From c7b749fd091cff18b08015cb383691fa9bf7bc46 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 12:54:49 +0500 Subject: [PATCH 01/51] ++ --- apps/auth-flow/d8-ugmk-prod/namespace.yaml | 2 +- apps/bim/base/backend-deployment.yaml | 108 ----- apps/bim/base/backend-service.yaml | 15 - apps/bim/base/backend.yaml | 217 ++++++++++ apps/bim/base/kustomization.yaml | 4 +- apps/bim/base/serviceaccount.yaml | 5 - apps/bim/d8-ugmk-prod/kustomization.yaml | 10 + apps/bim/d8-ugmk-prod/namespace.yaml | 8 + apps/bim/dsinv/backend.yaml | 141 +++--- apps/bim/dsinv/kustomization.yaml | 2 +- apps/bim/yc-k8s-test/kustomization.yaml | 2 +- apps/bim/yc-k8s-test/replicas.yaml | 11 +- apps/cde/base/backend-service.yaml | 15 - apps/cde/base/cde-flowscallback.yaml | 156 ++++--- apps/cde/base/cde-splitpdf.yaml | 156 ++++--- apps/cde/base/cde-worker-copy.yaml | 156 ++++--- apps/cde/base/cde-worker-create-versions.yaml | 156 ++++--- apps/cde/base/cde-worker-markings.yaml | 156 ++++--- apps/cde/base/cde-worker-sign.yaml | 156 ++++--- apps/cde/base/cde-worker-update-bundles.yaml | 156 ++++--- apps/cde/base/cde.yaml | 171 +++++--- apps/cde/base/kustomization.yaml | 2 - apps/cde/base/serviceaccount.yaml | 5 - apps/cde/d8-ugmk-prod/kustomization.yaml | 10 + apps/cde/d8-ugmk-prod/namespace.yaml | 8 + apps/comparisons/d8-ugmk-prod/namespace.yaml | 2 +- .../d8-ugmk-prod/namespace.yaml | 2 +- .../cross-section/d8-ugmk-prod/namespace.yaml | 2 +- .../document-link/d8-ugmk-prod/namespace.yaml | 2 +- apps/drawings/d8-ugmk-prod/namespace.yaml | 2 +- apps/eav/base/django-configmap.yaml | 9 +- apps/faas/d8-ugmk-prod/namespace.yaml | 2 +- apps/flows/base/backend-deployment.yaml | 137 ------ apps/flows/base/backend-service.yaml | 15 - apps/flows/base/backend.yaml | 258 +++++++++++ apps/flows/base/celery-deployment.yaml | 137 ------ apps/flows/base/celery.yaml | 243 +++++++++++ apps/flows/base/frontend-deployment.yaml | 32 -- apps/flows/base/frontend-service.yaml | 15 - apps/flows/base/frontend.yaml | 90 ++++ apps/flows/base/kustomization.yaml | 9 +- apps/flows/base/serviceaccount.yaml | 5 - apps/flows/d8-ugmk-prod/kustomization.yaml | 10 + apps/flows/d8-ugmk-prod/namespace.yaml | 8 + apps/flows/dsinv/backend.yaml | 264 ++++++++---- apps/flows/dsinv/celery.yaml | 281 ++++++++---- apps/flows/dsinv/frontend.yaml | 15 +- apps/flows/dsinv/kustomization.yaml | 6 +- apps/inspections/base/backend-service.yaml | 15 - apps/inspections/base/backend.yaml | 240 +++++++++++ apps/inspections/base/kustomization.yaml | 4 +- apps/inspections/base/serviceaccount.yaml | 5 - .../d8-ugmk-prod/kustomization.yaml | 10 + apps/inspections/d8-ugmk-prod/namespace.yaml | 8 + .../dsinv/inspections-backend.yaml | 66 +-- apps/inspections/dsinv/kustomization.yaml | 4 +- apps/issues/base/backend-deployment.yaml | 135 ------ apps/issues/base/backend-service.yaml | 15 - apps/issues/base/backend.yaml | 237 ++++++++++ apps/issues/base/celery-deployment.yaml | 135 ------ apps/issues/base/celery.yaml | 222 ++++++++++ apps/issues/base/frontend-deployment.yaml | 32 -- apps/issues/base/frontend-service.yaml | 15 - apps/issues/base/frontend.yaml | 90 ++++ apps/issues/base/kustomization.yaml | 9 +- apps/issues/base/serviceaccount.yaml | 5 - apps/issues/d8-ugmk-prod/kustomization.yaml | 10 + apps/issues/d8-ugmk-prod/namespace.yaml | 8 + apps/issues/dsinv/backend.yaml | 145 ++++--- apps/issues/dsinv/celery.yaml | 157 ++++--- apps/issues/dsinv/frontend.yaml | 15 +- apps/issues/dsinv/kustomization.yaml | 6 +- apps/mapper/d8-ugmk-prod/namespace.yaml | 2 +- apps/measurements/d8-ugmk-prod/namespace.yaml | 2 +- apps/message-hub/base/deployment.yaml | 96 ----- apps/message-hub/base/kustomization.yaml | 4 +- apps/message-hub/base/message-hub.yaml | 183 ++++++++ apps/message-hub/base/service.yaml | 15 - apps/message-hub/base/serviceaccount.yaml | 5 - .../d8-ugmk-prod/kustomization.yaml | 10 + apps/message-hub/d8-ugmk-prod/namespace.yaml | 8 + apps/message-hub/dsinv/kustomization.yaml | 2 +- apps/message-hub/dsinv/message-hub.yaml | 129 ++++-- apps/pm/base/backend-deployment.yaml | 132 ------ apps/pm/base/backend-service.yaml | 15 - apps/pm/base/backend.yaml | 255 +++++++++++ apps/pm/base/celery-deployment.yaml | 131 ------ apps/pm/base/celery.yaml | 238 ++++++++++ apps/pm/base/kustomization.yaml | 6 +- apps/pm/base/serviceaccount.yaml | 5 - apps/pm/d8-ugmk-prod/kustomization.yaml | 10 + apps/pm/d8-ugmk-prod/namespace.yaml | 8 + apps/pm/dsinv/backend.yaml | 137 ++++-- apps/pm/dsinv/celery.yaml | 137 ++++-- apps/pm/dsinv/kustomization.yaml | 4 +- .../prescriptions/d8-ugmk-prod/namespace.yaml | 2 +- apps/processing/d8-ugmk-prod/namespace.yaml | 2 +- apps/projects/d8-ugmk-prod/namespace.yaml | 2 +- apps/remarks/d8-ugmk-prod/namespace.yaml | 2 +- apps/reviews/d8-ugmk-prod/namespace.yaml | 2 +- .../d8-ugmk-prod/namespace.yaml | 2 +- apps/system-log/d8-ugmk-prod/namespace.yaml | 2 +- apps/transmittal/base/backend-deployment.yaml | 211 --------- apps/transmittal/base/backend-service.yaml | 15 - apps/transmittal/base/backend.yaml | 401 +++++++++++++++++ .../transmittal/base/frontend-deployment.yaml | 32 -- apps/transmittal/base/frontend-service.yaml | 15 - apps/transmittal/base/frontend.yaml | 90 ++++ apps/transmittal/base/kustomization.yaml | 9 +- apps/transmittal/base/serviceaccount.yaml | 5 - apps/transmittal/base/worker-deployment.yaml | 211 --------- apps/transmittal/base/worker.yaml | 386 +++++++++++++++++ .../d8-ugmk-prod/kustomization.yaml | 10 + apps/transmittal/d8-ugmk-prod/namespace.yaml | 8 + apps/transmittal/dsinv/backend.yaml | 405 ++++++++++++------ apps/transmittal/dsinv/frontend.yaml | 15 +- apps/transmittal/dsinv/kustomization.yaml | 6 +- apps/transmittal/dsinv/worker.yaml | 405 ++++++++++++------ clusters/d8-ugmk-prod/kustomization.yaml | 10 +- 119 files changed, 5796 insertions(+), 2948 deletions(-) delete mode 100644 apps/bim/base/backend-deployment.yaml delete mode 100644 apps/bim/base/backend-service.yaml create mode 100644 apps/bim/base/backend.yaml delete mode 100644 apps/bim/base/serviceaccount.yaml create mode 100644 apps/bim/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/bim/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/cde/base/backend-service.yaml delete mode 100644 apps/cde/base/serviceaccount.yaml create mode 100644 apps/cde/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/cde/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/flows/base/backend-deployment.yaml delete mode 100644 apps/flows/base/backend-service.yaml create mode 100644 apps/flows/base/backend.yaml delete mode 100644 apps/flows/base/celery-deployment.yaml create mode 100644 apps/flows/base/celery.yaml delete mode 100644 apps/flows/base/frontend-deployment.yaml delete mode 100644 apps/flows/base/frontend-service.yaml create mode 100644 apps/flows/base/frontend.yaml delete mode 100644 apps/flows/base/serviceaccount.yaml create mode 100644 apps/flows/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/flows/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/inspections/base/backend-service.yaml create mode 100644 apps/inspections/base/backend.yaml delete mode 100644 apps/inspections/base/serviceaccount.yaml create mode 100644 apps/inspections/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/inspections/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/issues/base/backend-deployment.yaml delete mode 100644 apps/issues/base/backend-service.yaml create mode 100644 apps/issues/base/backend.yaml delete mode 100644 apps/issues/base/celery-deployment.yaml create mode 100644 apps/issues/base/celery.yaml delete mode 100644 apps/issues/base/frontend-deployment.yaml delete mode 100644 apps/issues/base/frontend-service.yaml create mode 100644 apps/issues/base/frontend.yaml delete mode 100644 apps/issues/base/serviceaccount.yaml create mode 100644 apps/issues/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/issues/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/message-hub/base/deployment.yaml create mode 100644 apps/message-hub/base/message-hub.yaml delete mode 100644 apps/message-hub/base/service.yaml delete mode 100644 apps/message-hub/base/serviceaccount.yaml create mode 100644 apps/message-hub/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/message-hub/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/pm/base/backend-deployment.yaml delete mode 100644 apps/pm/base/backend-service.yaml create mode 100644 apps/pm/base/backend.yaml delete mode 100644 apps/pm/base/celery-deployment.yaml create mode 100644 apps/pm/base/celery.yaml delete mode 100644 apps/pm/base/serviceaccount.yaml create mode 100644 apps/pm/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/pm/d8-ugmk-prod/namespace.yaml delete mode 100644 apps/transmittal/base/backend-deployment.yaml delete mode 100644 apps/transmittal/base/backend-service.yaml create mode 100644 apps/transmittal/base/backend.yaml delete mode 100644 apps/transmittal/base/frontend-deployment.yaml delete mode 100644 apps/transmittal/base/frontend-service.yaml create mode 100644 apps/transmittal/base/frontend.yaml delete mode 100644 apps/transmittal/base/serviceaccount.yaml delete mode 100644 apps/transmittal/base/worker-deployment.yaml create mode 100644 apps/transmittal/base/worker.yaml create mode 100644 apps/transmittal/d8-ugmk-prod/kustomization.yaml create mode 100644 apps/transmittal/d8-ugmk-prod/namespace.yaml diff --git a/apps/auth-flow/d8-ugmk-prod/namespace.yaml b/apps/auth-flow/d8-ugmk-prod/namespace.yaml index fc05086..7c70f41 100644 --- a/apps/auth-flow/d8-ugmk-prod/namespace.yaml +++ b/apps/auth-flow/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: auth-flow labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/bim/base/backend-deployment.yaml b/apps/bim/base/backend-deployment.yaml deleted file mode 100644 index 9457626..0000000 --- a/apps/bim/base/backend-deployment.yaml +++ /dev/null @@ -1,108 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: backend - namespace: bim - labels: - app: backend -spec: - replicas: 1 - selector: - matchLabels: - app: backend - template: - metadata: - labels: - app: backend - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: bim - vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim - vault.hashicorp.com/agent-inject-template-bim-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/bim" -}} - POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local - POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local - POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local - POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local - POSTGRES_PORT=5432 - POSTGRES_PORT_2=5432 - POSTGRES_PORT_3=5432 - POSTGRES_PORT_4=5432 - POSTGRES_DB=bim_db - POSTGRES_DB_2=bim_db - POSTGRES_DB_3=bim_db - POSTGRES_DB_4=bim_db - POSTGRES_USER={{ index .Data.data "username" }} - POSTGRES_USER_2={{ index .Data.data "username" }} - POSTGRES_USER_3={{ index .Data.data "username" }} - POSTGRES_USER_4={{ index .Data.data "username" }} - POSTGRES_PASSWORD={{ index .Data.data "password" }} - POSTGRES_PASSWORD_2={{ index .Data.data "password" }} - POSTGRES_PASSWORD_3={{ index .Data.data "password" }} - POSTGRES_PASSWORD_4={{ index .Data.data "password" }} - {{- end -}} - spec: - serviceAccountName: bim-vault - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef - imagePullPolicy: IfNotPresent - command: ["/bin/sh", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql - set +a - exec ./httpserver - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: LAST_MASTER_BIM - value: "100000" - - name: LAST_MASTER_BIM_V3 - value: "100000" - - name: DB_CERT_PATH_4 - value: /root/yandex_pg.pem - - name: DB_CERT_PATH_3 - value: /root/yandex_pg.pem - - name: DB_CERT_PATH_2 - value: /root/yandex_pg.pem - - name: LAST_SLAVE_1_BIM - value: "1000000" - - name: POSTGRES_POOL_SIZE - value: "30" - - name: API_ADDRESS - value: 0.0.0.0:8000 - - name: DJANGO_HOST - value: http://backend.django.svc.cluster.local:8000 - - name: ENABLE_SQL_QUERY - value: "0" - - name: ENABLE_SSL - value: "0" - resources: - requests: - cpu: 25m - memory: 100Mi - livenessProbe: - httpGet: - path: /ping - port: 8000 - initialDelaySeconds: 10 - periodSeconds: 60 - failureThreshold: 10 - readinessProbe: - httpGet: - path: /ping - port: 8000 - initialDelaySeconds: 5 - periodSeconds: 5 - failureThreshold: 20 - imagePullSecrets: - - name: regcred diff --git a/apps/bim/base/backend-service.yaml b/apps/bim/base/backend-service.yaml deleted file mode 100644 index 0f62368..0000000 --- a/apps/bim/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: backend-svc - namespace: bim -spec: - type: ClusterIP - selector: - app: backend - ports: - - name: http - port: 80 - targetPort: 8000 - protocol: TCP diff --git a/apps/bim/base/backend.yaml b/apps/bim/base/backend.yaml new file mode 100644 index 0000000..b424252 --- /dev/null +++ b/apps/bim/base/backend.yaml @@ -0,0 +1,217 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: bim + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: bim-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql + set +a + exec ./httpserver + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 100Mi + + probes: + liveness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 8000 + initialDelaySeconds: + _default: 10 + periodSeconds: + _default: 60 + failureThreshold: + _default: 10 + readiness: + enabled: + _default: true + type: + _default: httpGet + httpGet: + path: + _default: /ping + port: + _default: 8000 + initialDelaySeconds: + _default: 5 + periodSeconds: + _default: 5 + failureThreshold: + _default: 20 + + service: + enabled: true + + name: + _default: backend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: LAST_MASTER_BIM + value: + _default: "100000" + + - name: LAST_MASTER_BIM_V3 + value: + _default: "100000" + + - name: DB_CERT_PATH_4 + value: + _default: "/root/yandex_pg.pem" + + - name: DB_CERT_PATH_3 + value: + _default: "/root/yandex_pg.pem" + + - name: DB_CERT_PATH_2 + value: + _default: "/root/yandex_pg.pem" + + - name: LAST_SLAVE_1_BIM + value: + _default: "1000000" + + - name: POSTGRES_POOL_SIZE + value: + _default: "30" + + - name: API_ADDRESS + value: + _default: "0.0.0.0:8000" + + - name: DJANGO_HOST + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: ENABLE_SQL_QUERY + value: + _default: "0" + + - name: ENABLE_SSL + value: + _default: "0" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: bim + vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim + vault.hashicorp.com/agent-inject-template-bim-postgresql: |- + {{- with secret "secrets/data/postgresql/apps/bim" -}} + POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local + POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local + POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local + POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local + POSTGRES_PORT=5432 + POSTGRES_PORT_2=5432 + POSTGRES_PORT_3=5432 + POSTGRES_PORT_4=5432 + POSTGRES_DB=bim_db + POSTGRES_DB_2=bim_db + POSTGRES_DB_3=bim_db + POSTGRES_DB_4=bim_db + POSTGRES_USER={{ index .Data.data "username" }} + POSTGRES_USER_2={{ index .Data.data "username" }} + POSTGRES_USER_3={{ index .Data.data "username" }} + POSTGRES_USER_4={{ index .Data.data "username" }} + POSTGRES_PASSWORD={{ index .Data.data "password" }} + POSTGRES_PASSWORD_2={{ index .Data.data "password" }} + POSTGRES_PASSWORD_3={{ index .Data.data "password" }} + POSTGRES_PASSWORD_4={{ index .Data.data "password" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/bim/base/kustomization.yaml b/apps/bim/base/kustomization.yaml index f47e36a..4312ba7 100644 --- a/apps/bim/base/kustomization.yaml +++ b/apps/bim/base/kustomization.yaml @@ -4,6 +4,4 @@ kind: Kustomization namespace: bim resources: - namespace.yaml - - serviceaccount.yaml - - backend-deployment.yaml - - backend-service.yaml + - backend.yaml diff --git a/apps/bim/base/serviceaccount.yaml b/apps/bim/base/serviceaccount.yaml deleted file mode 100644 index ae3568c..0000000 --- a/apps/bim/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: bim-vault - namespace: bim diff --git a/apps/bim/d8-ugmk-prod/kustomization.yaml b/apps/bim/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..5dbc44f --- /dev/null +++ b/apps/bim/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: bim diff --git a/apps/bim/d8-ugmk-prod/namespace.yaml b/apps/bim/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..d9a0582 --- /dev/null +++ b/apps/bim/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: bim + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/bim/dsinv/backend.yaml b/apps/bim/dsinv/backend.yaml index 5392c45..02bc032 100644 --- a/apps/bim/dsinv/backend.yaml +++ b/apps/bim/dsinv/backend.yaml @@ -1,53 +1,98 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: backend namespace: bim spec: - template: - spec: - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc - env: - - name: LAST_MASTER_BIM - value: '100000' - - name: LAST_SLAVE_1_BIM - value: '94015' - - name: LAST_MASTER_BIM_V3 - value: '100000' - - name: LAST_SLAVE_1_BIM_V3 - value: '0' - - name: DB_CERT_PATH_3 - value: /root/yandex_pg.pem - - name: POSTGRES_ADDRESS_3 - value: postgres-service - - name: POSTGRES_PORT_3 - value: '5432' - - name: POSTGRES_DB_3 - value: bimapidb - - name: DB_CERT_PATH_2 - value: /root/yandex_pg.pem - - name: POSTGRES_ADDRESS_2 - value: postgres-service - - name: POSTGRES_PORT_2 - value: '5432' - - name: POSTGRES_DB_2 - value: bimapidb - - name: POSTGRES_ADDRESS - value: postgres-service - - name: POSTGRES_PORT - value: '5432' - - name: POSTGRES_DB - value: bimapidb - - name: POSTGRES_POOL_SIZE - value: '30' - - name: API_ADDRESS - value: 0.0.0.0:8000 - - name: DJANGO_HOST - value: http://backend.django.svc.cluster.local:8000 - - name: ENABLE_SQL_QUERY - value: '0' - - name: ENABLE_SSL - value: '0' + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc + + envs: + - name: LAST_MASTER_BIM + value: + _default: "100000" + + - name: LAST_SLAVE_1_BIM + value: + _default: "94015" + + - name: LAST_MASTER_BIM_V3 + value: + _default: "100000" + + - name: LAST_SLAVE_1_BIM_V3 + value: + _default: "0" + + - name: DB_CERT_PATH_3 + value: + _default: "/root/yandex_pg.pem" + + - name: POSTGRES_ADDRESS_3 + value: + _default: "postgres-service" + + - name: POSTGRES_PORT_3 + value: + _default: "5432" + + - name: POSTGRES_DB_3 + value: + _default: "bimapidb" + + - name: DB_CERT_PATH_2 + value: + _default: "/root/yandex_pg.pem" + + - name: POSTGRES_ADDRESS_2 + value: + _default: "postgres-service" + + - name: POSTGRES_PORT_2 + value: + _default: "5432" + + - name: POSTGRES_DB_2 + value: + _default: "bimapidb" + + - name: POSTGRES_ADDRESS + value: + _default: "postgres-service" + + - name: POSTGRES_PORT + value: + _default: "5432" + + - name: POSTGRES_DB + value: + _default: "bimapidb" + + - name: POSTGRES_POOL_SIZE + value: + _default: "30" + + - name: API_ADDRESS + value: + _default: "0.0.0.0:8000" + + - name: DJANGO_HOST + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: ENABLE_SQL_QUERY + value: + _default: "0" + + - name: ENABLE_SSL + value: + _default: "0" + + - name: DB_CERT_PATH_4 + value: + _default: "/root/yandex_pg.pem" diff --git a/apps/bim/dsinv/kustomization.yaml b/apps/bim/dsinv/kustomization.yaml index 71179d1..c9109fb 100644 --- a/apps/bim/dsinv/kustomization.yaml +++ b/apps/bim/dsinv/kustomization.yaml @@ -9,5 +9,5 @@ resources: patches: - path: backend.yaml target: - kind: Deployment + kind: HelmRelease name: backend diff --git a/apps/bim/yc-k8s-test/kustomization.yaml b/apps/bim/yc-k8s-test/kustomization.yaml index 050d882..c8f7064 100644 --- a/apps/bim/yc-k8s-test/kustomization.yaml +++ b/apps/bim/yc-k8s-test/kustomization.yaml @@ -7,5 +7,5 @@ resources: patches: - path: replicas.yaml target: - kind: Deployment + kind: HelmRelease name: backend diff --git a/apps/bim/yc-k8s-test/replicas.yaml b/apps/bim/yc-k8s-test/replicas.yaml index 6ae8686..b620579 100644 --- a/apps/bim/yc-k8s-test/replicas.yaml +++ b/apps/bim/yc-k8s-test/replicas.yaml @@ -1,8 +1,13 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: backend namespace: bim spec: - replicas: 1 + values: + services: + backend: + deployment: + replicaCount: + _default: 1 diff --git a/apps/cde/base/backend-service.yaml b/apps/cde/base/backend-service.yaml deleted file mode 100644 index 6a3f366..0000000 --- a/apps/cde/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: cde-svc - namespace: faas -spec: - type: ClusterIP - selector: - app: cde - ports: - - name: http - port: 80 - targetPort: 8000 - protocol: TCP diff --git a/apps/cde/base/cde-flowscallback.yaml b/apps/cde/base/cde-flowscallback.yaml index 15e14c0..406212e 100644 --- a/apps/cde/base/cde-flowscallback.yaml +++ b/apps/cde/base/cde-flowscallback.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-flowscallback namespace: cde - labels: - app: cde-flowscallback - service: cde-flowscallback + spec: - replicas: 1 - selector: - matchLabels: - app: cde-flowscallback - template: - metadata: - labels: - app: cde-flowscallback - service: cde-flowscallback - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-flowscallback - image: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-flowscallback: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-flowscallback + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-splitpdf.yaml b/apps/cde/base/cde-splitpdf.yaml index 1c5ca83..a50615f 100644 --- a/apps/cde/base/cde-splitpdf.yaml +++ b/apps/cde/base/cde-splitpdf.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-splitpdf namespace: cde - labels: - app: cde-splitpdf - service: cde-splitpdf + spec: - replicas: 1 - selector: - matchLabels: - app: cde-splitpdf - template: - metadata: - labels: - app: cde-splitpdf - service: cde-splitpdf - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-splitpdf - image: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-splitpdf: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-splitpdf + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-copy.yaml b/apps/cde/base/cde-worker-copy.yaml index 6f27510..622243f 100644 --- a/apps/cde/base/cde-worker-copy.yaml +++ b/apps/cde/base/cde-worker-copy.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-worker-copy namespace: cde - labels: - app: cde-worker-copy - service: cde-worker-copy + spec: - replicas: 1 - selector: - matchLabels: - app: cde-worker-copy - template: - metadata: - labels: - app: cde-worker-copy - service: cde-worker-copy - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-worker-copy - image: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-copy: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-copy + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-create-versions.yaml b/apps/cde/base/cde-worker-create-versions.yaml index d49dd1a..36b788d 100644 --- a/apps/cde/base/cde-worker-create-versions.yaml +++ b/apps/cde/base/cde-worker-create-versions.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-worker-create-versions namespace: cde - labels: - app: cde-worker-create-versions - service: cde-worker-create-versions + spec: - replicas: 1 - selector: - matchLabels: - app: cde-worker-create-versions - template: - metadata: - labels: - app: cde-worker-create-versions - service: cde-worker-create-versions - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-worker-create-versions - image: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-create-versions: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-create-versions + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-markings.yaml b/apps/cde/base/cde-worker-markings.yaml index 5601e96..018bd6a 100644 --- a/apps/cde/base/cde-worker-markings.yaml +++ b/apps/cde/base/cde-worker-markings.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-worker-markings namespace: cde - labels: - app: cde-worker-markings - service: cde-worker-markings + spec: - replicas: 1 - selector: - matchLabels: - app: cde-worker-markings - template: - metadata: - labels: - app: cde-worker-markings - service: cde-worker-markings - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-worker-markings - image: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-markings: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-markings + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-sign.yaml b/apps/cde/base/cde-worker-sign.yaml index ae7fa82..153caab 100644 --- a/apps/cde/base/cde-worker-sign.yaml +++ b/apps/cde/base/cde-worker-sign.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-worker-sign namespace: cde - labels: - app: cde-worker-sign - service: cde-worker-sign + spec: - replicas: 1 - selector: - matchLabels: - app: cde-worker-sign - template: - metadata: - labels: - app: cde-worker-sign - service: cde-worker-sign - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-worker-sign - image: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-sign: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-sign + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-update-bundles.yaml b/apps/cde/base/cde-worker-update-bundles.yaml index 5af1db5..0edcf5b 100644 --- a/apps/cde/base/cde-worker-update-bundles.yaml +++ b/apps/cde/base/cde-worker-update-bundles.yaml @@ -1,60 +1,116 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde-worker-update-bundles namespace: cde - labels: - app: cde-worker-update-bundles - service: cde-worker-update-bundles + spec: - replicas: 1 - selector: - matchLabels: - app: cde-worker-update-bundles - template: - metadata: - labels: - app: cde-worker-update-bundles - service: cde-worker-update-bundles - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: cde-worker-update-bundles - image: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-update-bundles: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-update-bundles + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /worker - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde.yaml b/apps/cde/base/cde.yaml index de4bc69..1cade42 100644 --- a/apps/cde/base/cde.yaml +++ b/apps/cde/base/cde.yaml @@ -1,60 +1,131 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: cde namespace: cde - labels: - app: cde - service: cde + spec: - replicas: 1 - selector: - matchLabels: - app: cde - template: - metadata: - labels: - app: cde - service: cde - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: cde - vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde - vault.hashicorp.com/agent-inject-template-cde-env: |- - {{- with secret "secrets/data/vault/apps/cde" -}} - {{- range $k, $v := .Data.data }} - export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) - {{- end }} - {{- end -}} + interval: 10m + + chart: spec: - serviceAccountName: cde-vault - containers: - - name: api - image: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a - imagePullPolicy: IfNotPresent + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde + + replicaCount: + _default: 1 + + port: + _default: 8000 + command: - - /bin/bash - - -lc + _default: ["/bin/bash", "-lc"] args: - - | - set -e - source /vault/secrets/cde-env - exec /http - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: S3_IS_CONTOUR - value: "true" + _default: + - | + set -e + source /vault/secrets/cde-env + exec /http + resources: requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: cde-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/kustomization.yaml b/apps/cde/base/kustomization.yaml index 9c18fbf..66da886 100644 --- a/apps/cde/base/kustomization.yaml +++ b/apps/cde/base/kustomization.yaml @@ -4,10 +4,8 @@ kind: Kustomization namespace: cde resources: - namespace.yaml - - serviceaccount.yaml - cde.yaml - cde-splitpdf.yaml - - backend-service.yaml - cde-flowscallback.yaml - cde-worker-copy.yaml - cde-worker-create-versions.yaml diff --git a/apps/cde/base/serviceaccount.yaml b/apps/cde/base/serviceaccount.yaml deleted file mode 100644 index ebb471d..0000000 --- a/apps/cde/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: cde-vault - namespace: cde diff --git a/apps/cde/d8-ugmk-prod/kustomization.yaml b/apps/cde/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..0fee837 --- /dev/null +++ b/apps/cde/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: cde diff --git a/apps/cde/d8-ugmk-prod/namespace.yaml b/apps/cde/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..453a53c --- /dev/null +++ b/apps/cde/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: cde + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/comparisons/d8-ugmk-prod/namespace.yaml b/apps/comparisons/d8-ugmk-prod/namespace.yaml index 9c83f6a..cc54650 100644 --- a/apps/comparisons/d8-ugmk-prod/namespace.yaml +++ b/apps/comparisons/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: comparisons labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/control-interface/d8-ugmk-prod/namespace.yaml b/apps/control-interface/d8-ugmk-prod/namespace.yaml index e773ad1..f4c67bb 100644 --- a/apps/control-interface/d8-ugmk-prod/namespace.yaml +++ b/apps/control-interface/d8-ugmk-prod/namespace.yaml @@ -3,5 +3,5 @@ kind: Namespace metadata: name: control-interface labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/cross-section/d8-ugmk-prod/namespace.yaml b/apps/cross-section/d8-ugmk-prod/namespace.yaml index 10b2d97..5b8d5e4 100644 --- a/apps/cross-section/d8-ugmk-prod/namespace.yaml +++ b/apps/cross-section/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: cross-section labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/document-link/d8-ugmk-prod/namespace.yaml b/apps/document-link/d8-ugmk-prod/namespace.yaml index dd4f6ec..4a9e663 100644 --- a/apps/document-link/d8-ugmk-prod/namespace.yaml +++ b/apps/document-link/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: document-link labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/drawings/d8-ugmk-prod/namespace.yaml b/apps/drawings/d8-ugmk-prod/namespace.yaml index 5d45457..468680a 100644 --- a/apps/drawings/d8-ugmk-prod/namespace.yaml +++ b/apps/drawings/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: drawings labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/eav/base/django-configmap.yaml b/apps/eav/base/django-configmap.yaml index b610500..6f03ee7 100644 --- a/apps/eav/base/django-configmap.yaml +++ b/apps/eav/base/django-configmap.yaml @@ -103,10 +103,11 @@ data: "django_filters.rest_framework.DjangoFilterBackend" ], "DEFAULT_AUTHENTICATION_CLASSES": [ - "core.auth.ZitadelJWTAuthentication", - "rest_framework_simplejwt.authentication.JWTAuthentication", - "rest_framework.authentication.SessionAuthentication", - "rest_framework.authentication.BasicAuthentication", + #"core.auth.ZitadelJWTAuthentication", + "rest_framework_simplejwt.authentication.JWTStatelessUserAuthentication", + #"rest_framework_simplejwt.authentication.JWTAuthentication", + #"rest_framework.authentication.SessionAuthentication", + #"rest_framework.authentication.BasicAuthentication", ], "DEFAULT_PERMISSION_CLASSES": [ "rest_framework.permissions.AllowAny", diff --git a/apps/faas/d8-ugmk-prod/namespace.yaml b/apps/faas/d8-ugmk-prod/namespace.yaml index 3058a54..332fe39 100644 --- a/apps/faas/d8-ugmk-prod/namespace.yaml +++ b/apps/faas/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: faas labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/flows/base/backend-deployment.yaml b/apps/flows/base/backend-deployment.yaml deleted file mode 100644 index baf18f3..0000000 --- a/apps/flows/base/backend-deployment.yaml +++ /dev/null @@ -1,137 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: backend - namespace: flows - labels: - app: backend - service: backend -spec: - replicas: 1 - selector: - matchLabels: - app: backend - template: - metadata: - labels: - app: backend - service: backend - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: flows - vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows - vault.hashicorp.com/agent-inject-template-flows-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/flows" -}} - PG_DB=flows_db - PG_LOGIN={{ index .Data.data "username" }} - PG_HOST=postgresql.flows.svc.cluster.local - PG_PORT=5432 - PG_PASSWORD={{ index .Data.data "password" }} - DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local - DOCUMENTATION_PG_PORT=5432 - DOCUMENTATION_PG_DATABASE=flows_db - DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }} - DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows - vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/flows" -}} - RABBITMQ_USERNAME={{ index .Data.data "username" }} - RABBITMQ_PASSWORD={{ index .Data.data "password" }} - RABBITMQ_VHOST={{ index .Data.data "vhost" }} - RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local - RABBITMQ_PORT=5672 - ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672 - {{- end -}} - vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-flows-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - DJANGO_TOKEN={{ index .Data.data "key" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-flows-jwt-public: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - {{ index .Data.data "public_key" }} - {{- end -}} - spec: - serviceAccountName: flows-vault - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111 - imagePullPolicy: IfNotPresent - command: ["/bin/sh", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql - [ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq - [ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth - [ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)" - set +a - exec /opt/entrypoint.sh - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: LOG_LEVEL - value: DEBUG - - name: BASE_HOST - value: https://srx.wb.ru - - name: CELERY_QUEUE - value: flow - - name: EAV_HOST - value: http://backend-svc.eav.svc.cluster.local:80 - - name: DJANGO_HOST - value: http://backend-svc.django.svc.cluster.local:80/api - - name: PLANNING_HOST - value: http://backend-svc.pm.svc.cluster.local:80/api/pm/msp - - name: PLANNING_USE - value: "True" - - name: DOCUMENTATION_HOST - value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1 - - name: DOCUMENTATION_EXTERNAL_HOST - value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1 - - name: ENABLE_ANALYTICS - value: "1" - - name: ENABLE_CELERY - value: "1" - - name: ENABLE_MAILGUN - value: "0" - - name: ENABLE_METRICS - value: "0" - - name: FROM_EMAIL - value: sarex@rwb.ru - - name: GATEWAY_URL - value: http://pdm-api.documentations.svc.cluster.local:8080 - - name: RESOURCE_URL - value: http://resources-service.resources.svc.cluster.local:8000 - - name: SERVICE_HOST - value: https://srx.wb.ru/flows/api/v1 - - name: SMTP_HOST - value: mail.rwb.ru - - name: CHECKLIST_HOST - value: http://checklists-backend-service.checklists.svc.cluster.local:80 - - name: SMTP_PORT - value: "465" - - name: SYNC_RESOURCE_ID - value: "1" - - name: TIMEOUT - value: "120" - - name: WORKFLOWS_HOST - value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1 - - name: WORKFLOWS_TIMEOUT - value: "60" - - name: DOCUMENTATION_TIMEOUT - value: "60" - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/flows/base/backend-service.yaml b/apps/flows/base/backend-service.yaml deleted file mode 100644 index 7a8d196..0000000 --- a/apps/flows/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: backend-svc - namespace: flows -spec: - type: ClusterIP - selector: - app: backend - ports: - - name: http - port: 80 - targetPort: 8000 - protocol: TCP diff --git a/apps/flows/base/backend.yaml b/apps/flows/base/backend.yaml new file mode 100644 index 0000000..225527a --- /dev/null +++ b/apps/flows/base/backend.yaml @@ -0,0 +1,258 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: flows-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql + [ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq + [ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth + [ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)" + set +a + exec /opt/entrypoint.sh + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: LOG_LEVEL + value: + _default: "DEBUG" + + - name: BASE_HOST + value: + _default: "https://srx.wb.ru" + + - name: CELERY_QUEUE + value: + _default: "flow" + + - name: EAV_HOST + value: + _default: "http://backend-svc.eav.svc.cluster.local:80" + + - name: DJANGO_HOST + value: + _default: "http://backend-svc.django.svc.cluster.local:80/api" + + - name: PLANNING_HOST + value: + _default: "http://backend-svc.pm.svc.cluster.local:80/api/pm/msp" + + - name: PLANNING_USE + value: + _default: "True" + + - name: DOCUMENTATION_HOST + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1" + + - name: DOCUMENTATION_EXTERNAL_HOST + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1" + + - name: ENABLE_ANALYTICS + value: + _default: "1" + + - name: ENABLE_CELERY + value: + _default: "1" + + - name: ENABLE_MAILGUN + value: + _default: "0" + + - name: ENABLE_METRICS + value: + _default: "0" + + - name: FROM_EMAIL + value: + _default: "sarex@rwb.ru" + + - name: GATEWAY_URL + value: + _default: "http://pdm-api.documentations.svc.cluster.local:8080" + + - name: RESOURCE_URL + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: SERVICE_HOST + value: + _default: "https://srx.wb.ru/flows/api/v1" + + - name: SMTP_HOST + value: + _default: "mail.rwb.ru" + + - name: CHECKLIST_HOST + value: + _default: "http://checklists-backend-service.checklists.svc.cluster.local:80" + + - name: SMTP_PORT + value: + _default: "465" + + - name: SYNC_RESOURCE_ID + value: + _default: "1" + + - name: TIMEOUT + value: + _default: "120" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1" + + - name: WORKFLOWS_TIMEOUT + value: + _default: "60" + + - name: DOCUMENTATION_TIMEOUT + value: + _default: "60" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: flows + vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows + vault.hashicorp.com/agent-inject-template-flows-postgresql: |- + {{- with secret "secrets/data/postgresql/apps/flows" -}} + PG_DB=flows_db + PG_LOGIN={{ index .Data.data "username" }} + PG_HOST=postgresql.flows.svc.cluster.local + PG_PORT=5432 + PG_PASSWORD={{ index .Data.data "password" }} + DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local + DOCUMENTATION_PG_PORT=5432 + DOCUMENTATION_PG_DATABASE=flows_db + DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }} + DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows + vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/flows" -}} + RABBITMQ_USERNAME={{ index .Data.data "username" }} + RABBITMQ_PASSWORD={{ index .Data.data "password" }} + RABBITMQ_VHOST={{ index .Data.data "vhost" }} + RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local + RABBITMQ_PORT=5672 + ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672 + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-flows-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + DJANGO_TOKEN={{ index .Data.data "key" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-flows-jwt-public: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + {{ index .Data.data "public_key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/flows/base/celery-deployment.yaml b/apps/flows/base/celery-deployment.yaml deleted file mode 100644 index 78e1d72..0000000 --- a/apps/flows/base/celery-deployment.yaml +++ /dev/null @@ -1,137 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: celery - namespace: flows - labels: - app: celery - service: celery -spec: - replicas: 1 - selector: - matchLabels: - app: celery - template: - metadata: - labels: - app: celery - service: celery - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: flows - vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows - vault.hashicorp.com/agent-inject-template-flows-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/flows" -}} - PG_DB=flows_db - PG_LOGIN={{ index .Data.data "username" }} - PG_HOST=postgresql.flows.svc.cluster.local - PG_PORT=5432 - PG_PASSWORD={{ index .Data.data "password" }} - DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local - DOCUMENTATION_PG_PORT=5432 - DOCUMENTATION_PG_DATABASE=flows_db - DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }} - DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows - vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/flows" -}} - RABBITMQ_USERNAME={{ index .Data.data "username" }} - RABBITMQ_PASSWORD={{ index .Data.data "password" }} - RABBITMQ_VHOST={{ index .Data.data "vhost" }} - RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local - RABBITMQ_PORT=5672 - ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672 - {{- end -}} - vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-flows-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - DJANGO_TOKEN={{ index .Data.data "key" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-flows-jwt-public: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - {{ index .Data.data "public_key" }} - {{- end -}} - spec: - serviceAccountName: flows-vault - containers: - - name: celery - image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111 - imagePullPolicy: IfNotPresent - command: ["/bin/sh", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql - [ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq - [ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth - [ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)" - set +a - exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: LOG_LEVEL - value: DEBUG - - name: BASE_HOST - value: https://srx.wb.ru - - name: CELERY_QUEUE - value: flow - - name: EAV_HOST - value: http://backend-svc.eav.svc.cluster.local:80 - - name: DJANGO_HOST - value: http://backend-svc.django.svc.cluster.local:80/api - - name: PLANNING_HOST - value: http://backend-service.pm.svc.cluster.local:80/api/pm/msp - - name: PLANNING_USE - value: "True" - - name: DOCUMENTATION_HOST - value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1 - - name: DOCUMENTATION_EXTERNAL_HOST - value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1 - - name: ENABLE_ANALYTICS - value: "1" - - name: ENABLE_CELERY - value: "1" - - name: ENABLE_MAILGUN - value: "0" - - name: ENABLE_METRICS - value: "0" - - name: FROM_EMAIL - value: sarex@rwb.ru - - name: GATEWAY_URL - value: http://pdm-api.documentations.svc.cluster.local:8080 - - name: RESOURCE_URL - value: http://resources-service.resources.svc.cluster.local:8000 - - name: SERVICE_HOST - value: https://srx.wb.ru/flows/api/v1 - - name: SMTP_HOST - value: mail.rwb.ru - - name: CHECKLIST_HOST - value: http://checklists-backend-service.checklists.svc.cluster.local:80 - - name: SMTP_PORT - value: "465" - - name: SYNC_RESOURCE_ID - value: "1" - - name: TIMEOUT - value: "120" - - name: WORKFLOWS_HOST - value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1 - - name: WORKFLOWS_TIMEOUT - value: "60" - - name: DOCUMENTATION_TIMEOUT - value: "60" - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/flows/base/celery.yaml b/apps/flows/base/celery.yaml new file mode 100644 index 0000000..b7893bd --- /dev/null +++ b/apps/flows/base/celery.yaml @@ -0,0 +1,243 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: celery + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + celery: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: flows-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: celery + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql + [ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq + [ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth + [ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)" + set +a + exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: LOG_LEVEL + value: + _default: "DEBUG" + + - name: BASE_HOST + value: + _default: "https://srx.wb.ru" + + - name: CELERY_QUEUE + value: + _default: "flow" + + - name: EAV_HOST + value: + _default: "http://backend-svc.eav.svc.cluster.local:80" + + - name: DJANGO_HOST + value: + _default: "http://backend-svc.django.svc.cluster.local:80/api" + + - name: PLANNING_HOST + value: + _default: "http://backend-service.pm.svc.cluster.local:80/api/pm/msp" + + - name: PLANNING_USE + value: + _default: "True" + + - name: DOCUMENTATION_HOST + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1" + + - name: DOCUMENTATION_EXTERNAL_HOST + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1" + + - name: ENABLE_ANALYTICS + value: + _default: "1" + + - name: ENABLE_CELERY + value: + _default: "1" + + - name: ENABLE_MAILGUN + value: + _default: "0" + + - name: ENABLE_METRICS + value: + _default: "0" + + - name: FROM_EMAIL + value: + _default: "sarex@rwb.ru" + + - name: GATEWAY_URL + value: + _default: "http://pdm-api.documentations.svc.cluster.local:8080" + + - name: RESOURCE_URL + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: SERVICE_HOST + value: + _default: "https://srx.wb.ru/flows/api/v1" + + - name: SMTP_HOST + value: + _default: "mail.rwb.ru" + + - name: CHECKLIST_HOST + value: + _default: "http://checklists-backend-service.checklists.svc.cluster.local:80" + + - name: SMTP_PORT + value: + _default: "465" + + - name: SYNC_RESOURCE_ID + value: + _default: "1" + + - name: TIMEOUT + value: + _default: "120" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1" + + - name: WORKFLOWS_TIMEOUT + value: + _default: "60" + + - name: DOCUMENTATION_TIMEOUT + value: + _default: "60" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: flows + vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows + vault.hashicorp.com/agent-inject-template-flows-postgresql: |- + {{- with secret "secrets/data/postgresql/apps/flows" -}} + PG_DB=flows_db + PG_LOGIN={{ index .Data.data "username" }} + PG_HOST=postgresql.flows.svc.cluster.local + PG_PORT=5432 + PG_PASSWORD={{ index .Data.data "password" }} + DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local + DOCUMENTATION_PG_PORT=5432 + DOCUMENTATION_PG_DATABASE=flows_db + DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }} + DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows + vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/flows" -}} + RABBITMQ_USERNAME={{ index .Data.data "username" }} + RABBITMQ_PASSWORD={{ index .Data.data "password" }} + RABBITMQ_VHOST={{ index .Data.data "vhost" }} + RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local + RABBITMQ_PORT=5672 + ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672 + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-flows-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + DJANGO_TOKEN={{ index .Data.data "key" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-flows-jwt-public: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + {{ index .Data.data "public_key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/flows/base/frontend-deployment.yaml b/apps/flows/base/frontend-deployment.yaml deleted file mode 100644 index d22c44a..0000000 --- a/apps/flows/base/frontend-deployment.yaml +++ /dev/null @@ -1,32 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: frontend - namespace: flows - labels: - app: frontend -spec: - replicas: 1 - selector: - matchLabels: - app: frontend - template: - metadata: - labels: - app: frontend - spec: - containers: - - name: frontend - image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144 - imagePullPolicy: IfNotPresent - ports: - - name: http - containerPort: 80 - protocol: TCP - resources: - requests: - cpu: 25m - memory: 100Mi - imagePullSecrets: - - name: regcred diff --git a/apps/flows/base/frontend-service.yaml b/apps/flows/base/frontend-service.yaml deleted file mode 100644 index 560deee..0000000 --- a/apps/flows/base/frontend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: frontend-svc - namespace: flows -spec: - type: ClusterIP - selector: - app: frontend - ports: - - name: http - port: 80 - targetPort: 80 - protocol: TCP diff --git a/apps/flows/base/frontend.yaml b/apps/flows/base/frontend.yaml new file mode 100644 index 0000000..2864ef0 --- /dev/null +++ b/apps/flows/base/frontend.yaml @@ -0,0 +1,90 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: flows + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 100Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred diff --git a/apps/flows/base/kustomization.yaml b/apps/flows/base/kustomization.yaml index 2f070b6..7986c03 100644 --- a/apps/flows/base/kustomization.yaml +++ b/apps/flows/base/kustomization.yaml @@ -4,9 +4,6 @@ kind: Kustomization namespace: flows resources: - namespace.yaml - - serviceaccount.yaml - - backend-deployment.yaml - - celery-deployment.yaml - - frontend-deployment.yaml - - backend-service.yaml - - frontend-service.yaml + - backend.yaml + - celery.yaml + - frontend.yaml diff --git a/apps/flows/base/serviceaccount.yaml b/apps/flows/base/serviceaccount.yaml deleted file mode 100644 index 90ea5b2..0000000 --- a/apps/flows/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: flows-vault - namespace: flows diff --git a/apps/flows/d8-ugmk-prod/kustomization.yaml b/apps/flows/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..d399533 --- /dev/null +++ b/apps/flows/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: flows diff --git a/apps/flows/d8-ugmk-prod/namespace.yaml b/apps/flows/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..c02e305 --- /dev/null +++ b/apps/flows/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: flows + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/flows/dsinv/backend.yaml b/apps/flows/dsinv/backend.yaml index 1daaea0..2cd9861 100644 --- a/apps/flows/dsinv/backend.yaml +++ b/apps/flows/dsinv/backend.yaml @@ -1,92 +1,182 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: backend namespace: flows spec: - replicas: 2 - template: - spec: - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0 - env: - - name: DEBUG - value: 'false' - - name: PLANNING_HOST - value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp - - name: PLANNING_USE - value: 'True' - - name: PG_PORT - value: '5432' - - name: EAV_HOST - value: http://eav-service.eav.svc.cluster.local:8000 - - name: PROXY_PATH_PREFIX - value: /flows - - name: DJANGO_HOST - value: http://backend.django.svc.cluster.local:8000/api - - name: DOCUMENTATION_TIMEOUT - value: '240' - - name: DOCUMENTATION_HOST - value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1 - - name: DOCUMENTATION_EXTERNAL_HOST - value: http://documentations-service.documentations.svc.cluster.local:8080/api/v1 - - name: BASE_HOST - value: https://sarex.dsinv.ru - - name: DOCUMENTATION_PG_PORT - value: '5432' - - name: DOCUMENTATION_PG_DATABASE - value: documentations - - name: DOCUMENTATION_PG_HOST - value: postgres-service.documentations.svc.cluster.local - - name: WORKFLOWS_HOST - value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1 - - name: WORKFLOWS_NOTIFICATIONS_REGISTRY - value: cr.yandex/crp3ccidau046kdj8g9q - - name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST - value: relay.dsinv.ru - - name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT - value: '25' - - name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI - value: sarex@dsinv.ru - - name: NOTIFICATION_SETTINGS_USE_MAILGUN - value: '0' - - name: RESOURCES_HOST - value: http://resources-service.resources.svc.cluster.local:8000 - - name: ENABLE_METRICS - value: '0' - - name: ENABLE_MAILGUN - value: '0' - - name: SMTP_HOST - value: relay.dsinv.ru - - name: SMTP_PORT - value: '25' - - name: FROM_EMAIL - value: sarex@dsinv.ru - - name: TIMEOUT - value: '240' - - name: WORKFLOWS_TIMEOUT - value: '20' - - name: RESOURCE_URL - value: http://resources-service.resources.svc.cluster.local:8000/ - - name: GATEWAY_URL - value: http://pdm-api.documentations.svc.cluster.local:8080/ - - name: SYNC_RESOURCE_ID - value: '1' - - name: SERVICE_HOST - value: https://sarex.dsinv.ru/flows/api/v1 - - name: ENABLE_ANALYTICS - value: '1' - - name: ENABLE_CELERY - value: '1' - - name: CELERY_QUEUE - value: flow - - name: RABBITMQ_HOST - value: rabbitmq-service.flows.svc - - name: RABBITMQ_PORT - value: '5672' - - name: RABBITMQ_VHOST - value: flow - - name: PG_HOST - value: postgres-service.flows.svc.cluster.local + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0 + + deployment: + replicaCount: + _default: 2 + + envs: + - name: LOG_LEVEL + value: + _default: "DEBUG" + + - name: BASE_HOST + value: + _default: "https://sarex.dsinv.ru" + + - name: CELERY_QUEUE + value: + _default: "flow" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav.svc.cluster.local:8000" + + - name: DJANGO_HOST + value: + _default: "http://backend.django.svc.cluster.local:8000/api" + + - name: PLANNING_HOST + value: + _default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp" + + - name: PLANNING_USE + value: + _default: "True" + + - name: DOCUMENTATION_HOST + value: + _default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1" + + - name: DOCUMENTATION_EXTERNAL_HOST + value: + _default: "http://documentations-service.documentations.svc.cluster.local:8080/api/v1" + + - name: ENABLE_ANALYTICS + value: + _default: "1" + + - name: ENABLE_CELERY + value: + _default: "1" + + - name: ENABLE_MAILGUN + value: + _default: "0" + + - name: ENABLE_METRICS + value: + _default: "0" + + - name: FROM_EMAIL + value: + _default: "sarex@dsinv.ru" + + - name: GATEWAY_URL + value: + _default: "http://pdm-api.documentations.svc.cluster.local:8080/" + + - name: RESOURCE_URL + value: + _default: "http://resources-service.resources.svc.cluster.local:8000/" + + - name: SERVICE_HOST + value: + _default: "https://sarex.dsinv.ru/flows/api/v1" + + - name: SMTP_HOST + value: + _default: "relay.dsinv.ru" + + - name: CHECKLIST_HOST + value: + _default: "http://checklists-backend-service.checklists.svc.cluster.local:80" + + - name: SMTP_PORT + value: + _default: "25" + + - name: SYNC_RESOURCE_ID + value: + _default: "1" + + - name: TIMEOUT + value: + _default: "240" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1" + + - name: WORKFLOWS_TIMEOUT + value: + _default: "20" + + - name: DOCUMENTATION_TIMEOUT + value: + _default: "240" + + - name: DEBUG + value: + _default: "false" + + - name: PG_PORT + value: + _default: "5432" + + - name: PROXY_PATH_PREFIX + value: + _default: "/flows" + + - name: DOCUMENTATION_PG_PORT + value: + _default: "5432" + + - name: DOCUMENTATION_PG_DATABASE + value: + _default: "documentations" + + - name: DOCUMENTATION_PG_HOST + value: + _default: "postgres-service.documentations.svc.cluster.local" + + - name: WORKFLOWS_NOTIFICATIONS_REGISTRY + value: + _default: "cr.yandex/crp3ccidau046kdj8g9q" + + - name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST + value: + _default: "relay.dsinv.ru" + + - name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT + value: + _default: "25" + + - name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI + value: + _default: "sarex@dsinv.ru" + + - name: NOTIFICATION_SETTINGS_USE_MAILGUN + value: + _default: "0" + + - name: RESOURCES_HOST + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: RABBITMQ_HOST + value: + _default: "rabbitmq-service.flows.svc" + + - name: RABBITMQ_PORT + value: + _default: "5672" + + - name: RABBITMQ_VHOST + value: + _default: "flow" + + - name: PG_HOST + value: + _default: "postgres-service.flows.svc.cluster.local" diff --git a/apps/flows/dsinv/celery.yaml b/apps/flows/dsinv/celery.yaml index c77e992..a3e146b 100644 --- a/apps/flows/dsinv/celery.yaml +++ b/apps/flows/dsinv/celery.yaml @@ -1,93 +1,198 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: celery namespace: flows spec: - template: - spec: - containers: - - name: celery - image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0 - env: - - name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL - value: sarex@dsinv.ru - - name: ENABLE_METRICS - value: '0' - - name: ENABLE_MAILGUN - value: '0' - - name: SMTP_HOST - value: relay.dsinv.ru - - name: SMTP_PORT - value: '25' - - name: FROM_EMAIL - value: sarex@dsinv.ru - - name: MAILGUN_HOST - value: http:localhost:8000 - - name: MAILGUN_API_KEY - value: empty - - name: NOTIFICATION_SETTINGS_USE_MAILGUN - value: '0' - - name: WORKFLOWS_HOST - value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1 - - name: FLOWS_HOST - value: http://backend-service.flows.svc.cluster.local:8000 - - name: WORKFLOWS_NOTIFICATIONS_REGISTRY - value: cr.yandex/crp3ccidau046kdj8g9q - - name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST - value: relay.dsinv.ru - - name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT - value: '25' - - name: PLANNING_HOST - value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp - - name: PLANNING_USE - value: 'True' - - name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI - value: sarex@dsinv.ru - - name: FLOWS_DB_HOST - value: postgres-service.flows.svc.cluster.local - - name: ISSUES_DB_HOST - value: postgres-service.issues.svc.cluster.local - - name: DEBUG - value: '0' - - name: PG_PORT - value: '5432' - - name: FLOWS_DB_PORT - value: '5432' - - name: ISSUES_DB_PORT - value: '5432' - - name: DJANGO_HOST - value: http://backend.django.svc.cluster.local:8000/api - - name: DJANGO_BASE_HOST - value: https://sarex.dsinv.ru - - name: DOCUMENTATION_HOST - value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1 - - name: BASE_HOST - value: https://sarex.dsinv.ru - - name: RESOURCES_HOST - value: http://resources-service.resources.svc.cluster.local:8000/ - - name: TIMEOUT - value: '120' - - name: RESOURCE_URL - value: http://resources-service.resources/api/v1 - - name: GATEWAY_URL - value: http://pdm-api.documentations.svc.cluster.local:8080/api/v1 - - name: SYNC_RESOURCE_ID - value: '1' - - name: SERVICE_HOST - value: https://sarex.dsinv.ru/flows/api/v1 - - name: ENABLE_ANALYTICS - value: '1' - - name: ENABLE_CELERY - value: '1' - - name: CELERY_QUEUE - value: flow - - name: RABBITMQ_HOST - value: rabbitmq-service.flows.svc - - name: RABBITMQ_PORT - value: '5672' - - name: RABBITMQ_VHOST - value: flow - - name: PG_HOST - value: postgres-service.flows.svc.cluster.local + values: + services: + celery: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0 + + envs: + - name: LOG_LEVEL + value: + _default: "DEBUG" + + - name: BASE_HOST + value: + _default: "https://sarex.dsinv.ru" + + - name: CELERY_QUEUE + value: + _default: "flow" + + - name: EAV_HOST + value: + _default: "http://backend-svc.eav.svc.cluster.local:80" + + - name: DJANGO_HOST + value: + _default: "http://backend.django.svc.cluster.local:8000/api" + + - name: PLANNING_HOST + value: + _default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp" + + - name: PLANNING_USE + value: + _default: "True" + + - name: DOCUMENTATION_HOST + value: + _default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1" + + - name: DOCUMENTATION_EXTERNAL_HOST + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1" + + - name: ENABLE_ANALYTICS + value: + _default: "1" + + - name: ENABLE_CELERY + value: + _default: "1" + + - name: ENABLE_MAILGUN + value: + _default: "0" + + - name: ENABLE_METRICS + value: + _default: "0" + + - name: FROM_EMAIL + value: + _default: "sarex@dsinv.ru" + + - name: GATEWAY_URL + value: + _default: "http://pdm-api.documentations.svc.cluster.local:8080/api/v1" + + - name: RESOURCE_URL + value: + _default: "http://resources-service.resources/api/v1" + + - name: SERVICE_HOST + value: + _default: "https://sarex.dsinv.ru/flows/api/v1" + + - name: SMTP_HOST + value: + _default: "relay.dsinv.ru" + + - name: CHECKLIST_HOST + value: + _default: "http://checklists-backend-service.checklists.svc.cluster.local:80" + + - name: SMTP_PORT + value: + _default: "25" + + - name: SYNC_RESOURCE_ID + value: + _default: "1" + + - name: TIMEOUT + value: + _default: "120" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1" + + - name: WORKFLOWS_TIMEOUT + value: + _default: "60" + + - name: DOCUMENTATION_TIMEOUT + value: + _default: "60" + + - name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL + value: + _default: "sarex@dsinv.ru" + + - name: MAILGUN_HOST + value: + _default: "http:localhost:8000" + + - name: MAILGUN_API_KEY + value: + _default: "empty" + + - name: NOTIFICATION_SETTINGS_USE_MAILGUN + value: + _default: "0" + + - name: FLOWS_HOST + value: + _default: "http://backend-service.flows.svc.cluster.local:8000" + + - name: WORKFLOWS_NOTIFICATIONS_REGISTRY + value: + _default: "cr.yandex/crp3ccidau046kdj8g9q" + + - name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST + value: + _default: "relay.dsinv.ru" + + - name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT + value: + _default: "25" + + - name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI + value: + _default: "sarex@dsinv.ru" + + - name: FLOWS_DB_HOST + value: + _default: "postgres-service.flows.svc.cluster.local" + + - name: ISSUES_DB_HOST + value: + _default: "postgres-service.issues.svc.cluster.local" + + - name: DEBUG + value: + _default: "0" + + - name: PG_PORT + value: + _default: "5432" + + - name: FLOWS_DB_PORT + value: + _default: "5432" + + - name: ISSUES_DB_PORT + value: + _default: "5432" + + - name: DJANGO_BASE_HOST + value: + _default: "https://sarex.dsinv.ru" + + - name: RESOURCES_HOST + value: + _default: "http://resources-service.resources.svc.cluster.local:8000/" + + - name: RABBITMQ_HOST + value: + _default: "rabbitmq-service.flows.svc" + + - name: RABBITMQ_PORT + value: + _default: "5672" + + - name: RABBITMQ_VHOST + value: + _default: "flow" + + - name: PG_HOST + value: + _default: "postgres-service.flows.svc.cluster.local" diff --git a/apps/flows/dsinv/frontend.yaml b/apps/flows/dsinv/frontend.yaml index 2665046..a7938ed 100644 --- a/apps/flows/dsinv/frontend.yaml +++ b/apps/flows/dsinv/frontend.yaml @@ -1,12 +1,13 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: frontend namespace: flows spec: - template: - spec: - containers: - - name: frontend - image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2 + values: + services: + frontend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2 diff --git a/apps/flows/dsinv/kustomization.yaml b/apps/flows/dsinv/kustomization.yaml index 0f1f7e1..77a3b6e 100644 --- a/apps/flows/dsinv/kustomization.yaml +++ b/apps/flows/dsinv/kustomization.yaml @@ -10,13 +10,13 @@ resources: patches: - path: backend.yaml target: - kind: Deployment + kind: HelmRelease name: backend - path: celery.yaml target: - kind: Deployment + kind: HelmRelease name: celery - path: frontend.yaml target: - kind: Deployment + kind: HelmRelease name: frontend diff --git a/apps/inspections/base/backend-service.yaml b/apps/inspections/base/backend-service.yaml deleted file mode 100644 index f938e6d..0000000 --- a/apps/inspections/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: rfi-backend-api-svc - namespace: rfi -spec: - type: ClusterIP - selector: - app: rfi-backend-api - ports: - - name: http - port: 80 - targetPort: 8000 - protocol: TCP diff --git a/apps/inspections/base/backend.yaml b/apps/inspections/base/backend.yaml new file mode 100644 index 0000000..b8f1da9 --- /dev/null +++ b/apps/inspections/base/backend.yaml @@ -0,0 +1,240 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: inspections + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: inspections-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: inspections-backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/bash", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db + [ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka + [ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth + set +a + exec ./entrypoint.sh + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: DEBUG + value: + _default: "false" + + - name: SERVICE_URL + value: + _default: "https://srx.wb.ru" + + - name: HTTP_APP_HOST + value: + _default: "0.0.0.0" + + - name: HTTP_APP_PORT + value: + _default: "8000" + + - name: HTTP_APP_ROOT_PATH + value: + _default: "/inspections" + + - name: HTTP_APP_WORKERS + value: + _default: "3" + + - name: HTTP_APP_ADMIN_ENABLE + value: + _default: "true" + + - name: KAFKA_SSL_CAFILE + value: + _default: "/usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt" + + - name: KAFKA_EAV_ASSETS_TOPIC + value: + _default: "assets_broadcast" + + - name: JWT_AUTH_ENABLE + value: + _default: "true" + + - name: NOTIFICATIONS_ENABLE + value: + _default: "true" + + - name: NOTIFICATIONS_EMAIL_FROM + value: + _default: "hello@sarex.io" + + - name: SAREX_BACKEND_URL + value: + _default: "https://srx.wb.ru" + + - name: SAREX_BACKEND_TIMEOUT + value: + _default: "30" + + - name: EAV_URL + value: + _default: "http://eav-service.eav" + + - name: EAV_TIMEOUT + value: + _default: "30" + + - name: WORKFLOWS_URL + value: + _default: "http://workflows-service.processing-prod" + + - name: WORKFLOWS_TIMEOUT + value: + _default: "30" + + - name: WORKFLOWS_EMAIL_DOCKER_IMAGE + value: + _default: "cr.yandex/crp3ccidau046kdj8g9q/notification:email" + + - name: MOBILE_APP_CURRENT_VERSION + value: + _default: "1.0.0" + + - name: MOBILE_APP_RECOMMENDED_VERSION + value: + _default: "1.0.0" + + - name: MOBILE_APP_REQUIRED_VERSION + value: + _default: "1.0.0" + + - name: MAILER_URL + value: + _default: "http://mailer-service.mailer:8000" + + - name: MAILER_TIMEOUT + value: + _default: "30" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: inspections + vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/postgresql/apps/inspections + vault.hashicorp.com/agent-inject-template-inspections-db: |- + {{- with secret "secrets/data/postgresql/apps/inspections" -}} + DATABASE_HOST=postgresql.inspections.svc.cluster.local + DATABASE_PORT=5432 + DATABASE_NAME=inspections_db + DATABASE_USER={{ index .Data.data "username" }} + DATABASE_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections + vault.hashicorp.com/agent-inject-template-inspections-kafka: |- + {{- with secret "secrets/data/kafka/apps/inspections" -}} + KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }} + KAFKA_USERNAME={{ index .Data.data "username" }} + KAFKA_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-inspections-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + SAREX_BACKEND_AUTH={{ index .Data.data "key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/inspections/base/kustomization.yaml b/apps/inspections/base/kustomization.yaml index 2b4238a..53d2b37 100644 --- a/apps/inspections/base/kustomization.yaml +++ b/apps/inspections/base/kustomization.yaml @@ -4,6 +4,4 @@ kind: Kustomization namespace: inspections resources: - namespace.yaml - - serviceaccount.yaml - - backend-deployment.yaml - - backend-service.yaml + - backend.yaml diff --git a/apps/inspections/base/serviceaccount.yaml b/apps/inspections/base/serviceaccount.yaml deleted file mode 100644 index b9f482d..0000000 --- a/apps/inspections/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: inspections-vault - namespace: inspections diff --git a/apps/inspections/d8-ugmk-prod/kustomization.yaml b/apps/inspections/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..025bf58 --- /dev/null +++ b/apps/inspections/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: inspections diff --git a/apps/inspections/d8-ugmk-prod/namespace.yaml b/apps/inspections/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..983b433 --- /dev/null +++ b/apps/inspections/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: inspections + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/inspections/dsinv/inspections-backend.yaml b/apps/inspections/dsinv/inspections-backend.yaml index b35cd4d..ce1c50f 100644 --- a/apps/inspections/dsinv/inspections-backend.yaml +++ b/apps/inspections/dsinv/inspections-backend.yaml @@ -1,61 +1,13 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: - name: inspections-backend + name: backend namespace: inspections spec: - template: - spec: - containers: - - name: inspections-backend - image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d - env: - - name: DEBUG - value: 'false' - - name: SERVICE_URL - value: https://srx.wb.ru - - name: HTTP_APP_HOST - value: 0.0.0.0 - - name: HTTP_APP_PORT - value: '8000' - - name: HTTP_APP_ROOT_PATH - value: /inspections - - name: HTTP_APP_WORKERS - value: '3' - - name: HTTP_APP_ADMIN_ENABLE - value: 'true' - - name: KAFKA_SSL_CAFILE - value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt - - name: KAFKA_EAV_ASSETS_TOPIC - value: assets_broadcast - - name: JWT_AUTH_ENABLE - value: 'true' - - name: NOTIFICATIONS_ENABLE - value: 'true' - - name: NOTIFICATIONS_EMAIL_FROM - value: hello@sarex.io - - name: SAREX_BACKEND_URL - value: https://srx.wb.ru - - name: SAREX_BACKEND_TIMEOUT - value: '30' - - name: EAV_URL - value: http://eav-service.eav - - name: EAV_TIMEOUT - value: '30' - - name: WORKFLOWS_URL - value: http://workflows-service.processing-prod - - name: WORKFLOWS_TIMEOUT - value: '30' - - name: WORKFLOWS_EMAIL_DOCKER_IMAGE - value: cr.yandex/crp3ccidau046kdj8g9q/notification:email - - name: MOBILE_APP_CURRENT_VERSION - value: 1.0.0 - - name: MOBILE_APP_RECOMMENDED_VERSION - value: 1.0.0 - - name: MOBILE_APP_REQUIRED_VERSION - value: 1.0.0 - - name: MAILER_URL - value: http://mailer-service.mailer:8000 - - name: MAILER_TIMEOUT - value: '30' + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d diff --git a/apps/inspections/dsinv/kustomization.yaml b/apps/inspections/dsinv/kustomization.yaml index afe1f3d..d7a1bd2 100644 --- a/apps/inspections/dsinv/kustomization.yaml +++ b/apps/inspections/dsinv/kustomization.yaml @@ -9,5 +9,5 @@ resources: patches: - path: inspections-backend.yaml target: - kind: Deployment - name: inspections-backend + kind: HelmRelease + name: backend diff --git a/apps/issues/base/backend-deployment.yaml b/apps/issues/base/backend-deployment.yaml deleted file mode 100644 index 24c69ab..0000000 --- a/apps/issues/base/backend-deployment.yaml +++ /dev/null @@ -1,135 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: backend - namespace: issues - labels: - app: backend - service: backend -spec: - replicas: 1 - selector: - matchLabels: - app: backend - template: - metadata: - labels: - app: backend - service: backend - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: issues - vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues - vault.hashicorp.com/agent-inject-template-issues-db: |- - {{- with secret "secrets/data/postgresql/apps/issues" -}} - DATABASE_PORT=5432 - DATABASE_HOST=postgresql.issues.svc.cluster.local - DATABASE_USER={{ index .Data.data "username" }} - DATABASE_PASSWORD={{ index .Data.data "password" }} - DATABASE_NAME=issues_db - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues - vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/issues" -}} - RABBITMQ_VHOST={{ index .Data.data "vhost" }} - RABBITMQ_USERNAME={{ index .Data.data "username" }} - RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local - RABBITMQ_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues - vault.hashicorp.com/agent-inject-template-issues-s3: |- - {{- with secret "secrets/data/minio/apps/issues" -}} - YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }} - YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }} - YC_S3_BUCKET_NAME=rfi - YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-issues-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - DJANGO_TOKEN={{ index .Data.data "key" }} - SAREX_USERNAME={{ index .Data.data "username" }} - SAREX_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-issues-jwt-private: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - {{ index .Data.data "private_key" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-issues-jwt-public: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - {{ index .Data.data "public_key" }} - {{- end -}} - spec: - serviceAccountName: issues-vault - volumes: - - name: production-configmap - configMap: - name: production-configmap - items: - - key: production.py - path: production.py - defaultMode: 420 - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa - imagePullPolicy: IfNotPresent - command: ["/bin/sh", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db - [ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq - [ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3 - [ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth - [ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)" - [ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)" - set +a - exec /src/entrypoint.sh - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: ENVIRONMENT - value: production - - name: AERO_PUBLIC_HOST - value: https://sarex.contour.infra.sarex.tech - - name: AERO_HOST - value: https://sarex.contour.infra.sarex.tech - - name: BASE_AERO_URL - value: https://sarex.contour.infra.sarex.tech - - name: BASE_AUTH_URL - value: http://backend-svc.django.svc.cluster.local:80 - - name: WORKFLOWS_HOST - value: http://backend-svc.workflow.svc.cluster.local:80 - - name: WORKFLOWS_URL - value: http://backend-svc.workflow.svc.cluster.local:80 - - name: RESOURCES_API_HOST - value: http://backend-svc.resources.svc.cluster.local:80 - - name: EAV_HOST - value: http://backend-svc.eav.svc.cluster.local:80 - - name: SAREX_API - value: https://sarex.contour.infra.sarex.tech - - name: DOCUMENTATIONS_URL - value: http://documentations-api-svc.documentations.svc.cluster.local:80 - - name: DJANGO_SETTINGS_MODULE - value: config.settings.production - - name: API_ADDRESS - value: "8000" - resources: - requests: - cpu: "25m" - memory: 128Mi - volumeMounts: - - name: production-configmap - mountPath: /src/config/settings/production.py - subPath: production.py - imagePullSecrets: - - name: regcred diff --git a/apps/issues/base/backend-service.yaml b/apps/issues/base/backend-service.yaml deleted file mode 100644 index d5d299e..0000000 --- a/apps/issues/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: backend-svc - namespace: issues -spec: - type: ClusterIP - selector: - app: backend - ports: - - name: http - port: 80 - targetPort: 8000 - protocol: TCP diff --git a/apps/issues/base/backend.yaml b/apps/issues/base/backend.yaml new file mode 100644 index 0000000..9644a58 --- /dev/null +++ b/apps/issues/base/backend.yaml @@ -0,0 +1,237 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: issues-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db + [ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq + [ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3 + [ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth + [ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)" + [ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)" + set +a + exec /src/entrypoint.sh + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + volumes: + _default: + - name: production-configmap + mountPath: + _default: /src/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: production-configmap + items: + - key: production.py + path: + _default: production.py + + envs: + - name: ENVIRONMENT + value: + _default: "production" + + - name: AERO_PUBLIC_HOST + value: + _default: "https://sarex.contour.infra.sarex.tech" + + - name: AERO_HOST + value: + _default: "https://sarex.contour.infra.sarex.tech" + + - name: BASE_AERO_URL + value: + _default: "https://sarex.contour.infra.sarex.tech" + + - name: BASE_AUTH_URL + value: + _default: "http://backend-svc.django.svc.cluster.local:80" + + - name: WORKFLOWS_HOST + value: + _default: "http://backend-svc.workflow.svc.cluster.local:80" + + - name: WORKFLOWS_URL + value: + _default: "http://backend-svc.workflow.svc.cluster.local:80" + + - name: RESOURCES_API_HOST + value: + _default: "http://backend-svc.resources.svc.cluster.local:80" + + - name: EAV_HOST + value: + _default: "http://backend-svc.eav.svc.cluster.local:80" + + - name: SAREX_API + value: + _default: "https://sarex.contour.infra.sarex.tech" + + - name: DOCUMENTATIONS_URL + value: + _default: "http://documentations-api-svc.documentations.svc.cluster.local:80" + + - name: DJANGO_SETTINGS_MODULE + value: + _default: "config.settings.production" + + - name: API_ADDRESS + value: + _default: "8000" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: issues + vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues + vault.hashicorp.com/agent-inject-template-issues-db: |- + {{- with secret "secrets/data/postgresql/apps/issues" -}} + DATABASE_PORT=5432 + DATABASE_HOST=postgresql.issues.svc.cluster.local + DATABASE_USER={{ index .Data.data "username" }} + DATABASE_PASSWORD={{ index .Data.data "password" }} + DATABASE_NAME=issues_db + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues + vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/issues" -}} + RABBITMQ_VHOST={{ index .Data.data "vhost" }} + RABBITMQ_USERNAME={{ index .Data.data "username" }} + RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local + RABBITMQ_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues + vault.hashicorp.com/agent-inject-template-issues-s3: |- + {{- with secret "secrets/data/minio/apps/issues" -}} + YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }} + YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }} + YC_S3_BUCKET_NAME=rfi + YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-issues-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + DJANGO_TOKEN={{ index .Data.data "key" }} + SAREX_USERNAME={{ index .Data.data "username" }} + SAREX_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-issues-jwt-private: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + {{ index .Data.data "private_key" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-issues-jwt-public: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + {{ index .Data.data "public_key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/issues/base/celery-deployment.yaml b/apps/issues/base/celery-deployment.yaml deleted file mode 100644 index c5fd887..0000000 --- a/apps/issues/base/celery-deployment.yaml +++ /dev/null @@ -1,135 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: celery - namespace: issues - labels: - app: celery - service: celery -spec: - replicas: 1 - selector: - matchLabels: - app: celery - template: - metadata: - labels: - app: celery - service: celery - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: issues - vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues - vault.hashicorp.com/agent-inject-template-issues-db: |- - {{- with secret "secrets/data/postgresql/apps/issues" -}} - DATABASE_PORT=5432 - DATABASE_HOST=postgresql.issues.svc.cluster.local - DATABASE_USER={{ index .Data.data "username" }} - DATABASE_PASSWORD={{ index .Data.data "password" }} - DATABASE_NAME=issues_db - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues - vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/issues" -}} - RABBITMQ_VHOST={{ index .Data.data "vhost" }} - RABBITMQ_USERNAME={{ index .Data.data "username" }} - RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local - RABBITMQ_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues - vault.hashicorp.com/agent-inject-template-issues-s3: |- - {{- with secret "secrets/data/minio/apps/issues" -}} - YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }} - YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }} - YC_S3_BUCKET_NAME=rfi - YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-issues-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - DJANGO_TOKEN={{ index .Data.data "key" }} - SAREX_USERNAME={{ index .Data.data "username" }} - SAREX_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-issues-jwt-private: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - {{ index .Data.data "private_key" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-issues-jwt-public: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - {{ index .Data.data "public_key" }} - {{- end -}} - spec: - serviceAccountName: issues-vault - volumes: - - name: production-configmap - configMap: - name: production-configmap - items: - - key: production.py - path: production.py - defaultMode: 420 - containers: - - name: celery - image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa - imagePullPolicy: IfNotPresent - command: ["/bin/sh", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db - [ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq - [ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3 - [ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth - [ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)" - [ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)" - set +a - exec celery -A config worker -l info -E - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: ENVIRONMENT - value: production - - name: AERO_PUBLIC_HOST - value: https://srx.wb.ru - - name: AERO_HOST - value: https://srx.wb.ru - - name: BASE_AERO_URL - value: https://srx.wb.ru - - name: BASE_AUTH_URL - value: http://backend-svc.django.svc.cluster.local:80 - - name: WORKFLOWS_HOST - value: http://workflows-api-service.workflow.svc.cluster.local:8000 - - name: WORKFLOWS_URL - value: http://workflows-api-service.workflow.svc.cluster.local:8000 - - name: RESOURCES_API_HOST - value: http://backend-svc.resources.svc.cluster.local:80 - - name: EAV_HOST - value: http://backend-svc.eav.svc.cluster.local:80 - - name: SAREX_API - value: https://srx.wb.ru - - name: DOCUMENTATIONS_URL - value: http://backend-api-svc.documentations.svc.cluster.local:80 - - name: DJANGO_SETTINGS_MODULE - value: config.settings.production - - name: API_ADDRESS - value: "8000" - resources: - requests: - cpu: "25m" - memory: 128Mi - volumeMounts: - - name: production-configmap - mountPath: /src/config/settings/production.py - subPath: production.py - imagePullSecrets: - - name: regcred diff --git a/apps/issues/base/celery.yaml b/apps/issues/base/celery.yaml new file mode 100644 index 0000000..c8eeefe --- /dev/null +++ b/apps/issues/base/celery.yaml @@ -0,0 +1,222 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: celery + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + celery: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: issues-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: celery + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db + [ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq + [ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3 + [ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth + [ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)" + [ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)" + set +a + exec celery -A config worker -l info -E + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + volumes: + _default: + - name: production-configmap + mountPath: + _default: /src/config/settings/production.py + subPath: + _default: production.py + readOnly: + _default: true + configMap: + name: + _default: production-configmap + items: + - key: production.py + path: + _default: production.py + + envs: + - name: ENVIRONMENT + value: + _default: "production" + + - name: AERO_PUBLIC_HOST + value: + _default: "https://srx.wb.ru" + + - name: AERO_HOST + value: + _default: "https://srx.wb.ru" + + - name: BASE_AERO_URL + value: + _default: "https://srx.wb.ru" + + - name: BASE_AUTH_URL + value: + _default: "http://backend-svc.django.svc.cluster.local:80" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-api-service.workflow.svc.cluster.local:8000" + + - name: WORKFLOWS_URL + value: + _default: "http://workflows-api-service.workflow.svc.cluster.local:8000" + + - name: RESOURCES_API_HOST + value: + _default: "http://backend-svc.resources.svc.cluster.local:80" + + - name: EAV_HOST + value: + _default: "http://backend-svc.eav.svc.cluster.local:80" + + - name: SAREX_API + value: + _default: "https://srx.wb.ru" + + - name: DOCUMENTATIONS_URL + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80" + + - name: DJANGO_SETTINGS_MODULE + value: + _default: "config.settings.production" + + - name: API_ADDRESS + value: + _default: "8000" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: issues + vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues + vault.hashicorp.com/agent-inject-template-issues-db: |- + {{- with secret "secrets/data/postgresql/apps/issues" -}} + DATABASE_PORT=5432 + DATABASE_HOST=postgresql.issues.svc.cluster.local + DATABASE_USER={{ index .Data.data "username" }} + DATABASE_PASSWORD={{ index .Data.data "password" }} + DATABASE_NAME=issues_db + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues + vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/issues" -}} + RABBITMQ_VHOST={{ index .Data.data "vhost" }} + RABBITMQ_USERNAME={{ index .Data.data "username" }} + RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local + RABBITMQ_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues + vault.hashicorp.com/agent-inject-template-issues-s3: |- + {{- with secret "secrets/data/minio/apps/issues" -}} + YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }} + YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }} + YC_S3_BUCKET_NAME=rfi + YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-issues-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + DJANGO_TOKEN={{ index .Data.data "key" }} + SAREX_USERNAME={{ index .Data.data "username" }} + SAREX_PASSWORD={{ index .Data.data "password" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-issues-jwt-private: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + {{ index .Data.data "private_key" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-issues-jwt-public: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + {{ index .Data.data "public_key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/issues/base/frontend-deployment.yaml b/apps/issues/base/frontend-deployment.yaml deleted file mode 100644 index f34f03e..0000000 --- a/apps/issues/base/frontend-deployment.yaml +++ /dev/null @@ -1,32 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: frontend - namespace: issues - labels: - app: frontend -spec: - replicas: 1 - selector: - matchLabels: - app: frontend - template: - metadata: - labels: - app: frontend - spec: - containers: - - name: frontend - image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73 - imagePullPolicy: IfNotPresent - ports: - - name: http - containerPort: 80 - protocol: TCP - resources: - requests: - cpu: 25m - memory: 100Mi - imagePullSecrets: - - name: regcred diff --git a/apps/issues/base/frontend-service.yaml b/apps/issues/base/frontend-service.yaml deleted file mode 100644 index fdb438b..0000000 --- a/apps/issues/base/frontend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: frontend-svc - namespace: issues -spec: - type: ClusterIP - selector: - app: frontend - ports: - - name: http - port: 80 - targetPort: 80 - protocol: TCP diff --git a/apps/issues/base/frontend.yaml b/apps/issues/base/frontend.yaml new file mode 100644 index 0000000..d01827e --- /dev/null +++ b/apps/issues/base/frontend.yaml @@ -0,0 +1,90 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: issues + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 100Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred diff --git a/apps/issues/base/kustomization.yaml b/apps/issues/base/kustomization.yaml index 2b1272a..36da654 100644 --- a/apps/issues/base/kustomization.yaml +++ b/apps/issues/base/kustomization.yaml @@ -4,10 +4,7 @@ kind: Kustomization namespace: issues resources: - namespace.yaml - - serviceaccount.yaml - - backend-deployment.yaml - - celery-deployment.yaml - - frontend-deployment.yaml - - backend-service.yaml - - frontend-service.yaml + - backend.yaml + - celery.yaml + - frontend.yaml - production-configmap.yaml diff --git a/apps/issues/base/serviceaccount.yaml b/apps/issues/base/serviceaccount.yaml deleted file mode 100644 index 30a477e..0000000 --- a/apps/issues/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: issues-vault - namespace: issues diff --git a/apps/issues/d8-ugmk-prod/kustomization.yaml b/apps/issues/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..b64e558 --- /dev/null +++ b/apps/issues/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: issues diff --git a/apps/issues/d8-ugmk-prod/namespace.yaml b/apps/issues/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..10ec0c1 --- /dev/null +++ b/apps/issues/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: issues + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/issues/dsinv/backend.yaml b/apps/issues/dsinv/backend.yaml index d168bfd..05c5595 100644 --- a/apps/issues/dsinv/backend.yaml +++ b/apps/issues/dsinv/backend.yaml @@ -1,53 +1,102 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: backend namespace: issues spec: - template: - spec: - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b - env: - - name: ENABLE_MAILGUN - value: 'False' - - name: SMTP_HOST - value: relay.dsinv.ru - - name: SMTP_PORT - value: '25' - - name: EMAIL_FROM - value: sarex@dsinv.ru - - name: USE_NOTIFICATIONS - value: 'True' - - name: DJANGO_SETTINGS_MODULE - value: config.settings.production - - name: REDIS_HOST - value: redis-service.issues.svc.cluster.local - - name: DATABASE_HOST - value: postgres-service.issues.svc.cluster.local - - name: DATABASE_PORT - value: '5432' - - name: DATABASE_NAME - value: issues - - name: API_ADDRESS - value: '8000' - - name: ENVIRONMENT - value: production - - name: AERO_PUBLIC_HOST - value: https://sarex.dsinv.ru - - name: BASE_AERO_URL - value: http://backend.django.svc.cluster.local:8000 - - name: BASE_AUTH_URL - value: http://backend.django.svc.cluster.local:8000 - - name: WORKFLOWS_HOST - value: http://workflows-service.workflow.svc.cluster.local:8000 - - name: WORKFLOWS_URL - value: https://sarex.dsinv.ru - - name: RESOURCES_API_HOST - value: http://resources-service.resources.svc.cluster.local:8000 - - name: EAV_HOST - value: http://eav-service.eav.svc.cluster.local:8000 - - name: SAREX_API - value: http://backend.django.svc.cluster.local:8000 + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b + + envs: + - name: ENVIRONMENT + value: + _default: "production" + + - name: AERO_PUBLIC_HOST + value: + _default: "https://sarex.dsinv.ru" + + - name: AERO_HOST + value: + _default: "https://sarex.contour.infra.sarex.tech" + + - name: BASE_AERO_URL + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: BASE_AUTH_URL + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-service.workflow.svc.cluster.local:8000" + + - name: WORKFLOWS_URL + value: + _default: "https://sarex.dsinv.ru" + + - name: RESOURCES_API_HOST + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav.svc.cluster.local:8000" + + - name: SAREX_API + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: DOCUMENTATIONS_URL + value: + _default: "http://documentations-api-svc.documentations.svc.cluster.local:80" + + - name: DJANGO_SETTINGS_MODULE + value: + _default: "config.settings.production" + + - name: API_ADDRESS + value: + _default: "8000" + + - name: ENABLE_MAILGUN + value: + _default: "False" + + - name: SMTP_HOST + value: + _default: "relay.dsinv.ru" + + - name: SMTP_PORT + value: + _default: "25" + + - name: EMAIL_FROM + value: + _default: "sarex@dsinv.ru" + + - name: USE_NOTIFICATIONS + value: + _default: "True" + + - name: REDIS_HOST + value: + _default: "redis-service.issues.svc.cluster.local" + + - name: DATABASE_HOST + value: + _default: "postgres-service.issues.svc.cluster.local" + + - name: DATABASE_PORT + value: + _default: "5432" + + - name: DATABASE_NAME + value: + _default: "issues" diff --git a/apps/issues/dsinv/celery.yaml b/apps/issues/dsinv/celery.yaml index 53618ac..8c6a8e7 100644 --- a/apps/issues/dsinv/celery.yaml +++ b/apps/issues/dsinv/celery.yaml @@ -1,57 +1,110 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: celery namespace: issues spec: - template: - spec: - containers: - - name: celery - image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b - env: - - name: KAFKA_EAV_ASSETS_TOPIC - value: sarex - - name: AERO_PUBLIC_HOST - value: https://sarex.dsinv.ru - - name: ENABLE_MAILGUN - value: 'False' - - name: SMTP_HOST - value: relay.dsinv.ru - - name: SMTP_PORT - value: '25' - - name: EMAIL_FROM - value: sarex@dsinv.ru - - name: REDIS_HOST - value: redis-service.issues.svc.cluster.local - - name: DATABASE_HOST - value: postgres-service.issues.svc.cluster.local - - name: DATABASE_PORT - value: '5432' - - name: DATABASE_NAME - value: issues - - name: USE_NOTIFICATIONS - value: 'True' - - name: API_ADDRESS - value: '8000' - - name: YC_S3_VERIFY - value: 'False' - - name: ENVIRONMENT - value: production - - name: AERO_HOST - value: https://sarex.dsinv.ru - - name: BASE_AERO_URL - value: http://backend.django.svc.cluster.local:8000 - - name: BASE_AUTH_URL - value: https://sarex.dsinv.ru - - name: WORKFLOWS_HOST - value: http://workflows-service.workflow.svc.cluster.local:8000 - - name: WORKFLOWS_URL - value: https://sarex.dsinv.ru - - name: RESOURCES_API_HOST - value: http://resources-service.resources.svc.cluster.local:8000 - - name: EAV_HOST - value: http://eav-service.eav.svc.cluster.local:8000 - - name: SAREX_API - value: http://backend.django.svc.cluster.local:8000 + values: + services: + celery: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b + + envs: + - name: ENVIRONMENT + value: + _default: "production" + + - name: AERO_PUBLIC_HOST + value: + _default: "https://sarex.dsinv.ru" + + - name: AERO_HOST + value: + _default: "https://sarex.dsinv.ru" + + - name: BASE_AERO_URL + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: BASE_AUTH_URL + value: + _default: "https://sarex.dsinv.ru" + + - name: WORKFLOWS_HOST + value: + _default: "http://workflows-service.workflow.svc.cluster.local:8000" + + - name: WORKFLOWS_URL + value: + _default: "https://sarex.dsinv.ru" + + - name: RESOURCES_API_HOST + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav.svc.cluster.local:8000" + + - name: SAREX_API + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: DOCUMENTATIONS_URL + value: + _default: "http://backend-api-svc.documentations.svc.cluster.local:80" + + - name: DJANGO_SETTINGS_MODULE + value: + _default: "config.settings.production" + + - name: API_ADDRESS + value: + _default: "8000" + + - name: KAFKA_EAV_ASSETS_TOPIC + value: + _default: "sarex" + + - name: ENABLE_MAILGUN + value: + _default: "False" + + - name: SMTP_HOST + value: + _default: "relay.dsinv.ru" + + - name: SMTP_PORT + value: + _default: "25" + + - name: EMAIL_FROM + value: + _default: "sarex@dsinv.ru" + + - name: REDIS_HOST + value: + _default: "redis-service.issues.svc.cluster.local" + + - name: DATABASE_HOST + value: + _default: "postgres-service.issues.svc.cluster.local" + + - name: DATABASE_PORT + value: + _default: "5432" + + - name: DATABASE_NAME + value: + _default: "issues" + + - name: USE_NOTIFICATIONS + value: + _default: "True" + + - name: YC_S3_VERIFY + value: + _default: "False" diff --git a/apps/issues/dsinv/frontend.yaml b/apps/issues/dsinv/frontend.yaml index c255a44..5fa4785 100644 --- a/apps/issues/dsinv/frontend.yaml +++ b/apps/issues/dsinv/frontend.yaml @@ -1,12 +1,13 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: frontend namespace: issues spec: - template: - spec: - containers: - - name: frontend - image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b + values: + services: + frontend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b diff --git a/apps/issues/dsinv/kustomization.yaml b/apps/issues/dsinv/kustomization.yaml index 951dc84..ec32d79 100644 --- a/apps/issues/dsinv/kustomization.yaml +++ b/apps/issues/dsinv/kustomization.yaml @@ -7,13 +7,13 @@ resources: patches: - path: backend.yaml target: - kind: Deployment + kind: HelmRelease name: backend - path: celery.yaml target: - kind: Deployment + kind: HelmRelease name: celery - path: frontend.yaml target: - kind: Deployment + kind: HelmRelease name: frontend diff --git a/apps/mapper/d8-ugmk-prod/namespace.yaml b/apps/mapper/d8-ugmk-prod/namespace.yaml index 3e969b0..ce8019c 100644 --- a/apps/mapper/d8-ugmk-prod/namespace.yaml +++ b/apps/mapper/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: mapper labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/measurements/d8-ugmk-prod/namespace.yaml b/apps/measurements/d8-ugmk-prod/namespace.yaml index c05d4e2..3067c9b 100644 --- a/apps/measurements/d8-ugmk-prod/namespace.yaml +++ b/apps/measurements/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: measurements labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/message-hub/base/deployment.yaml b/apps/message-hub/base/deployment.yaml deleted file mode 100644 index 90b3cce..0000000 --- a/apps/message-hub/base/deployment.yaml +++ /dev/null @@ -1,96 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: message-hub - namespace: message-hub - labels: - app: message-hub - service: message-hub -spec: - replicas: 1 - selector: - matchLabels: - app: message-hub - template: - metadata: - labels: - app: message-hub - service: message-hub - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: message-hub - vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/postgresql/apps/message-hub - vault.hashicorp.com/agent-inject-template-message-hub-db: |- - {{- with secret "secrets/data/postgresql/apps/message-hub" -}} - DB_USERNAME={{ index .Data.data "username" }} - DB_PASSWORD={{ index .Data.data "password" }} - DB_DATABASE=pm_db - DB_HOST=postgresql.pm.svc.cluster.local - DB_PORT=5432 - {{- end -}} - vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub - vault.hashicorp.com/agent-inject-template-message-hub-s3: |- - {{- with secret "secrets/data/minio/apps/message-hub" -}} - S3_HOST={{ index .Data.data.client "endpoint" }} - S3_LOGIN={{ index .Data.data "access_key" }} - S3_PASSWORD={{ index .Data.data "secret_key" }} - {{- $buckets := index .Data.data "buckets" }} - S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}rfi{{- end -}} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/message-hub - vault.hashicorp.com/agent-inject-template-message-hub-kafka: |- - {{- with secret "secrets/data/kafka/apps/message-hub" -}} - KAFKA_USERNAME={{ index .Data.data "username" }} - KAFKA_PASSWORD={{ index .Data.data "password" }} - KAFKA_HOST=kafka-kafka-contour-controller-headless.kafka.svc.cluster.local - KAFKA_PORT=9094 - KAFKA_SECURITY_PROTOCOL={{ index .Data.data.auth "security_protocol" }} - KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }} - {{- end -}} - spec: - serviceAccountName: message-hub-vault - containers: - - name: message-hub - image: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_24425472 - imagePullPolicy: IfNotPresent - command: ["/bin/bash", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/message-hub-db ] && . /vault/secrets/message-hub-db - [ -f /vault/secrets/message-hub-s3 ] && . /vault/secrets/message-hub-s3 - [ -f /vault/secrets/message-hub-kafka ] && . /vault/secrets/message-hub-kafka - set +a - exec /opt/entrypoint.sh - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: WORKER_TIMEOUT - value: "60" - - name: PYTHONPATH - value: src - - name: SETTINGS_MAX_RETRIES - value: "1" - - name: SETTINGS_TOPICS - value: '{"planning": "pm", "assets": "assets_broadcast", "project_entity": "issues_broadcast"}' - - name: SETTINGS_PDF_CONVERTER_HOST - value: http://export-project-service.django.svc.cluster.local:8000 - - name: SAREX_BASE_HOST - value: http://backend-service.pm.svc.cluster.local:8000 - - name: CACHE_HOST - value: redis.pm.svc.cluster.local - - name: CACHE_PORT - value: "6379" - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/message-hub/base/kustomization.yaml b/apps/message-hub/base/kustomization.yaml index 8ae7d0c..30e0638 100644 --- a/apps/message-hub/base/kustomization.yaml +++ b/apps/message-hub/base/kustomization.yaml @@ -4,6 +4,4 @@ kind: Kustomization namespace: message-hub resources: - namespace.yaml - - serviceaccount.yaml - - deployment.yaml - - service.yaml + - message-hub.yaml diff --git a/apps/message-hub/base/message-hub.yaml b/apps/message-hub/base/message-hub.yaml new file mode 100644 index 0000000..f9e0241 --- /dev/null +++ b/apps/message-hub/base/message-hub.yaml @@ -0,0 +1,183 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: message-hub + namespace: message-hub + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: message-hub-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_24425472 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: message-hub + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/bash", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/message-hub-db ] && . /vault/secrets/message-hub-db + [ -f /vault/secrets/message-hub-s3 ] && . /vault/secrets/message-hub-s3 + [ -f /vault/secrets/message-hub-kafka ] && . /vault/secrets/message-hub-kafka + set +a + exec /opt/entrypoint.sh + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: message-hub-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: WORKER_TIMEOUT + value: + _default: "60" + + - name: PYTHONPATH + value: + _default: "src" + + - name: SETTINGS_MAX_RETRIES + value: + _default: "1" + + - name: SETTINGS_TOPICS + value: + _default: '{"planning": "pm", "assets": "assets_broadcast", "project_entity": "issues_broadcast"}' + + - name: SETTINGS_PDF_CONVERTER_HOST + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: SAREX_BASE_HOST + value: + _default: "http://backend-service.pm.svc.cluster.local:8000" + + - name: CACHE_HOST + value: + _default: "redis.pm.svc.cluster.local" + + - name: CACHE_PORT + value: + _default: "6379" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: message-hub + vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/postgresql/apps/message-hub + vault.hashicorp.com/agent-inject-template-message-hub-db: |- + {{- with secret "secrets/data/postgresql/apps/message-hub" -}} + DB_USERNAME={{ index .Data.data "username" }} + DB_PASSWORD={{ index .Data.data "password" }} + DB_DATABASE=pm_db + DB_HOST=postgresql.pm.svc.cluster.local + DB_PORT=5432 + {{- end -}} + vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub + vault.hashicorp.com/agent-inject-template-message-hub-s3: |- + {{- with secret "secrets/data/minio/apps/message-hub" -}} + S3_HOST={{ index .Data.data.client "endpoint" }} + S3_LOGIN={{ index .Data.data "access_key" }} + S3_PASSWORD={{ index .Data.data "secret_key" }} + {{- $buckets := index .Data.data "buckets" }} + S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}rfi{{- end -}} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/message-hub + vault.hashicorp.com/agent-inject-template-message-hub-kafka: |- + {{- with secret "secrets/data/kafka/apps/message-hub" -}} + KAFKA_USERNAME={{ index .Data.data "username" }} + KAFKA_PASSWORD={{ index .Data.data "password" }} + KAFKA_HOST=kafka-kafka-contour-controller-headless.kafka.svc.cluster.local + KAFKA_PORT=9094 + KAFKA_SECURITY_PROTOCOL={{ index .Data.data.auth "security_protocol" }} + KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/message-hub/base/service.yaml b/apps/message-hub/base/service.yaml deleted file mode 100644 index 087538d..0000000 --- a/apps/message-hub/base/service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: message-hub-svc - namespace: message-hub -spec: - type: ClusterIP - selector: - app: message-hub - ports: - - name: http - port: 80 - targetPort: 80 - protocol: TCP diff --git a/apps/message-hub/base/serviceaccount.yaml b/apps/message-hub/base/serviceaccount.yaml deleted file mode 100644 index c5f9269..0000000 --- a/apps/message-hub/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: message-hub-vault - namespace: message-hub diff --git a/apps/message-hub/d8-ugmk-prod/kustomization.yaml b/apps/message-hub/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..fed75be --- /dev/null +++ b/apps/message-hub/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: message-hub diff --git a/apps/message-hub/d8-ugmk-prod/namespace.yaml b/apps/message-hub/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..8a7c4da --- /dev/null +++ b/apps/message-hub/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: message-hub + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/message-hub/dsinv/kustomization.yaml b/apps/message-hub/dsinv/kustomization.yaml index eea88a2..5c6ba46 100644 --- a/apps/message-hub/dsinv/kustomization.yaml +++ b/apps/message-hub/dsinv/kustomization.yaml @@ -7,5 +7,5 @@ resources: patches: - path: message-hub.yaml target: - kind: Deployment + kind: HelmRelease name: message-hub diff --git a/apps/message-hub/dsinv/message-hub.yaml b/apps/message-hub/dsinv/message-hub.yaml index 85723db..a7dd8e9 100644 --- a/apps/message-hub/dsinv/message-hub.yaml +++ b/apps/message-hub/dsinv/message-hub.yaml @@ -1,49 +1,90 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: message-hub namespace: message-hub spec: - template: - spec: - containers: - - name: message-hub - image: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_d11aa910 - env: - - name: WORKER_TIMEOUT - value: '60' - - name: PYTHONPATH - value: src - - name: SETTINGS_MAX_RETRIES - value: '1' - - name: SETTINGS_TOPICS - value: '{"planning": "message-hub-prod", "assets":"assets_broadcast","issues": "issues_broadcast_prod"}' - - name: PDF_CONVERTER_HOST - value: http://export-project-service.django.svc.cluster.local:8000 - - name: SAREX_BASE_HOST - value: http://backend-service.pm.svc.cluster.local:8000 - - name: PM_HOST - value: http://backend-service.pm.svc.cluster.local:8000 - - name: DB_HOST - value: postgres-service.pm.svc.cluster.local - - name: DB_PORT - value: '5432' - - name: DB_DATABASE - value: pm - - name: CACHE_HOST - value: redis.pm.svc.cluster.local - - name: CACHE_PORT - value: '6379' - - name: CACHE_SSL - value: '0' - - name: KAFKA_HOST - value: donstroi-kafka-bootstrap.kafka.svc.cluster.local - - name: KAFKA_PORT - value: '9093' - - name: KAFKA_SECURITY_PROTOCOL - value: SSL - - name: KAFKA_SASL_MECHANISM - value: PLAIN - - name: KAFKA_SSL_CAFILE - value: /usr/local/share/ca-certificates/kafka.crt + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_d11aa910 + + envs: + - name: WORKER_TIMEOUT + value: + _default: "60" + + - name: PYTHONPATH + value: + _default: "src" + + - name: SETTINGS_MAX_RETRIES + value: + _default: "1" + + - name: SETTINGS_TOPICS + value: + _default: '{"planning": "message-hub-prod", "assets":"assets_broadcast","issues": "issues_broadcast_prod"}' + + - name: SETTINGS_PDF_CONVERTER_HOST + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: SAREX_BASE_HOST + value: + _default: "http://backend-service.pm.svc.cluster.local:8000" + + - name: CACHE_HOST + value: + _default: "redis.pm.svc.cluster.local" + + - name: CACHE_PORT + value: + _default: "6379" + + - name: PDF_CONVERTER_HOST + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: PM_HOST + value: + _default: "http://backend-service.pm.svc.cluster.local:8000" + + - name: DB_HOST + value: + _default: "postgres-service.pm.svc.cluster.local" + + - name: DB_PORT + value: + _default: "5432" + + - name: DB_DATABASE + value: + _default: "pm" + + - name: CACHE_SSL + value: + _default: "0" + + - name: KAFKA_HOST + value: + _default: "donstroi-kafka-bootstrap.kafka.svc.cluster.local" + + - name: KAFKA_PORT + value: + _default: "9093" + + - name: KAFKA_SECURITY_PROTOCOL + value: + _default: "SSL" + + - name: KAFKA_SASL_MECHANISM + value: + _default: "PLAIN" + + - name: KAFKA_SSL_CAFILE + value: + _default: "/usr/local/share/ca-certificates/kafka.crt" diff --git a/apps/pm/base/backend-deployment.yaml b/apps/pm/base/backend-deployment.yaml deleted file mode 100644 index 6c2ea97..0000000 --- a/apps/pm/base/backend-deployment.yaml +++ /dev/null @@ -1,132 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: backend - namespace: pm - labels: - app: backend - service: api -spec: - replicas: 1 - selector: - matchLabels: - app: backend - template: - metadata: - labels: - app: backend - service: api - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: pm - vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm - vault.hashicorp.com/agent-inject-template-pm-db: |- - {{- with secret "secrets/data/postgresql/apps/pm" -}} - DB_USERNAME={{ index .Data.data "username" }} - DB_PASSWORD={{ index .Data.data "password" }} - DB_DATABASE=pm_db - DB_HOST=postgresql.pm.svc.cluster.local - DB_PORT=5432 - {{- end -}} - vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm - vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/pm" -}} - CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local - CELERY_RABBITMQ_PORT=5672 - CELERY_RABBITMQ_USER={{ index .Data.data "username" }} - CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }} - CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm - vault.hashicorp.com/agent-inject-template-pm-s3: |- - {{- with secret "secrets/data/minio/apps/pm" -}} - S3_HOST={{ index .Data.data.client "endpoint" }} - S3_LOGIN={{ index .Data.data "access_key" }} - S3_PASSWORD={{ index .Data.data "secret_key" }} - {{- $buckets := index .Data.data "buckets" }} - S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}} - S3_VERIFY=False - {{- end -}} - spec: - serviceAccountName: pm-vault - containers: - - name: api - image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d - imagePullPolicy: IfNotPresent - command: ["/bin/bash", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db - [ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq - [ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3 - set +a - exec /opt/sarex/entrypoint.sh - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: USERS_INTERNAL_HOST - value: http://backend-service.sarex.svc.cluster.local:8000 - - name: CELERY_REDIS_HOST - value: redis.pm.svc.cluster.local - - name: RESOURCES_INTERNAL_HOST - value: http://sarex-resources-service.resources - - name: EAV_HOST - value: http://eav-service.eav - - name: EAV_API_PREFIX - value: /api/v0 - - name: EAV_API_PREFIX_V1 - value: /api/v1 - - name: TRACING_INSECURE - value: "False" - - name: SERVER_ENABLE_SYNC_RESOURCES - value: "True" - - name: SERVER_DELETED_TASK_MAX_AGE_DAYS - value: "1" - - name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR - value: "17" - - name: LANG - value: C.UTF-8 - - name: LC_ALL - value: C.UTF-8 - - name: PYTHONUTF8 - value: "1" - - name: CACHE_SSL - value: "False" - - name: CACHE_SSL_CA_CERTS - value: "" - - name: CACHE_ENABLE - value: "False" - - name: CLICKHOUSE_ENABLE - value: "False" - - name: KAFKA_ENABLE - value: "False" - - name: AUTH_PUBLIC_TOKEN_URL - value: "https://lk.sarex.io/api/token/public/" - - name: SERVER_HOST - value: "https://lk.sarex.io" - - name: SERVER_API_HOST - value: "https://api.sarex.io" - - name: SERVER_DEBUG - value: "False" - - name: SERVER_ALLOWED_HOSTS - value: '["*"]' - - name: SERVER_USE_OTEL - value: "False" - - name: SERVER_VERIFY_SSL - value: "False" - - name: SERVER_LOG_LEVEL - value: "INFO" - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/pm/base/backend-service.yaml b/apps/pm/base/backend-service.yaml deleted file mode 100644 index 55abdc2..0000000 --- a/apps/pm/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: backend-svc - namespace: pm -spec: - type: ClusterIP - selector: - app: backend - ports: - - name: http - port: 8000 - targetPort: 8000 - protocol: TCP diff --git a/apps/pm/base/backend.yaml b/apps/pm/base/backend.yaml new file mode 100644 index 0000000..c103c6e --- /dev/null +++ b/apps/pm/base/backend.yaml @@ -0,0 +1,255 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: pm + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: pm-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/bash", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db + [ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq + [ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3 + set +a + exec /opt/sarex/entrypoint.sh + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-svc + + type: + _default: ClusterIP + + port: + _default: 8000 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: USERS_INTERNAL_HOST + value: + _default: "http://backend-service.sarex.svc.cluster.local:8000" + + - name: CELERY_REDIS_HOST + value: + _default: "redis.pm.svc.cluster.local" + + - name: RESOURCES_INTERNAL_HOST + value: + _default: "http://sarex-resources-service.resources" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav" + + - name: EAV_API_PREFIX + value: + _default: "/api/v0" + + - name: EAV_API_PREFIX_V1 + value: + _default: "/api/v1" + + - name: TRACING_INSECURE + value: + _default: "False" + + - name: SERVER_ENABLE_SYNC_RESOURCES + value: + _default: "True" + + - name: SERVER_DELETED_TASK_MAX_AGE_DAYS + value: + _default: "1" + + - name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR + value: + _default: "17" + + - name: LANG + value: + _default: "C.UTF-8" + + - name: LC_ALL + value: + _default: "C.UTF-8" + + - name: PYTHONUTF8 + value: + _default: "1" + + - name: CACHE_SSL + value: + _default: "False" + + - name: CACHE_SSL_CA_CERTS + value: + _default: "" + + - name: CACHE_ENABLE + value: + _default: "False" + + - name: CLICKHOUSE_ENABLE + value: + _default: "False" + + - name: KAFKA_ENABLE + value: + _default: "False" + + - name: AUTH_PUBLIC_TOKEN_URL + value: + _default: "https://lk.sarex.io/api/token/public/" + + - name: SERVER_HOST + value: + _default: "https://lk.sarex.io" + + - name: SERVER_API_HOST + value: + _default: "https://api.sarex.io" + + - name: SERVER_DEBUG + value: + _default: "False" + + - name: SERVER_ALLOWED_HOSTS + value: + _default: '["*"]' + + - name: SERVER_USE_OTEL + value: + _default: "False" + + - name: SERVER_VERIFY_SSL + value: + _default: "False" + + - name: SERVER_LOG_LEVEL + value: + _default: "INFO" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: pm + vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm + vault.hashicorp.com/agent-inject-template-pm-db: |- + {{- with secret "secrets/data/postgresql/apps/pm" -}} + DB_USERNAME={{ index .Data.data "username" }} + DB_PASSWORD={{ index .Data.data "password" }} + DB_DATABASE=pm_db + DB_HOST=postgresql.pm.svc.cluster.local + DB_PORT=5432 + {{- end -}} + vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm + vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/pm" -}} + CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local + CELERY_RABBITMQ_PORT=5672 + CELERY_RABBITMQ_USER={{ index .Data.data "username" }} + CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }} + CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm + vault.hashicorp.com/agent-inject-template-pm-s3: |- + {{- with secret "secrets/data/minio/apps/pm" -}} + S3_HOST={{ index .Data.data.client "endpoint" }} + S3_LOGIN={{ index .Data.data "access_key" }} + S3_PASSWORD={{ index .Data.data "secret_key" }} + {{- $buckets := index .Data.data "buckets" }} + S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}} + S3_VERIFY=False + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/pm/base/celery-deployment.yaml b/apps/pm/base/celery-deployment.yaml deleted file mode 100644 index e063065..0000000 --- a/apps/pm/base/celery-deployment.yaml +++ /dev/null @@ -1,131 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: celery - namespace: pm - labels: - app: celery - service: celery -spec: - replicas: 1 - selector: - matchLabels: - app: celery - template: - metadata: - labels: - app: celery - service: celery - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: pm - vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm - vault.hashicorp.com/agent-inject-template-pm-db: |- - {{- with secret "secrets/data/postgresql/apps/pm" -}} - DB_USERNAME={{ index .Data.data "username" }} - DB_PASSWORD={{ index .Data.data "password" }} - DB_DATABASE=pm_db - DB_HOST=postgresql.pm.svc.cluster.local - DB_PORT=5432 - {{- end -}} - vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm - vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/pm" -}} - CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local - CELERY_RABBITMQ_PORT=5672 - CELERY_RABBITMQ_USER={{ index .Data.data "username" }} - CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }} - CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm - vault.hashicorp.com/agent-inject-template-pm-s3: |- - {{- with secret "secrets/data/minio/apps/pm" -}} - S3_HOST={{ index .Data.data.client "endpoint" }} - S3_LOGIN={{ index .Data.data "access_key" }} - S3_PASSWORD={{ index .Data.data "secret_key" }} - {{- $buckets := index .Data.data "buckets" }} - S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}} - S3_VERIFY=False - {{- end -}} - spec: - serviceAccountName: pm-vault - containers: - - name: celery - image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d - imagePullPolicy: IfNotPresent - command: ["/bin/bash", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db - [ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq - [ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3 - set +a - exec celery -A config worker -B -l info -E -Q pm -n default_worker.%h --concurrency=2 - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: USERS_INTERNAL_HOST - value: http://backend-service.sarex.svc.cluster.local:8000 - - name: CELERY_REDIS_HOST - value: redis.pm.svc.cluster.local - - name: RESOURCES_INTERNAL_HOST - value: http://sarex-resources-service.resources - - name: EAV_HOST - value: http://eav-service.eav - - name: EAV_API_PREFIX - value: /api/v0 - - name: EAV_API_PREFIX_V1 - value: /api/v1 - - name: TRACING_INSECURE - value: "False" - - name: SERVER_ENABLE_SYNC_RESOURCES - value: "True" - - name: SERVER_DELETED_TASK_MAX_AGE_DAYS - value: "1" - - name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR - value: "17" - - name: LANG - value: C.UTF-8 - - name: LC_ALL - value: C.UTF-8 - - name: PYTHONUTF8 - value: "1" - - name: CACHE_SSL - value: "False" - - name: CACHE_SSL_CA_CERTS - value: "" - - name: CACHE_ENABLE - value: "False" - - name: CLICKHOUSE_ENABLE - value: "False" - - name: KAFKA_ENABLE - value: "False" - - name: AUTH_PUBLIC_TOKEN_URL - value: "https://lk.sarex.io/api/token/public/" - - name: SERVER_HOST - value: "https://lk.sarex.io" - - name: SERVER_API_HOST - value: "https://api.sarex.io" - - name: SERVER_DEBUG - value: "False" - - name: SERVER_ALLOWED_HOSTS - value: '["*"]' - - name: SERVER_USE_OTEL - value: "False" - - name: SERVER_VERIFY_SSL - value: "False" - - name: SERVER_LOG_LEVEL - value: "INFO" - resources: - requests: - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/pm/base/celery.yaml b/apps/pm/base/celery.yaml new file mode 100644 index 0000000..cb171f6 --- /dev/null +++ b/apps/pm/base/celery.yaml @@ -0,0 +1,238 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: celery + namespace: pm + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + celery: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: pm-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: celery + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/bash", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/pm-db ] && . /vault/secrets/pm-db + [ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq + [ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3 + set +a + exec celery -A config worker -B -l info -E -Q pm -n default_worker.%h --concurrency=2 + + resources: + requests: + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: USERS_INTERNAL_HOST + value: + _default: "http://backend-service.sarex.svc.cluster.local:8000" + + - name: CELERY_REDIS_HOST + value: + _default: "redis.pm.svc.cluster.local" + + - name: RESOURCES_INTERNAL_HOST + value: + _default: "http://sarex-resources-service.resources" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav" + + - name: EAV_API_PREFIX + value: + _default: "/api/v0" + + - name: EAV_API_PREFIX_V1 + value: + _default: "/api/v1" + + - name: TRACING_INSECURE + value: + _default: "False" + + - name: SERVER_ENABLE_SYNC_RESOURCES + value: + _default: "True" + + - name: SERVER_DELETED_TASK_MAX_AGE_DAYS + value: + _default: "1" + + - name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR + value: + _default: "17" + + - name: LANG + value: + _default: "C.UTF-8" + + - name: LC_ALL + value: + _default: "C.UTF-8" + + - name: PYTHONUTF8 + value: + _default: "1" + + - name: CACHE_SSL + value: + _default: "False" + + - name: CACHE_SSL_CA_CERTS + value: + _default: "" + + - name: CACHE_ENABLE + value: + _default: "False" + + - name: CLICKHOUSE_ENABLE + value: + _default: "False" + + - name: KAFKA_ENABLE + value: + _default: "False" + + - name: AUTH_PUBLIC_TOKEN_URL + value: + _default: "https://lk.sarex.io/api/token/public/" + + - name: SERVER_HOST + value: + _default: "https://lk.sarex.io" + + - name: SERVER_API_HOST + value: + _default: "https://api.sarex.io" + + - name: SERVER_DEBUG + value: + _default: "False" + + - name: SERVER_ALLOWED_HOSTS + value: + _default: '["*"]' + + - name: SERVER_USE_OTEL + value: + _default: "False" + + - name: SERVER_VERIFY_SSL + value: + _default: "False" + + - name: SERVER_LOG_LEVEL + value: + _default: "INFO" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: pm + vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm + vault.hashicorp.com/agent-inject-template-pm-db: |- + {{- with secret "secrets/data/postgresql/apps/pm" -}} + DB_USERNAME={{ index .Data.data "username" }} + DB_PASSWORD={{ index .Data.data "password" }} + DB_DATABASE=pm_db + DB_HOST=postgresql.pm.svc.cluster.local + DB_PORT=5432 + {{- end -}} + vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm + vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/pm" -}} + CELERY_RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local + CELERY_RABBITMQ_PORT=5672 + CELERY_RABBITMQ_USER={{ index .Data.data "username" }} + CELERY_RABBITMQ_PASSWORD={{ index .Data.data "password" }} + CELERY_RABBITMQ_VHOST={{ index .Data.data "vhost" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-pm-s3: secrets/data/minio/apps/pm + vault.hashicorp.com/agent-inject-template-pm-s3: |- + {{- with secret "secrets/data/minio/apps/pm" -}} + S3_HOST={{ index .Data.data.client "endpoint" }} + S3_LOGIN={{ index .Data.data "access_key" }} + S3_PASSWORD={{ index .Data.data "secret_key" }} + {{- $buckets := index .Data.data "buckets" }} + S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}pm-bucket{{- end -}} + S3_VERIFY=False + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/pm/base/kustomization.yaml b/apps/pm/base/kustomization.yaml index d742c1d..f16efbf 100644 --- a/apps/pm/base/kustomization.yaml +++ b/apps/pm/base/kustomization.yaml @@ -4,8 +4,6 @@ kind: Kustomization namespace: pm resources: - namespace.yaml - - serviceaccount.yaml - - backend-deployment.yaml - - backend-service.yaml - - celery-deployment.yaml + - backend.yaml + - celery.yaml - backend-configmap.yaml diff --git a/apps/pm/base/serviceaccount.yaml b/apps/pm/base/serviceaccount.yaml deleted file mode 100644 index e6e28dc..0000000 --- a/apps/pm/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: pm-vault - namespace: pm diff --git a/apps/pm/d8-ugmk-prod/kustomization.yaml b/apps/pm/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..8c72385 --- /dev/null +++ b/apps/pm/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: pm diff --git a/apps/pm/d8-ugmk-prod/namespace.yaml b/apps/pm/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..4c42f10 --- /dev/null +++ b/apps/pm/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: pm + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/pm/dsinv/backend.yaml b/apps/pm/dsinv/backend.yaml index fa93fa6..d96d44e 100644 --- a/apps/pm/dsinv/backend.yaml +++ b/apps/pm/dsinv/backend.yaml @@ -1,29 +1,118 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: backend namespace: pm spec: - template: - spec: - containers: - - name: api - image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_3d7e8ea6 - env: - - name: LANG - value: C.UTF-8 - - name: LC_ALL - value: C.UTF-8 - - name: PYTHONUTF8 - value: '1' - - name: USERS_INTERNAL_HOST - value: http://backend.django.svc.cluster.local:8000 - - name: RESOURCES_INTERNAL_HOST - value: http://resources-service.resources.svc.cluster.local:8000 - - name: EAV_HOST - value: http://eav-service.eav.svc.cluster.local:8000 - - name: EAV_API_PREFIX - value: /api/v0 - - name: EAV_API_PREFIX_V1 - value: /api/v1 + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_3d7e8ea6 + + envs: + - name: USERS_INTERNAL_HOST + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: CELERY_REDIS_HOST + value: + _default: "redis.pm.svc.cluster.local" + + - name: RESOURCES_INTERNAL_HOST + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav.svc.cluster.local:8000" + + - name: EAV_API_PREFIX + value: + _default: "/api/v0" + + - name: EAV_API_PREFIX_V1 + value: + _default: "/api/v1" + + - name: TRACING_INSECURE + value: + _default: "False" + + - name: SERVER_ENABLE_SYNC_RESOURCES + value: + _default: "True" + + - name: SERVER_DELETED_TASK_MAX_AGE_DAYS + value: + _default: "1" + + - name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR + value: + _default: "17" + + - name: LANG + value: + _default: "C.UTF-8" + + - name: LC_ALL + value: + _default: "C.UTF-8" + + - name: PYTHONUTF8 + value: + _default: "1" + + - name: CACHE_SSL + value: + _default: "False" + + - name: CACHE_SSL_CA_CERTS + value: + _default: "" + + - name: CACHE_ENABLE + value: + _default: "False" + + - name: CLICKHOUSE_ENABLE + value: + _default: "False" + + - name: KAFKA_ENABLE + value: + _default: "False" + + - name: AUTH_PUBLIC_TOKEN_URL + value: + _default: "https://lk.sarex.io/api/token/public/" + + - name: SERVER_HOST + value: + _default: "https://lk.sarex.io" + + - name: SERVER_API_HOST + value: + _default: "https://api.sarex.io" + + - name: SERVER_DEBUG + value: + _default: "False" + + - name: SERVER_ALLOWED_HOSTS + value: + _default: '["*"]' + + - name: SERVER_USE_OTEL + value: + _default: "False" + + - name: SERVER_VERIFY_SSL + value: + _default: "False" + + - name: SERVER_LOG_LEVEL + value: + _default: "INFO" diff --git a/apps/pm/dsinv/celery.yaml b/apps/pm/dsinv/celery.yaml index 1f50c91..c4a3b17 100644 --- a/apps/pm/dsinv/celery.yaml +++ b/apps/pm/dsinv/celery.yaml @@ -1,29 +1,118 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: celery namespace: pm spec: - template: - spec: - containers: - - name: celery - image: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_2becf38c - env: - - name: USERS_INTERNAL_HOST - value: http://backend.django.svc.cluster.local:8000 - - name: RESOURCES_INTERNAL_HOST - value: http://resources-service.resources.svc.cluster.local:8000 - - name: EAV_HOST - value: http://eav-service.eav.svc.cluster.local:8000 - - name: EAV_API_PREFIX - value: /api/v0 - - name: EAV_API_PREFIX_V1 - value: /api/v1 - - name: LANG - value: C.UTF-8 - - name: LC_ALL - value: C.UTF-8 - - name: PYTHONUTF8 - value: '1' + values: + services: + celery: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_2becf38c + + envs: + - name: USERS_INTERNAL_HOST + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: CELERY_REDIS_HOST + value: + _default: "redis.pm.svc.cluster.local" + + - name: RESOURCES_INTERNAL_HOST + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: EAV_HOST + value: + _default: "http://eav-service.eav.svc.cluster.local:8000" + + - name: EAV_API_PREFIX + value: + _default: "/api/v0" + + - name: EAV_API_PREFIX_V1 + value: + _default: "/api/v1" + + - name: TRACING_INSECURE + value: + _default: "False" + + - name: SERVER_ENABLE_SYNC_RESOURCES + value: + _default: "True" + + - name: SERVER_DELETED_TASK_MAX_AGE_DAYS + value: + _default: "1" + + - name: SERVER_EXPIRED_TASK_NOTIFICATION_HOUR + value: + _default: "17" + + - name: LANG + value: + _default: "C.UTF-8" + + - name: LC_ALL + value: + _default: "C.UTF-8" + + - name: PYTHONUTF8 + value: + _default: "1" + + - name: CACHE_SSL + value: + _default: "False" + + - name: CACHE_SSL_CA_CERTS + value: + _default: "" + + - name: CACHE_ENABLE + value: + _default: "False" + + - name: CLICKHOUSE_ENABLE + value: + _default: "False" + + - name: KAFKA_ENABLE + value: + _default: "False" + + - name: AUTH_PUBLIC_TOKEN_URL + value: + _default: "https://lk.sarex.io/api/token/public/" + + - name: SERVER_HOST + value: + _default: "https://lk.sarex.io" + + - name: SERVER_API_HOST + value: + _default: "https://api.sarex.io" + + - name: SERVER_DEBUG + value: + _default: "False" + + - name: SERVER_ALLOWED_HOSTS + value: + _default: '["*"]' + + - name: SERVER_USE_OTEL + value: + _default: "False" + + - name: SERVER_VERIFY_SSL + value: + _default: "False" + + - name: SERVER_LOG_LEVEL + value: + _default: "INFO" diff --git a/apps/pm/dsinv/kustomization.yaml b/apps/pm/dsinv/kustomization.yaml index 65dd5ff..825915b 100644 --- a/apps/pm/dsinv/kustomization.yaml +++ b/apps/pm/dsinv/kustomization.yaml @@ -8,9 +8,9 @@ resources: patches: - path: backend.yaml target: - kind: Deployment + kind: HelmRelease name: backend - path: celery.yaml target: - kind: Deployment + kind: HelmRelease name: celery diff --git a/apps/prescriptions/d8-ugmk-prod/namespace.yaml b/apps/prescriptions/d8-ugmk-prod/namespace.yaml index b591ad0..1ecd7b1 100644 --- a/apps/prescriptions/d8-ugmk-prod/namespace.yaml +++ b/apps/prescriptions/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: prescriptions labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/processing/d8-ugmk-prod/namespace.yaml b/apps/processing/d8-ugmk-prod/namespace.yaml index f2b167e..85f81c0 100644 --- a/apps/processing/d8-ugmk-prod/namespace.yaml +++ b/apps/processing/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: processing labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/projects/d8-ugmk-prod/namespace.yaml b/apps/projects/d8-ugmk-prod/namespace.yaml index 8765f8f..2d9d84c 100644 --- a/apps/projects/d8-ugmk-prod/namespace.yaml +++ b/apps/projects/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: projects labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/remarks/d8-ugmk-prod/namespace.yaml b/apps/remarks/d8-ugmk-prod/namespace.yaml index 8060131..a978585 100644 --- a/apps/remarks/d8-ugmk-prod/namespace.yaml +++ b/apps/remarks/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: remarks labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/reviews/d8-ugmk-prod/namespace.yaml b/apps/reviews/d8-ugmk-prod/namespace.yaml index 721a28c..469b77a 100644 --- a/apps/reviews/d8-ugmk-prod/namespace.yaml +++ b/apps/reviews/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: reviews labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/stamp-verification/d8-ugmk-prod/namespace.yaml b/apps/stamp-verification/d8-ugmk-prod/namespace.yaml index c6c157d..cd1142d 100644 --- a/apps/stamp-verification/d8-ugmk-prod/namespace.yaml +++ b/apps/stamp-verification/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: stamp-verification labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/system-log/d8-ugmk-prod/namespace.yaml b/apps/system-log/d8-ugmk-prod/namespace.yaml index 58875f5..4d234bb 100644 --- a/apps/system-log/d8-ugmk-prod/namespace.yaml +++ b/apps/system-log/d8-ugmk-prod/namespace.yaml @@ -4,5 +4,5 @@ kind: Namespace metadata: name: system-log labels: - istio-injection: disabled + istio-injection: enabled security.deckhouse.io/pod-policy: privileged diff --git a/apps/transmittal/base/backend-deployment.yaml b/apps/transmittal/base/backend-deployment.yaml deleted file mode 100644 index f03dec5..0000000 --- a/apps/transmittal/base/backend-deployment.yaml +++ /dev/null @@ -1,211 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: backend - namespace: transmittal - labels: - app: backend - service: backend -spec: - replicas: 1 - selector: - matchLabels: - app: backend - template: - metadata: - labels: - app: backend - service: backend - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: transmittal - vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/postgresql/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-db: |- - {{- with secret "secrets/data/postgresql/apps/transmittal" -}} - TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} - TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} - TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local - TRANSMITTAL_SERVICE_DATABASE__PORT=5432 - TRANSMITTAL_SERVICE_DATABASE__NAME=transmittal_db - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-rabbitmq: secrets/data/rabbitmq/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/transmittal" -}} - TRANSMITTAL_SERVICE_RABBITMQ__USER={{ index .Data.data "username" }} - TRANSMITTAL_SERVICE_RABBITMQ__PASSWORD={{ index .Data.data "password" }} - TRANSMITTAL_SERVICE_RABBITMQ__VHOST={{ index .Data.data "vhost" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-s3: secrets/data/minio/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-s3: |- - {{- with secret "secrets/data/minio/apps/transmittal" -}} - TRANSMITTAL_SERVICE_S3_CLIENT__ACCESS_KEY={{ index .Data.data "access_key" }} - TRANSMITTAL_SERVICE_S3_CLIENT__SECRET_KEY={{ index .Data.data "secret_key" }} - {{- $buckets := index .Data.data "buckets" }} - TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}transmittal-storage{{- end -}} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-transmittal-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASIC_AUTH_ENCODED={{ index .Data.data "key" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-public-key: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-transmittal-public-key: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - TRANSMITTAL_SERVICE_AUTH__PUBLIC_KEY={{ printf "%q" (index .Data.data "public_key") }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-mailgun: secrets/data/vault/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-mailgun: |- - {{- with secret "secrets/data/vault/apps/transmittal" -}} - TRANSMITTAL_SERVICE_MAILGUN__API_KEY={{ index .Data.data "TRANSMITTAL_SERVICE_MAILGUN__API_KEY" }} - {{- end -}} - spec: - serviceAccountName: transmittal-vault - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_a9d879ae - imagePullPolicy: IfNotPresent - command: ["/bin/bash", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/transmittal-db ] && . /vault/secrets/transmittal-db - [ -f /vault/secrets/transmittal-rabbitmq ] && . /vault/secrets/transmittal-rabbitmq - [ -f /vault/secrets/transmittal-s3 ] && . /vault/secrets/transmittal-s3 - [ -f /vault/secrets/transmittal-django-auth ] && . /vault/secrets/transmittal-django-auth - [ -f /vault/secrets/transmittal-public-key ] && . /vault/secrets/transmittal-public-key - [ -f /vault/secrets/transmittal-mailgun ] && . /vault/secrets/transmittal-mailgun - set +a - exec scripts/entrypoint.sh - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: TRANSMITTAL_SERVICE_APP__NAME - value: Transmittal Service - - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL - value: ERROR - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL - value: http://backend-svc.flows.svc.cluster.local:80 - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT - value: "30" - - name: TRANSMITTAL_SERVICE_APP__HOST - value: https://sarex.contour.infra.sarex.tech/transmittal - - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT - value: prod - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS - value: "true" - - name: TRANSMITTAL_SERVICE_UVICORN__HOST - value: 0.0.0.0 - - name: TRANSMITTAL_SERVICE_UVICORN__PORT - value: "8000" - - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD - value: "false" - - name: TRANSMITTAL_SERVICE_OTEL__ENABLE - value: "false" - - name: TRANSMITTAL_SERVICE_OTEL__HOST - value: http://signoz-otel-collector-external.signoz.svc.cluster.local:4317 - - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME - value: backend.transmittals-prod - - name: TRANSMITTAL_SERVICE_OTEL__INSECURE - value: "false" - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE - value: verify-full - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH - value: /opt/.postgresql/root.crt - - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL - value: info - - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS - value: "2" - - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH - - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL - value: "false" - - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST - value: rabbitmq.rabbitmq.svc.cluster.local - - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT - value: "5672" - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL - value: http://backend-svc.django.svc.cluster.local:80 - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL - value: http://backend-svc.resources.svc.cluster.local:80 - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL - value: http://documentations-api.documentations.svc.cluster.local:8080 - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT - value: "10" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT - value: "50" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME - value: ru-central1 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY - value: "true" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT - value: minio.minio.svc.cluster.local:9000 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL - value: "false" - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL - value: http://export-project-service.django.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT - value: "50" - - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL - value: http://marks-service.documentations.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT - value: "50" - - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL - value: https://api.mailgun.net/v3/mg.sarex.io - - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL - value: hello@wb.io - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/transmittal/base/backend-service.yaml b/apps/transmittal/base/backend-service.yaml deleted file mode 100644 index 47f7a8d..0000000 --- a/apps/transmittal/base/backend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: backend-svc - namespace: transmittal -spec: - type: ClusterIP - selector: - app: backend - ports: - - name: http - port: 80 - targetPort: 8000 - protocol: TCP diff --git a/apps/transmittal/base/backend.yaml b/apps/transmittal/base/backend.yaml new file mode 100644 index 0000000..84ab267 --- /dev/null +++ b/apps/transmittal/base/backend.yaml @@ -0,0 +1,401 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: transmittal + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + backend: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: transmittal-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_a9d879ae + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: backend + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/bash", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/transmittal-db ] && . /vault/secrets/transmittal-db + [ -f /vault/secrets/transmittal-rabbitmq ] && . /vault/secrets/transmittal-rabbitmq + [ -f /vault/secrets/transmittal-s3 ] && . /vault/secrets/transmittal-s3 + [ -f /vault/secrets/transmittal-django-auth ] && . /vault/secrets/transmittal-django-auth + [ -f /vault/secrets/transmittal-public-key ] && . /vault/secrets/transmittal-public-key + [ -f /vault/secrets/transmittal-mailgun ] && . /vault/secrets/transmittal-mailgun + set +a + exec scripts/entrypoint.sh + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: backend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 8000 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: TRANSMITTAL_SERVICE_APP__NAME + value: + _default: "Transmittal Service" + + - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL + value: + _default: "ERROR" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL + value: + _default: "http://backend-svc.flows.svc.cluster.local:80" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_APP__HOST + value: + _default: "https://sarex.contour.infra.sarex.tech/transmittal" + + - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT + value: + _default: "prod" + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS + value: + _default: "true" + + - name: TRANSMITTAL_SERVICE_UVICORN__HOST + value: + _default: "0.0.0.0" + + - name: TRANSMITTAL_SERVICE_UVICORN__PORT + value: + _default: "8000" + + - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__ENABLE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__HOST + value: + _default: "http://signoz-otel-collector-external.signoz.svc.cluster.local:4317" + + - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME + value: + _default: "backend.transmittals-prod" + + - name: TRANSMITTAL_SERVICE_OTEL__INSECURE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE + value: + _default: "verify-full" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH + value: + _default: "/opt/.postgresql/root.crt" + + - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL + value: + _default: "info" + + - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS + value: + _default: "2" + + - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH + value: + _default: "" + + - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST + value: + _default: "rabbitmq.rabbitmq.svc.cluster.local" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT + value: + _default: "5672" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL + value: + _default: "http://backend-svc.django.svc.cluster.local:80" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL + value: + _default: "http://backend-svc.resources.svc.cluster.local:80" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL + value: + _default: "http://documentations-api.documentations.svc.cluster.local:8080" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT + value: + _default: "50" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME + value: + _default: "ru-central1" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY + value: + _default: "true" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT + value: + _default: "minio.minio.svc.cluster.local:9000" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT + value: + _default: "50" + + - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL + value: + _default: "http://marks-service.documentations.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT + value: + _default: "50" + + - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL + value: + _default: "https://api.mailgun.net/v3/mg.sarex.io" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL + value: + _default: "hello@wb.io" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: transmittal + vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/postgresql/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-db: |- + {{- with secret "secrets/data/postgresql/apps/transmittal" -}} + TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} + TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} + TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local + TRANSMITTAL_SERVICE_DATABASE__PORT=5432 + TRANSMITTAL_SERVICE_DATABASE__NAME=transmittal_db + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-rabbitmq: secrets/data/rabbitmq/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/transmittal" -}} + TRANSMITTAL_SERVICE_RABBITMQ__USER={{ index .Data.data "username" }} + TRANSMITTAL_SERVICE_RABBITMQ__PASSWORD={{ index .Data.data "password" }} + TRANSMITTAL_SERVICE_RABBITMQ__VHOST={{ index .Data.data "vhost" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-s3: secrets/data/minio/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-s3: |- + {{- with secret "secrets/data/minio/apps/transmittal" -}} + TRANSMITTAL_SERVICE_S3_CLIENT__ACCESS_KEY={{ index .Data.data "access_key" }} + TRANSMITTAL_SERVICE_S3_CLIENT__SECRET_KEY={{ index .Data.data "secret_key" }} + {{- $buckets := index .Data.data "buckets" }} + TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}transmittal-storage{{- end -}} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-transmittal-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASIC_AUTH_ENCODED={{ index .Data.data "key" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-public-key: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-transmittal-public-key: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + TRANSMITTAL_SERVICE_AUTH__PUBLIC_KEY={{ printf "%q" (index .Data.data "public_key") }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-mailgun: secrets/data/vault/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-mailgun: |- + {{- with secret "secrets/data/vault/apps/transmittal" -}} + TRANSMITTAL_SERVICE_MAILGUN__API_KEY={{ index .Data.data "TRANSMITTAL_SERVICE_MAILGUN__API_KEY" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/transmittal/base/frontend-deployment.yaml b/apps/transmittal/base/frontend-deployment.yaml deleted file mode 100644 index cd346e5..0000000 --- a/apps/transmittal/base/frontend-deployment.yaml +++ /dev/null @@ -1,32 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: frontend - namespace: transmittal - labels: - app: frontend -spec: - replicas: 1 - selector: - matchLabels: - app: frontend - template: - metadata: - labels: - app: frontend - spec: - containers: - - name: frontend - image: cr.yandex/crp3ccidau046kdj8g9q/transmittal-frontend:wb1_dbf61443 - imagePullPolicy: IfNotPresent - ports: - - name: http - containerPort: 80 - protocol: TCP - resources: - requests: - cpu: 25m - memory: 100Mi - imagePullSecrets: - - name: regcred diff --git a/apps/transmittal/base/frontend-service.yaml b/apps/transmittal/base/frontend-service.yaml deleted file mode 100644 index 9bdeadb..0000000 --- a/apps/transmittal/base/frontend-service.yaml +++ /dev/null @@ -1,15 +0,0 @@ ---- -apiVersion: v1 -kind: Service -metadata: - name: frontend-svc - namespace: transmittal -spec: - type: ClusterIP - selector: - app: frontend - ports: - - name: http - port: 80 - targetPort: 80 - protocol: TCP diff --git a/apps/transmittal/base/frontend.yaml b/apps/transmittal/base/frontend.yaml new file mode 100644 index 0000000..b886bf1 --- /dev/null +++ b/apps/transmittal/base/frontend.yaml @@ -0,0 +1,90 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: transmittal + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-frontend:wb1_dbf61443 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 100Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred diff --git a/apps/transmittal/base/kustomization.yaml b/apps/transmittal/base/kustomization.yaml index 0356b25..b2993ef 100644 --- a/apps/transmittal/base/kustomization.yaml +++ b/apps/transmittal/base/kustomization.yaml @@ -4,9 +4,6 @@ kind: Kustomization namespace: transmittal resources: - namespace.yaml - - serviceaccount.yaml - - backend-deployment.yaml - - worker-deployment.yaml - - frontend-deployment.yaml - - backend-service.yaml - - frontend-service.yaml + - backend.yaml + - worker.yaml + - frontend.yaml diff --git a/apps/transmittal/base/serviceaccount.yaml b/apps/transmittal/base/serviceaccount.yaml deleted file mode 100644 index cb9d042..0000000 --- a/apps/transmittal/base/serviceaccount.yaml +++ /dev/null @@ -1,5 +0,0 @@ -apiVersion: v1 -kind: ServiceAccount -metadata: - name: transmittal-vault - namespace: transmittal diff --git a/apps/transmittal/base/worker-deployment.yaml b/apps/transmittal/base/worker-deployment.yaml deleted file mode 100644 index ea01603..0000000 --- a/apps/transmittal/base/worker-deployment.yaml +++ /dev/null @@ -1,211 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: worker - namespace: transmittal - labels: - app: worker - service: worker -spec: - replicas: 1 - selector: - matchLabels: - app: worker - template: - metadata: - labels: - app: worker - service: worker - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: transmittal - vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/postgresql/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-db: |- - {{- with secret "secrets/data/postgresql/apps/transmittal" -}} - TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} - TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} - TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local - TRANSMITTAL_SERVICE_DATABASE__PORT=5432 - TRANSMITTAL_SERVICE_DATABASE__NAME=transmittal_db - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-rabbitmq: secrets/data/rabbitmq/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-rabbitmq: |- - {{- with secret "secrets/data/rabbitmq/apps/transmittal" -}} - TRANSMITTAL_SERVICE_RABBITMQ__USER={{ index .Data.data "username" }} - TRANSMITTAL_SERVICE_RABBITMQ__PASSWORD={{ index .Data.data "password" }} - TRANSMITTAL_SERVICE_RABBITMQ__VHOST={{ index .Data.data "vhost" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-s3: secrets/data/minio/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-s3: |- - {{- with secret "secrets/data/minio/apps/transmittal" -}} - TRANSMITTAL_SERVICE_S3_CLIENT__ACCESS_KEY={{ index .Data.data "access_key" }} - TRANSMITTAL_SERVICE_S3_CLIENT__SECRET_KEY={{ index .Data.data "secret_key" }} - {{- $buckets := index .Data.data "buckets" }} - TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}transmittal-storage{{- end -}} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-transmittal-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASIC_AUTH_ENCODED={{ index .Data.data "key" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-public-key: secrets/data/vault/common/rsa_keys - vault.hashicorp.com/agent-inject-template-transmittal-public-key: |- - {{- with secret "secrets/data/vault/common/rsa_keys" -}} - TRANSMITTAL_SERVICE_AUTH__PUBLIC_KEY={{ printf "%q" (index .Data.data "public_key") }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-transmittal-mailgun: secrets/data/vault/apps/transmittal - vault.hashicorp.com/agent-inject-template-transmittal-mailgun: |- - {{- with secret "secrets/data/vault/apps/transmittal" -}} - TRANSMITTAL_SERVICE_MAILGUN__API_KEY={{ index .Data.data "TRANSMITTAL_SERVICE_MAILGUN__API_KEY" }} - {{- end -}} - spec: - serviceAccountName: transmittal-vault - containers: - - name: worker - image: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_a9d879ae - imagePullPolicy: IfNotPresent - command: ["/bin/bash", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/transmittal-db ] && . /vault/secrets/transmittal-db - [ -f /vault/secrets/transmittal-rabbitmq ] && . /vault/secrets/transmittal-rabbitmq - [ -f /vault/secrets/transmittal-s3 ] && . /vault/secrets/transmittal-s3 - [ -f /vault/secrets/transmittal-django-auth ] && . /vault/secrets/transmittal-django-auth - [ -f /vault/secrets/transmittal-public-key ] && . /vault/secrets/transmittal-public-key - [ -f /vault/secrets/transmittal-mailgun ] && . /vault/secrets/transmittal-mailgun - set +a - exec taskiq worker --no-parse transmittal_service.tasks.broker:broker transmittal_service.tasks.transmittal.tasks transmittal_service.tasks.email.tasks - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL - value: http://backend-svc.flows.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT - value: "30" - - name: TRANSMITTAL_SERVICE_APP__NAME - value: Transmittal Service - - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL - value: ERROR - - name: TRANSMITTAL_SERVICE_APP__HOST - value: https://lk.srx.wb.ru:30443/transmittal - - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT - value: prod - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS - value: "true" - - name: TRANSMITTAL_SERVICE_UVICORN__HOST - value: 0.0.0.0 - - name: TRANSMITTAL_SERVICE_UVICORN__PORT - value: "8000" - - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD - value: "false" - - name: TRANSMITTAL_SERVICE_OTEL__ENABLE - value: "false" - - name: TRANSMITTAL_SERVICE_OTEL__HOST - value: http://signoz-otel-collector-external.signoz.svc.cluster.local:4317 - - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME - value: backend.transmittals-prod - - name: TRANSMITTAL_SERVICE_OTEL__INSECURE - value: "false" - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE - value: verify-full - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH - value: /opt/.postgresql/root.crt - - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL - value: info - - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS - value: "2" - - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH - - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL - value: "false" - - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST - value: rabbitmq.rabbitmq.svc.cluster.local - - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT - value: "5672" - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL - value: http://backend.django.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL - value: http://resources-service.resources.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL - value: http://documentations-api.documentations.svc.cluster.local:8080 - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT - value: "10" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT - value: "50" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME - value: ru-central1 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY - value: "true" - - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT - value: minio.minio.svc.cluster.local:9000 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL - value: "false" - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL - value: http://export-project-service.django.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT - value: "50" - - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL - value: http://marks-service.documentations.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT - value: "50" - - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL - value: https://api.mailgun.net/v3/mg.sarex.io - - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS - value: "10" - - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS - value: "5" - - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT - value: "15" - - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL - value: hello@wb.io - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/transmittal/base/worker.yaml b/apps/transmittal/base/worker.yaml new file mode 100644 index 0000000..53efb7a --- /dev/null +++ b/apps/transmittal/base/worker.yaml @@ -0,0 +1,386 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: worker + namespace: transmittal + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + worker: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: transmittal-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_a9d879ae + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: worker + + replicaCount: + _default: 1 + + port: + _default: 8000 + + command: + _default: ["/bin/bash", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/transmittal-db ] && . /vault/secrets/transmittal-db + [ -f /vault/secrets/transmittal-rabbitmq ] && . /vault/secrets/transmittal-rabbitmq + [ -f /vault/secrets/transmittal-s3 ] && . /vault/secrets/transmittal-s3 + [ -f /vault/secrets/transmittal-django-auth ] && . /vault/secrets/transmittal-django-auth + [ -f /vault/secrets/transmittal-public-key ] && . /vault/secrets/transmittal-public-key + [ -f /vault/secrets/transmittal-mailgun ] && . /vault/secrets/transmittal-mailgun + set +a + exec taskiq worker --no-parse transmittal_service.tasks.broker:broker transmittal_service.tasks.transmittal.tasks transmittal_service.tasks.email.tasks + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + envs: + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL + value: + _default: "http://backend-svc.flows.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_APP__NAME + value: + _default: "Transmittal Service" + + - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL + value: + _default: "ERROR" + + - name: TRANSMITTAL_SERVICE_APP__HOST + value: + _default: "https://lk.srx.wb.ru:30443/transmittal" + + - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT + value: + _default: "prod" + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS + value: + _default: "true" + + - name: TRANSMITTAL_SERVICE_UVICORN__HOST + value: + _default: "0.0.0.0" + + - name: TRANSMITTAL_SERVICE_UVICORN__PORT + value: + _default: "8000" + + - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__ENABLE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__HOST + value: + _default: "http://signoz-otel-collector-external.signoz.svc.cluster.local:4317" + + - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME + value: + _default: "backend.transmittals-prod" + + - name: TRANSMITTAL_SERVICE_OTEL__INSECURE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE + value: + _default: "verify-full" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH + value: + _default: "/opt/.postgresql/root.crt" + + - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL + value: + _default: "info" + + - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS + value: + _default: "2" + + - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH + value: + _default: "" + + - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST + value: + _default: "rabbitmq.rabbitmq.svc.cluster.local" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT + value: + _default: "5672" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL + value: + _default: "http://backend.django.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL + value: + _default: "http://resources-service.resources.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL + value: + _default: "http://documentations-api.documentations.svc.cluster.local:8080" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT + value: + _default: "50" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME + value: + _default: "ru-central1" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY + value: + _default: "true" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT + value: + _default: "minio.minio.svc.cluster.local:9000" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT + value: + _default: "50" + + - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL + value: + _default: "http://marks-service.documentations.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT + value: + _default: "50" + + - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL + value: + _default: "https://api.mailgun.net/v3/mg.sarex.io" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL + value: + _default: "hello@wb.io" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: transmittal + vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/postgresql/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-db: |- + {{- with secret "secrets/data/postgresql/apps/transmittal" -}} + TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} + TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} + TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local + TRANSMITTAL_SERVICE_DATABASE__PORT=5432 + TRANSMITTAL_SERVICE_DATABASE__NAME=transmittal_db + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-rabbitmq: secrets/data/rabbitmq/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/transmittal" -}} + TRANSMITTAL_SERVICE_RABBITMQ__USER={{ index .Data.data "username" }} + TRANSMITTAL_SERVICE_RABBITMQ__PASSWORD={{ index .Data.data "password" }} + TRANSMITTAL_SERVICE_RABBITMQ__VHOST={{ index .Data.data "vhost" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-s3: secrets/data/minio/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-s3: |- + {{- with secret "secrets/data/minio/apps/transmittal" -}} + TRANSMITTAL_SERVICE_S3_CLIENT__ACCESS_KEY={{ index .Data.data "access_key" }} + TRANSMITTAL_SERVICE_S3_CLIENT__SECRET_KEY={{ index .Data.data "secret_key" }} + {{- $buckets := index .Data.data "buckets" }} + TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}transmittal-storage{{- end -}} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-django-auth: secrets/data/vault/common/django_auth + vault.hashicorp.com/agent-inject-template-transmittal-django-auth: |- + {{- with secret "secrets/data/vault/common/django_auth" -}} + TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASIC_AUTH_ENCODED={{ index .Data.data "key" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-public-key: secrets/data/vault/common/rsa_keys + vault.hashicorp.com/agent-inject-template-transmittal-public-key: |- + {{- with secret "secrets/data/vault/common/rsa_keys" -}} + TRANSMITTAL_SERVICE_AUTH__PUBLIC_KEY={{ printf "%q" (index .Data.data "public_key") }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-transmittal-mailgun: secrets/data/vault/apps/transmittal + vault.hashicorp.com/agent-inject-template-transmittal-mailgun: |- + {{- with secret "secrets/data/vault/apps/transmittal" -}} + TRANSMITTAL_SERVICE_MAILGUN__API_KEY={{ index .Data.data "TRANSMITTAL_SERVICE_MAILGUN__API_KEY" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/transmittal/d8-ugmk-prod/kustomization.yaml b/apps/transmittal/d8-ugmk-prod/kustomization.yaml new file mode 100644 index 0000000..eed0fa0 --- /dev/null +++ b/apps/transmittal/d8-ugmk-prod/kustomization.yaml @@ -0,0 +1,10 @@ +--- +apiVersion: kustomize.config.k8s.io/v1beta1 +kind: Kustomization +resources: + - ../base +patches: + - path: namespace.yaml + target: + kind: Namespace + name: transmittal diff --git a/apps/transmittal/d8-ugmk-prod/namespace.yaml b/apps/transmittal/d8-ugmk-prod/namespace.yaml new file mode 100644 index 0000000..0d819a0 --- /dev/null +++ b/apps/transmittal/d8-ugmk-prod/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: transmittal + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/transmittal/dsinv/backend.yaml b/apps/transmittal/dsinv/backend.yaml index 586d271..5e272f0 100644 --- a/apps/transmittal/dsinv/backend.yaml +++ b/apps/transmittal/dsinv/backend.yaml @@ -1,129 +1,286 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: backend namespace: transmittal spec: - template: - spec: - containers: - - name: backend - image: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_4de0b503 - env: - - name: TRANSMITTAL_SERVICE_SMTP__ENABLE_TLS - value: 'false' - - name: TRANSMITTAL_SERVICE_SMTP__HOST - value: relay.dsinv.ru - - name: TRANSMITTAL_SERVICE_SMTP__PORT - value: '25' - - name: TRANSMITTAL_SERVICE_SMTP__EMAIL - value: sarex@dsinv.ru - - name: TRANSMITTAL_SERVICE_APP__NAME - value: Transmittal Service - - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL - value: ERROR - - name: TRANSMITTAL_SERVICE_APP__HOST - value: https://sarex.dsinv.ru/transmittal - - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT - value: prod - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS - value: '["https://lk.sarex.io", "lk.sarex.io"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS - value: 'true' - - name: TRANSMITTAL_SERVICE_UVICORN__HOST - value: 0.0.0.0 - - name: TRANSMITTAL_SERVICE_UVICORN__PORT - value: '8000' - - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD - value: 'false' - - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL - value: info - - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS - value: '2' - - name: TRANSMITTAL_SERVICE_DATABASE__HOST - value: postgres-service - - name: TRANSMITTAL_SERVICE_DATABASE__PORT - value: '5432' - - name: TRANSMITTAL_SERVICE_DATABASE__NAME - value: transmittals - - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL - value: 'false' - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE - value: verify-full - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH - value: /opt/.postgresql/root.crt - - name: TRANSMITTAL_SERVICE_RABBITMQ__VHOST - value: api - - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST - value: rabbitmq-service - - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT - value: '5672' - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL - value: https://sarex.dsinv.ru - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL - value: http://sarex-resources-service.resources-prod - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL - value: http://documentations-service.documentations-prod - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT - value: '10' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME - value: ru-central1 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY - value: 'false' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET - value: transmittal-storage - - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT - value: minio-service.minio.svc.cluster.local:9000 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL - value: 'false' - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL - value: http://export-project-service.django.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL - value: http://marks-service.workflow.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_OTEL__ENABLE - value: 'false' - - name: TRANSMITTAL_SERVICE_OTEL__HOST - value: http://signoz-otel-collector-external.signoz.svc.cluster.local:4317 - - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME - value: backend.transmittals-prod - - name: TRANSMITTAL_SERVICE_OTEL__INSECURE - value: 'false' + values: + services: + backend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_4de0b503 + + envs: + - name: TRANSMITTAL_SERVICE_APP__NAME + value: + _default: "Transmittal Service" + + - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL + value: + _default: "ERROR" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL + value: + _default: "http://backend-svc.flows.svc.cluster.local:80" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_APP__HOST + value: + _default: "https://sarex.dsinv.ru/transmittal" + + - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT + value: + _default: "prod" + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS + value: + _default: '["https://lk.sarex.io", "lk.sarex.io"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS + value: + _default: "true" + + - name: TRANSMITTAL_SERVICE_UVICORN__HOST + value: + _default: "0.0.0.0" + + - name: TRANSMITTAL_SERVICE_UVICORN__PORT + value: + _default: "8000" + + - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__ENABLE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__HOST + value: + _default: "http://signoz-otel-collector-external.signoz.svc.cluster.local:4317" + + - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME + value: + _default: "backend.transmittals-prod" + + - name: TRANSMITTAL_SERVICE_OTEL__INSECURE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE + value: + _default: "verify-full" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH + value: + _default: "/opt/.postgresql/root.crt" + + - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL + value: + _default: "info" + + - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS + value: + _default: "2" + + - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH + value: + _default: "" + + - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST + value: + _default: "rabbitmq-service" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT + value: + _default: "5672" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL + value: + _default: "https://sarex.dsinv.ru" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL + value: + _default: "http://sarex-resources-service.resources-prod" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL + value: + _default: "http://documentations-service.documentations-prod" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME + value: + _default: "ru-central1" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT + value: + _default: "minio-service.minio.svc.cluster.local:9000" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL + value: + _default: "http://marks-service.workflow.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL + value: + _default: "https://api.mailgun.net/v3/mg.sarex.io" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL + value: + _default: "hello@wb.io" + + - name: TRANSMITTAL_SERVICE_SMTP__ENABLE_TLS + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_SMTP__HOST + value: + _default: "relay.dsinv.ru" + + - name: TRANSMITTAL_SERVICE_SMTP__PORT + value: + _default: "25" + + - name: TRANSMITTAL_SERVICE_SMTP__EMAIL + value: + _default: "sarex@dsinv.ru" + + - name: TRANSMITTAL_SERVICE_DATABASE__HOST + value: + _default: "postgres-service" + + - name: TRANSMITTAL_SERVICE_DATABASE__PORT + value: + _default: "5432" + + - name: TRANSMITTAL_SERVICE_DATABASE__NAME + value: + _default: "transmittals" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__VHOST + value: + _default: "api" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET + value: + _default: "transmittal-storage" diff --git a/apps/transmittal/dsinv/frontend.yaml b/apps/transmittal/dsinv/frontend.yaml index 2095754..bb3a1fe 100644 --- a/apps/transmittal/dsinv/frontend.yaml +++ b/apps/transmittal/dsinv/frontend.yaml @@ -1,12 +1,13 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: frontend namespace: transmittal spec: - template: - spec: - containers: - - name: frontend - image: cr.yandex/crp3ccidau046kdj8g9q/transmittal-frontend:4c915d45 + values: + services: + frontend: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-frontend:4c915d45 diff --git a/apps/transmittal/dsinv/kustomization.yaml b/apps/transmittal/dsinv/kustomization.yaml index 2553b7b..a6599fa 100644 --- a/apps/transmittal/dsinv/kustomization.yaml +++ b/apps/transmittal/dsinv/kustomization.yaml @@ -7,13 +7,13 @@ resources: patches: - path: backend.yaml target: - kind: Deployment + kind: HelmRelease name: backend - path: frontend.yaml target: - kind: Deployment + kind: HelmRelease name: frontend - path: worker.yaml target: - kind: Deployment + kind: HelmRelease name: worker diff --git a/apps/transmittal/dsinv/worker.yaml b/apps/transmittal/dsinv/worker.yaml index 90a0130..467d2e2 100644 --- a/apps/transmittal/dsinv/worker.yaml +++ b/apps/transmittal/dsinv/worker.yaml @@ -1,129 +1,286 @@ --- -apiVersion: apps/v1 -kind: Deployment +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease metadata: name: worker namespace: transmittal spec: - template: - spec: - containers: - - name: worker - image: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_4de0b503 - env: - - name: TRANSMITTAL_SERVICE_SMTP__ENABLE_TLS - value: 'false' - - name: TRANSMITTAL_SERVICE_SMTP__HOST - value: relay.dsinv.ru - - name: TRANSMITTAL_SERVICE_SMTP__PORT - value: '25' - - name: TRANSMITTAL_SERVICE_SMTP__EMAIL - value: sarex@dsinv.ru - - name: TRANSMITTAL_SERVICE_APP__NAME - value: Transmittal Service - - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL - value: ERROR - - name: TRANSMITTAL_SERVICE_APP__HOST - value: https://sarex.dsinv.ru/transmittal - - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT - value: prod - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS - value: '["https://lk.sarex.io", "lk.sarex.io"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS - value: '["*"]' - - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS - value: 'true' - - name: TRANSMITTAL_SERVICE_UVICORN__HOST - value: 0.0.0.0 - - name: TRANSMITTAL_SERVICE_UVICORN__PORT - value: '8000' - - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD - value: 'false' - - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL - value: info - - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS - value: '2' - - name: TRANSMITTAL_SERVICE_DATABASE__HOST - value: postgres-service - - name: TRANSMITTAL_SERVICE_DATABASE__PORT - value: '5432' - - name: TRANSMITTAL_SERVICE_DATABASE__NAME - value: transmittals - - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL - value: 'false' - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE - value: verify-full - - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH - value: /opt/.postgresql/root.crt - - name: TRANSMITTAL_SERVICE_RABBITMQ__VHOST - value: api - - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST - value: rabbitmq-service - - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT - value: '5672' - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL - value: https://sarex.dsinv.ru - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL - value: http://sarex-resources-service.resources-prod - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL - value: http://documentations-service.documentations-prod - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT - value: '10' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME - value: ru-central1 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY - value: 'false' - - name: TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET - value: transmittal-storage - - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT - value: minio-service.minio.svc.cluster.local:9000 - - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL - value: 'false' - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL - value: http://export-project-service.django.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL - value: http://marks-service.workflow.svc.cluster.local:8000 - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS - value: '10' - - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS - value: '5' - - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT - value: '30' - - name: TRANSMITTAL_SERVICE_OTEL__ENABLE - value: 'false' - - name: TRANSMITTAL_SERVICE_OTEL__HOST - value: http://signoz-otel-collector-external.signoz.svc.cluster.local:4317 - - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME - value: backend.transmittals-prod - - name: TRANSMITTAL_SERVICE_OTEL__INSECURE - value: 'false' + values: + services: + worker: + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_4de0b503 + + envs: + - name: TRANSMITTAL_SERVICE_APP__NAME + value: + _default: "Transmittal Service" + + - name: TRANSMITTAL_SERVICE_APP__LOG_LEVEL + value: + _default: "ERROR" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL + value: + _default: "http://backend-svc.flows.svc.cluster.local:80" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_APP__HOST + value: + _default: "https://sarex.dsinv.ru/transmittal" + + - name: TRANSMITTAL_SERVICE_APP__ENVIRONMENT + value: + _default: "prod" + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_ORIGINS + value: + _default: '["https://lk.sarex.io", "lk.sarex.io"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_METHODS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_HEADERS + value: + _default: '["*"]' + + - name: TRANSMITTAL_SERVICE_CORS__ALLOW_CREDENTIALS + value: + _default: "true" + + - name: TRANSMITTAL_SERVICE_UVICORN__HOST + value: + _default: "0.0.0.0" + + - name: TRANSMITTAL_SERVICE_UVICORN__PORT + value: + _default: "8000" + + - name: TRANSMITTAL_SERVICE_UVICORN__ENABLE_AUTO_RELOAD + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__ENABLE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_OTEL__HOST + value: + _default: "http://signoz-otel-collector-external.signoz.svc.cluster.local:4317" + + - name: TRANSMITTAL_SERVICE_OTEL__SERVICE_NAME + value: + _default: "backend.transmittals-prod" + + - name: TRANSMITTAL_SERVICE_OTEL__INSECURE + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_MODE + value: + _default: "verify-full" + + - name: TRANSMITTAL_SERVICE_DATABASE__SSL_ROOT_CERT_PATH + value: + _default: "/opt/.postgresql/root.crt" + + - name: TRANSMITTAL_SERVICE_UVICORN__LOG_LEVEL + value: + _default: "info" + + - name: TRANSMITTAL_SERVICE_UVICORN__NUM_WORKERS + value: + _default: "2" + + - name: TRANSMITTAL_SERVICE_UVICORN__ROOT_PATH + value: + _default: "" + + - name: TRANSMITTAL_SERVICE_DATABASE__ENABLE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__HOST + value: + _default: "rabbitmq-service" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__PORT + value: + _default: "5672" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__BASE_URL + value: + _default: "https://sarex.dsinv.ru" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_SAREX_BACKEND_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL + value: + _default: "http://sarex-resources-service.resources-prod" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__BASE_URL + value: + _default: "http://documentations-service.documentations-prod" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_DOCUMENTATIONS_REPOSITORY__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__MAX_POOL_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__CONNECT_TIMEOUT + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__READ_TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__REGION_NAME + value: + _default: "ru-central1" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__VERIFY + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__ENDPOINT + value: + _default: "minio-service.minio.svc.cluster.local:9000" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__USE_SSL + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__BASE_URL + value: + _default: "http://export-project-service.django.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_HTML_TO_PDF_CONVERTER__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_MARKINGS__BASE_URL + value: + _default: "http://marks-service.workflow.svc.cluster.local:8000" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MARKINGS__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MARKINGS__TIMEOUT + value: + _default: "30" + + - name: TRANSMITTAL_SERVICE_MAILGUN__BASE_URL + value: + _default: "https://api.mailgun.net/v3/mg.sarex.io" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_CONNECTIONS + value: + _default: "10" + + - name: TRANSMITTAL_SERVICE_MAILGUN__MAX_KEEPALIVE_CONNECTIONS + value: + _default: "5" + + - name: TRANSMITTAL_SERVICE_MAILGUN__TIMEOUT + value: + _default: "15" + + - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL + value: + _default: "hello@wb.io" + + - name: TRANSMITTAL_SERVICE_SMTP__ENABLE_TLS + value: + _default: "false" + + - name: TRANSMITTAL_SERVICE_SMTP__HOST + value: + _default: "relay.dsinv.ru" + + - name: TRANSMITTAL_SERVICE_SMTP__PORT + value: + _default: "25" + + - name: TRANSMITTAL_SERVICE_SMTP__EMAIL + value: + _default: "sarex@dsinv.ru" + + - name: TRANSMITTAL_SERVICE_DATABASE__HOST + value: + _default: "postgres-service" + + - name: TRANSMITTAL_SERVICE_DATABASE__PORT + value: + _default: "5432" + + - name: TRANSMITTAL_SERVICE_DATABASE__NAME + value: + _default: "transmittals" + + - name: TRANSMITTAL_SERVICE_RABBITMQ__VHOST + value: + _default: "api" + + - name: TRANSMITTAL_SERVICE_S3_CLIENT__DEFAULT_BUCKET + value: + _default: "transmittal-storage" diff --git a/clusters/d8-ugmk-prod/kustomization.yaml b/clusters/d8-ugmk-prod/kustomization.yaml index bede3ef..7294059 100644 --- a/clusters/d8-ugmk-prod/kustomization.yaml +++ b/clusters/d8-ugmk-prod/kustomization.yaml @@ -42,4 +42,12 @@ resources: - ../../apps/prescriptions/d8-ugmk-prod - ../../apps/mapper/d8-ugmk-prod - ../../apps/stamp-verification/d8-ugmk-prod - - ../../apps/document-link/d8-ugmk-prod \ No newline at end of file + - ../../apps/document-link/d8-ugmk-prod + - ../../apps/bim/d8-ugmk-prod + - ../../apps/cde/d8-ugmk-prod + - ../../apps/flows/d8-ugmk-prod + - ../../apps/inspections/d8-ugmk-prod + - ../../apps/issues/d8-ugmk-prod + - ../../apps/pm/d8-ugmk-prod + - ../../apps/message-hub/d8-ugmk-prod + - ../../apps/transmittal/d8-ugmk-prod \ No newline at end of file From edd357ba72642149549fce4017ef7a2e5e913b0a Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 13:55:22 +0500 Subject: [PATCH 02/51] ++ --- apps/django/base/frontend.yaml | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/apps/django/base/frontend.yaml b/apps/django/base/frontend.yaml index 1059d1e..d560621 100644 --- a/apps/django/base/frontend.yaml +++ b/apps/django/base/frontend.yaml @@ -85,17 +85,17 @@ spec: path: _default: nginx.conf - - name: zitadel-configmap - mountPath: - _default: /opt/react_client/static/config.json - subPath: - _default: config.json - readOnly: - _default: true - configMap: - name: - _default: zitadel-configmap - items: - - key: config.json - path: - _default: config.json + # - name: zitadel-configmap + # mountPath: + # _default: /opt/react_client/static/config.json + # subPath: + # _default: config.json + # readOnly: + # _default: true + # configMap: + # name: + # _default: zitadel-configmap + # items: + # - key: config.json + # path: + # _default: config.json From d57fcf82297bc1cf37addd1f60b97e0bf814f732 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 13:59:05 +0500 Subject: [PATCH 03/51] ++ --- .../istio-config/d8-ugmk-prod/istio-config.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 0d01b9d..4eae4c9 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -158,6 +158,19 @@ spec: rewrite: / service: pdm-svc.documentations.svc.cluster.local port: 80 + eav-api: + name: eav-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /eav/api/ + rewrite: /api/ + service: backend-svc.eav.svc.cluster.local + port: 80 srx-admin-frontend: name: srx-admin-frontend-virt-service namespace: default From 3fb27a9e53dc261509f7bcca8a7883535cb5de46 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 14:13:51 +0500 Subject: [PATCH 04/51] ++ --- apps/eav/base/django-configmap.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/eav/base/django-configmap.yaml b/apps/eav/base/django-configmap.yaml index 6f03ee7..09ebaf5 100644 --- a/apps/eav/base/django-configmap.yaml +++ b/apps/eav/base/django-configmap.yaml @@ -126,7 +126,7 @@ data: return default raise ImproperlyConfigured(error_msg) - SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="django") + SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="default_issuer") SIMPLE_JWT = { From 0d0b2cc5f8f36dc1dd01e6b49c46fdf9fae52798 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 14:45:28 +0500 Subject: [PATCH 05/51] ++ --- apps/flows/base/backend.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/apps/flows/base/backend.yaml b/apps/flows/base/backend.yaml index 225527a..f0101d9 100644 --- a/apps/flows/base/backend.yaml +++ b/apps/flows/base/backend.yaml @@ -220,10 +220,10 @@ spec: vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows vault.hashicorp.com/agent-inject-template-flows-postgresql: |- {{- with secret "secrets/data/postgresql/apps/flows" -}} - PG_DB=flows_db + PG_DB={{ index .Data.data "database" }} PG_LOGIN={{ index .Data.data "username" }} - PG_HOST=postgresql.flows.svc.cluster.local - PG_PORT=5432 + PG_HOST={{ index .Data.data "host" }} + PG_PORT={{ index .Data.data "port" }} PG_PASSWORD={{ index .Data.data "password" }} DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local DOCUMENTATION_PG_PORT=5432 From d6a830db051a6b2a7ae2433babda5be4b47ada0d Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 14:54:33 +0500 Subject: [PATCH 06/51] ++ --- apps/attachments/base/helmrelease.yaml | 4 +- apps/bim/base/backend.yaml | 4 +- apps/comparisons/base/backend.yaml | 4 +- apps/contracts/base/helmrelease.yaml | 4 +- apps/drawings/base/backend.yaml | 4 +- apps/flows/base/backend.yaml | 4 +- apps/flows/base/celery.yaml | 4 +- apps/inspections/base/backend-deployment.yaml | 120 ------------------ apps/inspections/base/backend.yaml | 4 +- apps/issues/base/backend.yaml | 4 +- apps/issues/base/celery.yaml | 4 +- apps/mapper/base/backend.yaml | 4 +- apps/message-hub/base/message-hub.yaml | 4 +- apps/pm/base/backend.yaml | 4 +- apps/pm/base/celery.yaml | 4 +- apps/processing/base/api.yaml | 4 +- apps/processing/base/engine-low.yaml | 4 +- apps/processing/base/engine.yaml | 4 +- apps/resources/base/backend-deployment.yaml | 4 +- .../base/backend-deployment.yaml | 4 +- apps/system-log/base/api.yaml | 4 +- apps/system-log/base/worker.yaml | 4 +- apps/transmittal/base/backend.yaml | 4 +- apps/transmittal/base/worker.yaml | 4 +- 24 files changed, 46 insertions(+), 166 deletions(-) delete mode 100644 apps/inspections/base/backend-deployment.yaml diff --git a/apps/attachments/base/helmrelease.yaml b/apps/attachments/base/helmrelease.yaml index a7a5e46..aee5f94 100644 --- a/apps/attachments/base/helmrelease.yaml +++ b/apps/attachments/base/helmrelease.yaml @@ -87,9 +87,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: attachments - vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/postgresql/apps/attachments + vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres vault.hashicorp.com/agent-inject-template-attachments-db: |- - {{- with secret "secrets/data/postgresql/apps/attachments" -}} + {{- with secret "secrets/data/apps/attachments/postgres" -}} DATABASE_HOST={{ index .Data.data "host" }} DATABASE_PORT={{ index .Data.data "port" }} DATABASE_NAME={{ index .Data.data "database" }} diff --git a/apps/bim/base/backend.yaml b/apps/bim/base/backend.yaml index b424252..0d332eb 100644 --- a/apps/bim/base/backend.yaml +++ b/apps/bim/base/backend.yaml @@ -186,9 +186,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: bim - vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim + vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/apps/bim/postgres vault.hashicorp.com/agent-inject-template-bim-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/bim" -}} + {{- with secret "secrets/data/apps/bim/postgres" -}} POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local diff --git a/apps/comparisons/base/backend.yaml b/apps/comparisons/base/backend.yaml index cdb60db..df630ff 100644 --- a/apps/comparisons/base/backend.yaml +++ b/apps/comparisons/base/backend.yaml @@ -244,9 +244,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: comparisons - vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/postgresql/apps/comparisons + vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/apps/comparisons/postgres vault.hashicorp.com/agent-inject-template-comparisons-db: |- - {{- with secret "secrets/data/postgresql/apps/comparisons" -}} + {{- with secret "secrets/data/apps/comparisons/postgres" -}} DATABASE_HOST=postgresql.comparisons.svc.cluster.local DATABASE_PORT=5432 DATABASE_DB=comparisons_db diff --git a/apps/contracts/base/helmrelease.yaml b/apps/contracts/base/helmrelease.yaml index 4cb4942..a42e8ae 100644 --- a/apps/contracts/base/helmrelease.yaml +++ b/apps/contracts/base/helmrelease.yaml @@ -90,9 +90,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: contracts - vault.hashicorp.com/agent-inject-secret-contracts-db: secrets/data/postgresql/apps/contracts + vault.hashicorp.com/agent-inject-secret-contracts-db: secrets/data/apps/contracts/postgres vault.hashicorp.com/agent-inject-template-contracts-db: |- - {{- with secret "secrets/data/postgresql/apps/contracts" -}} + {{- with secret "secrets/data/apps/contracts/postgres" -}} DB_URL=postgresql://{{ index .Data.data "username" }}:{{ index .Data.data "password" }}@postgresql.contracts.svc.cluster.local:5432/contracts_db?sslmode=disable {{- end -}} vault.hashicorp.com/agent-inject-secret-contracts-jwt-public: secrets/data/vault/common/rsa_keys diff --git a/apps/drawings/base/backend.yaml b/apps/drawings/base/backend.yaml index 341bdb6..1c309e0 100644 --- a/apps/drawings/base/backend.yaml +++ b/apps/drawings/base/backend.yaml @@ -119,9 +119,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: drawings - vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/postgresql/apps/drawings + vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/apps/drawings/postgres vault.hashicorp.com/agent-inject-template-drawings-db: |- - {{- with secret "secrets/data/postgresql/apps/drawings" -}} + {{- with secret "secrets/data/apps/drawings/postgres" -}} POSTGRES_ADDRESS=postgresql.drawings.svc.cluster.local:5432 POSTGRES_DB=drawings_db POSTGRES_USER={{ index .Data.data "username" }} diff --git a/apps/flows/base/backend.yaml b/apps/flows/base/backend.yaml index f0101d9..1e7eb39 100644 --- a/apps/flows/base/backend.yaml +++ b/apps/flows/base/backend.yaml @@ -217,9 +217,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: flows - vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows + vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres vault.hashicorp.com/agent-inject-template-flows-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/flows" -}} + {{- with secret "secrets/data/apps/flows/postgres" -}} PG_DB={{ index .Data.data "database" }} PG_LOGIN={{ index .Data.data "username" }} PG_HOST={{ index .Data.data "host" }} diff --git a/apps/flows/base/celery.yaml b/apps/flows/base/celery.yaml index b7893bd..0c90eb6 100644 --- a/apps/flows/base/celery.yaml +++ b/apps/flows/base/celery.yaml @@ -202,9 +202,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: flows - vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows + vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres vault.hashicorp.com/agent-inject-template-flows-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/flows" -}} + {{- with secret "secrets/data/apps/flows/postgres" -}} PG_DB=flows_db PG_LOGIN={{ index .Data.data "username" }} PG_HOST=postgresql.flows.svc.cluster.local diff --git a/apps/inspections/base/backend-deployment.yaml b/apps/inspections/base/backend-deployment.yaml deleted file mode 100644 index a61a392..0000000 --- a/apps/inspections/base/backend-deployment.yaml +++ /dev/null @@ -1,120 +0,0 @@ ---- -apiVersion: apps/v1 -kind: Deployment -metadata: - name: inspections-backend - namespace: inspections - labels: - app: inspections-backend -spec: - replicas: 1 - selector: - matchLabels: - app: inspections-backend - template: - metadata: - labels: - app: inspections-backend - annotations: - traffic.sidecar.istio.io/excludeOutboundPorts: "8200" - vault.hashicorp.com/agent-init-first: "true" - vault.hashicorp.com/agent-inject: "true" - vault.hashicorp.com/agent-pre-populate-only: "true" - vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: inspections - vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/postgresql/apps/inspections - vault.hashicorp.com/agent-inject-template-inspections-db: |- - {{- with secret "secrets/data/postgresql/apps/inspections" -}} - DATABASE_HOST=postgresql.inspections.svc.cluster.local - DATABASE_PORT=5432 - DATABASE_NAME=inspections_db - DATABASE_USER={{ index .Data.data "username" }} - DATABASE_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections - vault.hashicorp.com/agent-inject-template-inspections-kafka: |- - {{- with secret "secrets/data/kafka/apps/inspections" -}} - KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }} - KAFKA_USERNAME={{ index .Data.data "username" }} - KAFKA_PASSWORD={{ index .Data.data "password" }} - {{- end -}} - vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth - vault.hashicorp.com/agent-inject-template-inspections-django-auth: |- - {{- with secret "secrets/data/vault/common/django_auth" -}} - SAREX_BACKEND_AUTH={{ index .Data.data "key" }} - {{- end -}} - spec: - serviceAccountName: inspections-vault - containers: - - name: inspections-backend - image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4 - imagePullPolicy: IfNotPresent - command: ["/bin/bash", "-ec"] - args: - - | - set -a - [ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db - [ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka - [ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth - set +a - exec ./entrypoint.sh - ports: - - name: http - containerPort: 8000 - protocol: TCP - env: - - name: DEBUG - value: "false" - - name: SERVICE_URL - value: https://srx.wb.ru - - name: HTTP_APP_HOST - value: 0.0.0.0 - - name: HTTP_APP_PORT - value: "8000" - - name: HTTP_APP_ROOT_PATH - value: /inspections - - name: HTTP_APP_WORKERS - value: "3" - - name: HTTP_APP_ADMIN_ENABLE - value: "true" - - name: KAFKA_SSL_CAFILE - value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt - - name: KAFKA_EAV_ASSETS_TOPIC - value: assets_broadcast - - name: JWT_AUTH_ENABLE - value: "true" - - name: NOTIFICATIONS_ENABLE - value: "true" - - name: NOTIFICATIONS_EMAIL_FROM - value: hello@sarex.io - - name: SAREX_BACKEND_URL - value: https://srx.wb.ru - - name: SAREX_BACKEND_TIMEOUT - value: "30" - - name: EAV_URL - value: http://eav-service.eav - - name: EAV_TIMEOUT - value: "30" - - name: WORKFLOWS_URL - value: http://workflows-service.processing-prod - - name: WORKFLOWS_TIMEOUT - value: "30" - - name: WORKFLOWS_EMAIL_DOCKER_IMAGE - value: cr.yandex/crp3ccidau046kdj8g9q/notification:email - - name: MOBILE_APP_CURRENT_VERSION - value: 1.0.0 - - name: MOBILE_APP_RECOMMENDED_VERSION - value: 1.0.0 - - name: MOBILE_APP_REQUIRED_VERSION - value: 1.0.0 - - name: MAILER_URL - value: http://mailer-service.mailer:8000 - - name: MAILER_TIMEOUT - value: "30" - - resources: - requests: - cpu: "25m" - memory: 128Mi - imagePullSecrets: - - name: regcred diff --git a/apps/inspections/base/backend.yaml b/apps/inspections/base/backend.yaml index b8f1da9..017a83f 100644 --- a/apps/inspections/base/backend.yaml +++ b/apps/inspections/base/backend.yaml @@ -212,9 +212,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: inspections - vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/postgresql/apps/inspections + vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/apps/inspections/postgres vault.hashicorp.com/agent-inject-template-inspections-db: |- - {{- with secret "secrets/data/postgresql/apps/inspections" -}} + {{- with