From d44378a4329908e09b7222b19852d3650a171452 Mon Sep 17 00:00:00 2001 From: ivan Date: Thu, 1 Oct 2026 18:50:27 +0500 Subject: [PATCH] brusnika-stage: route checklists/inspections/workflows/workspaces/comparisons/etc. through Istio instead of the global-ingress nginx proxy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds 13 new VirtualServices on the existing test.sarex.brusnika.tech host and ingress-nginx/main-gateway, matching the active (non-commented) location blocks in global-ingress's nginx-configmap (fetched live from the cluster and cross-checked service/port/namespace names against what's actually running). The root path (/) stays routed to nginx-service.global-ingress as a fallback for anything not covered here. Two deliberate deviations from literally replaying the nginx config: - /comparisons/api/: nginx proxies to port 8080, but the real backend-service.comparisons Service listens on 80 (targetPort 8080) — used 80. - /orchestrator/: nginx declares 4 location blocks, but the first (bare ~^/orchestrator/) shadows the other three for any non-empty path (nginx picks the first matching regex location, not the most specific), so only one route (no rewrite) was ported, matching what nginx actually does today. Co-Authored-By: Claude Sonnet 5 --- .../brusnika-stage/istio-config.yaml | 206 ++++++++++++++++++ 1 file changed, 206 insertions(+) diff --git a/infrastructure/istio-config/brusnika-stage/istio-config.yaml b/infrastructure/istio-config/brusnika-stage/istio-config.yaml index 582899a..30fff9d 100644 --- a/infrastructure/istio-config/brusnika-stage/istio-config.yaml +++ b/infrastructure/istio-config/brusnika-stage/istio-config.yaml @@ -469,6 +469,212 @@ spec: prefix: / service: gitea.gitea.svc.cluster.local port: 3000 + workflows-static-vs: + namespace: workflow + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /static/workflows/ + rewrite: / + service: frontend-service.workflow.svc.cluster.local + port: 8080 + workspaces-v2-static-vs: + namespace: workspaces + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /static/workspaces-v2/ + rewrite: / + service: workspaces-v2-frontend-static-service.workspaces.svc.cluster.local + port: 8080 + checklists-vs: + namespace: checklist + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /checklists/admin/ + service: backend-service.checklist.svc.cluster.local + port: 8000 + - path: + prefix: /checklists/api/ + rewrite: /api/ + service: backend-service.checklist.svc.cluster.local + port: 8000 + res-admin-vs: + namespace: resources + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /res-admin/ + service: resources-service.resources.svc.cluster.local + port: 8000 + inspections-vs: + namespace: inspections + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /inspections/static/ + rewrite: / + service: frontend-service.inspections.svc.cluster.local + port: 80 + - path: + prefix: /inspections/api/ + rewrite: /api/ + service: inspections-service.inspections.svc.cluster.local + port: 80 + workflows-api-vs: + namespace: workflow + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /workflows/api/ + rewrite: /api/ + service: workflows-api-service.workflow.svc.cluster.local + port: 8000 + workspaces-api-vs: + namespace: workspaces + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /workspaces/api/ + rewrite: /api/ + service: workspaces-service.workspaces.svc.cluster.local + port: 8000 + global-media-vs: + namespace: django + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /media/ + rewrite: / + service: s3-proxy-service.django.svc.cluster.local + port: 80 + remarks-static-vs: + namespace: issues + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /remarks/static/ + rewrite: / + service: remarks-static.issues.svc.cluster.local + port: 80 + global-resources-vs: + namespace: resources + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /resources/ + rewrite: / + service: resources-service.resources.svc.cluster.local + port: 8000 + comparisons-vs: + namespace: comparisons + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /comparisons/static/ + rewrite: / + service: comparisons-service.comparisons.svc.cluster.local + port: 8080 + - path: + prefix: /comparisons/api/ + rewrite: /api/ + service: backend-service.comparisons.svc.cluster.local + port: 80 + administration-users-vs: + namespace: django + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /administration/users + service: frontend-service.django.svc.cluster.local + port: 80 + orchestrator-vs: + namespace: orchestrator + hosts: + - test.sarex.brusnika.tech + gateways: + - ingress-nginx/main-gateway + cors: + allowOrigins: + - regex: ".*" + routes: + - path: + prefix: /orchestrator/ + service: cde.orchestrator.svc.cluster.local + port: 8080 global-test-vs: namespace: global-ingress hosts: