: cde-splitpdf
spec:
replicas: 1
selector:
matchLabels:
app: cde-splitpdf
template:
metadata:
labels:
app: cde-splitpdf
service: cde-splitpdf
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-splitpdf
image: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-splitpdf:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-splitpdf
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-copy
namespace: cde
labels:
app: cde-worker-copy
service: cde-worker-copy
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-copy
template:
metadata:
labels:
app: cde-worker-copy
service: cde-worker-copy
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-copy
image: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-copy:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-copy
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-create-versions
namespace: cde
labels:
app: cde-worker-create-versions
service: cde-worker-create-versions
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-create-versions
template:
metadata:
labels:
app: cde-worker-create-versions
service: cde-worker-create-versions
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-create-versions
image: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-create-versions:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-create-versions
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-markings
namespace: cde
labels:
app: cde-worker-markings
service: cde-worker-markings
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-markings
template:
metadata:
labels:
app: cde-worker-markings
service: cde-worker-markings
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-markings
image: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-markings:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-markings
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-sign
namespace: cde
labels:
app: cde-worker-sign
service: cde-worker-sign
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-sign
template:
metadata:
labels:
app: cde-worker-sign
service: cde-worker-sign
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-sign
image: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-sign:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-sign
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,116 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-update-bundles
namespace: cde
labels:
app: cde-worker-update-bundles
service: cde-worker-update-bundles
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-update-bundles
template:
metadata:
labels:
app: cde-worker-update-bundles
service: cde-worker-update-bundles
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-update-bundles
image: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-update-bundles:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-update-bundles
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,131 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde
namespace: cde
labels:
app: cde
service: cde
spec:
replicas: 1
selector:
matchLabels:
app: cde
template:
metadata:
labels:
app: cde
service: cde
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: api
image: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde
replicaCount:
_default: 1
port:
_default: 8000
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /http
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /http
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: cde-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,10 +4,8 @@ kind: Kustomization
namespace: cde
resources:
- namespace.yaml
- serviceaccount.yaml
- cde.yaml
- cde-splitpdf.yaml
- backend-service.yaml
- cde-flowscallback.yaml
- cde-worker-copy.yaml
- cde-worker-create-versions.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: cde-vault
namespace: cde

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: cde

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cde
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: comparisons
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -3,5 +3,5 @@ kind: Namespace
metadata:
name: control-interface
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: cross-section
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: document-link
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: drawings
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -103,10 +103,11 @@ data:
"django_filters.rest_framework.DjangoFilterBackend"
],
"DEFAULT_AUTHENTICATION_CLASSES": [
"core.auth.ZitadelJWTAuthentication",
"rest_framework_simplejwt.authentication.JWTAuthentication",
"rest_framework.authentication.SessionAuthentication",
"rest_framework.authentication.BasicAuthentication",
#"core.auth.ZitadelJWTAuthentication",
"rest_framework_simplejwt.authentication.JWTStatelessUserAuthentication",
#"rest_framework_simplejwt.authentication.JWTAuthentication",
#"rest_framework.authentication.SessionAuthentication",
#"rest_framework.authentication.BasicAuthentication",
],
"DEFAULT_PERMISSION_CLASSES": [
"rest_framework.permissions.AllowAny",

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: faas
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,137 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: flows
labels:
app: backend
service: backend
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
service: backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/flows" -}}
PG_DB=flows_db
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST=postgresql.flows.svc.cluster.local
PG_PORT=5432
PG_PASSWORD={{ index .Data.data "password" }}
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
DOCUMENTATION_PG_PORT=5432
DOCUMENTATION_PG_DATABASE=flows_db
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: flows-vault
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec /opt/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: LOG_LEVEL
value: DEBUG
- name: BASE_HOST
value: https://srx.wb.ru
- name: CELERY_QUEUE
value: flow
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: DJANGO_HOST
value: http://backend-svc.django.svc.cluster.local:80/api
- name: PLANNING_HOST
value: http://backend-svc.pm.svc.cluster.local:80/api/pm/msp
- name: PLANNING_USE
value: "True"
- name: DOCUMENTATION_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1
- name: DOCUMENTATION_EXTERNAL_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1
- name: ENABLE_ANALYTICS
value: "1"
- name: ENABLE_CELERY
value: "1"
- name: ENABLE_MAILGUN
value: "0"
- name: ENABLE_METRICS
value: "0"
- name: FROM_EMAIL
value: sarex@rwb.ru
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080
- name: RESOURCE_URL
value: http://resources-service.resources.svc.cluster.local:8000
- name: SERVICE_HOST
value: https://srx.wb.ru/flows/api/v1
- name: SMTP_HOST
value: mail.rwb.ru
- name: CHECKLIST_HOST
value: http://checklists-backend-service.checklists.svc.cluster.local:80
- name: SMTP_PORT
value: "465"
- name: SYNC_RESOURCE_ID
value: "1"
- name: TIMEOUT
value: "120"
- name: WORKFLOWS_HOST
value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1
- name: WORKFLOWS_TIMEOUT
value: "60"
- name: DOCUMENTATION_TIMEOUT
value: "60"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: flows
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -0,0 +1,258 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: flows
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: flows-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec /opt/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://srx.wb.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: DJANGO_HOST
value:
_default: "http://backend-svc.django.svc.cluster.local:80/api"
- name: PLANNING_HOST
value:
_default: "http://backend-svc.pm.svc.cluster.local:80/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@rwb.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: SERVICE_HOST
value:
_default: "https://srx.wb.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "mail.rwb.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "465"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "120"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "60"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "60"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/flows" -}}
PG_DB=flows_db
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST=postgresql.flows.svc.cluster.local
PG_PORT=5432
PG_PASSWORD={{ index .Data.data "password" }}
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
DOCUMENTATION_PG_PORT=5432
DOCUMENTATION_PG_DATABASE=flows_db
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,137 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: celery
namespace: flows
labels:
app: celery
service: celery
spec:
replicas: 1
selector:
matchLabels:
app: celery
template:
metadata:
labels:
app: celery
service: celery
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/flows" -}}
PG_DB=flows_db
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST=postgresql.flows.svc.cluster.local
PG_PORT=5432
PG_PASSWORD={{ index .Data.data "password" }}
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
DOCUMENTATION_PG_PORT=5432
DOCUMENTATION_PG_DATABASE=flows_db
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: flows-vault
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: LOG_LEVEL
value: DEBUG
- name: BASE_HOST
value: https://srx.wb.ru
- name: CELERY_QUEUE
value: flow
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: DJANGO_HOST
value: http://backend-svc.django.svc.cluster.local:80/api
- name: PLANNING_HOST
value: http://backend-service.pm.svc.cluster.local:80/api/pm/msp
- name: PLANNING_USE
value: "True"
- name: DOCUMENTATION_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1
- name: DOCUMENTATION_EXTERNAL_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1
- name: ENABLE_ANALYTICS
value: "1"
- name: ENABLE_CELERY
value: "1"
- name: ENABLE_MAILGUN
value: "0"
- name: ENABLE_METRICS
value: "0"
- name: FROM_EMAIL
value: sarex@rwb.ru
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080
- name: RESOURCE_URL
value: http://resources-service.resources.svc.cluster.local:8000
- name: SERVICE_HOST
value: https://srx.wb.ru/flows/api/v1
- name: SMTP_HOST
value: mail.rwb.ru
- name: CHECKLIST_HOST
value: http://checklists-backend-service.checklists.svc.cluster.local:80
- name: SMTP_PORT
value: "465"
- name: SYNC_RESOURCE_ID
value: "1"
- name: TIMEOUT
value: "120"
- name: WORKFLOWS_HOST
value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1
- name: WORKFLOWS_TIMEOUT
value: "60"
- name: DOCUMENTATION_TIMEOUT
value: "60"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

243
apps/flows/base/celery.yaml Normal file
View File

@ -0,0 +1,243 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: flows
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
celery:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: flows-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: celery
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://srx.wb.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: DJANGO_HOST
value:
_default: "http://backend-svc.django.svc.cluster.local:80/api"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:80/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@rwb.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: SERVICE_HOST
value:
_default: "https://srx.wb.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "mail.rwb.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "465"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "120"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "60"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "60"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/flows" -}}
PG_DB=flows_db
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST=postgresql.flows.svc.cluster.local
PG_PORT=5432
PG_PASSWORD={{ index .Data.data "password" }}
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
DOCUMENTATION_PG_PORT=5432
DOCUMENTATION_PG_DATABASE=flows_db
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,32 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontend
namespace: flows
labels:
app: frontend
spec:
replicas: 1
selector:
matchLabels:
app: frontend
template:
metadata:
labels:
app: frontend
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 80
protocol: TCP
resources:
requests:
cpu: 25m
memory: 100Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: frontend-svc
namespace: flows
spec:
type: ClusterIP
selector:
app: frontend
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP

View File

@ -0,0 +1,90 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: flows
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
frontend:
enabled: true
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: frontend
replicaCount:
_default: 1
port:
_default: 80
resources:
requests:
cpu:
_default: 25m
memory:
_default: 100Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: frontend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred

View File

@ -4,9 +4,6 @@ kind: Kustomization
namespace: flows
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- celery-deployment.yaml
- frontend-deployment.yaml
- backend-service.yaml
- frontend-service.yaml
- backend.yaml
- celery.yaml
- frontend.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: flows-vault
namespace: flows

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: flows

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: flows
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,92 +1,182 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: flows
spec:
replicas: 2
template:
spec:
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0
env:
- name: DEBUG
value: 'false'
- name: PLANNING_HOST
value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp
- name: PLANNING_USE
value: 'True'
- name: PG_PORT
value: '5432'
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: PROXY_PATH_PREFIX
value: /flows
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000/api
- name: DOCUMENTATION_TIMEOUT
value: '240'
- name: DOCUMENTATION_HOST
value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1
- name: DOCUMENTATION_EXTERNAL_HOST
value: http://documentations-service.documentations.svc.cluster.local:8080/api/v1
- name: BASE_HOST
value: https://sarex.dsinv.ru
- name: DOCUMENTATION_PG_PORT
value: '5432'
- name: DOCUMENTATION_PG_DATABASE
value: documentations
- name: DOCUMENTATION_PG_HOST
value: postgres-service.documentations.svc.cluster.local
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value: cr.yandex/crp3ccidau046kdj8g9q
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value: relay.dsinv.ru
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value: '25'
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value: sarex@dsinv.ru
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value: '0'
- name: RESOURCES_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: ENABLE_METRICS
value: '0'
- name: ENABLE_MAILGUN
value: '0'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: FROM_EMAIL
value: sarex@dsinv.ru
- name: TIMEOUT
value: '240'
- name: WORKFLOWS_TIMEOUT
value: '20'
- name: RESOURCE_URL
value: http://resources-service.resources.svc.cluster.local:8000/
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080/
- name: SYNC_RESOURCE_ID
value: '1'
- name: SERVICE_HOST
value: https://sarex.dsinv.ru/flows/api/v1
- name: ENABLE_ANALYTICS
value: '1'
- name: ENABLE_CELERY
value: '1'
- name: CELERY_QUEUE
value: flow
- name: RABBITMQ_HOST
value: rabbitmq-service.flows.svc
- name: RABBITMQ_PORT
value: '5672'
- name: RABBITMQ_VHOST
value: flow
- name: PG_HOST
value: postgres-service.flows.svc.cluster.local
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0
deployment:
replicaCount:
_default: 2
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000/api"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://documentations-service.documentations.svc.cluster.local:8080/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@dsinv.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080/"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources.svc.cluster.local:8000/"
- name: SERVICE_HOST
value:
_default: "https://sarex.dsinv.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "25"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "240"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "20"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "240"
- name: DEBUG
value:
_default: "false"
- name: PG_PORT
value:
_default: "5432"
- name: PROXY_PATH_PREFIX
value:
_default: "/flows"
- name: DOCUMENTATION_PG_PORT
value:
_default: "5432"
- name: DOCUMENTATION_PG_DATABASE
value:
_default: "documentations"
- name: DOCUMENTATION_PG_HOST
value:
_default: "postgres-service.documentations.svc.cluster.local"
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value:
_default: "25"
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value:
_default: "sarex@dsinv.ru"
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value:
_default: "0"
- name: RESOURCES_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: RABBITMQ_HOST
value:
_default: "rabbitmq-service.flows.svc"
- name: RABBITMQ_PORT
value:
_default: "5672"
- name: RABBITMQ_VHOST
value:
_default: "flow"
- name: PG_HOST
value:
_default: "postgres-service.flows.svc.cluster.local"

View File

@ -1,93 +1,198 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: flows
spec:
template:
spec:
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0
env:
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL
value: sarex@dsinv.ru
- name: ENABLE_METRICS
value: '0'
- name: ENABLE_MAILGUN
value: '0'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: FROM_EMAIL
value: sarex@dsinv.ru
- name: MAILGUN_HOST
value: http:localhost:8000
- name: MAILGUN_API_KEY
value: empty
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value: '0'
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1
- name: FLOWS_HOST
value: http://backend-service.flows.svc.cluster.local:8000
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value: cr.yandex/crp3ccidau046kdj8g9q
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value: relay.dsinv.ru
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value: '25'
- name: PLANNING_HOST
value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp
- name: PLANNING_USE
value: 'True'
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value: sarex@dsinv.ru
- name: FLOWS_DB_HOST
value: postgres-service.flows.svc.cluster.local
- name: ISSUES_DB_HOST
value: postgres-service.issues.svc.cluster.local
- name: DEBUG
value: '0'
- name: PG_PORT
value: '5432'
- name: FLOWS_DB_PORT
value: '5432'
- name: ISSUES_DB_PORT
value: '5432'
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000/api
- name: DJANGO_BASE_HOST
value: https://sarex.dsinv.ru
- name: DOCUMENTATION_HOST
value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1
- name: BASE_HOST
value: https://sarex.dsinv.ru
- name: RESOURCES_HOST
value: http://resources-service.resources.svc.cluster.local:8000/
- name: TIMEOUT
value: '120'
- name: RESOURCE_URL
value: http://resources-service.resources/api/v1
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080/api/v1
- name: SYNC_RESOURCE_ID
value: '1'
- name: SERVICE_HOST
value: https://sarex.dsinv.ru/flows/api/v1
- name: ENABLE_ANALYTICS
value: '1'
- name: ENABLE_CELERY
value: '1'
- name: CELERY_QUEUE
value: flow
- name: RABBITMQ_HOST
value: rabbitmq-service.flows.svc
- name: RABBITMQ_PORT
value: '5672'
- name: RABBITMQ_VHOST
value: flow
- name: PG_HOST
value: postgres-service.flows.svc.cluster.local
values:
services:
celery:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000/api"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@dsinv.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080/api/v1"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources/api/v1"
- name: SERVICE_HOST
value:
_default: "https://sarex.dsinv.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "25"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "120"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "60"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "60"
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL
value:
_default: "sarex@dsinv.ru"
- name: MAILGUN_HOST
value:
_default: "http:localhost:8000"
- name: MAILGUN_API_KEY
value:
_default: "empty"
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value:
_default: "0"
- name: FLOWS_HOST
value:
_default: "http://backend-service.flows.svc.cluster.local:8000"
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value:
_default: "25"
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value:
_default: "sarex@dsinv.ru"
- name: FLOWS_DB_HOST
value:
_default: "postgres-service.flows.svc.cluster.local"
- name: ISSUES_DB_HOST
value:
_default: "postgres-service.issues.svc.cluster.local"
- name: DEBUG
value:
_default: "0"
- name: PG_PORT
value:
_default: "5432"
- name: FLOWS_DB_PORT
value:
_default: "5432"
- name: ISSUES_DB_PORT
value:
_default: "5432"
- name: DJANGO_BASE_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: RESOURCES_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000/"
- name: RABBITMQ_HOST
value:
_default: "rabbitmq-service.flows.svc"
- name: RABBITMQ_PORT
value:
_default: "5672"
- name: RABBITMQ_VHOST
value:
_default: "flow"
- name: PG_HOST
value:
_default: "postgres-service.flows.svc.cluster.local"

View File

@ -1,12 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: flows
spec:
template:
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2
values:
services:
frontend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2

View File

@ -10,13 +10,13 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend
- path: celery.yaml
target:
kind: Deployment
kind: HelmRelease
name: celery
- path: frontend.yaml
target:
kind: Deployment
kind: HelmRelease
name: frontend

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: rfi-backend-api-svc
namespace: rfi
spec:
type: ClusterIP
selector:
app: rfi-backend-api
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -0,0 +1,240 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: inspections
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: inspections-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: inspections-backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/bash", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db
[ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka
[ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth
set +a
exec ./entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: DEBUG
value:
_default: "false"
- name: SERVICE_URL
value:
_default: "https://srx.wb.ru"
- name: HTTP_APP_HOST
value:
_default: "0.0.0.0"
- name: HTTP_APP_PORT
value:
_default: "8000"
- name: HTTP_APP_ROOT_PATH
value:
_default: "/inspections"
- name: HTTP_APP_WORKERS
value:
_default: "3"
- name: HTTP_APP_ADMIN_ENABLE
value:
_default: "true"
- name: KAFKA_SSL_CAFILE
value:
_default: "/usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt"
- name: KAFKA_EAV_ASSETS_TOPIC
value:
_default: "assets_broadcast"
- name: JWT_AUTH_ENABLE
value:
_default: "true"
- name: NOTIFICATIONS_ENABLE
value:
_default: "true"
- name: NOTIFICATIONS_EMAIL_FROM
value:
_default: "hello@sarex.io"
- name: SAREX_BACKEND_URL
value:
_default: "https://srx.wb.ru"
- name: SAREX_BACKEND_TIMEOUT
value:
_default: "30"
- name: EAV_URL
value:
_default: "http://eav-service.eav"
- name: EAV_TIMEOUT
value:
_default: "30"
- name: WORKFLOWS_URL
value:
_default: "http://workflows-service.processing-prod"
- name: WORKFLOWS_TIMEOUT
value:
_default: "30"
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q/notification:email"
- name: MOBILE_APP_CURRENT_VERSION
value:
_default: "1.0.0"
- name: MOBILE_APP_RECOMMENDED_VERSION
value:
_default: "1.0.0"
- name: MOBILE_APP_REQUIRED_VERSION
value:
_default: "1.0.0"
- name: MAILER_URL
value:
_default: "http://mailer-service.mailer:8000"
- name: MAILER_TIMEOUT
value:
_default: "30"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: inspections
vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/postgresql/apps/inspections
vault.hashicorp.com/agent-inject-template-inspections-db: |-
{{- with secret "secrets/data/postgresql/apps/inspections" -}}
DATABASE_HOST=postgresql.inspections.svc.cluster.local
DATABASE_PORT=5432
DATABASE_NAME=inspections_db
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections
vault.hashicorp.com/agent-inject-template-inspections-kafka: |-
{{- with secret "secrets/data/kafka/apps/inspections" -}}
KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-inspections-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
SAREX_BACKEND_AUTH={{ index .Data.data "key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,6 +4,4 @@ kind: Kustomization
namespace: inspections
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- backend-service.yaml
- backend.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: inspections-vault
namespace: inspections

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: inspections

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: inspections
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,61 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: inspections-backend
name: backend
namespace: inspections
spec:
template:
spec:
containers:
- name: inspections-backend
image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d
env:
- name: DEBUG
value: 'false'
- name: SERVICE_URL
value: https://srx.wb.ru
- name: HTTP_APP_HOST
value: 0.0.0.0
- name: HTTP_APP_PORT
value: '8000'
- name: HTTP_APP_ROOT_PATH
value: /inspections
- name: HTTP_APP_WORKERS
value: '3'
- name: HTTP_APP_ADMIN_ENABLE
value: 'true'
- name: KAFKA_SSL_CAFILE
value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt
- name: KAFKA_EAV_ASSETS_TOPIC
value: assets_broadcast
- name: JWT_AUTH_ENABLE
value: 'true'
- name: NOTIFICATIONS_ENABLE
value: 'true'
- name: NOTIFICATIONS_EMAIL_FROM
value: hello@sarex.io
- name: SAREX_BACKEND_URL
value: https://srx.wb.ru
- name: SAREX_BACKEND_TIMEOUT
value: '30'
- name: EAV_URL
value: http://eav-service.eav
- name: EAV_TIMEOUT
value: '30'
- name: WORKFLOWS_URL
value: http://workflows-service.processing-prod
- name: WORKFLOWS_TIMEOUT
value: '30'
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
value: cr.yandex/crp3ccidau046kdj8g9q/notification:email
- name: MOBILE_APP_CURRENT_VERSION
value: 1.0.0
- name: MOBILE_APP_RECOMMENDED_VERSION
value: 1.0.0
- name: MOBILE_APP_REQUIRED_VERSION
value: 1.0.0
- name: MAILER_URL
value: http://mailer-service.mailer:8000
- name: MAILER_TIMEOUT
value: '30'
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d

View File

@ -9,5 +9,5 @@ resources:
patches:
- path: inspections-backend.yaml
target:
kind: Deployment
name: inspections-backend
kind: HelmRelease
name: backend

View File

@ -1,135 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: issues
labels:
app: backend
service: backend
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
service: backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/postgresql/apps/issues" -}}
DATABASE_PORT=5432
DATABASE_HOST=postgresql.issues.svc.cluster.local
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME=issues_db
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: issues-vault
volumes:
- name: production-configmap
configMap:
name: production-configmap
items:
- key: production.py
path: production.py
defaultMode: 420
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec /src/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: ENVIRONMENT
value: production
- name: AERO_PUBLIC_HOST
value: https://sarex.contour.infra.sarex.tech
- name: AERO_HOST
value: https://sarex.contour.infra.sarex.tech
- name: BASE_AERO_URL
value: https://sarex.contour.infra.sarex.tech
- name: BASE_AUTH_URL
value: http://backend-svc.django.svc.cluster.local:80
- name: WORKFLOWS_HOST
value: http://backend-svc.workflow.svc.cluster.local:80
- name: WORKFLOWS_URL
value: http://backend-svc.workflow.svc.cluster.local:80
- name: RESOURCES_API_HOST
value: http://backend-svc.resources.svc.cluster.local:80
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: SAREX_API
value: https://sarex.contour.infra.sarex.tech
- name: DOCUMENTATIONS_URL
value: http://documentations-api-svc.documentations.svc.cluster.local:80
- name: DJANGO_SETTINGS_MODULE
value: config.settings.production
- name: API_ADDRESS
value: "8000"
resources:
requests:
cpu: "25m"
memory: 128Mi
volumeMounts:
- name: production-configmap
mountPath: /src/config/settings/production.py
subPath: production.py
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: issues
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -0,0 +1,237 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: issues
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: issues-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec /src/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
volumes:
_default:
- name: production-configmap
mountPath:
_default: /src/config/settings/production.py
subPath:
_default: production.py
readOnly:
_default: true
configMap:
name:
_default: production-configmap
items:
- key: production.py
path:
_default: production.py
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: AERO_HOST
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: BASE_AERO_URL
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: BASE_AUTH_URL
value:
_default: "http://backend-svc.django.svc.cluster.local:80"
- name: WORKFLOWS_HOST
value:
_default: "http://backend-svc.workflow.svc.cluster.local:80"
- name: WORKFLOWS_URL
value:
_default: "http://backend-svc.workflow.svc.cluster.local:80"
- name: RESOURCES_API_HOST
value:
_default: "http://backend-svc.resources.svc.cluster.local:80"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: SAREX_API
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: DOCUMENTATIONS_URL
value:
_default: "http://documentations-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/postgresql/apps/issues" -}}
DATABASE_PORT=5432
DATABASE_HOST=postgresql.issues.svc.cluster.local
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME=issues_db
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,135 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: celery
namespace: issues
labels:
app: celery
service: celery
spec:
replicas: 1
selector:
matchLabels:
app: celery
template:
metadata:
labels:
app: celery
service: celery
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/postgresql/apps/issues" -}}
DATABASE_PORT=5432
DATABASE_HOST=postgresql.issues.svc.cluster.local
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME=issues_db
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: issues-vault
volumes:
- name: production-configmap
configMap:
name: production-configmap
items:
- key: production.py
path: production.py
defaultMode: 420
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec celery -A config worker -l info -E
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: ENVIRONMENT
value: production
- name: AERO_PUBLIC_HOST
value: https://srx.wb.ru
- name: AERO_HOST
value: https://srx.wb.ru
- name: BASE_AERO_URL
value: https://srx.wb.ru
- name: BASE_AUTH_URL
value: http://backend-svc.django.svc.cluster.local:80
- name: WORKFLOWS_HOST
value: http://workflows-api-service.workflow.svc.cluster.local:8000
- name: WORKFLOWS_URL
value: http://workflows-api-service.workflow.svc.cluster.local:8000
- name: RESOURCES_API_HOST
value: http://backend-svc.resources.svc.cluster.local:80
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: SAREX_API
value: https://srx.wb.ru
- name: DOCUMENTATIONS_URL
value: http://backend-api-svc.documentations.svc.cluster.local:80
- name: DJANGO_SETTINGS_MODULE
value: config.settings.production
- name: API_ADDRESS
value: "8000"
resources:
requests:
cpu: "25m"
memory: 128Mi
volumeMounts:
- name: production-configmap
mountPath: /src/config/settings/production.py
subPath: production.py
imagePullSecrets:
- name: regcred

View File

@ -0,0 +1,222 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: issues
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
celery:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: issues-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: celery
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec celery -A config worker -l info -E
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
volumes:
_default:
- name: production-configmap
mountPath:
_default: /src/config/settings/production.py
subPath:
_default: production.py
readOnly:
_default: true
configMap:
name:
_default: production-configmap
items:
- key: production.py
path:
_default: production.py
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://srx.wb.ru"
- name: AERO_HOST
value:
_default: "https://srx.wb.ru"
- name: BASE_AERO_URL
value:
_default: "https://srx.wb.ru"
- name: BASE_AUTH_URL
value:
_default: "http://backend-svc.django.svc.cluster.local:80"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000"
- name: WORKFLOWS_URL
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000"
- name: RESOURCES_API_HOST
value:
_default: "http://backend-svc.resources.svc.cluster.local:80"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: SAREX_API
value:
_default: "https://srx.wb.ru"
- name: DOCUMENTATIONS_URL
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/postgresql/apps/issues" -}}
DATABASE_PORT=5432
DATABASE_HOST=postgresql.issues.svc.cluster.local
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME=issues_db
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,32 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontend
namespace: issues
labels:
app: frontend
spec:
replicas: 1
selector:
matchLabels:
app: frontend
template:
metadata:
labels:
app: frontend
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 80
protocol: TCP
resources:
requests:
cpu: 25m
memory: 100Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: frontend-svc
namespace: issues
spec:
type: ClusterIP
selector:
app: frontend
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP

View File

@ -0,0 +1,90 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: issues
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
frontend:
enabled: true
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: frontend
replicaCount:
_default: 1
port:
_default: 80
resources:
requests:
cpu:
_default: 25m
memory:
_default: 100Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: frontend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred

View File

@ -4,10 +4,7 @@ kind: Kustomization
namespace: issues
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- celery-deployment.yaml
- frontend-deployment.yaml
- backend-service.yaml
- frontend-service.yaml
- backend.yaml
- celery.yaml
- frontend.yaml
- production-configmap.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: issues-vault
namespace: issues

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: issues

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: issues
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,53 +1,102 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: issues
spec:
template:
spec:
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
env:
- name: ENABLE_MAILGUN
value: 'False'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: EMAIL_FROM
value: sarex@dsinv.ru
- name: USE_NOTIFICATIONS
value: 'True'
- name: DJANGO_SETTINGS_MODULE
value: config.settings.production
- name: REDIS_HOST
value: redis-service.issues.svc.cluster.local
- name: DATABASE_HOST
value: postgres-service.issues.svc.cluster.local
- name: DATABASE_PORT
value: '5432'
- name: DATABASE_NAME
value: issues
- name: API_ADDRESS
value: '8000'
- name: ENVIRONMENT
value: production
- name: AERO_PUBLIC_HOST
value: https://sarex.dsinv.ru
- name: BASE_AERO_URL
value: http://backend.django.svc.cluster.local:8000
- name: BASE_AUTH_URL
value: http://backend.django.svc.cluster.local:8000
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000
- name: WORKFLOWS_URL
value: https://sarex.dsinv.ru
- name: RESOURCES_API_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: SAREX_API
value: http://backend.django.svc.cluster.local:8000
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: AERO_HOST
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: BASE_AERO_URL
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: BASE_AUTH_URL
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000"
- name: WORKFLOWS_URL
value:
_default: "https://sarex.dsinv.ru"
- name: RESOURCES_API_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: SAREX_API
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: DOCUMENTATIONS_URL
value:
_default: "http://documentations-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
- name: ENABLE_MAILGUN
value:
_default: "False"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: SMTP_PORT
value:
_default: "25"
- name: EMAIL_FROM
value:
_default: "sarex@dsinv.ru"
- name: USE_NOTIFICATIONS
value:
_default: "True"
- name: REDIS_HOST
value:
_default: "redis-service.issues.svc.cluster.local"
- name: DATABASE_HOST
value:
_default: "postgres-service.issues.svc.cluster.local"
- name: DATABASE_PORT
value:
_default: "5432"
- name: DATABASE_NAME
value:
_default: "issues"

View File

@ -1,57 +1,110 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: issues
spec:
template:
spec:
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
env:
- name: KAFKA_EAV_ASSETS_TOPIC
value: sarex
- name: AERO_PUBLIC_HOST
value: https://sarex.dsinv.ru
- name: ENABLE_MAILGUN
value: 'False'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: EMAIL_FROM
value: sarex@dsinv.ru
- name: REDIS_HOST
value: redis-service.issues.svc.cluster.local
- name: DATABASE_HOST
value: postgres-service.issues.svc.cluster.local
- name: DATABASE_PORT
value: '5432'
- name: DATABASE_NAME
value: issues
- name: USE_NOTIFICATIONS
value: 'True'
- name: API_ADDRESS
value: '8000'
- name: YC_S3_VERIFY
value: 'False'
- name: ENVIRONMENT
value: production
- name: AERO_HOST
value: https://sarex.dsinv.ru
- name: BASE_AERO_URL
value: http://backend.django.svc.cluster.local:8000
- name: BASE_AUTH_URL
value: https://sarex.dsinv.ru
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000
- name: WORKFLOWS_URL
value: https://sarex.dsinv.ru
- name: RESOURCES_API_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: SAREX_API
value: http://backend.django.svc.cluster.local:8000
values:
services:
celery:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: AERO_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: BASE_AERO_URL
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: BASE_AUTH_URL
value:
_default: "https://sarex.dsinv.ru"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000"
- name: WORKFLOWS_URL
value:
_default: "https://sarex.dsinv.ru"
- name: RESOURCES_API_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: SAREX_API
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: DOCUMENTATIONS_URL
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
- name: KAFKA_EAV_ASSETS_TOPIC
value:
_default: "sarex"
- name: ENABLE_MAILGUN
value:
_default: "False"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: SMTP_PORT
value:
_default: "25"
- name: EMAIL_FROM
value:
_default: "sarex@dsinv.ru"
- name: REDIS_HOST
value:
_default: "redis-service.issues.svc.cluster.local"
- name: DATABASE_HOST
value:
_default: "postgres-service.issues.svc.cluster.local"
- name: DATABASE_PORT
value:
_default: "5432"
- name: DATABASE_NAME
value:
_default: "issues"
- name: USE_NOTIFICATIONS
value:
_default: "True"
- name: YC_S3_VERIFY
value:
_default: "False"

View File

@ -1,12 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: issues
spec:
template:
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b
values:
services:
frontend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b

View File

@ -7,13 +7,13 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend
- path: celery.yaml
target:
kind: Deployment
kind: HelmRelease
name: celery
- path: frontend.yaml
target:
kind: Deployment
kind: HelmRelease
name: frontend

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: mapper
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: measurements
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,96 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: message-hub
namespace: message-hub
labels:
app: message-hub
service: message-hub
spec:
replicas: 1
selector:
matchLabels:
app: message-hub
template:
metadata:
labels:
app: message-hub
service: message-hub
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: message-hub
vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/postgresql/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-db: |-
{{- with secret "secrets/data/postgresql/apps/message-hub" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-s3: |-
{{- with secret "secrets/data/minio/apps/message-hub" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}rfi{{- end -}}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-kafka: |-
{{- with secret "secrets/data/kafka/apps/message-hub" -}}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
KAFKA_HOST=kafka-kafka-contour-controller-headless.kafka.svc.cluster.local
KAFKA_PORT=9094
KAFKA_SECURITY_PROTOCOL={{ index .Data.data.auth "security_protocol" }}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }}
{{- end -}}
spec:
serviceAccountName: message-hub-vault
containers:
- name: message-hub
image: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_24425472
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/message-hub-db ] && . /vault/secrets/message-hub-db
[ -f /vault/secrets/message-hub-s3 ] && . /vault/secrets/message-hub-s3
[ -f /vault/secrets/message-hub-kafka ] && . /vault/secrets/message-hub-kafka
set +a
exec /opt/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: WORKER_TIMEOUT
value: "60"
- name: PYTHONPATH
value: src
- name: SETTINGS_MAX_RETRIES
value: "1"
- name: SETTINGS_TOPICS
value: '{"planning": "pm", "assets": "assets_broadcast", "project_entity": "issues_broadcast"}'
- name: SETTINGS_PDF_CONVERTER_HOST
value: http://export-project-service.django.svc.cluster.local:8000
- name: SAREX_BASE_HOST
value: http://backend-service.pm.svc.cluster.local:8000
- name: CACHE_HOST
value: redis.pm.svc.cluster.local
- name: CACHE_PORT
value: "6379"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

View File

@ -4,6 +4,4 @@ kind: Kustomization
namespace: message-hub
resources:
- namespace.yaml
- serviceaccount.yaml
- deployment.yaml
- service.yaml
- message-hub.yaml

View File

@ -0,0 +1,183 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: message-hub
namespace: message-hub
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: message-hub-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_24425472
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: message-hub
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/bash", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/message-hub-db ] && . /vault/secrets/message-hub-db
[ -f /vault/secrets/message-hub-s3 ] && . /vault/secrets/message-hub-s3
[ -f /vault/secrets/message-hub-kafka ] && . /vault/secrets/message-hub-kafka
set +a
exec /opt/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: message-hub-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: WORKER_TIMEOUT
value:
_default: "60"
- name: PYTHONPATH
value:
_default: "src"
- name: SETTINGS_MAX_RETRIES
value:
_default: "1"
- name: SETTINGS_TOPICS
value:
_default: '{"planning": "pm", "assets": "assets_broadcast", "project_entity": "issues_broadcast"}'
- name: SETTINGS_PDF_CONVERTER_HOST
value:
_default: "http://export-project-service.django.svc.cluster.local:8000"
- name: SAREX_BASE_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000"
- name: CACHE_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: CACHE_PORT
value:
_default: "6379"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: message-hub
vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/postgresql/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-db: |-
{{- with secret "secrets/data/postgresql/apps/message-hub" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-s3: |-
{{- with secret "secrets/data/minio/apps/message-hub" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}rfi{{- end -}}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-kafka: |-
{{- with secret "secrets/data/kafka/apps/message-hub" -}}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
KAFKA_HOST=kafka-kafka-contour-controller-headless.kafka.svc.cluster.local
KAFKA_PORT=9094
KAFKA_SECURITY_PROTOCOL={{ index .Data.data.auth "security_protocol" }}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: message-hub-svc
namespace: message-hub
spec:
type: ClusterIP
selector:
app: message-hub
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: message-hub-vault
namespace: message-hub

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: message-hub

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: message-hub
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -7,5 +7,5 @@ resources:
patches:
- path: message-hub.yaml
target:
kind: Deployment
kind: HelmRelease
name: message-hub

View File

@ -1,49 +1,90 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: message-hub
namespace: message-hub
spec:
template:
spec:
containers:
- name: message-hub
image: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_d11aa910
env:
- name: WORKER_TIMEOUT
value: '60'
- name: PYTHONPATH
value: src
- name: SETTINGS_MAX_RETRIES
value: '1'
- name: SETTINGS_TOPICS
value: '{"planning": "message-hub-prod", "assets":"assets_broadcast","issues": "issues_broadcast_prod"}'
- name: PDF_CONVERTER_HOST
value: http://export-project-service.django.svc.cluster.local:8000
- name: SAREX_BASE_HOST
value: http://backend-service.pm.svc.cluster.local:8000
- name: PM_HOST
value: http://backend-service.pm.svc.cluster.local:8000
- name: DB_HOST
value: postgres-service.pm.svc.cluster.local
- name: DB_PORT
value: '5432'
- name: DB_DATABASE
value: pm
- name: CACHE_HOST
value: redis.pm.svc.cluster.local
- name: CACHE_PORT
value: '6379'
- name: CACHE_SSL
value: '0'
- name: KAFKA_HOST
value: donstroi-kafka-bootstrap.kafka.svc.cluster.local
- name: KAFKA_PORT
value: '9093'
- name: KAFKA_SECURITY_PROTOCOL
value: SSL
- name: KAFKA_SASL_MECHANISM
value: PLAIN
- name: KAFKA_SSL_CAFILE
value: /usr/local/share/ca-certificates/kafka.crt
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_d11aa910
envs:
- name: WORKER_TIMEOUT
value:
_default: "60"
- name: PYTHONPATH
value:
_default: "src"
- name: SETTINGS_MAX_RETRIES
value:
_default: "1"
- name: SETTINGS_TOPICS
value:
_default: '{"planning": "message-hub-prod", "assets":"assets_broadcast","issues": "issues_broadcast_prod"}'
- name: SETTINGS_PDF_CONVERTER_HOST
value:
_default: "http://export-project-service.django.svc.cluster.local:8000"
- name: SAREX_BASE_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000"
- name: CACHE_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: CACHE_PORT
value:
_default: "6379"
- name: PDF_CONVERTER_HOST
value:
_default: "http://export-project-service.django.svc.cluster.local:8000"
- name: PM_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000"
- name: DB_HOST
value:
_default: "postgres-service.pm.svc.cluster.local"
- name: DB_PORT
value:
_default: "5432"
- name: DB_DATABASE
value:
_default: "pm"
- name: CACHE_SSL
value:
_default: "0"
- name: KAFKA_HOST
value:
_default: "donstroi-kafka-bootstrap.kafka.svc.cluster.local"
- name: KAFKA_PORT
value:
_default: "9093"
- name: KAFKA_SECURITY_PROTOCOL
value:
_default: "SSL"
- name: KAFKA_SASL_MECHANISM
value:
_default: "PLAIN"
- name: KAFKA_SSL_CAFILE
value:
_default: "/usr/local/share/ca-certificates/kafka.crt"

View File

@ -1,132 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: pm
labels:
app: backend
service: api
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
service: api
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: pm
vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm
vault.hashicorp.com/agent-inject-template-pm-db: |-
{{- with secret "secrets/data/postgresql/apps/pm" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm
vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/pm" -}}
CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
CELERY_RABBITMQ_PORT=5672
CELERY_RABBITMQ_USER={{ index .Data.data "username" }}
CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }}
CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm
vault.hashicorp.com/agent-inject-template-pm-s3: |-
{{- with secret "secrets/data/minio/apps/pm" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}}
S3_VERIFY=False
{{- end -}}
spec:
serviceAccountName: pm-vault
containers:
- name: api
image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db
[ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq
[ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3
set +a
exec /opt/sarex/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: USERS_INTERNAL_HOST
value: http://backend-service.sarex.svc.cluster.local:8000
- name: CELERY_REDIS_HOST
value: redis.pm.svc.cluster.local
- name: RESOURCES_INTERNAL_HOST
value: http://sarex-resources-service.resources
- name: EAV_HOST
value: http://eav-service.eav
- name: EAV_API_PREFIX
value: /api/v0
- name: EAV_API_PREFIX_V1
value: /api/v1
- name: TRACING_INSECURE
value: "False"
- name: SERVER_ENABLE_SYNC_RESOURCES
value: "True"
- name: SERVER_DELETED_TASK_MAX_AGE_DAYS
value: "1"
- name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR
value: "17"
- name: LANG
value: C.UTF-8
- name: LC_ALL
value: C.UTF-8
- name: PYTHONUTF8
value: "1"
- name: CACHE_SSL
value: "False"
- name: CACHE_SSL_CA_CERTS
value: ""
- name: CACHE_ENABLE
value: "False"
- name: CLICKHOUSE_ENABLE
value: "False"
- name: KAFKA_ENABLE
value: "False"
- name: AUTH_PUBLIC_TOKEN_URL
value: "https://lk.sarex.io/api/token/public/"
- name: SERVER_HOST
value: "https://lk.sarex.io"
- name: SERVER_API_HOST
value: "https://api.sarex.io"
- name: SERVER_DEBUG
value: "False"
- name: SERVER_ALLOWED_HOSTS
value: '["*"]'
- name: SERVER_USE_OTEL
value: "False"
- name: SERVER_VERIFY_SSL
value: "False"
- name: SERVER_LOG_LEVEL
value: "INFO"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: pm
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 8000
targetPort: 8000
protocol: TCP