secret "secrets/data/apps/inspections/postgres" -}} DATABASE_HOST=postgresql.inspections.svc.cluster.local DATABASE_PORT=5432 DATABASE_NAME=inspections_db diff --git a/apps/issues/base/backend.yaml b/apps/issues/base/backend.yaml index 9644a58..77cee41 100644 --- a/apps/issues/base/backend.yaml +++ b/apps/issues/base/backend.yaml @@ -188,9 +188,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: issues - vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues + vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres vault.hashicorp.com/agent-inject-template-issues-db: |- - {{- with secret "secrets/data/postgresql/apps/issues" -}} + {{- with secret "secrets/data/apps/issues/postgres" -}} DATABASE_PORT=5432 DATABASE_HOST=postgresql.issues.svc.cluster.local DATABASE_USER={{ index .Data.data "username" }} diff --git a/apps/issues/base/celery.yaml b/apps/issues/base/celery.yaml index c8eeefe..6158e30 100644 --- a/apps/issues/base/celery.yaml +++ b/apps/issues/base/celery.yaml @@ -173,9 +173,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: issues - vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues + vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres vault.hashicorp.com/agent-inject-template-issues-db: |- - {{- with secret "secrets/data/postgresql/apps/issues" -}} + {{- with secret "secrets/data/apps/issues/postgres" -}} DATABASE_PORT=5432 DATABASE_HOST=postgresql.issues.svc.cluster.local DATABASE_USER={{ index .Data.data "username" }} diff --git a/apps/mapper/base/backend.yaml b/apps/mapper/base/backend.yaml index b5bf4d2..bacb7d8 100644 --- a/apps/mapper/base/backend.yaml +++ b/apps/mapper/base/backend.yaml @@ -147,9 +147,9 @@ spec: {{- with secret "secrets/data/vault/common/django_auth" -}} MAPPER_DJANGO_TOKEN={{ index .Data.data "key" }} {{- end -}} - vault.hashicorp.com/agent-inject-secret-mapper-db: secrets/data/postgresql/apps/mapper + vault.hashicorp.com/agent-inject-secret-mapper-db: secrets/data/apps/mapper/postgres vault.hashicorp.com/agent-inject-template-mapper-db: |- - {{- with secret "secrets/data/postgresql/apps/mapper" -}} + {{- with secret "secrets/data/apps/mapper/postgres" -}} MAPPER_DB_USER={{ index .Data.data "username" }} MAPPER_DB_PASSWORD={{ index .Data.data "password" }} MAPPER_DB_HOST=postgresql.mapper.svc.cluster.local diff --git a/apps/message-hub/base/message-hub.yaml b/apps/message-hub/base/message-hub.yaml index f9e0241..4d97f27 100644 --- a/apps/message-hub/base/message-hub.yaml +++ b/apps/message-hub/base/message-hub.yaml @@ -148,9 +148,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: message-hub - vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/postgresql/apps/message-hub + vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/apps/message-hub/postgres vault.hashicorp.com/agent-inject-template-message-hub-db: |- - {{- with secret "secrets/data/postgresql/apps/message-hub" -}} + {{- with secret "secrets/data/apps/message-hub/postgres" -}} DB_USERNAME={{ index .Data.data "username" }} DB_PASSWORD={{ index .Data.data "password" }} DB_DATABASE=pm_db diff --git a/apps/pm/base/backend.yaml b/apps/pm/base/backend.yaml index c103c6e..625d222 100644 --- a/apps/pm/base/backend.yaml +++ b/apps/pm/base/backend.yaml @@ -220,9 +220,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: pm - vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm + vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/apps/pm/postgres vault.hashicorp.com/agent-inject-template-pm-db: |- - {{- with secret "secrets/data/postgresql/apps/pm" -}} + {{- with secret "secrets/data/apps/pm/postgres" -}} DB_USERNAME={{ index .Data.data "username" }} DB_PASSWORD={{ index .Data.data "password" }} DB_DATABASE=pm_db diff --git a/apps/pm/base/celery.yaml b/apps/pm/base/celery.yaml index cb171f6..b9095de 100644 --- a/apps/pm/base/celery.yaml +++ b/apps/pm/base/celery.yaml @@ -203,9 +203,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: pm - vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/postgresql/apps/pm + vault.hashicorp.com/agent-inject-secret-pm-db: secrets/data/apps/pm/postgres vault.hashicorp.com/agent-inject-template-pm-db: |- - {{- with secret "secrets/data/postgresql/apps/pm" -}} + {{- with secret "secrets/data/apps/pm/postgres" -}} DB_USERNAME={{ index .Data.data "username" }} DB_PASSWORD={{ index .Data.data "password" }} DB_DATABASE=pm_db diff --git a/apps/processing/base/api.yaml b/apps/processing/base/api.yaml index fbfd678..31f4408 100644 --- a/apps/processing/base/api.yaml +++ b/apps/processing/base/api.yaml @@ -139,9 +139,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: processing - vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/postgresql/apps/processing + vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/apps/processing/postgres vault.hashicorp.com/agent-inject-template-processing-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/processing" -}} + {{- with secret "secrets/data/apps/processing/postgres" -}} POSTGRES_ADDRESS=postgresql.processing.svc.cluster.local POSTGRES_PORT=5432 POSTGRES_USER={{ index .Data.data "username" }} diff --git a/apps/processing/base/engine-low.yaml b/apps/processing/base/engine-low.yaml index 51d410b..4a59781 100644 --- a/apps/processing/base/engine-low.yaml +++ b/apps/processing/base/engine-low.yaml @@ -399,9 +399,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: processing - vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/postgresql/apps/processing + vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/apps/processing/postgres vault.hashicorp.com/agent-inject-template-processing-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/processing" -}} + {{- with secret "secrets/data/apps/processing/postgres" -}} POSTGRES_ADDRESS=postgresql.processing.svc.cluster.local POSTGRES_PORT=5432 POSTGRES_USER={{ index .Data.data "username" }} diff --git a/apps/processing/base/engine.yaml b/apps/processing/base/engine.yaml index 5916e90..dd43481 100644 --- a/apps/processing/base/engine.yaml +++ b/apps/processing/base/engine.yaml @@ -391,9 +391,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: processing - vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/postgresql/apps/processing + vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/apps/processing/postgres vault.hashicorp.com/agent-inject-template-processing-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/processing" -}} + {{- with secret "secrets/data/apps/processing/postgres" -}} POSTGRES_ADDRESS=postgresql.processing.svc.cluster.local POSTGRES_PORT=5432 POSTGRES_USER={{ index .Data.data "username" }} diff --git a/apps/resources/base/backend-deployment.yaml b/apps/resources/base/backend-deployment.yaml index 58a7475..f595f5a 100644 --- a/apps/resources/base/backend-deployment.yaml +++ b/apps/resources/base/backend-deployment.yaml @@ -21,9 +21,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: resources - vault.hashicorp.com/agent-inject-secret-resources-db: secrets/data/postgresql/apps/resources + vault.hashicorp.com/agent-inject-secret-resources-db: secrets/data/apps/resources/postgres vault.hashicorp.com/agent-inject-template-resources-db: |- - {{- with secret "secrets/data/postgresql/apps/resources" -}} + {{- with secret "secrets/data/apps/resources/postgres" -}} DATABASE_HOST=postgresql.resources.svc.cluster.local DATABASE_PORT=5432 DATABASE_NAME=resources_db diff --git a/apps/subscriptions/base/backend-deployment.yaml b/apps/subscriptions/base/backend-deployment.yaml index b9e881d..a467eeb 100644 --- a/apps/subscriptions/base/backend-deployment.yaml +++ b/apps/subscriptions/base/backend-deployment.yaml @@ -22,9 +22,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: subscriptions - vault.hashicorp.com/agent-inject-secret-subscriptions-postgresql: secrets/data/postgresql/apps/subscriptions + vault.hashicorp.com/agent-inject-secret-subscriptions-postgresql: secrets/data/apps/subscriptions/postgres vault.hashicorp.com/agent-inject-template-subscriptions-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/subscriptions" -}} + {{- with secret "secrets/data/apps/subscriptions/postgres" -}} DATABASE_HOST=postgresql.subscriptions.svc.cluster.local DATABASE_PORT=5432 DATABASE_NAME=subscriptions_db diff --git a/apps/system-log/base/api.yaml b/apps/system-log/base/api.yaml index 2e8c0f1..7164577 100644 --- a/apps/system-log/base/api.yaml +++ b/apps/system-log/base/api.yaml @@ -179,9 +179,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: system-log - vault.hashicorp.com/agent-inject-secret-system-log-postgresql: secrets/data/postgresql/apps/system-log + vault.hashicorp.com/agent-inject-secret-system-log-postgresql: secrets/data/apps/system-log/postgres vault.hashicorp.com/agent-inject-template-system-log-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/system-log" -}} + {{- with secret "secrets/data/apps/system-log/postgres" -}} POSTGRES_ADDRESS=postgresql.system-log.svc.cluster.local POSTGRES_PORT=5432 POSTGRES_DB=system_log_db diff --git a/apps/system-log/base/worker.yaml b/apps/system-log/base/worker.yaml index a1c32e7..4dab1a9 100644 --- a/apps/system-log/base/worker.yaml +++ b/apps/system-log/base/worker.yaml @@ -155,9 +155,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: system-log - vault.hashicorp.com/agent-inject-secret-system-log-postgresql: secrets/data/postgresql/apps/system-log + vault.hashicorp.com/agent-inject-secret-system-log-postgresql: secrets/data/apps/system-log/postgres vault.hashicorp.com/agent-inject-template-system-log-postgresql: |- - {{- with secret "secrets/data/postgresql/apps/system-log" -}} + {{- with secret "secrets/data/apps/system-log/postgres" -}} POSTGRES_ADDRESS=postgresql.system-log.svc.cluster.local POSTGRES_PORT=5432 POSTGRES_DB=system_log_db diff --git a/apps/transmittal/base/backend.yaml b/apps/transmittal/base/backend.yaml index 84ab267..4985e84 100644 --- a/apps/transmittal/base/backend.yaml +++ b/apps/transmittal/base/backend.yaml @@ -355,9 +355,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: transmittal - vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/postgresql/apps/transmittal + vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/apps/transmittal/postgres vault.hashicorp.com/agent-inject-template-transmittal-db: |- - {{- with secret "secrets/data/postgresql/apps/transmittal" -}} + {{- with secret "secrets/data/apps/transmittal/postgres" -}} TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local diff --git a/apps/transmittal/base/worker.yaml b/apps/transmittal/base/worker.yaml index 53efb7a..b5ee138 100644 --- a/apps/transmittal/base/worker.yaml +++ b/apps/transmittal/base/worker.yaml @@ -340,9 +340,9 @@ spec: vault.hashicorp.com/agent-pre-populate-only: "true" vault.hashicorp.com/auth-path: auth/kubernetes vault.hashicorp.com/role: transmittal - vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/postgresql/apps/transmittal + vault.hashicorp.com/agent-inject-secret-transmittal-db: secrets/data/apps/transmittal/postgres vault.hashicorp.com/agent-inject-template-transmittal-db: |- - {{- with secret "secrets/data/postgresql/apps/transmittal" -}} + {{- with secret "secrets/data/apps/transmittal/postgres" -}} TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local From b14e342955983f5612edc8cbddc936a6a6a80e8f Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 14:57:31 +0500 Subject: [PATCH 07/51] ++ --- apps/flows/base/backend.yaml | 11 ++++++++--- apps/flows/base/celery.yaml | 11 ++++++++--- 2 files changed, 16 insertions(+), 6 deletions(-) diff --git a/apps/flows/base/backend.yaml b/apps/flows/base/backend.yaml index 1e7eb39..409e118 100644 --- a/apps/flows/base/backend.yaml +++ b/apps/flows/base/backend.yaml @@ -65,6 +65,7 @@ spec: - | set -a [ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql + [ -f /vault/secrets/flows-documentations-db ] && . /vault/secrets/flows-documentations-db [ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq [ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth [ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)" @@ -225,9 +226,13 @@ spec: PG_HOST={{ index .Data.data "host" }} PG_PORT={{ index .Data.data "port" }} PG_PASSWORD={{ index .Data.data "password" }} - DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local - DOCUMENTATION_PG_PORT=5432 - DOCUMENTATION_PG_DATABASE=flows_db + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres + vault.hashicorp.com/agent-inject-template-flows-documentations-db: |- + {{- with secret "secrets/data/apps/documentations/postgres" -}} + DOCUMENTATION_PG_HOST={{ index .Data.data "host" }} + DOCUMENTATION_PG_PORT={{ index .Data.data "port" }} + DOCUMENTATION_PG_DATABASE={{ index .Data.data "database" }} DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }} DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/flows/base/celery.yaml b/apps/flows/base/celery.yaml index 0c90eb6..dc51b1b 100644 --- a/apps/flows/base/celery.yaml +++ b/apps/flows/base/celery.yaml @@ -65,6 +65,7 @@ spec: - | set -a [ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql + [ -f /vault/secrets/flows-documentations-db ] && . /vault/secrets/flows-documentations-db [ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq [ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth [ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)" @@ -210,9 +211,13 @@ spec: PG_HOST=postgresql.flows.svc.cluster.local PG_PORT=5432 PG_PASSWORD={{ index .Data.data "password" }} - DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local - DOCUMENTATION_PG_PORT=5432 - DOCUMENTATION_PG_DATABASE=flows_db + {{- end -}} + vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres + vault.hashicorp.com/agent-inject-template-flows-documentations-db: |- + {{- with secret "secrets/data/apps/documentations/postgres" -}} + DOCUMENTATION_PG_HOST={{ index .Data.data "host" }} + DOCUMENTATION_PG_PORT={{ index .Data.data "port" }} + DOCUMENTATION_PG_DATABASE={{ index .Data.data "database" }} DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }} DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }} {{- end -}} From 7868779771614d01b6bb34ba2dd74b8e13cb6813 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 15:12:16 +0500 Subject: [PATCH 08/51] ++ --- apps/bim/base/backend.yaml | 24 +++---- apps/comparisons/base/backend.yaml | 12 ++-- apps/drawings/base/backend.yaml | 4 +- apps/flows/base/celery.yaml | 6 +- apps/inspections/base/backend.yaml | 6 +- apps/issues/base/backend.yaml | 6 +- apps/issues/base/celery.yaml | 6 +- apps/mapper/base/backend.yaml | 6 +- apps/message-hub/base/message-hub.yaml | 6 +- apps/pm/base/backend.yaml | 6 +- apps/pm/base/celery.yaml | 6 +- apps/processing/base/api.yaml | 6 +- apps/processing/base/engine-low.yaml | 6 +- apps/processing/base/engine.yaml | 6 +- apps/resources/base/backend-deployment.yaml | 6 +- .../base/backend-deployment.yaml | 6 +- apps/system-log/base/api.yaml | 6 +- apps/system-log/base/worker.yaml | 6 +- apps/transmittal/base/backend.yaml | 6 +- apps/transmittal/base/worker.yaml | 6 +- .../d8-ugmk-prod/istio-config.yaml | 65 +++++++++++++++++++ 21 files changed, 136 insertions(+), 71 deletions(-) diff --git a/apps/bim/base/backend.yaml b/apps/bim/base/backend.yaml index 0d332eb..bb212b2 100644 --- a/apps/bim/base/backend.yaml +++ b/apps/bim/base/backend.yaml @@ -189,18 +189,18 @@ spec: vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/apps/bim/postgres vault.hashicorp.com/agent-inject-template-bim-postgresql: |- {{- with secret "secrets/data/apps/bim/postgres" -}} - POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local - POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local - POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local - POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local - POSTGRES_PORT=5432 - POSTGRES_PORT_2=5432 - POSTGRES_PORT_3=5432 - POSTGRES_PORT_4=5432 - POSTGRES_DB=bim_db - POSTGRES_DB_2=bim_db - POSTGRES_DB_3=bim_db - POSTGRES_DB_4=bim_db + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_ADDRESS_2={{ index .Data.data "host" }} + POSTGRES_ADDRESS_3={{ index .Data.data "host" }} + POSTGRES_ADDRESS_4={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} + POSTGRES_PORT_2={{ index .Data.data "port" }} + POSTGRES_PORT_3={{ index .Data.data "port" }} + POSTGRES_PORT_4={{ index .Data.data "port" }} + POSTGRES_DB={{ index .Data.data "database" }} + POSTGRES_DB_2={{ index .Data.data "database" }} + POSTGRES_DB_3={{ index .Data.data "database" }} + POSTGRES_DB_4={{ index .Data.data "database" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_USER_2={{ index .Data.data "username" }} POSTGRES_USER_3={{ index .Data.data "username" }} diff --git a/apps/comparisons/base/backend.yaml b/apps/comparisons/base/backend.yaml index df630ff..bcf8476 100644 --- a/apps/comparisons/base/backend.yaml +++ b/apps/comparisons/base/backend.yaml @@ -247,14 +247,14 @@ spec: vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/apps/comparisons/postgres vault.hashicorp.com/agent-inject-template-comparisons-db: |- {{- with secret "secrets/data/apps/comparisons/postgres" -}} - DATABASE_HOST=postgresql.comparisons.svc.cluster.local - DATABASE_PORT=5432 - DATABASE_DB=comparisons_db + DATABASE_HOST={{ index .Data.data "host" }} + DATABASE_PORT={{ index .Data.data "port" }} + DATABASE_DB={{ index .Data.data "database" }} DATABASE_USER={{ index .Data.data "username" }} DATABASE_PASSWORD={{ index .Data.data "password" }} - POSTGRES_ADDRESS=postgresql.comparisons.svc.cluster.local - POSTGRES_PORT=5432 - POSTGRES_DB=comparisons_db + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} + POSTGRES_DB={{ index .Data.data "database" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/drawings/base/backend.yaml b/apps/drawings/base/backend.yaml index 1c309e0..0cf8937 100644 --- a/apps/drawings/base/backend.yaml +++ b/apps/drawings/base/backend.yaml @@ -122,8 +122,8 @@ spec: vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/apps/drawings/postgres vault.hashicorp.com/agent-inject-template-drawings-db: |- {{- with secret "secrets/data/apps/drawings/postgres" -}} - POSTGRES_ADDRESS=postgresql.drawings.svc.cluster.local:5432 - POSTGRES_DB=drawings_db + POSTGRES_ADDRESS={{ index .Data.data "host" }}:{{ index .Data.data "port" }} + POSTGRES_DB={{ index .Data.data "database" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/flows/base/celery.yaml b/apps/flows/base/celery.yaml index dc51b1b..4e20e5f 100644 --- a/apps/flows/base/celery.yaml +++ b/apps/flows/base/celery.yaml @@ -206,10 +206,10 @@ spec: vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres vault.hashicorp.com/agent-inject-template-flows-postgresql: |- {{- with secret "secrets/data/apps/flows/postgres" -}} - PG_DB=flows_db + PG_DB={{ index .Data.data "database" }} PG_LOGIN={{ index .Data.data "username" }} - PG_HOST=postgresql.flows.svc.cluster.local - PG_PORT=5432 + PG_HOST={{ index .Data.data "host" }} + PG_PORT={{ index .Data.data "port" }} PG_PASSWORD={{ index .Data.data "password" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres diff --git a/apps/inspections/base/backend.yaml b/apps/inspections/base/backend.yaml index 017a83f..e85976a 100644 --- a/apps/inspections/base/backend.yaml +++ b/apps/inspections/base/backend.yaml @@ -215,9 +215,9 @@ spec: vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/apps/inspections/postgres vault.hashicorp.com/agent-inject-template-inspections-db: |- {{- with secret "secrets/data/apps/inspections/postgres" -}} - DATABASE_HOST=postgresql.inspections.svc.cluster.local - DATABASE_PORT=5432 - DATABASE_NAME=inspections_db + DATABASE_HOST={{ index .Data.data "host" }} + DATABASE_PORT={{ index .Data.data "port" }} + DATABASE_NAME={{ index .Data.data "database" }} DATABASE_USER={{ index .Data.data "username" }} DATABASE_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/issues/base/backend.yaml b/apps/issues/base/backend.yaml index 77cee41..f99594c 100644 --- a/apps/issues/base/backend.yaml +++ b/apps/issues/base/backend.yaml @@ -191,11 +191,11 @@ spec: vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres vault.hashicorp.com/agent-inject-template-issues-db: |- {{- with secret "secrets/data/apps/issues/postgres" -}} - DATABASE_PORT=5432 - DATABASE_HOST=postgresql.issues.svc.cluster.local + DATABASE_PORT={{ index .Data.data "port" }} + DATABASE_HOST={{ index .Data.data "host" }} DATABASE_USER={{ index .Data.data "username" }} DATABASE_PASSWORD={{ index .Data.data "password" }} - DATABASE_NAME=issues_db + DATABASE_NAME={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |- diff --git a/apps/issues/base/celery.yaml b/apps/issues/base/celery.yaml index 6158e30..5e790bc 100644 --- a/apps/issues/base/celery.yaml +++ b/apps/issues/base/celery.yaml @@ -176,11 +176,11 @@ spec: vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres vault.hashicorp.com/agent-inject-template-issues-db: |- {{- with secret "secrets/data/apps/issues/postgres" -}} - DATABASE_PORT=5432 - DATABASE_HOST=postgresql.issues.svc.cluster.local + DATABASE_PORT={{ index .Data.data "port" }} + DATABASE_HOST={{ index .Data.data "host" }} DATABASE_USER={{ index .Data.data "username" }} DATABASE_PASSWORD={{ index .Data.data "password" }} - DATABASE_NAME=issues_db + DATABASE_NAME={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |- diff --git a/apps/mapper/base/backend.yaml b/apps/mapper/base/backend.yaml index bacb7d8..84c779e 100644 --- a/apps/mapper/base/backend.yaml +++ b/apps/mapper/base/backend.yaml @@ -152,9 +152,9 @@ spec: {{- with secret "secrets/data/apps/mapper/postgres" -}} MAPPER_DB_USER={{ index .Data.data "username" }} MAPPER_DB_PASSWORD={{ index .Data.data "password" }} - MAPPER_DB_HOST=postgresql.mapper.svc.cluster.local - MAPPER_DB_PORT=5432 - MAPPER_DB_NAME=mapper_db + MAPPER_DB_HOST={{ index .Data.data "host" }} + MAPPER_DB_PORT={{ index .Data.data "port" }} + MAPPER_DB_NAME={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-mapper-rabbitmq: secrets/data/rabbitmq/apps/mapper vault.hashicorp.com/agent-inject-template-mapper-rabbitmq: |- diff --git a/apps/message-hub/base/message-hub.yaml b/apps/message-hub/base/message-hub.yaml index 4d97f27..eec8a25 100644 --- a/apps/message-hub/base/message-hub.yaml +++ b/apps/message-hub/base/message-hub.yaml @@ -153,9 +153,9 @@ spec: {{- with secret "secrets/data/apps/message-hub/postgres" -}} DB_USERNAME={{ index .Data.data "username" }} DB_PASSWORD={{ index .Data.data "password" }} - DB_DATABASE=pm_db - DB_HOST=postgresql.pm.svc.cluster.local - DB_PORT=5432 + DB_DATABASE={{ index .Data.data "database" }} + DB_HOST={{ index .Data.data "host" }} + DB_PORT={{ index .Data.data "port" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub vault.hashicorp.com/agent-inject-template-message-hub-s3: |- diff --git a/apps/pm/base/backend.yaml b/apps/pm/base/backend.yaml index 625d222..d15f3b1 100644 --- a/apps/pm/base/backend.yaml +++ b/apps/pm/base/backend.yaml @@ -225,9 +225,9 @@ spec: {{- with secret "secrets/data/apps/pm/postgres" -}} DB_USERNAME={{ index .Data.data "username" }} DB_PASSWORD={{ index .Data.data "password" }} - DB_DATABASE=pm_db - DB_HOST=postgresql.pm.svc.cluster.local - DB_PORT=5432 + DB_DATABASE={{ index .Data.data "database" }} + DB_HOST={{ index .Data.data "host" }} + DB_PORT={{ index .Data.data "port" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |- diff --git a/apps/pm/base/celery.yaml b/apps/pm/base/celery.yaml index b9095de..8b94b02 100644 --- a/apps/pm/base/celery.yaml +++ b/apps/pm/base/celery.yaml @@ -208,9 +208,9 @@ spec: {{- with secret "secrets/data/apps/pm/postgres" -}} DB_USERNAME={{ index .Data.data "username" }} DB_PASSWORD={{ index .Data.data "password" }} - DB_DATABASE=pm_db - DB_HOST=postgresql.pm.svc.cluster.local - DB_PORT=5432 + DB_DATABASE={{ index .Data.data "database" }} + DB_HOST={{ index .Data.data "host" }} + DB_PORT={{ index .Data.data "port" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-pm-rabbitmq: secrets/data/rabbitmq/apps/pm vault.hashicorp.com/agent-inject-template-pm-rabbitmq: |- diff --git a/apps/processing/base/api.yaml b/apps/processing/base/api.yaml index 31f4408..88226b9 100644 --- a/apps/processing/base/api.yaml +++ b/apps/processing/base/api.yaml @@ -142,11 +142,11 @@ spec: vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/apps/processing/postgres vault.hashicorp.com/agent-inject-template-processing-postgresql: |- {{- with secret "secrets/data/apps/processing/postgres" -}} - POSTGRES_ADDRESS=postgresql.processing.svc.cluster.local - POSTGRES_PORT=5432 + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} - POSTGRES_DB=workflow_db + POSTGRES_DB={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-processing-jwt-public: secrets/data/vault/common/rsa_keys vault.hashicorp.com/agent-inject-template-processing-jwt-public: |- diff --git a/apps/processing/base/engine-low.yaml b/apps/processing/base/engine-low.yaml index 4a59781..eaed6b5 100644 --- a/apps/processing/base/engine-low.yaml +++ b/apps/processing/base/engine-low.yaml @@ -402,11 +402,11 @@ spec: vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/apps/processing/postgres vault.hashicorp.com/agent-inject-template-processing-postgresql: |- {{- with secret "secrets/data/apps/processing/postgres" -}} - POSTGRES_ADDRESS=postgresql.processing.svc.cluster.local - POSTGRES_PORT=5432 + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} - POSTGRES_DB=workflow_db + POSTGRES_DB={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-processing-rabbitmq: secrets/data/rabbitmq/apps/processing vault.hashicorp.com/agent-inject-template-processing-rabbitmq: |- diff --git a/apps/processing/base/engine.yaml b/apps/processing/base/engine.yaml index dd43481..049437b 100644 --- a/apps/processing/base/engine.yaml +++ b/apps/processing/base/engine.yaml @@ -394,11 +394,11 @@ spec: vault.hashicorp.com/agent-inject-secret-processing-postgresql: secrets/data/apps/processing/postgres vault.hashicorp.com/agent-inject-template-processing-postgresql: |- {{- with secret "secrets/data/apps/processing/postgres" -}} - POSTGRES_ADDRESS=postgresql.processing.svc.cluster.local - POSTGRES_PORT=5432 + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} - POSTGRES_DB=workflow_db + POSTGRES_DB={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-processing-rabbitmq: secrets/data/rabbitmq/apps/processing vault.hashicorp.com/agent-inject-template-processing-rabbitmq: |- diff --git a/apps/resources/base/backend-deployment.yaml b/apps/resources/base/backend-deployment.yaml index f595f5a..13923c6 100644 --- a/apps/resources/base/backend-deployment.yaml +++ b/apps/resources/base/backend-deployment.yaml @@ -24,9 +24,9 @@ spec: vault.hashicorp.com/agent-inject-secret-resources-db: secrets/data/apps/resources/postgres vault.hashicorp.com/agent-inject-template-resources-db: |- {{- with secret "secrets/data/apps/resources/postgres" -}} - DATABASE_HOST=postgresql.resources.svc.cluster.local - DATABASE_PORT=5432 - DATABASE_NAME=resources_db + DATABASE_HOST={{ index .Data.data "host" }} + DATABASE_PORT={{ index .Data.data "port" }} + DATABASE_NAME={{ index .Data.data "database" }} DATABASE_USER={{ index .Data.data "username" }} DATABASE_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/subscriptions/base/backend-deployment.yaml b/apps/subscriptions/base/backend-deployment.yaml index a467eeb..896cc93 100644 --- a/apps/subscriptions/base/backend-deployment.yaml +++ b/apps/subscriptions/base/backend-deployment.yaml @@ -25,9 +25,9 @@ spec: vault.hashicorp.com/agent-inject-secret-subscriptions-postgresql: secrets/data/apps/subscriptions/postgres vault.hashicorp.com/agent-inject-template-subscriptions-postgresql: |- {{- with secret "secrets/data/apps/subscriptions/postgres" -}} - DATABASE_HOST=postgresql.subscriptions.svc.cluster.local - DATABASE_PORT=5432 - DATABASE_NAME=subscriptions_db + DATABASE_HOST={{ index .Data.data "host" }} + DATABASE_PORT={{ index .Data.data "port" }} + DATABASE_NAME={{ index .Data.data "database" }} DATABASE_USER={{ index .Data.data "username" }} DATABASE_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/system-log/base/api.yaml b/apps/system-log/base/api.yaml index 7164577..e82e541 100644 --- a/apps/system-log/base/api.yaml +++ b/apps/system-log/base/api.yaml @@ -182,9 +182,9 @@ spec: vault.hashicorp.com/agent-inject-secret-system-log-postgresql: secrets/data/apps/system-log/postgres vault.hashicorp.com/agent-inject-template-system-log-postgresql: |- {{- with secret "secrets/data/apps/system-log/postgres" -}} - POSTGRES_ADDRESS=postgresql.system-log.svc.cluster.local - POSTGRES_PORT=5432 - POSTGRES_DB=system_log_db + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} + POSTGRES_DB={{ index .Data.data "database" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/system-log/base/worker.yaml b/apps/system-log/base/worker.yaml index 4dab1a9..ae2173d 100644 --- a/apps/system-log/base/worker.yaml +++ b/apps/system-log/base/worker.yaml @@ -158,9 +158,9 @@ spec: vault.hashicorp.com/agent-inject-secret-system-log-postgresql: secrets/data/apps/system-log/postgres vault.hashicorp.com/agent-inject-template-system-log-postgresql: |- {{- with secret "secrets/data/apps/system-log/postgres" -}} - POSTGRES_ADDRESS=postgresql.system-log.svc.cluster.local - POSTGRES_PORT=5432 - POSTGRES_DB=system_log_db + POSTGRES_ADDRESS={{ index .Data.data "host" }} + POSTGRES_PORT={{ index .Data.data "port" }} + POSTGRES_DB={{ index .Data.data "database" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} {{- end -}} diff --git a/apps/transmittal/base/backend.yaml b/apps/transmittal/base/backend.yaml index 4985e84..fd21457 100644 --- a/apps/transmittal/base/backend.yaml +++ b/apps/transmittal/base/backend.yaml @@ -360,9 +360,9 @@ spec: {{- with secret "secrets/data/apps/transmittal/postgres" -}} TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} - TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local - TRANSMITTAL_SERVICE_DATABASE__PORT=5432 - TRANSMITTAL_SERVICE_DATABASE__NAME=transmittal_db + TRANSMITTAL_SERVICE_DATABASE__HOST={{ index .Data.data "host" }} + TRANSMITTAL_SERVICE_DATABASE__PORT={{ index .Data.data "port" }} + TRANSMITTAL_SERVICE_DATABASE__NAME={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-transmittal-rabbitmq: secrets/data/rabbitmq/apps/transmittal vault.hashicorp.com/agent-inject-template-transmittal-rabbitmq: |- diff --git a/apps/transmittal/base/worker.yaml b/apps/transmittal/base/worker.yaml index b5ee138..82ce921 100644 --- a/apps/transmittal/base/worker.yaml +++ b/apps/transmittal/base/worker.yaml @@ -345,9 +345,9 @@ spec: {{- with secret "secrets/data/apps/transmittal/postgres" -}} TRANSMITTAL_SERVICE_DATABASE__USER={{ index .Data.data "username" }} TRANSMITTAL_SERVICE_DATABASE__PASSWORD={{ index .Data.data "password" }} - TRANSMITTAL_SERVICE_DATABASE__HOST=postgresql.transmittal.svc.cluster.local - TRANSMITTAL_SERVICE_DATABASE__PORT=5432 - TRANSMITTAL_SERVICE_DATABASE__NAME=transmittal_db + TRANSMITTAL_SERVICE_DATABASE__HOST={{ index .Data.data "host" }} + TRANSMITTAL_SERVICE_DATABASE__PORT={{ index .Data.data "port" }} + TRANSMITTAL_SERVICE_DATABASE__NAME={{ index .Data.data "database" }} {{- end -}} vault.hashicorp.com/agent-inject-secret-transmittal-rabbitmq: secrets/data/rabbitmq/apps/transmittal vault.hashicorp.com/agent-inject-template-transmittal-rabbitmq: |- diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 4eae4c9..73d4d05 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -158,6 +158,71 @@ spec: rewrite: / service: pdm-svc.documentations.svc.cluster.local port: 80 + issues-api: + name: issues-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /issues/api/ + rewrite: /api/ + service: backend-svc.issues.svc.cluster.local + port: 80 + flows-api: + name: flows-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /flows/api/ + rewrite: /api/ + service: backend-svc.flows.svc.cluster.local + port: 80 + issues-frontend: + name: issues-frontend-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /issues/static/ + rewrite: / + service: frontend-svc.issues.svc.cluster.local + port: 80 + flows-frontend: + name: flows-frontend-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /flows/static/ + rewrite: / + service: frontend-svc.flows.svc.cluster.local + port: 80 + reviews-frontend: + name: reviews-frontend-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /reviews/static/ + rewrite: / + service: frontend-svc.reviews.svc.cluster.local + port: 80 eav-api: name: eav-api-virt-service namespace: default From b98d3f6ab2c96eca1ccc2043b9b6851f66119941 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 15:27:24 +0500 Subject: [PATCH 09/51] ++ --- .../d8-ugmk-prod/istio-config.yaml | 26 +++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 73d4d05..15a31de 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -210,6 +210,32 @@ spec: rewrite: / service: frontend-svc.flows.svc.cluster.local port: 80 + transmittal-frontend: + name: transmittal-frontend-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /transmittal/static/ + rewrite: / + service: frontend-svc.transmittal.svc.cluster.local + port: 80 + transmittals-api: + name: flows-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /transmittals/api/ + rewrite: /api/ + service: backend-svc.transmittal.svc.cluster.local + port: 80 reviews-frontend: name: reviews-frontend-virt-service namespace: default From 106b5d450d3b3b3e269e0a3b2971dd66650cd111 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 15:46:58 +0500 Subject: [PATCH 10/51] ++ --- apps/issues/base/backend.yaml | 2 +- apps/issues/base/celery.yaml | 2 +- apps/transmittal/base/backend.yaml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/apps/issues/base/backend.yaml b/apps/issues/base/backend.yaml index f99594c..cc341c8 100644 --- a/apps/issues/base/backend.yaml +++ b/apps/issues/base/backend.yaml @@ -158,7 +158,7 @@ spec: - name: RESOURCES_API_HOST value: - _default: "http://backend-svc.resources.svc.cluster.local:80" + _default: "http://iam-backend.iam.svc.cluster.local:8000" - name: EAV_HOST value: diff --git a/apps/issues/base/celery.yaml b/apps/issues/base/celery.yaml index 5e790bc..5caf9ee 100644 --- a/apps/issues/base/celery.yaml +++ b/apps/issues/base/celery.yaml @@ -143,7 +143,7 @@ spec: - name: RESOURCES_API_HOST value: - _default: "http://backend-svc.resources.svc.cluster.local:80" + _default: "http://iam-backend.iam.svc.cluster.local:8000" - name: EAV_HOST value: diff --git a/apps/transmittal/base/backend.yaml b/apps/transmittal/base/backend.yaml index fd21457..fce07eb 100644 --- a/apps/transmittal/base/backend.yaml +++ b/apps/transmittal/base/backend.yaml @@ -237,7 +237,7 @@ spec: - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__BASE_URL value: - _default: "http://backend-svc.resources.svc.cluster.local:80" + _default: "http://iam-backend.iam.svc.cluster.local:8000" - name: TRANSMITTAL_SERVICE_RESOURCE_REPOSITORY__MAX_CONNECTIONS value: From 8b6133a81ab9fe0f46bd9e69d3cfa04e26596c2d Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:07:34 +0500 Subject: [PATCH 11/51] ++ --- apps/inspections/base/backend.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/inspections/base/backend.yaml b/apps/inspections/base/backend.yaml index e85976a..5176017 100644 --- a/apps/inspections/base/backend.yaml +++ b/apps/inspections/base/backend.yaml @@ -166,7 +166,7 @@ spec: - name: EAV_URL value: - _default: "http://eav-service.eav" + _default: "http://backend-svc.eav.svc.cluster.local:80" - name: EAV_TIMEOUT value: @@ -174,7 +174,7 @@ spec: - name: WORKFLOWS_URL value: - _default: "http://workflows-service.processing-prod" + _default: "http://backend-svc.processing.svc.cluster.local:80" - name: WORKFLOWS_TIMEOUT value: From 4e7757b7b4e28e56fb96fe8483554f1ed4849e24 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:08:52 +0500 Subject: [PATCH 12/51] ++ --- .../istio-config/d8-ugmk-prod/istio-config.yaml | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 15a31de..d0fee6c 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -224,7 +224,7 @@ spec: service: frontend-svc.transmittal.svc.cluster.local port: 80 transmittals-api: - name: flows-api-virt-service + name: transmittals-api-virt-service namespace: default hosts: - sarex.uralmine.com @@ -236,6 +236,19 @@ spec: rewrite: /api/ service: backend-svc.transmittal.svc.cluster.local port: 80 + inspections-api: + name: flows-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /inspections/api/ + rewrite: /api/ + service: backend-svc.inspections.svc.cluster.local + port: 80 reviews-frontend: name: reviews-frontend-virt-service namespace: default From 11fbf26d6db4b3898b89711a30bc74a95089fc94 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:12:24 +0500 Subject: [PATCH 13/51] ++ --- apps/rfi/base/celery.yaml | 2 +- .../d8-ugmk-prod/istio-config.yaml | 26 +++++++++++++++++++ 2 files changed, 27 insertions(+), 1 deletion(-) diff --git a/apps/rfi/base/celery.yaml b/apps/rfi/base/celery.yaml index fae9018..4b42a33 100644 --- a/apps/rfi/base/celery.yaml +++ b/apps/rfi/base/celery.yaml @@ -90,7 +90,7 @@ spec: _default: https://lk.srx.wb.ru:30443/rfi - name: SAREX_BACKEND_URL value: - _default: http://backend-svc.django.svc.cluster.local + _default: http://backend-svc.django.svc.cluster.local:80 - name: EAV_URL value: _default: http://backend-svc.eav.svc.cluster.local:80 diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index d0fee6c..05946f0 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -132,6 +132,32 @@ spec: rewrite: / service: frontend-svc.documentations.svc.cluster.local port: 80 + rfi-frontend: + name: rfi-frontend-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /rfi/static/ + rewrite: / + service: frontend-svc.rfi.svc.cluster.local + port: 80 + rfi-api: + name: rfi-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /rfi/api/ + rewrite: /api/ + service: backend-svc.rfi.svc.cluster.local + port: 80 documentations-api: name: documentations-api-virt-service namespace: default From 9a8a80328a259b540b965986804468ac867c2b58 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:22:27 +0500 Subject: [PATCH 14/51] ++ --- apps/processing/base/kustomization.yaml | 1 + apps/processing/base/rbac.yaml | 33 +++++++++++++++++++++++++ 2 files changed, 34 insertions(+) create mode 100644 apps/processing/base/rbac.yaml diff --git a/apps/processing/base/kustomization.yaml b/apps/processing/base/kustomization.yaml index b41abbe..8619375 100644 --- a/apps/processing/base/kustomization.yaml +++ b/apps/processing/base/kustomization.yaml @@ -4,6 +4,7 @@ kind: Kustomization namespace: processing resources: - namespace.yaml + - rbac.yaml - api.yaml - engine-low.yaml - engine.yaml diff --git a/apps/processing/base/rbac.yaml b/apps/processing/base/rbac.yaml new file mode 100644 index 0000000..1661e08 --- /dev/null +++ b/apps/processing/base/rbac.yaml @@ -0,0 +1,33 @@ +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: Role +metadata: + name: processing-jobs + namespace: processing +rules: + - apiGroups: + - batch + resources: + - jobs + verbs: + - get + - list + - watch + - create + - update + - patch + - delete +--- +apiVersion: rbac.authorization.k8s.io/v1 +kind: RoleBinding +metadata: + name: processing-jobs + namespace: processing +subjects: + - kind: ServiceAccount + name: processing-vault + namespace: processing +roleRef: + apiGroup: rbac.authorization.k8s.io + kind: Role + name: processing-jobs From e09067365f142a6b041545329ebeb6e5179c7695 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:26:47 +0500 Subject: [PATCH 15/51] ++ --- apps/flows/base/backend.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/apps/flows/base/backend.yaml b/apps/flows/base/backend.yaml index 409e118..c399461 100644 --- a/apps/flows/base/backend.yaml +++ b/apps/flows/base/backend.yaml @@ -45,7 +45,6 @@ spec: _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111 pullPolicy: _default: IfNotPresent - deployment: enabled: true From 798648e85d9b723ae6803f01f8fc60932ca922b4 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:53:33 +0500 Subject: [PATCH 16/51] ++ --- apps/django/base/nginx-configmap.yaml | 32 +++++++++++++-------------- 1 file changed, 16 insertions(+), 16 deletions(-) diff --git a/apps/django/base/nginx-configmap.yaml b/apps/django/base/nginx-configmap.yaml index cfe04eb..e26a353 100644 --- a/apps/django/base/nginx-configmap.yaml +++ b/apps/django/base/nginx-configmap.yaml @@ -79,20 +79,20 @@ data: # proxy_pass http://backend-svc.django.svc.cluster.local:80; # } - # location ~^/workspaces-v2/(.+).js { - # proxy_http_version 1.1; - # proxy_set_header Connection ""; - # rewrite /workspaces-v2/(.+) /$1 break; - # proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80; - # } + location ~^/workspaces-v2/(.+).js { + proxy_http_version 1.1; + proxy_set_header Connection ""; + rewrite /workspaces-v2/(.+) /$1 break; + proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80; + } - # location ~^/workspaces-v2/(.+)\.wasm$ { - # proxy_http_version 1.1; - # proxy_set_header Connection ""; - # rewrite ^/workspaces-v2/(.+) /$1 break; - # proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80; - # } + location ~^/workspaces-v2/(.+)\.wasm$ { + proxy_http_version 1.1; + proxy_set_header Connection ""; + rewrite ^/workspaces-v2/(.+) /$1 break; + proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80; + } location @index { add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0'; @@ -101,10 +101,10 @@ data: try_files /static/index.html =404; } - # location ~^/workflows/(.+).js { - # rewrite /workflows/(.+) /$1 break; - # proxy_pass http://frontend-svc.processing.svc.cluster.local:80; - # } + location ~^/workflows/(.+).js { + rewrite /workflows/(.+) /$1 break; + proxy_pass http://frontend-svc.processing.svc.cluster.local:80; + } location /service-worker.js { try_files /static/$uri @index; } From e88027ffa6b3223b9338c09ccfb684191a772b80 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 16:56:56 +0500 Subject: [PATCH 17/51] ++ --- .../istio-config/d8-ugmk-prod/istio-config.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 05946f0..d55ebe3 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -249,6 +249,19 @@ spec: rewrite: / service: frontend-svc.transmittal.svc.cluster.local port: 80 + workflows-api: + name: workflows-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /workflows/api/ + rewrite: /api/ + service: backend-svc.processing.svc.cluster.local + port: 80 transmittals-api: name: transmittals-api-virt-service namespace: default From 800718737da246d699f97bf6dbe069505a69dac5 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:01:48 +0500 Subject: [PATCH 18/51] ++ --- apps/pm/base/backend.yaml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/apps/pm/base/backend.yaml b/apps/pm/base/backend.yaml index d15f3b1..4688514 100644 --- a/apps/pm/base/backend.yaml +++ b/apps/pm/base/backend.yaml @@ -110,7 +110,7 @@ spec: envs: - name: USERS_INTERNAL_HOST value: - _default: "http://backend-service.sarex.svc.cluster.local:8000" + _default: "http://backend-svc.django.svc.cluster.local:80" - name: CELERY_REDIS_HOST value: @@ -118,11 +118,11 @@ spec: - name: RESOURCES_INTERNAL_HOST value: - _default: "http://sarex-resources-service.resources" + _default: "http://iam-backend.iam.svc.cluster.local:8000" - name: EAV_HOST value: - _default: "http://eav-service.eav" + _default: "http://backend-svc.eav.svc.cluster.local:80" - name: EAV_API_PREFIX value: @@ -182,15 +182,15 @@ spec: - name: AUTH_PUBLIC_TOKEN_URL value: - _default: "https://lk.sarex.io/api/token/public/" + _default: "https://sarex.uralmine.com/api/token/public/" - name: SERVER_HOST value: - _default: "https://lk.sarex.io" + _default: "https://sarex.uralmine.com" - name: SERVER_API_HOST value: - _default: "https://api.sarex.io" + _default: "https://sarex.uralmine.com" - name: SERVER_DEBUG value: From 396702429f94dcaf8785bdca2729cc7a8960694d Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:10:00 +0500 Subject: [PATCH 19/51] ++ --- apps/pm/base/backend.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/apps/pm/base/backend.yaml b/apps/pm/base/backend.yaml index 4688514..6f8576a 100644 --- a/apps/pm/base/backend.yaml +++ b/apps/pm/base/backend.yaml @@ -68,6 +68,7 @@ spec: [ -f /vault/secrets/pm-rabbitmq ] && . /vault/secrets/pm-rabbitmq [ -f /vault/secrets/pm-s3 ] && . /vault/secrets/pm-s3 set +a + python manage.py migrate exec /opt/sarex/entrypoint.sh resources: From 84c51343f917de91e7a0ac877393706e61212035 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:32:56 +0500 Subject: [PATCH 20/51] ++ --- apps/django/base/django-configmap.yaml | 5 ++ apps/django/base/nginx-configmap.yaml | 10 +-- apps/pm/base/backend.yaml | 2 +- apps/pm/base/celery.yaml | 2 +- apps/pm/base/frontend.yaml | 90 +++++++++++++++++++ apps/pm/base/kustomization.yaml | 1 + .../d8-ugmk-prod/istio-config.yaml | 18 ++++ 7 files changed, 121 insertions(+), 7 deletions(-) create mode 100644 apps/pm/base/frontend.yaml diff --git a/apps/django/base/django-configmap.yaml b/apps/django/base/django-configmap.yaml index 9b7db5d..77ca238 100644 --- a/apps/django/base/django-configmap.yaml +++ b/apps/django/base/django-configmap.yaml @@ -296,6 +296,11 @@ data: "name": "Запросы", "uri": "/rfi" }, + { + "name": "Управление проектами", + "uri": "/management/projects" + }, + # { # "name": "Обзор", # "uri": "/projects" diff --git a/apps/django/base/nginx-configmap.yaml b/apps/django/base/nginx-configmap.yaml index e26a353..cf4eed8 100644 --- a/apps/django/base/nginx-configmap.yaml +++ b/apps/django/base/nginx-configmap.yaml @@ -62,11 +62,11 @@ data: if_modified_since off; expires off; } - # location ~^/api/pm/ { - # #rewrite /api/(.+) /$1 break; - # proxy_set_header Host $host; - # proxy_pass http://backend-svc.pm.svc.cluster.local:8000; - # } + location ~^/api/pm/ { + #rewrite /api/(.+) /$1 break; + proxy_set_header Host $host; + proxy_pass http://backend-svc.pm.svc.cluster.local:8000; + } # location ~^/api/v1/documents/ { # #rewrite /api/(.+) /$1 break; diff --git a/apps/pm/base/backend.yaml b/apps/pm/base/backend.yaml index 6f8576a..1a98551 100644 --- a/apps/pm/base/backend.yaml +++ b/apps/pm/base/backend.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_a889f6a3 pullPolicy: _default: IfNotPresent diff --git a/apps/pm/base/celery.yaml b/apps/pm/base/celery.yaml index 8b94b02..b04f8a7 100644 --- a/apps/pm/base/celery.yaml +++ b/apps/pm/base/celery.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_0843a55d + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-backend:production_a889f6a3 pullPolicy: _default: IfNotPresent diff --git a/apps/pm/base/frontend.yaml b/apps/pm/base/frontend.yaml new file mode 100644 index 0000000..d52e7d9 --- /dev/null +++ b/apps/pm/base/frontend.yaml @@ -0,0 +1,90 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: frontend + namespace: pm + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + frontend: + enabled: true + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pm-frontend:contour_e5c3d387 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: frontend + + replicaCount: + _default: 1 + + port: + _default: 80 + + resources: + requests: + cpu: + _default: 25m + memory: + _default: 100Mi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: true + + name: + _default: frontend-svc + + type: + _default: ClusterIP + + port: + _default: 80 + + targetPort: + _default: 80 + + portName: + _default: http + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred diff --git a/apps/pm/base/kustomization.yaml b/apps/pm/base/kustomization.yaml index f16efbf..aa00f14 100644 --- a/apps/pm/base/kustomization.yaml +++ b/apps/pm/base/kustomization.yaml @@ -6,4 +6,5 @@ resources: - namespace.yaml - backend.yaml - celery.yaml + - frontend.yaml - backend-configmap.yaml diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index d55ebe3..a689651 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -158,6 +158,24 @@ spec: rewrite: /api/ service: backend-svc.rfi.svc.cluster.local port: 80 + pm: + name: pm-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /pm/api/ + rewrite: /api/ + service: backend-svc.pm.svc.cluster.local + port: 8000 + - path: + prefix: /pm/ + rewrite: / + service: frontend-svc.pm.svc.cluster.local + port: 80 documentations-api: name: documentations-api-virt-service namespace: default From fc9e75945abfb7602ded83f08d0ba1a2f9313da4 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:42:37 +0500 Subject: [PATCH 21/51] ++ --- apps/transmittal/brusnika-prod/backend.yaml | 2 +- apps/transmittal/brusnika-prod/worker.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/transmittal/brusnika-prod/backend.yaml b/apps/transmittal/brusnika-prod/backend.yaml index 766e8e5..a3d7e7f 100644 --- a/apps/transmittal/brusnika-prod/backend.yaml +++ b/apps/transmittal/brusnika-prod/backend.yaml @@ -35,7 +35,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_a9d879ae + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_4e0db600 pullPolicy: _default: IfNotPresent diff --git a/apps/transmittal/brusnika-prod/worker.yaml b/apps/transmittal/brusnika-prod/worker.yaml index 95e7011..22bf530 100644 --- a/apps/transmittal/brusnika-prod/worker.yaml +++ b/apps/transmittal/brusnika-prod/worker.yaml @@ -35,7 +35,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_d94cce67 + _default: cr.yandex/crp3ccidau046kdj8g9q/transmittal-api:prod_4e0db600 pullPolicy: _default: IfNotPresent From ab7611fc7ecfadf28754ec715070c3e85ec3cbd5 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:47:56 +0500 Subject: [PATCH 22/51] ++ --- .../istio-config/d8-ugmk-prod/istio-config.yaml | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index a689651..c8def9e 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -79,15 +79,15 @@ spec: gateways: - default/platform-gateway routes: - - path: - prefix: /admin/ - service: backend-svc.django.svc.cluster.local - port: 80 + # - path: + # prefix: /admin/ + # service: backend-svc.django.svc.cluster.local + # port: 80 - - path: - prefix: /api/ - service: backend-svc.django.svc.cluster.local - port: 80 + # - path: + # prefix: /api/ + # service: backend-svc.django.svc.cluster.local + # port: 80 - path: prefix: / From c470dacee3151070c484716aff80ec38df8adbed Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:48:17 +0500 Subject: [PATCH 23/51] ++ --- apps/django/base/nginx-configmap.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/apps/django/base/nginx-configmap.yaml b/apps/django/base/nginx-configmap.yaml index cf4eed8..dcd095c 100644 --- a/apps/django/base/nginx-configmap.yaml +++ b/apps/django/base/nginx-configmap.yaml @@ -74,10 +74,10 @@ data: # proxy_pass http://backend-filestream-svc.documentations.svc.cluster.local:80; # } - # location ~^/(api|admin)/ { - # proxy_set_header Host $host; - # proxy_pass http://backend-svc.django.svc.cluster.local:80; - # } + location ~^/(api|admin)/ { + proxy_set_header Host $host; + proxy_pass http://backend-svc.django.svc.cluster.local:80; + } location ~^/workspaces-v2/(.+).js { proxy_http_version 1.1; From 80da663600e39f224bc30690f15224c4d716dbeb Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 17:53:50 +0500 Subject: [PATCH 24/51] ++ --- apps/django/base/nginx-configmap.yaml | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/apps/django/base/nginx-configmap.yaml b/apps/django/base/nginx-configmap.yaml index dcd095c..4080296 100644 --- a/apps/django/base/nginx-configmap.yaml +++ b/apps/django/base/nginx-configmap.yaml @@ -64,6 +64,8 @@ data: } location ~^/api/pm/ { #rewrite /api/(.+) /$1 break; + proxy_http_version 1.1; + proxy_set_header Connection ""; proxy_set_header Host $host; proxy_pass http://backend-svc.pm.svc.cluster.local:8000; } @@ -75,6 +77,8 @@ data: # } location ~^/(api|admin)/ { + proxy_http_version 1.1; + proxy_set_header Connection ""; proxy_set_header Host $host; proxy_pass http://backend-svc.django.svc.cluster.local:80; } @@ -102,6 +106,8 @@ data: } location ~^/workflows/(.+).js { + proxy_http_version 1.1; + proxy_set_header Connection ""; rewrite /workflows/(.+) /$1 break; proxy_pass http://frontend-svc.processing.svc.cluster.local:80; } From 50cee9c4d37f028739802e71196e0a4389d49778 Mon Sep 17 00:00:00 2001 From: ivan Date: Fri, 31 Jul 2026 18:40:52 +0500 Subject: [PATCH 25/51] ++ --- apps/attachments/d8-ugmk-prod/patch.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/apps/attachments/d8-ugmk-prod/patch.yaml b/apps/attachments/d8-ugmk-prod/patch.yaml index 8c185da..ad66013 100644 --- a/apps/attachments/d8-ugmk-prod/patch.yaml +++ b/apps/attachments/d8-ugmk-prod/patch.yaml @@ -11,10 +11,10 @@ spec: podAnnotations: _default: vault.hashicorp.com/auth-path: auth/kubernetes - vault.hashicorp.com/role: attachments-vault - vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/postgresql/apps/attachments + vault.hashicorp.com/role: attachments + vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres vault.hashicorp.com/agent-inject-template-attachments-db: |- - {{- with secret "secrets/data/postgresql/apps/attachments" -}} + {{- with secret "secrets/data/apps/attachments/postgres" -}} DATABASE_HOST={{ index .Data.data "host" }} DATABASE_PORT={{ index .Data.data "port" }} DATABASE_NAME={{ index .Data.data "database" }} From 987e9e3a7f56510b4cfc29ed362a09cc095921f7 Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 12:50:10 +0500 Subject: [PATCH 26/51] ++ --- apps/attachments/base/kustomization.yaml | 1 + apps/attachments/base/namespace.yaml | 8 + apps/documentations/base/hasher.yaml | 163 +++++++++++++++++ apps/documentations/base/kustomization.yaml | 2 + .../base/pdf-markings-amqp.yaml | 172 ++++++++++++++++++ 5 files changed, 346 insertions(+) create mode 100644 apps/attachments/base/namespace.yaml create mode 100644 apps/documentations/base/hasher.yaml create mode 100644 apps/documentations/base/pdf-markings-amqp.yaml diff --git a/apps/attachments/base/kustomization.yaml b/apps/attachments/base/kustomization.yaml index c9ccb75..9cb4143 100644 --- a/apps/attachments/base/kustomization.yaml +++ b/apps/attachments/base/kustomization.yaml @@ -3,4 +3,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization namespace: attachments resources: + - namespace.yaml - helmrelease.yaml diff --git a/apps/attachments/base/namespace.yaml b/apps/attachments/base/namespace.yaml new file mode 100644 index 0000000..f58896f --- /dev/null +++ b/apps/attachments/base/namespace.yaml @@ -0,0 +1,8 @@ +--- +apiVersion: v1 +kind: Namespace +metadata: + name: attachments + labels: + istio-injection: enabled + security.deckhouse.io/pod-policy: privileged diff --git a/apps/documentations/base/hasher.yaml b/apps/documentations/base/hasher.yaml new file mode 100644 index 0000000..dff8e51 --- /dev/null +++ b/apps/documentations/base/hasher.yaml @@ -0,0 +1,163 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentations-hasher + namespace: documentations +spec: + interval: 10m + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + install: + remediation: + retries: 3 + upgrade: + remediation: + retries: 3 + values: + global: + env: _default + services: + backend: + enabled: true + serviceAccount: + enabled: + _default: true + name: + _default: documentations-vault + deployment: + enabled: true + name: + _default: hasher + replicaCount: + _default: 1 + port: + _default: 8080 + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/documentations-hasher-rabbitmq ] && . /vault/secrets/documentations-hasher-rabbitmq + [ -f /vault/secrets/documentations-hasher-s3 ] && . /vault/secrets/documentations-hasher-s3 + set +a + exec ./server + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + probes: + liveness: + enabled: false + readiness: + enabled: false + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/hasher:production_3f853d3a + pullPolicy: + _default: IfNotPresent + service: + enabled: true + name: + _default: hasher-service + type: + _default: ClusterIP + port: + _default: 8080 + targetPort: + _default: 8080 + portName: + _default: http + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + envs: + - name: HASHER_APP__LOG_LEVEL + value: + _default: INFO + + - name: HASHER_APP__NUM_WORKERS + value: + _default: "4" + + - name: HASHER_AMQP__ROUTING__TASK_INPUT_QUEUE + value: + _default: hash.compute.normal.tasks + + - name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE + value: + _default: hash.compute + + - name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE_TYPE + value: + _default: direct + + - name: HASHER_AMQP__ROUTING__TASK_INPUT_ROUTING_KEY + value: + _default: hash.compute.normal + + - name: HASHER_S3__MAX_POOL_CONNECTIONS + value: + _default: "10" + + - name: HASHER_S3__CONNECT_TIMEOUT + value: + _default: "10" + + - name: HASHER_S3__READ_TIMEOUT + value: + _default: "30" + + - name: HASHER_S3__REGION_NAME + value: + _default: ru-central1 + + - name: HASHER_S3__USE_SSL + value: + _default: "true" + + - name: HASHER_S3__VERIFY + value: + _default: "true" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411,8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: documentations + vault.hashicorp.com/agent-inject-secret-documentations-hasher-rabbitmq: secrets/data/apps/documentations/hasher/rabbitmq + vault.hashicorp.com/agent-inject-template-documentations-hasher-rabbitmq: |- + {{- with secret "secrets/data/apps/documentations/hasher/rabbitmq" -}} + HASHER_AMQP__HOST={{ index .Data.data "host" }} + HASHER_AMQP__PORT={{ index .Data.data "port" }} + HASHER_AMQP__USERNAME={{ index .Data.data "username" }} + HASHER_AMQP__PASSWORD={{ index .Data.data "password" }} + HASHER_AMQP__VHOST={{ index .Data.data "vhost" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-documentations-hasher-s3: secrets/data/apps/documentations/hasher/s3 + vault.hashicorp.com/agent-inject-template-documentations-hasher-s3: |- + {{- with secret "secrets/data/apps/documentations/hasher/s3" -}} + HASHER_S3__ENDPOINT={{ index .Data.data "endpoint" }} + HASHER_S3__ACCESS_KEY={{ index .Data.data "access_key" }} + HASHER_S3__SECRET_KEY={{ index .Data.data "secret_key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/documentations/base/kustomization.yaml b/apps/documentations/base/kustomization.yaml index d15ef61..a9e034f 100644 --- a/apps/documentations/base/kustomization.yaml +++ b/apps/documentations/base/kustomization.yaml @@ -8,5 +8,7 @@ resources: - filestream.yaml - frontend.yaml - pdm.yaml + - pdf-markings-amqp.yaml + - hasher.yaml - redis-deployment.yaml - redis-service.yaml diff --git a/apps/documentations/base/pdf-markings-amqp.yaml b/apps/documentations/base/pdf-markings-amqp.yaml new file mode 100644 index 0000000..772dee2 --- /dev/null +++ b/apps/documentations/base/pdf-markings-amqp.yaml @@ -0,0 +1,172 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentations-pdf-markings-amqp + namespace: documentations +spec: + interval: 10m + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + install: + remediation: + retries: 3 + upgrade: + remediation: + retries: 3 + values: + global: + env: _default + services: + backend: + enabled: true + serviceAccount: + enabled: + _default: true + name: + _default: documentations-vault + deployment: + enabled: true + name: + _default: pdf-markings-amqp + replicaCount: + _default: 1 + port: + _default: 8000 + command: + _default: ["/bin/sh", "-ec"] + args: + _default: + - | + set -a + [ -f /vault/secrets/documentations-marks-db ] && . /vault/secrets/documentations-marks-db + [ -f /vault/secrets/documentations-marks-rabbitmq ] && . /vault/secrets/documentations-marks-rabbitmq + [ -f /vault/secrets/documentations-marks-s3 ] && . /vault/secrets/documentations-marks-s3 + set +a + exec ./server + resources: + requests: + cpu: + _default: 25m + memory: + _default: 128Mi + probes: + liveness: + enabled: false + readiness: + enabled: false + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/pdf-markings-amqp:prod_3ab263be + pullPolicy: + _default: IfNotPresent + service: + enabled: true + name: + _default: marks-service + type: + _default: ClusterIP + port: + _default: 8000 + targetPort: + _default: 8000 + portName: + _default: http + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + envs: + - name: MARKS_APP__LOG_LEVEL + value: + _default: INFO + + - name: MARKS_CRYPTO__HASHING_ALGO + value: + _default: md_gost12_256 + + - name: MARKS_QR__REDIRECT_URL + value: + _default: "https://stamp-verification.srx.wb.ru/" + + - name: MARKS_QR__BASE_DOCUMENT_URL + value: + _default: "https://srx.wb.ru" + + - name: MARKS_S3__REGION + value: + _default: ru-central1 + + - name: MARKS_S3__USE_SSL + value: + _default: "true" + + - name: MARKS_S3__SSL_VERIFY + value: + _default: "true" + + - name: MARKS_S3__DEFAULT_BUCKET + value: + _default: documentations-marks + + - name: MARKS_RABBITMQ__ROUTING__INPUT_QUEUE + value: + _default: pdf_markings_input + + - name: MARKS_RABBITMQ__HOST + value: + _default: rabbitmq.rabbitmq.svc.cluster.local + + - name: MARKS_RABBITMQ__PORT + value: + _default: "5672" + + - name: MARKS_RABBITMQ__HEARTBEAT_SECONDS + value: + _default: "60" + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411,8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: documentations + vault.hashicorp.com/agent-inject-secret-documentations-marks-db: secrets/data/apps/documentations/postgres + vault.hashicorp.com/agent-inject-template-documentations-marks-db: |- + {{- with secret "secrets/data/apps/documentations/postgres" -}} + MARKS_DOCUMENTS_DB__HOST={{ index .Data.data "host" }} + MARKS_DOCUMENTS_DB__PORT={{ index .Data.data "port" }} + MARKS_DOCUMENTS_DB__DATABASE={{ index .Data.data "database" }} + MARKS_DOCUMENTS_DB__USERNAME={{ index .Data.data "username" }} + MARKS_DOCUMENTS_DB__PASSWORD={{ index .Data.data "password" }} + MARKS_DOCUMENTS_DB__SSLMODE=disable + {{- end -}} + vault.hashicorp.com/agent-inject-secret-documentations-marks-rabbitmq: secrets/data/rabbitmq/apps/documentations + vault.hashicorp.com/agent-inject-template-documentations-marks-rabbitmq: |- + {{- with secret "secrets/data/rabbitmq/apps/documentations" -}} + MARKS_RABBITMQ__USERNAME={{ index .Data.data "username" }} + MARKS_RABBITMQ__PASSWORD={{ index .Data.data "password" }} + MARKS_RABBITMQ__VHOST={{ index .Data.data "vhost" }} + {{- end -}} + vault.hashicorp.com/agent-inject-secret-documentations-marks-s3: secrets/data/apps/documentations/marks-s3 + vault.hashicorp.com/agent-inject-template-documentations-marks-s3: |- + {{- with secret "secrets/data/apps/documentations/marks-s3" -}} + MARKS_S3__URL={{ index .Data.data "endpoint_url" }} + MARKS_S3__ACCESS_KEY={{ index .Data.data "access_key" }} + MARKS_S3__SECRET_KEY={{ index .Data.data "secret_key" }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" From a148491f9504949cc46aa97fac366ffe957df637 Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 13:07:29 +0500 Subject: [PATCH 27/51] ++ --- apps/cde/base/cde-flowscallback.yaml | 13 +- apps/cde/base/cde-splitpdf.yaml | 13 +- apps/cde/base/cde-worker-alert.yaml | 111 ++++++++++++++++++ apps/cde/base/cde-worker-copy.yaml | 15 +-- apps/cde/base/cde-worker-copyv2.yaml | 111 ++++++++++++++++++ apps/cde/base/cde-worker-create-versions.yaml | 13 +- .../base/cde-worker-create-versionsv2.yaml | 111 ++++++++++++++++++ apps/cde/base/cde-worker-markings.yaml | 15 +-- apps/cde/base/cde-worker-markingsv2.yaml | 111 ++++++++++++++++++ apps/cde/base/cde-worker-sign.yaml | 13 +- apps/cde/base/cde-worker-signv2.yaml | 111 ++++++++++++++++++ apps/cde/base/cde-worker-update-bundles.yaml | 13 +- apps/cde/base/cde.yaml | 14 +-- apps/cde/base/kustomization.yaml | 5 + 14 files changed, 597 insertions(+), 72 deletions(-) create mode 100644 apps/cde/base/cde-worker-alert.yaml create mode 100644 apps/cde/base/cde-worker-copyv2.yaml create mode 100644 apps/cde/base/cde-worker-create-versionsv2.yaml create mode 100644 apps/cde/base/cde-worker-markingsv2.yaml create mode 100644 apps/cde/base/cde-worker-signv2.yaml diff --git a/apps/cde/base/cde-flowscallback.yaml b/apps/cde/base/cde-flowscallback.yaml index 406212e..a7c9716 100644 --- a/apps/cde/base/cde-flowscallback.yaml +++ b/apps/cde/base/cde-flowscallback.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -56,7 +56,7 @@ spec: _default: 1 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "1" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-splitpdf.yaml b/apps/cde/base/cde-splitpdf.yaml index a50615f..0dae414 100644 --- a/apps/cde/base/cde-splitpdf.yaml +++ b/apps/cde/base/cde-splitpdf.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -56,7 +56,7 @@ spec: _default: 1 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "1" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-alert.yaml b/apps/cde/base/cde-worker-alert.yaml new file mode 100644 index 0000000..142b7a3 --- /dev/null +++ b/apps/cde/base/cde-worker-alert.yaml @@ -0,0 +1,111 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cde-worker-alert + namespace: cde + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-alert: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/orchestrator:latest + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-alert + + replicaCount: + _default: 1 + + port: + _default: 8080 + + command: + _default: ["/bin/bash", "-lc"] + args: + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + + resources: + requests: + cpu: + _default: "1" + memory: + _default: 4Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-copy.yaml b/apps/cde/base/cde-worker-copy.yaml index 622243f..1aaafe0 100644 --- a/apps/cde/base/cde-worker-copy.yaml +++ b/apps/cde/base/cde-worker-copy.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -53,10 +53,10 @@ spec: _default: cde-worker-copy replicaCount: - _default: 1 + _default: 2 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "2" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-copyv2.yaml b/apps/cde/base/cde-worker-copyv2.yaml new file mode 100644 index 0000000..9f06f17 --- /dev/null +++ b/apps/cde/base/cde-worker-copyv2.yaml @@ -0,0 +1,111 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cde-worker-copyv2 + namespace: cde + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-copyv2: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/copyv2-worker:prod_4.5.0 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-copyv2 + + replicaCount: + _default: 2 + + port: + _default: 8080 + + command: + _default: ["/bin/bash", "-lc"] + args: + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + + resources: + requests: + cpu: + _default: "2" + memory: + _default: 4Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-create-versions.yaml b/apps/cde/base/cde-worker-create-versions.yaml index 36b788d..da74f8b 100644 --- a/apps/cde/base/cde-worker-create-versions.yaml +++ b/apps/cde/base/cde-worker-create-versions.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -56,7 +56,7 @@ spec: _default: 1 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "1" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-create-versionsv2.yaml b/apps/cde/base/cde-worker-create-versionsv2.yaml new file mode 100644 index 0000000..44c149f --- /dev/null +++ b/apps/cde/base/cde-worker-create-versionsv2.yaml @@ -0,0 +1,111 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cde-worker-create-versionsv2 + namespace: cde + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-create-versionsv2: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/createversionsv2-worker:prod_4.5.0 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-create-versionsv2 + + replicaCount: + _default: 1 + + port: + _default: 8080 + + command: + _default: ["/bin/bash", "-lc"] + args: + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + + resources: + requests: + cpu: + _default: "1" + memory: + _default: 4Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-markings.yaml b/apps/cde/base/cde-worker-markings.yaml index 018bd6a..1710eb7 100644 --- a/apps/cde/base/cde-worker-markings.yaml +++ b/apps/cde/base/cde-worker-markings.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -53,10 +53,10 @@ spec: _default: cde-worker-markings replicaCount: - _default: 1 + _default: 2 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "2" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-markingsv2.yaml b/apps/cde/base/cde-worker-markingsv2.yaml new file mode 100644 index 0000000..ff1e946 --- /dev/null +++ b/apps/cde/base/cde-worker-markingsv2.yaml @@ -0,0 +1,111 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cde-worker-markingsv2 + namespace: cde + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-markingsv2: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/markingsv2-worker:prod_4.5.0 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-markingsv2 + + replicaCount: + _default: 2 + + port: + _default: 8080 + + command: + _default: ["/bin/bash", "-lc"] + args: + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + + resources: + requests: + cpu: + _default: "2" + memory: + _default: 4Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-sign.yaml b/apps/cde/base/cde-worker-sign.yaml index 153caab..7c9fa93 100644 --- a/apps/cde/base/cde-worker-sign.yaml +++ b/apps/cde/base/cde-worker-sign.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -56,7 +56,7 @@ spec: _default: 1 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "2" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-signv2.yaml b/apps/cde/base/cde-worker-signv2.yaml new file mode 100644 index 0000000..1d8cafb --- /dev/null +++ b/apps/cde/base/cde-worker-signv2.yaml @@ -0,0 +1,111 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: cde-worker-signv2 + namespace: cde + +spec: + interval: 10m + + chart: + spec: + chart: universal-chart + version: "0.1.9" + sourceRef: + kind: HelmRepository + name: yc-oci-charts + namespace: flux-system + interval: 10m + + install: + remediation: + retries: 3 + + upgrade: + remediation: + retries: 3 + + values: + global: + env: _default + + services: + cde-worker-signv2: + enabled: true + + serviceAccount: + enabled: + _default: true + name: + _default: cde-vault + + image: + name: + _default: cr.yandex/crp3ccidau046kdj8g9q/signv2-worker:prod_4.5.0 + pullPolicy: + _default: IfNotPresent + + deployment: + enabled: true + + name: + _default: cde-worker-signv2 + + replicaCount: + _default: 1 + + port: + _default: 8080 + + command: + _default: ["/bin/bash", "-lc"] + args: + _default: + - | + set -e + source /vault/secrets/cde-env + exec /worker + + resources: + requests: + cpu: + _default: "2" + memory: + _default: 4Gi + + probes: + liveness: + enabled: false + readiness: + enabled: false + + service: + enabled: false + + imagePullSecrets: + enabled: + _default: true + name: + _default: regcred + + podAnnotations: + _default: + traffic.sidecar.istio.io/excludeOutboundPorts: "8200" + vault.hashicorp.com/agent-init-first: "true" + vault.hashicorp.com/agent-inject: "true" + vault.hashicorp.com/agent-pre-populate-only: "true" + vault.hashicorp.com/auth-path: auth/kubernetes + vault.hashicorp.com/role: cde + vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde + vault.hashicorp.com/agent-inject-template-cde-env: |- + {{- with secret "secrets/data/vault/apps/cde" -}} + {{- range $k, $v := .Data.data }} + export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }}) + {{- end }} + {{- end -}} + + commitSha: "" + gitlabUri: "" + gitlabJobUrl: "" + owner: "" diff --git a/apps/cde/base/cde-worker-update-bundles.yaml b/apps/cde/base/cde-worker-update-bundles.yaml index 0edcf5b..a71d510 100644 --- a/apps/cde/base/cde-worker-update-bundles.yaml +++ b/apps/cde/base/cde-worker-update-bundles.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_4.5.0 pullPolicy: _default: IfNotPresent @@ -56,7 +56,7 @@ spec: _default: 1 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "1" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -89,11 +89,6 @@ spec: name: _default: regcred - envs: - - name: S3_IS_CONTOUR - value: - _default: "true" - podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde.yaml b/apps/cde/base/cde.yaml index 1cade42..913a511 100644 --- a/apps/cde/base/cde.yaml +++ b/apps/cde/base/cde.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a + _default: cr.yandex/crp3ccidau046kdj8g9q/cde:production_54ec2a86 pullPolicy: _default: IfNotPresent @@ -56,7 +56,7 @@ spec: _default: 1 port: - _default: 8000 + _default: 8080 command: _default: ["/bin/bash", "-lc"] @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: 25m + _default: "2" memory: - _default: 128Mi + _default: 4Gi probes: liveness: @@ -93,7 +93,7 @@ spec: _default: 80 targetPort: - _default: 8000 + _default: 8080 portName: _default: http @@ -105,9 +105,9 @@ spec: _default: regcred envs: - - name: S3_IS_CONTOUR + - name: SAREX_BACKEND_BASE_URL value: - _default: "true" + _default: "https://lk.sarex.io" podAnnotations: _default: diff --git a/apps/cde/base/kustomization.yaml b/apps/cde/base/kustomization.yaml index 66da886..753fbe5 100644 --- a/apps/cde/base/kustomization.yaml +++ b/apps/cde/base/kustomization.yaml @@ -7,8 +7,13 @@ resources: - cde.yaml - cde-splitpdf.yaml - cde-flowscallback.yaml + - cde-worker-alert.yaml - cde-worker-copy.yaml + - cde-worker-copyv2.yaml - cde-worker-create-versions.yaml + - cde-worker-create-versionsv2.yaml - cde-worker-markings.yaml + - cde-worker-markingsv2.yaml - cde-worker-sign.yaml + - cde-worker-signv2.yaml - cde-worker-update-bundles.yaml From f1043df2da4b8c1ae7329136f2db9fe0646f7e0f Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 13:53:41 +0500 Subject: [PATCH 28/51] ++ --- apps/cde/base/namespace.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/apps/cde/base/namespace.yaml b/apps/cde/base/namespace.yaml index f080923..35c9fae 100644 --- a/apps/cde/base/namespace.yaml +++ b/apps/cde/base/namespace.yaml @@ -5,3 +5,4 @@ metadata: name: cde labels: istio-injection: enabled + security.deckhouse.io/pod-policy: privileged \ No newline at end of file From 950c1a5c51367ebe8d36f388f125e5022af8d3b9 Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 14:00:43 +0500 Subject: [PATCH 29/51] ++ --- .../d8-ugmk-prod/istio-config.yaml | 29 +++++++++++++++++-- 1 file changed, 27 insertions(+), 2 deletions(-) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index c8def9e..723e0fa 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -328,8 +328,33 @@ spec: - default/platform-gateway routes: - path: - prefix: /eav/api/ - rewrite: /api/ + prefix: /eav/api/v0 + rewrite: /api/v4 + service: backend-svc.eav.svc.cluster.local + port: 80 + - path: + prefix: /eav/api/v2 + rewrite: /api/v5 + service: backend-svc.eav.svc.cluster.local + port: 80 + - path: + prefix: /eav/api/v3 + rewrite: /api/v3 + service: backend-svc.eav.svc.cluster.local + port: 80 + - path: + prefix: /eav/api/v4 + rewrite: /api/v4 + service: backend-svc.eav.svc.cluster.local + port: 80 + - path: + prefix: /eav/api/v1 + rewrite: /api/v6 + service: backend-svc.eav.svc.cluster.local + port: 80 + - path: + prefix: /eav/admin/ + rewrite: /eav/admin/ service: backend-svc.eav.svc.cluster.local port: 80 srx-admin-frontend: From 5b2c6b99672384e598bdc330a03cdac43772e17a Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 14:08:35 +0500 Subject: [PATCH 30/51] ++ --- apps/cde/base/cde-flowscallback.yaml | 9 +++++++++ apps/cde/base/cde-splitpdf.yaml | 9 +++++++++ apps/cde/base/cde-worker-alert.yaml | 9 +++++++++ apps/cde/base/cde-worker-copy.yaml | 9 +++++++++ apps/cde/base/cde-worker-copyv2.yaml | 9 +++++++++ apps/cde/base/cde-worker-create-versions.yaml | 9 +++++++++ apps/cde/base/cde-worker-create-versionsv2.yaml | 9 +++++++++ apps/cde/base/cde-worker-markings.yaml | 9 +++++++++ apps/cde/base/cde-worker-markingsv2.yaml | 9 +++++++++ apps/cde/base/cde-worker-sign.yaml | 9 +++++++++ apps/cde/base/cde-worker-signv2.yaml | 9 +++++++++ apps/cde/base/cde-worker-update-bundles.yaml | 9 +++++++++ apps/cde/base/cde.yaml | 8 ++++++++ 13 files changed, 116 insertions(+) diff --git a/apps/cde/base/cde-flowscallback.yaml b/apps/cde/base/cde-flowscallback.yaml index a7c9716..53091bd 100644 --- a/apps/cde/base/cde-flowscallback.yaml +++ b/apps/cde/base/cde-flowscallback.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-splitpdf.yaml b/apps/cde/base/cde-splitpdf.yaml index 0dae414..61fd43a 100644 --- a/apps/cde/base/cde-splitpdf.yaml +++ b/apps/cde/base/cde-splitpdf.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-alert.yaml b/apps/cde/base/cde-worker-alert.yaml index 142b7a3..749adf9 100644 --- a/apps/cde/base/cde-worker-alert.yaml +++ b/apps/cde/base/cde-worker-alert.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-copy.yaml b/apps/cde/base/cde-worker-copy.yaml index 1aaafe0..9e7dbbe 100644 --- a/apps/cde/base/cde-worker-copy.yaml +++ b/apps/cde/base/cde-worker-copy.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-copyv2.yaml b/apps/cde/base/cde-worker-copyv2.yaml index 9f06f17..7bfba40 100644 --- a/apps/cde/base/cde-worker-copyv2.yaml +++ b/apps/cde/base/cde-worker-copyv2.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-create-versions.yaml b/apps/cde/base/cde-worker-create-versions.yaml index da74f8b..ef231c6 100644 --- a/apps/cde/base/cde-worker-create-versions.yaml +++ b/apps/cde/base/cde-worker-create-versions.