255
apps/pm/base/backend.yaml Normal file
View File

@ -0,0 +1,255 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: pm
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: pm-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/bash", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db
[ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq
[ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3
set +a
exec /opt/sarex/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 8000
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: USERS_INTERNAL_HOST
value:
_default: "http://backend-service.sarex.svc.cluster.local:8000"
- name: CELERY_REDIS_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://sarex-resources-service.resources"
- name: EAV_HOST
value:
_default: "http://eav-service.eav"
- name: EAV_API_PREFIX
value:
_default: "/api/v0"
- name: EAV_API_PREFIX_V1
value:
_default: "/api/v1"
- name: TRACING_INSECURE
value:
_default: "False"
- name: SERVER_ENABLE_SYNC_RESOURCES
value:
_default: "True"
- name: SERVER_DELETED_TASK_MAX_AGE_DAYS
value:
_default: "1"
- name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR
value:
_default: "17"
- name: LANG
value:
_default: "C.UTF-8"
- name: LC_ALL
value:
_default: "C.UTF-8"
- name: PYTHONUTF8
value:
_default: "1"
- name: CACHE_SSL
value:
_default: "False"
- name: CACHE_SSL_CA_CERTS
value:
_default: ""
- name: CACHE_ENABLE
value:
_default: "False"
- name: CLICKHOUSE_ENABLE
value:
_default: "False"
- name: KAFKA_ENABLE
value:
_default: "False"
- name: AUTH_PUBLIC_TOKEN_URL
value:
_default: "https://lk.sarex.io/api/token/public/"
- name: SERVER_HOST
value:
_default: "https://lk.sarex.io"
- name: SERVER_API_HOST
value:
_default: "https://api.sarex.io"
- name: SERVER_DEBUG
value:
_default: "False"
- name: SERVER_ALLOWED_HOSTS
value:
_default: '["*"]'
- name: SERVER_USE_OTEL
value:
_default: "False"
- name: SERVER_VERIFY_SSL
value:
_default: "False"
- name: SERVER_LOG_LEVEL
value:
_default: "INFO"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: pm
vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm
vault.hashicorp.com/agent-inject-template-pm-db: |-
{{- with secret "secrets/data/postgresql/apps/pm" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm
vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/pm" -}}
CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
CELERY_RABBITMQ_PORT=5672
CELERY_RABBITMQ_USER={{ index .Data.data "username" }}
CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }}
CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm
vault.hashicorp.com/agent-inject-template-pm-s3: |-
{{- with secret "secrets/data/minio/apps/pm" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}}
S3_VERIFY=False
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,131 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: celery
namespace: pm
labels:
app: celery
service: celery
spec:
replicas: 1
selector:
matchLabels:
app: celery
template:
metadata:
labels:
app: celery
service: celery
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: pm
vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm
vault.hashicorp.com/agent-inject-template-pm-db: |-
{{- with secret "secrets/data/postgresql/apps/pm" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm
vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/pm" -}}
CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
CELERY_RABBITMQ_PORT=5672
CELERY_RABBITMQ_USER={{ index .Data.data "username" }}
CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }}
CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm
vault.hashicorp.com/agent-inject-template-pm-s3: |-
{{- with secret "secrets/data/minio/apps/pm" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}}
S3_VERIFY=False
{{- end -}}
spec:
serviceAccountName: pm-vault
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db
[ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq
[ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3
set +a
exec celery -A config worker -B -l info -E -Q pm -n default_worker.%h --concurrency=2
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: USERS_INTERNAL_HOST
value: http://backend-service.sarex.svc.cluster.local:8000
- name: CELERY_REDIS_HOST
value: redis.pm.svc.cluster.local
- name: RESOURCES_INTERNAL_HOST
value: http://sarex-resources-service.resources
- name: EAV_HOST
value: http://eav-service.eav
- name: EAV_API_PREFIX
value: /api/v0
- name: EAV_API_PREFIX_V1
value: /api/v1
- name: TRACING_INSECURE
value: "False"
- name: SERVER_ENABLE_SYNC_RESOURCES
value: "True"
- name: SERVER_DELETED_TASK_MAX_AGE_DAYS
value: "1"
- name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR
value: "17"
- name: LANG
value: C.UTF-8
- name: LC_ALL
value: C.UTF-8
- name: PYTHONUTF8
value: "1"
- name: CACHE_SSL
value: "False"
- name: CACHE_SSL_CA_CERTS
value: ""
- name: CACHE_ENABLE
value: "False"
- name: CLICKHOUSE_ENABLE
value: "False"
- name: KAFKA_ENABLE
value: "False"
- name: AUTH_PUBLIC_TOKEN_URL
value: "https://lk.sarex.io/api/token/public/"
- name: SERVER_HOST
value: "https://lk.sarex.io"
- name: SERVER_API_HOST
value: "https://api.sarex.io"
- name: SERVER_DEBUG
value: "False"
- name: SERVER_ALLOWED_HOSTS
value: '["*"]'
- name: SERVER_USE_OTEL
value: "False"
- name: SERVER_VERIFY_SSL
value: "False"
- name: SERVER_LOG_LEVEL
value: "INFO"
resources:
requests:
memory: 128Mi
imagePullSecrets:
- name: regcred

238
apps/pm/base/celery.yaml Normal file
View File

@ -0,0 +1,238 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: pm
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
celery:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: pm-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: celery
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/bash", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db
[ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq
[ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3
set +a
exec celery -A config worker -B -l info -E -Q pm -n default_worker.%h --concurrency=2
resources:
requests:
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: USERS_INTERNAL_HOST
value:
_default: "http://backend-service.sarex.svc.cluster.local:8000"
- name: CELERY_REDIS_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://sarex-resources-service.resources"
- name: EAV_HOST
value:
_default: "http://eav-service.eav"
- name: EAV_API_PREFIX
value:
_default: "/api/v0"
- name: EAV_API_PREFIX_V1
value:
_default: "/api/v1"
- name: TRACING_INSECURE
value:
_default: "False"
- name: SERVER_ENABLE_SYNC_RESOURCES
value:
_default: "True"
- name: SERVER_DELETED_TASK_MAX_AGE_DAYS
value:
_default: "1"
- name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR
value:
_default: "17"
- name: LANG
value:
_default: "C.UTF-8"
- name: LC_ALL
value:
_default: "C.UTF-8"
- name: PYTHONUTF8
value:
_default: "1"
- name: CACHE_SSL
value:
_default: "False"
- name: CACHE_SSL_CA_CERTS
value:
_default: ""
- name: CACHE_ENABLE
value:
_default: "False"
- name: CLICKHOUSE_ENABLE
value:
_default: "False"
- name: KAFKA_ENABLE
value:
_default: "False"
- name: AUTH_PUBLIC_TOKEN_URL
value:
_default: "https://lk.sarex.io/api/token/public/"
- name: SERVER_HOST
value:
_default: "https://lk.sarex.io"
- name: SERVER_API_HOST
value:
_default: "https://api.sarex.io"
- name: SERVER_DEBUG
value:
_default: "False"
- name: SERVER_ALLOWED_HOSTS
value:
_default: '["*"]'
- name: SERVER_USE_OTEL
value:
_default: "False"
- name: SERVER_VERIFY_SSL
value:
_default: "False"
- name: SERVER_LOG_LEVEL
value:
_default: "INFO"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: pm
vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm
vault.hashicorp.com/agent-inject-template-pm-db: |-
{{- with secret "secrets/data/postgresql/apps/pm" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm
vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/pm" -}}
CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
CELERY_RABBITMQ_PORT=5672
CELERY_RABBITMQ_USER={{ index .Data.data "username" }}
CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }}
CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm
vault.hashicorp.com/agent-inject-template-pm-s3: |-
{{- with secret "secrets/data/minio/apps/pm" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}}
S3_VERIFY=False
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,8 +4,6 @@ kind: Kustomization
namespace: pm
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- backend-service.yaml
- celery-deployment.yaml
- backend.yaml
- celery.yaml
- backend-configmap.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: pm-vault
namespace: pm

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: pm

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: pm
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,29 +1,118 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: pm
spec:
template:
spec:
containers:
- name: api
image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_3d7e8ea6
env:
- name: LANG
value: C.UTF-8
- name: LC_ALL
value: C.UTF-8
- name: PYTHONUTF8
value: '1'
- name: USERS_INTERNAL_HOST
value: http://backend.django.svc.cluster.local:8000
- name: RESOURCES_INTERNAL_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: EAV_API_PREFIX
value: /api/v0
- name: EAV_API_PREFIX_V1
value: /api/v1
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_3d7e8ea6
envs:
- name: USERS_INTERNAL_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: CELERY_REDIS_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: EAV_API_PREFIX
value:
_default: "/api/v0"
- name: EAV_API_PREFIX_V1
value:
_default: "/api/v1"
- name: TRACING_INSECURE
value:
_default: "False"
- name: SERVER_ENABLE_SYNC_RESOURCES
value:
_default: "True"
- name: SERVER_DELETED_TASK_MAX_AGE_DAYS
value:
_default: "1"
- name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR
value:
_default: "17"
- name: LANG
value:
_default: "C.UTF-8"
- name: LC_ALL
value:
_default: "C.UTF-8"
- name: PYTHONUTF8
value:
_default: "1"
- name: CACHE_SSL
value:
_default: "False"
- name: CACHE_SSL_CA_CERTS
value:
_default: ""
- name: CACHE_ENABLE
value:
_default: "False"
- name: CLICKHOUSE_ENABLE
value:
_default: "False"
- name: KAFKA_ENABLE
value:
_default: "False"
- name: AUTH_PUBLIC_TOKEN_URL
value:
_default: "https://lk.sarex.io/api/token/public/"
- name: SERVER_HOST
value:
_default: "https://lk.sarex.io"
- name: SERVER_API_HOST
value:
_default: "https://api.sarex.io"
- name: SERVER_DEBUG
value:
_default: "False"
- name: SERVER_ALLOWED_HOSTS
value:
_default: '["*"]'
- name: SERVER_USE_OTEL
value:
_default: "False"
- name: SERVER_VERIFY_SSL
value:
_default: "False"
- name: SERVER_LOG_LEVEL
value:
_default: "INFO"

View File

@ -1,29 +1,118 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: pm
spec:
template:
spec:
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_2becf38c
env:
- name: USERS_INTERNAL_HOST
value: http://backend.django.svc.cluster.local:8000
- name: RESOURCES_INTERNAL_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: EAV_API_PREFIX
value: /api/v0
- name: EAV_API_PREFIX_V1
value: /api/v1
- name: LANG
value: C.UTF-8
- name: LC_ALL
value: C.UTF-8
- name: PYTHONUTF8
value: '1'
values:
services:
celery:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_2becf38c
envs:
- name: USERS_INTERNAL_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: CELERY_REDIS_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: EAV_API_PREFIX
value:
_default: "/api/v0"
- name: EAV_API_PREFIX_V1
value:
_default: "/api/v1"
- name: TRACING_INSECURE
value:
_default: "False"
- name: SERVER_ENABLE_SYNC_RESOURCES
value:
_default: "True"
- name: SERVER_DELETED_TASK_MAX_AGE_DAYS
value:
_default: "1"
- name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR
value:
_default: "17"
- name: LANG
value:
_default: "C.UTF-8"
- name: LC_ALL
value:
_default: "C.UTF-8"
- name: PYTHONUTF8
value:
_default: "1"
- name: CACHE_SSL
value:
_default: "False"
- name: CACHE_SSL_CA_CERTS
value:
_default: ""
- name: CACHE_ENABLE
value:
_default: "False"
- name: CLICKHOUSE_ENABLE
value:
_default: "False"
- name: KAFKA_ENABLE
value:
_default: "False"
- name: AUTH_PUBLIC_TOKEN_URL
value:
_default: "https://lk.sarex.io/api/token/public/"
- name: SERVER_HOST
value:
_default: "https://lk.sarex.io"
- name: SERVER_API_HOST
value:
_default: "https://api.sarex.io"
- name: SERVER_DEBUG
value:
_default: "False"
- name: SERVER_ALLOWED_HOSTS
value:
_default: '["*"]'
- name: SERVER_USE_OTEL
value:
_default: "False"
- name: SERVER_VERIFY_SSL
value:
_default: "False"
- name: SERVER_LOG_LEVEL
value:
_default: "INFO"

View File

@ -8,9 +8,9 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend
- path: celery.yaml
target:
kind: Deployment
kind: HelmRelease
name: celery

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: prescriptions
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: processing
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: projects
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: remarks
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: reviews
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

Some files were not shown because too many files have changed in this diff Show More