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-create-versionsv2.yaml b/apps/cde/base/cde-worker-create-versionsv2.yaml index 44c149f..dbef10d 100644 --- a/apps/cde/base/cde-worker-create-versionsv2.yaml +++ b/apps/cde/base/cde-worker-create-versionsv2.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-markings.yaml b/apps/cde/base/cde-worker-markings.yaml index 1710eb7..c5606b9 100644 --- a/apps/cde/base/cde-worker-markings.yaml +++ b/apps/cde/base/cde-worker-markings.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-markingsv2.yaml b/apps/cde/base/cde-worker-markingsv2.yaml index ff1e946..e1ba254 100644 --- a/apps/cde/base/cde-worker-markingsv2.yaml +++ b/apps/cde/base/cde-worker-markingsv2.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-sign.yaml b/apps/cde/base/cde-worker-sign.yaml index 7c9fa93..e0b49fc 100644 --- a/apps/cde/base/cde-worker-sign.yaml +++ b/apps/cde/base/cde-worker-sign.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-signv2.yaml b/apps/cde/base/cde-worker-signv2.yaml index 1d8cafb..655105e 100644 --- a/apps/cde/base/cde-worker-signv2.yaml +++ b/apps/cde/base/cde-worker-signv2.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde-worker-update-bundles.yaml b/apps/cde/base/cde-worker-update-bundles.yaml index a71d510..90e4ac3 100644 --- a/apps/cde/base/cde-worker-update-bundles.yaml +++ b/apps/cde/base/cde-worker-update-bundles.yaml @@ -89,6 +89,15 @@ spec: name: _default: regcred + envs: + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" diff --git a/apps/cde/base/cde.yaml b/apps/cde/base/cde.yaml index 913a511..7f9b60a 100644 --- a/apps/cde/base/cde.yaml +++ b/apps/cde/base/cde.yaml @@ -109,6 +109,14 @@ spec: value: _default: "https://lk.sarex.io" + - name: S3_IS_CONTOUR + value: + _default: "true" + + - name: IS_CONTOUR + value: + _default: "true" + podAnnotations: _default: traffic.sidecar.istio.io/excludeOutboundPorts: "8200" From 38a357ee6454b5fa884f3b67ee21132ea5086049 Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 14:21:30 +0500 Subject: [PATCH 31/51] ++ --- apps/cde/base/cde-worker-copy.yaml | 2 +- apps/cde/base/cde-worker-copyv2.yaml | 2 +- apps/cde/base/cde-worker-create-versions.yaml | 2 +- apps/cde/base/cde-worker-create-versionsv2.yaml | 2 +- apps/cde/base/cde-worker-markings.yaml | 6 +++--- apps/cde/base/cde-worker-markingsv2.yaml | 6 +++--- apps/cde/base/cde-worker-sign.yaml | 4 ++-- apps/cde/base/cde-worker-signv2.yaml | 4 ++-- apps/cde/base/cde-worker-update-bundles.yaml | 2 +- apps/cde/base/cde.yaml | 4 ++-- 10 files changed, 17 insertions(+), 17 deletions(-) diff --git a/apps/cde/base/cde-worker-copy.yaml b/apps/cde/base/cde-worker-copy.yaml index 9e7dbbe..b31afb5 100644 --- a/apps/cde/base/cde-worker-copy.yaml +++ b/apps/cde/base/cde-worker-copy.yaml @@ -53,7 +53,7 @@ spec: _default: cde-worker-copy replicaCount: - _default: 2 + _default: 1 port: _default: 8080 diff --git a/apps/cde/base/cde-worker-copyv2.yaml b/apps/cde/base/cde-worker-copyv2.yaml index 7bfba40..6f53b3c 100644 --- a/apps/cde/base/cde-worker-copyv2.yaml +++ b/apps/cde/base/cde-worker-copyv2.yaml @@ -53,7 +53,7 @@ spec: _default: cde-worker-copyv2 replicaCount: - _default: 2 + _default: 1 port: _default: 8080 diff --git a/apps/cde/base/cde-worker-create-versions.yaml b/apps/cde/base/cde-worker-create-versions.yaml index ef231c6..eb7d2ee 100644 --- a/apps/cde/base/cde-worker-create-versions.yaml +++ b/apps/cde/base/cde-worker-create-versions.yaml @@ -72,7 +72,7 @@ spec: cpu: _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-create-versionsv2.yaml b/apps/cde/base/cde-worker-create-versionsv2.yaml index dbef10d..f18c63b 100644 --- a/apps/cde/base/cde-worker-create-versionsv2.yaml +++ b/apps/cde/base/cde-worker-create-versionsv2.yaml @@ -72,7 +72,7 @@ spec: cpu: _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-markings.yaml b/apps/cde/base/cde-worker-markings.yaml index c5606b9..1c25a0b 100644 --- a/apps/cde/base/cde-worker-markings.yaml +++ b/apps/cde/base/cde-worker-markings.yaml @@ -53,7 +53,7 @@ spec: _default: cde-worker-markings replicaCount: - _default: 2 + _default: 1 port: _default: 8080 @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-markingsv2.yaml b/apps/cde/base/cde-worker-markingsv2.yaml index e1ba254..7b2d5d9 100644 --- a/apps/cde/base/cde-worker-markingsv2.yaml +++ b/apps/cde/base/cde-worker-markingsv2.yaml @@ -53,7 +53,7 @@ spec: _default: cde-worker-markingsv2 replicaCount: - _default: 2 + _default: 1 port: _default: 8080 @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-sign.yaml b/apps/cde/base/cde-worker-sign.yaml index e0b49fc..1b68839 100644 --- a/apps/cde/base/cde-worker-sign.yaml +++ b/apps/cde/base/cde-worker-sign.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-signv2.yaml b/apps/cde/base/cde-worker-signv2.yaml index 655105e..72d76dc 100644 --- a/apps/cde/base/cde-worker-signv2.yaml +++ b/apps/cde/base/cde-worker-signv2.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-update-bundles.yaml b/apps/cde/base/cde-worker-update-bundles.yaml index 90e4ac3..132d81b 100644 --- a/apps/cde/base/cde-worker-update-bundles.yaml +++ b/apps/cde/base/cde-worker-update-bundles.yaml @@ -72,7 +72,7 @@ spec: cpu: _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde.yaml b/apps/cde/base/cde.yaml index 7f9b60a..bbc57ce 100644 --- a/apps/cde/base/cde.yaml +++ b/apps/cde/base/cde.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: From 7ad5c5f4b10c82a8417458feda774b063c46349d Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 14:41:41 +0500 Subject: [PATCH 32/51] ++ --- apps/cde/base/cde-flowscallback.yaml | 2 +- apps/cde/base/cde-splitpdf.yaml | 2 +- apps/cde/base/cde-worker-alert.yaml | 2 +- apps/cde/base/cde-worker-copy.yaml | 2 +- apps/cde/base/cde-worker-copyv2.yaml | 2 +- apps/cde/base/cde-worker-create-versions.yaml | 2 +- .../base/cde-worker-create-versionsv2.yaml | 2 +- apps/cde/base/cde-worker-markings.yaml | 2 +- apps/cde/base/cde-worker-markingsv2.yaml | 2 +- apps/cde/base/cde-worker-sign.yaml | 2 +- apps/cde/base/cde-worker-signv2.yaml | 2 +- apps/cde/base/cde-worker-update-bundles.yaml | 2 +- apps/cde/base/cde.yaml | 2 +- .../d8-ugmk-prod/istio-config.yaml | 23 +++++++++++++++++++ 14 files changed, 36 insertions(+), 13 deletions(-) diff --git a/apps/cde/base/cde-flowscallback.yaml b/apps/cde/base/cde-flowscallback.yaml index 53091bd..70b6b51 100644 --- a/apps/cde/base/cde-flowscallback.yaml +++ b/apps/cde/base/cde-flowscallback.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-splitpdf.yaml b/apps/cde/base/cde-splitpdf.yaml index 61fd43a..66651a8 100644 --- a/apps/cde/base/cde-splitpdf.yaml +++ b/apps/cde/base/cde-splitpdf.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-alert.yaml b/apps/cde/base/cde-worker-alert.yaml index 749adf9..07bbe97 100644 --- a/apps/cde/base/cde-worker-alert.yaml +++ b/apps/cde/base/cde-worker-alert.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/orchestrator:latest + _default: cr.yandex/crp3ccidau046kdj8g9q/orchestrator:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-copy.yaml b/apps/cde/base/cde-worker-copy.yaml index b31afb5..4208b49 100644 --- a/apps/cde/base/cde-worker-copy.yaml +++ b/apps/cde/base/cde-worker-copy.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-copyv2.yaml b/apps/cde/base/cde-worker-copyv2.yaml index 6f53b3c..5f3866d 100644 --- a/apps/cde/base/cde-worker-copyv2.yaml +++ b/apps/cde/base/cde-worker-copyv2.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/copyv2-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/copyv2-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-create-versions.yaml b/apps/cde/base/cde-worker-create-versions.yaml index eb7d2ee..27ddf6f 100644 --- a/apps/cde/base/cde-worker-create-versions.yaml +++ b/apps/cde/base/cde-worker-create-versions.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-create-versionsv2.yaml b/apps/cde/base/cde-worker-create-versionsv2.yaml index f18c63b..4303693 100644 --- a/apps/cde/base/cde-worker-create-versionsv2.yaml +++ b/apps/cde/base/cde-worker-create-versionsv2.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/createversionsv2-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/createversionsv2-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-markings.yaml b/apps/cde/base/cde-worker-markings.yaml index 1c25a0b..765dc82 100644 --- a/apps/cde/base/cde-worker-markings.yaml +++ b/apps/cde/base/cde-worker-markings.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-markingsv2.yaml b/apps/cde/base/cde-worker-markingsv2.yaml index 7b2d5d9..c15c5d1 100644 --- a/apps/cde/base/cde-worker-markingsv2.yaml +++ b/apps/cde/base/cde-worker-markingsv2.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/markingsv2-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/markingsv2-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-sign.yaml b/apps/cde/base/cde-worker-sign.yaml index 1b68839..2e88c6e 100644 --- a/apps/cde/base/cde-worker-sign.yaml +++ b/apps/cde/base/cde-worker-sign.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-signv2.yaml b/apps/cde/base/cde-worker-signv2.yaml index 72d76dc..81f5b88 100644 --- a/apps/cde/base/cde-worker-signv2.yaml +++ b/apps/cde/base/cde-worker-signv2.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/signv2-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/signv2-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde-worker-update-bundles.yaml b/apps/cde/base/cde-worker-update-bundles.yaml index 132d81b..71ecb01 100644 --- a/apps/cde/base/cde-worker-update-bundles.yaml +++ b/apps/cde/base/cde-worker-update-bundles.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_4.5.0 + _default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/apps/cde/base/cde.yaml b/apps/cde/base/cde.yaml index bbc57ce..e567518 100644 --- a/apps/cde/base/cde.yaml +++ b/apps/cde/base/cde.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/cde:production_54ec2a86 + _default: cr.yandex/crp3ccidau046kdj8g9q/cde:preprod_4302d8f3 pullPolicy: _default: IfNotPresent diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 723e0fa..467da65 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -357,6 +357,29 @@ spec: rewrite: /eav/admin/ service: backend-svc.eav.svc.cluster.local port: 80 + cde-api: + name: cde-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /orchestrator/api/process/ + rewrite: /api/process/ + service: cde-svc.cde.svc.cluster.local + port: 80 + - path: + prefix: /orchestrator/api/sign + rewrite: /api/sign + service: cde-svc.cde.svc.cluster.local + port: 80 + - path: + prefix: /orchestrator/ + rewrite: /api/ + service: cde-svc.cde.svc.cluster.local + port: 80 srx-admin-frontend: name: srx-admin-frontend-virt-service namespace: default From d86bc2fbc568f6a9a06f2e5040eab864f8aada3f Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 14:49:07 +0500 Subject: [PATCH 33/51] ++ --- apps/cde/base/cde-flowscallback.yaml | 4 ++-- apps/cde/base/cde-splitpdf.yaml | 4 ++-- apps/cde/base/cde-worker-alert.yaml | 4 ++-- apps/cde/base/cde-worker-copy.yaml | 4 ++-- apps/cde/base/cde-worker-copyv2.yaml | 4 ++-- apps/cde/base/cde-worker-create-versions.yaml | 4 ++-- apps/cde/base/cde-worker-create-versionsv2.yaml | 4 ++-- apps/cde/base/cde-worker-markings.yaml | 4 ++-- apps/cde/base/cde-worker-markingsv2.yaml | 4 ++-- apps/cde/base/cde-worker-sign.yaml | 4 ++-- apps/cde/base/cde-worker-signv2.yaml | 4 ++-- apps/cde/base/cde-worker-update-bundles.yaml | 4 ++-- apps/cde/base/cde.yaml | 4 ++-- 13 files changed, 26 insertions(+), 26 deletions(-) diff --git a/apps/cde/base/cde-flowscallback.yaml b/apps/cde/base/cde-flowscallback.yaml index 70b6b51..f629edc 100644 --- a/apps/cde/base/cde-flowscallback.yaml +++ b/apps/cde/base/cde-flowscallback.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-splitpdf.yaml b/apps/cde/base/cde-splitpdf.yaml index 66651a8..044e1a3 100644 --- a/apps/cde/base/cde-splitpdf.yaml +++ b/apps/cde/base/cde-splitpdf.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-alert.yaml b/apps/cde/base/cde-worker-alert.yaml index 07bbe97..6cc5d01 100644 --- a/apps/cde/base/cde-worker-alert.yaml +++ b/apps/cde/base/cde-worker-alert.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-copy.yaml b/apps/cde/base/cde-worker-copy.yaml index 4208b49..e190b28 100644 --- a/apps/cde/base/cde-worker-copy.yaml +++ b/apps/cde/base/cde-worker-copy.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-copyv2.yaml b/apps/cde/base/cde-worker-copyv2.yaml index 5f3866d..2961697 100644 --- a/apps/cde/base/cde-worker-copyv2.yaml +++ b/apps/cde/base/cde-worker-copyv2.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "2" + _default: "1" memory: - _default: 4Gi + _default: 1Gi probes: liveness: diff --git a/apps/cde/base/cde-worker-create-versions.yaml b/apps/cde/base/cde-worker-create-versions.yaml index 27ddf6f..e67eb33 100644 --- a/apps/cde/base/cde-worker-create-versions.yaml +++ b/apps/cde/base/cde-worker-create-versions.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde-worker-create-versionsv2.yaml b/apps/cde/base/cde-worker-create-versionsv2.yaml index 4303693..2a0378a 100644 --- a/apps/cde/base/cde-worker-create-versionsv2.yaml +++ b/apps/cde/base/cde-worker-create-versionsv2.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde-worker-markings.yaml b/apps/cde/base/cde-worker-markings.yaml index 765dc82..bf01157 100644 --- a/apps/cde/base/cde-worker-markings.yaml +++ b/apps/cde/base/cde-worker-markings.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde-worker-markingsv2.yaml b/apps/cde/base/cde-worker-markingsv2.yaml index c15c5d1..4aff52e 100644 --- a/apps/cde/base/cde-worker-markingsv2.yaml +++ b/apps/cde/base/cde-worker-markingsv2.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde-worker-sign.yaml b/apps/cde/base/cde-worker-sign.yaml index 2e88c6e..eb64503 100644 --- a/apps/cde/base/cde-worker-sign.yaml +++ b/apps/cde/base/cde-worker-sign.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde-worker-signv2.yaml b/apps/cde/base/cde-worker-signv2.yaml index 81f5b88..fbbb009 100644 --- a/apps/cde/base/cde-worker-signv2.yaml +++ b/apps/cde/base/cde-worker-signv2.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde-worker-update-bundles.yaml b/apps/cde/base/cde-worker-update-bundles.yaml index 71ecb01..be24a12 100644 --- a/apps/cde/base/cde-worker-update-bundles.yaml +++ b/apps/cde/base/cde-worker-update-bundles.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: diff --git a/apps/cde/base/cde.yaml b/apps/cde/base/cde.yaml index e567518..b9e2f4e 100644 --- a/apps/cde/base/cde.yaml +++ b/apps/cde/base/cde.yaml @@ -70,9 +70,9 @@ spec: resources: requests: cpu: - _default: "1" + _default: 500m memory: - _default: 1Gi + _default: 512Mi probes: liveness: From 3dd3c125378bc280690567a9c426e87bafb050a8 Mon Sep 17 00:00:00 2001 From: ivan Date: Sat, 1 Aug 2026 15:13:48 +0500 Subject: [PATCH 34/51] ++ --- .../d8-ugmk-prod/istio-config.yaml | 67 ++++--------------- 1 file changed, 14 insertions(+), 53 deletions(-) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 467da65..3a1b7bf 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -14,52 +14,6 @@ spec: d8-ugmk-prod: istio: gateways: - camunda: - name: camunda-gateway - namespace: default - selector: - istio.deckhouse.io/ingress-gateway-class: istio - servers: - - hosts: - - camunda-keycloak.sarex-k8s.uralmine.com - tls: - credentialName: istio-ingress-tls - - hosts: - - camunda-identity.sarex-k8s.uralmine.com - tls: - credentialName: istio-ingress-tls - - hosts: - - camunda-operate.sarex-k8s.uralmine.com - tls: - credentialName: istio-ingress-tls - - hosts: - - camunda-tasklist.sarex-k8s.uralmine.com - tls: - credentialName: istio-ingress-tls - - hosts: - - camunda-optimize.sarex-k8s.uralmine.com - tls: - credentialName: istio-ingress-tls - rabbitmq: - name: rabbitmq-gateway - namespace: default - selector: - istio.deckhouse.io/ingress-gateway-class: istio - servers: - - hosts: - - rabbitmq.sarex-k8s.uralmine.com - tls: - credentialName: istio-ingress-tls - zitadel: - name: zitadel-gateway - namespace: default - selector: - istio.deckhouse.io/ingress-gateway-class: istio - servers: - - hosts: - - sarex-login.uralmine.com - tls: - credentialName: istio-ingress-tls platform: name: platform-gateway namespace: default @@ -68,6 +22,13 @@ spec: servers: - hosts: - sarex.uralmine.com + - sarex-login.uralmine.com + - rabbitmq.sarex-k8s.uralmine.com + - camunda-keycloak.sarex-k8s.uralmine.com + - camunda-identity.sarex-k8s.uralmine.com + - camunda-operate.sarex-k8s.uralmine.com + - camunda-tasklist.sarex-k8s.uralmine.com + - camunda-optimize.sarex-k8s.uralmine.com tls: credentialName: istio-ingress-tls virtualServices: @@ -398,7 +359,7 @@ spec: hosts: - camunda-keycloak.sarex-k8s.uralmine.com gateways: - - default/camunda-gateway + - default/platform-gateway routes: - path: prefix: / @@ -409,7 +370,7 @@ spec: hosts: - camunda-identity.sarex-k8s.uralmine.com gateways: - - default/camunda-gateway + - default/platform-gateway routes: - path: prefix: / @@ -420,7 +381,7 @@ spec: hosts: - camunda-operate.sarex-k8s.uralmine.com gateways: - - default/camunda-gateway + - default/platform-gateway routes: - path: prefix: / @@ -431,7 +392,7 @@ spec: hosts: - camunda-tasklist.sarex-k8s.uralmine.com gateways: - - default/camunda-gateway + - default/platform-gateway routes: - path: prefix: / @@ -442,7 +403,7 @@ spec: hosts: - camunda-optimize.sarex-k8s.uralmine.com gateways: - - default/camunda-gateway + - default/platform-gateway routes: - path: prefix: / @@ -453,7 +414,7 @@ spec: hosts: - rabbitmq.sarex-k8s.uralmine.com gateways: - - default/rabbitmq-gateway + - default/platform-gateway routes: - path: prefix: / @@ -464,7 +425,7 @@ spec: hosts: - sarex-login.uralmine.com gateways: - - default/zitadel-gateway + - default/platform-gateway routes: - path: prefix: / From c14d74050fe4a2a2a5234348ee9b741ef51e62d1 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 00:36:36 +0500 Subject: [PATCH 35/51] ++ --- apps/processing/base/rbac.yaml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/apps/processing/base/rbac.yaml b/apps/processing/base/rbac.yaml index 1661e08..32eaca5 100644 --- a/apps/processing/base/rbac.yaml +++ b/apps/processing/base/rbac.yaml @@ -17,6 +17,14 @@ rules: - update - patch - delete + - apiGroups: + - "" + resources: + - pods + verbs: + - get + - list + - watch --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding From 6c81ba0080d964836d4d5cf7847adc877e962125 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 00:41:18 +0500 Subject: [PATCH 36/51] ++ --- .../istio-config/d8-ugmk-prod/istio-config.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 3a1b7bf..309cb08 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -150,6 +150,19 @@ spec: rewrite: /api/ service: backend-api-svc.documentations.svc.cluster.local port: 80 + workspaces-api: + name: workspaces-api-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /workspaces/api/ + rewrite: /api/ + service: backend-svc.workspaces.svc.cluster.local + port: 80 gateway-platform: name: pdm-virt-service namespace: default From 38219249b31312119e301c36cf420b5b8671656a Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 00:44:21 +0500 Subject: [PATCH 37/51] ++ --- apps/django/base/frontend.yaml | 28 ++++++++++++++-------------- 1 file changed, 14 insertions(+), 14 deletions(-) diff --git a/apps/django/base/frontend.yaml b/apps/django/base/frontend.yaml index d560621..1059d1e 100644 --- a/apps/django/base/frontend.yaml +++ b/apps/django/base/frontend.yaml @@ -85,17 +85,17 @@ spec: path: _default: nginx.conf - # - name: zitadel-configmap - # mountPath: - # _default: /opt/react_client/static/config.json - # subPath: - # _default: config.json - # readOnly: - # _default: true - # configMap: - # name: - # _default: zitadel-configmap - # items: - # - key: config.json - # path: - # _default: config.json + - name: zitadel-configmap + mountPath: + _default: /opt/react_client/static/config.json + subPath: + _default: config.json + readOnly: + _default: true + configMap: + name: + _default: zitadel-configmap + items: + - key: config.json + path: + _default: config.json From 325aad49da3dc162cb0987ed261c46ea46752266 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 00:50:33 +0500 Subject: [PATCH 38/51] ++ --- .../istio-config/d8-ugmk-prod/istio-config.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 309cb08..b1559c4 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -215,6 +215,19 @@ spec: rewrite: / service: frontend-svc.issues.svc.cluster.local port: 80 + auth-frontend: + name: auth-frontend-virt-service + namespace: default + hosts: + - sarex.uralmine.com + gateways: + - default/platform-gateway + routes: + - path: + prefix: /auth/callback/ + rewrite: / + service: frontend-svc.auth-flow.svc.cluster.local + port: 80 flows-frontend: name: flows-frontend-virt-service namespace: default From 9cb672cf34e1939daa208b1c6aab84432a84725a Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:10:27 +0500 Subject: [PATCH 39/51] ++ --- apps/django/d8-ugmk-prod/backend.yaml | 20 +++++++++++++++++++ apps/django/d8-ugmk-prod/kustomization.yaml | 7 ++++++- .../d8-ugmk-prod/istio-config.yaml | 2 +- 3 files changed, 27 insertions(+), 2 deletions(-) create mode 100644 apps/django/d8-ugmk-prod/backend.yaml diff --git a/apps/django/d8-ugmk-prod/backend.yaml b/apps/django/d8-ugmk-prod/backend.yaml new file mode 100644 index 0000000..874de99 --- /dev/null +++ b/apps/django/d8-ugmk-prod/backend.yaml @@ -0,0 +1,20 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: backend + namespace: django +spec: + values: + services: + backend: + envs: + - name: SERVER_API_HOST + value: + _default: https://sarex.uralmine.com + - name: SERVER_HOST + value: + _default: https://sarex.uralmine.com + - name: ZITADEL_HOST + value: + _default: https://sarex-login.uralmine.com diff --git a/apps/django/d8-ugmk-prod/kustomization.yaml b/apps/django/d8-ugmk-prod/kustomization.yaml index 4956ad3..5296a3f 100644 --- a/apps/django/d8-ugmk-prod/kustomization.yaml +++ b/apps/django/d8-ugmk-prod/kustomization.yaml @@ -3,4 +3,9 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization namespace: django resources: - - ../base \ No newline at end of file + - ../base +patches: + - path: backend.yaml + target: + kind: HelmRelease + name: backend \ No newline at end of file diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index b1559c4..b181dd6 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -224,7 +224,7 @@ spec: - default/platform-gateway routes: - path: - prefix: /auth/callback/ + prefix: /auth/callback rewrite: / service: frontend-svc.auth-flow.svc.cluster.local port: 80 From f5e278fbbf21b0a01ceb57cdc22bd560f022fd26 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:20:01 +0500 Subject: [PATCH 40/51] ++ --- apps/documentations/base/api.yaml | 2 +- apps/documentations/d8-ugmk-prod/api.yaml | 20 +++++++++++++++++++ .../d8-ugmk-prod/filestream.yaml | 20 +++++++++++++++++++ .../d8-ugmk-prod/kustomization.yaml | 11 +++++++++- 4 files changed, 51 insertions(+), 2 deletions(-) create mode 100644 apps/documentations/d8-ugmk-prod/api.yaml create mode 100644 apps/documentations/d8-ugmk-prod/filestream.yaml diff --git a/apps/documentations/base/api.yaml b/apps/documentations/base/api.yaml index c0470f8..09d3372 100644 --- a/apps/documentations/base/api.yaml +++ b/apps/documentations/base/api.yaml @@ -96,7 +96,7 @@ spec: _default: zitadel-srx.wb.ru - name: USE_ZITADEL value: - _default: "0" + _default: "1" - name: FLOWS_URL value: _default: http://backend-svc.flows.svc.cluster.local:80 diff --git a/apps/documentations/d8-ugmk-prod/api.yaml b/apps/documentations/d8-ugmk-prod/api.yaml new file mode 100644 index 0000000..1e247c9 --- /dev/null +++ b/apps/documentations/d8-ugmk-prod/api.yaml @@ -0,0 +1,20 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentations-api + namespace: documentations +spec: + values: + services: + backend: + envs: + - name: ZITADEL_DOMAIN + value: + _default: sarex-login.uralmine.com + - name: WORKSPACE_V2_EXTERNAL_URL + value: + _default: https://sarex.uralmine.com/workspaces-v2/ + - name: FILE_STREAM_HOST + value: + _default: sarex.uralmine.com diff --git a/apps/documentations/d8-ugmk-prod/filestream.yaml b/apps/documentations/d8-ugmk-prod/filestream.yaml new file mode 100644 index 0000000..a615728 --- /dev/null +++ b/apps/documentations/d8-ugmk-prod/filestream.yaml @@ -0,0 +1,20 @@ +--- +apiVersion: helm.toolkit.fluxcd.io/v2 +kind: HelmRelease +metadata: + name: documentations-filestream + namespace: documentations +spec: + values: + services: + backend: + envs: + - name: ZITADEL_DOMAIN + value: + _default: sarex-login.uralmine.com + - name: WORKSPACE_V2_EXTERNAL_URL + value: + _default: https://sarex.uralmine.com/workspaces-v2/ + - name: FILE_STREAM_HOST + value: + _default: sarex.uralmine.com diff --git a/apps/documentations/d8-ugmk-prod/kustomization.yaml b/apps/documentations/d8-ugmk-prod/kustomization.yaml index 87e17f7..56d6b60 100644 --- a/apps/documentations/d8-ugmk-prod/kustomization.yaml +++ b/apps/documentations/d8-ugmk-prod/kustomization.yaml @@ -3,4 +3,13 @@ apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization namespace: documentations resources: - - ../base \ No newline at end of file + - ../base +patches: + - path: api.yaml + target: + kind: HelmRelease + name: documentations-api + - path: filestream.yaml + target: + kind: HelmRelease + name: documentations-filestream \ No newline at end of file From e069f38cb56f094fde3814a88b72d8e903b67c96 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:32:18 +0500 Subject: [PATCH 41/51] ++ --- apps/django/d8-ugmk-prod/backend.yaml | 120 +++++++++++++++++ apps/documentations/d8-ugmk-prod/api.yaml | 126 ++++++++++++++++++ .../d8-ugmk-prod/filestream.yaml | 126 ++++++++++++++++++ 3 files changed, 372 insertions(+) diff --git a/apps/django/d8-ugmk-prod/backend.yaml b/apps/django/d8-ugmk-prod/backend.yaml index 874de99..dde6df0 100644 --- a/apps/django/d8-ugmk-prod/backend.yaml +++ b/apps/django/d8-ugmk-prod/backend.yaml @@ -9,12 +9,132 @@ spec: services: backend: envs: + - name: ALLOWED_HOSTS + value: + _default: "*" + - name: SERVER_USE_CHANGELOG + value: + _default: "0" + - name: SERVER_ZITADEL_ENABLED + value: + _default: "True" + - name: DJANGO_SETTINGS_MODULE + value: + _default: config.settings.production + - name: CELERY_REDIS_HOST + value: + _default: redis + - name: CELERY_REDIS_PORT + value: + _default: "6379" + - name: DJANGO_REDIS_HOST + value: + _default: redis + - name: SERVER_EXTERNAL_FIND_BY_USERNAME_ENABLED + value: + _default: "True" + - name: SERVER_EXTERNAL_FIND_BY_EMAIL_ENABLED + value: + _default: "True" + - name: DJANGO_REDIS_PORT + value: + _default: "6379" + - name: BIMV2_INTERNAL_HOST + value: + _default: http://bim-backend-v2-service.bim-api + - name: BIMV2_TIMEOUT + value: + _default: "60" + - name: JWT_KID + value: + _default: "1" + - name: PDM_SYNC + value: + _default: "1" + - name: KC_SYNC_ENABLE + value: + _default: "0" + - name: MEASUREMENTS_HOST + value: + _default: http://measurements-service.measurements.svc.cluster.local:8000/api + - name: MEASUREMENTS_USE_MEASUREMENTS + value: + _default: "1" - name: SERVER_API_HOST value: _default: https://sarex.uralmine.com - name: SERVER_HOST value: _default: https://sarex.uralmine.com + - name: WORKFLOWS_HOST + value: + _default: http://backend-svc.processing.svc.cluster.local:80 + - name: WORKFLOWS_BASE_HOST + value: + _default: http://backend-svc.django.svc.cluster.local:80 + - name: WORKFLOWS_PREFIX + value: + _default: /internal/v1 + - name: WORKFLOWS_USE + value: + _default: "1" + - name: SERVER_S3_STREAM_IMPORT + value: + _default: "1" + - name: SERVER_SAVE_DIFF_DEM + value: + _default: "1" + - name: SERVER_USE_CLICKHOUSE + value: + _default: "0" + - name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK + value: + _default: "0" + - name: SERVER_USE_DJANGO_STORAGE + value: + _default: "1" + - name: SERVER_USE_METASHAPE + value: + _default: "0" + - name: SERVER_CHANGELOG_MODE_SYSTEM_LOG + value: + _default: "1" + - name: SERVER_CHANGELOG_MODE + value: + _default: "0" + - name: SERVER_DJANGO_URLS + value: + _default: "1" + - name: CHECK_IMPORT_HASH + value: + _default: "1" + - name: EAV_ENABLE + value: + _default: "1" + - name: SERVER_CHECK_IMPORT_HASH + value: + _default: "1" + - name: SERVER_CHUNKED_PATH + value: + _default: /tmp/chunked_uploads/%Y/%m/%d + - name: SERVER_HIDE_USER_SCROLL_PERMISSIONS + value: + _default: "0" + - name: SERVER_USE_WRORKFLOW_STATUS + value: + _default: "1" - name: ZITADEL_HOST value: _default: https://sarex-login.uralmine.com + - name: SERVER_KAFKA_ENABLED + value: + _default: "False" + - name: KAFKA_TOPICS + value: + _default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}' + - name: KAFKA_SSL_CAFILE + value: + _default: /usr/local/share/ca-certificates/kafka.crt + - name: KC_USE_REDIRECT_LOGOUT + value: + _default: "False" diff --git a/apps/documentations/d8-ugmk-prod/api.yaml b/apps/documentations/d8-ugmk-prod/api.yaml index 1e247c9..c5b7350 100644 --- a/apps/documentations/d8-ugmk-prod/api.yaml +++ b/apps/documentations/d8-ugmk-prod/api.yaml @@ -9,12 +9,138 @@ spec: services: backend: envs: + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: ZITADEL_ACCOUNT + value: + _default: /vault/secrets/documentations-zitadel-account-json - name: ZITADEL_DOMAIN value: _default: sarex-login.uralmine.com + - name: USE_ZITADEL + value: + _default: "1" + - name: FLOWS_URL + value: + _default: http://backend-svc.flows.svc.cluster.local:80 + - name: LAST_MASTER_BIM + value: + _default: "36311" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8080 + - name: API_ADDRESS_FILE + value: + _default: 0.0.0.0:8080 + - name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES + value: + _default: "5" + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_SSL + value: + _default: "0" - name: WORKSPACE_V2_EXTERNAL_URL value: _default: https://sarex.uralmine.com/workspaces-v2/ + - name: ENABLE_S3 + value: + _default: "1" + - name: CONTAINER_REGISTRY + value: + _default: cr.yandex/crp3ccidau046kdj8g9q + - name: ENVIRONMENT + value: + _default: production + - name: LAST_SLAVE_1_BIM + value: + _default: "1000000" + - name: HOST + value: + _default: http://backend-api-svc.documentations.svc.cluster.local:80 - name: FILE_STREAM_HOST value: _default: sarex.uralmine.com + - name: DOCUMENTATION_URL + value: + _default: http://documentations-api.documentations.svc.cluster.local:80/ + - name: WORKFLOW_URL + value: + _default: http://backend-svc.processing.svc.cluster.local:80/ + - name: WORKSPACE_URL + value: + _default: http://backend-svc.workspaces.svc.cluster.local:80/ + - name: BIM_API_URL + value: + _default: http://bim-api-service.bim.svc.cluster.local:8080/ + - name: BIM_API_V2_URL + value: + _default: http://backend-service.bim.svc.cluster.local:8000/ + - name: WORKSPACE_BUNDLE_VERSION + value: + _default: v1 + - name: SYSTEM_LOG_URL + value: + _default: http://backend-svc.system-log.svc.cluster.local:80 + - name: DJANGO_HOST + value: + _default: http://backend-svc.django.svc.cluster.local:80 + - name: MARKS_PROCESSING_URL + value: + _default: http://marks-service:8000 + - name: PUBLIC_LINK_HOST + value: + _default: https://document-link-srx.wb.ru + - name: NAMESPACE + value: + _default: documentations + - name: DJANGO_ORIGINATOR + value: + _default: docs_prod + - name: WORKFLOW_IMAGES_VERSION + value: + _default: master + - name: WORKFLOWS_IMAGES_VERSION + value: + _default: master + - name: S3_SERVICE_ACCOUNT + value: + _default: /vault/secrets/documentations-s3-account-json + - name: READ_WRITE_TIMEOUT_FILE_STREAM + value: + _default: 6h + - name: CACHE_DEFAULT_EXPIRATION + value: + _default: 60s + - name: ENABLE_SMTP + value: + _default: "True" + - name: ENABLE_MAILGUN + value: + _default: "False" + - name: CACHE_CLEANUP_INTERVAL + value: + _default: 60s + - name: DOCUMENT_PUBLIC_LINK_JWT_SECRET + value: + _default: "mock" + - name: ENABLE_AUTH_JWT_IN_URL + value: + _default: "true" + - name: ENABLE_SIGNATURE_IN_URL + value: + _default: "false" + - name: USE_CACHE_IN_FILE_STREAMER + value: + _default: "0" + - name: VALKEY_ADDR + value: + _default: redis:6379 + - name: VALKEY_HOST + value: + _default: redis + - name: VALKEY_PORT + value: + _default: "6379" diff --git a/apps/documentations/d8-ugmk-prod/filestream.yaml b/apps/documentations/d8-ugmk-prod/filestream.yaml index a615728..815c6f3 100644 --- a/apps/documentations/d8-ugmk-prod/filestream.yaml +++ b/apps/documentations/d8-ugmk-prod/filestream.yaml @@ -9,12 +9,138 @@ spec: services: backend: envs: + - name: POSTGRES_POOL_SIZE + value: + _default: "20" + - name: ZITADEL_ACCOUNT + value: + _default: /vault/secrets/documentations-zitadel-account-json - name: ZITADEL_DOMAIN value: _default: sarex-login.uralmine.com + - name: USE_ZITADEL + value: + _default: "0" + - name: FLOWS_URL + value: + _default: http://backend-svc.flows.svc.cluster.local:80 + - name: LAST_MASTER_BIM + value: + _default: "36311" + - name: API_ADDRESS + value: + _default: 0.0.0.0:8080 + - name: API_ADDRESS_FILE + value: + _default: 0.0.0.0:8080 + - name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES + value: + _default: "5" + - name: ENABLE_SQL_QUERY + value: + _default: "0" + - name: ENABLE_SSL + value: + _default: "0" - name: WORKSPACE_V2_EXTERNAL_URL value: _default: https://sarex.uralmine.com/workspaces-v2/ + - name: ENABLE_S3 + value: + _default: "1" + - name: CONTAINER_REGISTRY + value: + _default: cr.yandex/crp3ccidau046kdj8g9q + - name: ENVIRONMENT + value: + _default: production + - name: LAST_SLAVE_1_BIM + value: + _default: "1000000" + - name: HOST + value: + _default: http://backend-api-svc.documentations.svc.cluster.local:80 - name: FILE_STREAM_HOST value: _default: sarex.uralmine.com + - name: DOCUMENTATION_URL + value: + _default: http://backend-api-svc.documentations.svc.cluster.local:80/ + - name: WORKFLOW_URL + value: + _default: http://workflows-api-service.workflow.svc.cluster.local:8000/ + - name: WORKSPACE_URL + value: + _default: http://backend-svc.workspaces.svc.cluster.local:80/ + - name: BIM_API_URL + value: + _default: http://bim-api-service.bim.svc.cluster.local:8080/ + - name: BIM_API_V2_URL + value: + _default: http://backend-service.bim.svc.cluster.local:8000/ + - name: WORKSPACE_BUNDLE_VERSION + value: + _default: v1 + - name: SYSTEM_LOG_URL + value: + _default: http://api-service.system-log.svc.cluster.local:80 + - name: DJANGO_HOST + value: + _default: http://backend-svc.django.svc.cluster.local:80 + - name: MARKS_PROCESSING_URL + value: + _default: http://marks-service:8000 + - name: PUBLIC_LINK_HOST + value: + _default: https://document-link-srx.wb.ru + - name: NAMESPACE + value: + _default: documentations + - name: DJANGO_ORIGINATOR + value: + _default: docs_prod + - name: WORKFLOW_IMAGES_VERSION + value: + _default: master + - name: WORKFLOWS_IMAGES_VERSION + value: + _default: master + - name: S3_SERVICE_ACCOUNT + value: + _default: /vault/secrets/documentations-s3-account-json + - name: READ_WRITE_TIMEOUT_FILE_STREAM + value: + _default: 6h + - name: CACHE_DEFAULT_EXPIRATION + value: + _default: 60s + - name: ENABLE_SMTP + value: + _default: "True" + - name: ENABLE_MAILGUN + value: + _default: "False" + - name: CACHE_CLEANUP_INTERVAL + value: + _default: 60s + - name: ENABLE_AUTH_JWT_IN_URL + value: + _default: "false" + - name: ENABLE_SIGNATURE_IN_URL + value: + _default: "true" + - name: DOCUMENT_PUBLIC_LINK_JWT_SECRET + value: + _default: "mock" + - name: USE_CACHE_IN_FILE_STREAMER + value: + _default: "0" + - name: VALKEY_ADDR + value: + _default: redis:6379 + - name: VALKEY_HOST + value: + _default: redis + - name: VALKEY_PORT + value: + _default: "6379" From 66cd1a599f817e9d4984957a3f2858d673f01790 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:39:54 +0500 Subject: [PATCH 42/51] ++ --- apps/django/base/zitadel-configmap.yaml | 4 ++-- apps/django/d8-ugmk-prod/kustomization.yaml | 6 +++++- apps/django/d8-ugmk-prod/zitadel-configmap.yaml | 14 ++++++++++++++ 3 files changed, 21 insertions(+), 3 deletions(-) create mode 100644 apps/django/d8-ugmk-prod/zitadel-configmap.yaml diff --git a/apps/django/base/zitadel-configmap.yaml b/apps/django/base/zitadel-configmap.yaml index 8398f6a..8b71cec 100644 --- a/apps/django/base/zitadel-configmap.yaml +++ b/apps/django/base/zitadel-configmap.yaml @@ -8,8 +8,8 @@ data: { "auth_type": "zitadel", "zitadel": { - "client_id": "383923818340615274", - "host": "https://sarex-login.uralmine.com" + "client_id": "379557107642492501", + "host": "https://zitadel.contour.infra.sarex.tech" } } diff --git a/apps/django/d8-ugmk-prod/kustomization.yaml b/apps/django/d8-ugmk-prod/kustomization.yaml index 5296a3f..84d7732 100644 --- a/apps/django/d8-ugmk-prod/kustomization.yaml +++ b/apps/django/d8-ugmk-prod/kustomization.yaml @@ -8,4 +8,8 @@ patches: - path: backend.yaml target: kind: HelmRelease - name: backend \ No newline at end of file + name: backend + - path: zitadel-configmap.yaml + target: + kind: ConfigMap + name: zitadel-configmap \ No newline at end of file diff --git a/apps/django/d8-ugmk-prod/zitadel-configmap.yaml b/apps/django/d8-ugmk-prod/zitadel-configmap.yaml new file mode 100644 index 0000000..243b1bc --- /dev/null +++ b/apps/django/d8-ugmk-prod/zitadel-configmap.yaml @@ -0,0 +1,14 @@ +apiVersion: v1 +kind: ConfigMap +metadata: + name: zitadel-configmap + namespace: django +data: + config.json: | + { + "auth_type": "zitadel", + "zitadel": { + "client_id": "383923818340615274", + "host": "https://sarex-login.uralmine.com" + } + } From 278919eadec077faff401bfe0d484cf7eed37910 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:40:23 +0500 Subject: [PATCH 43/51] ++ --- apps/eav/base/django-configmap.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/eav/base/django-configmap.yaml b/apps/eav/base/django-configmap.yaml index 09ebaf5..040349e 100644 --- a/apps/eav/base/django-configmap.yaml +++ b/apps/eav/base/django-configmap.yaml @@ -103,7 +103,7 @@ data: "django_filters.rest_framework.DjangoFilterBackend" ], "DEFAULT_AUTHENTICATION_CLASSES": [ - #"core.auth.ZitadelJWTAuthentication", + "core.auth.ZitadelJWTAuthentication", "rest_framework_simplejwt.authentication.JWTStatelessUserAuthentication", #"rest_framework_simplejwt.authentication.JWTAuthentication", #"rest_framework.authentication.SessionAuthentication", From a99d93f41fd944bc8e32d2057de7077361b78c7c Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:44:15 +0500 Subject: [PATCH 44/51] ++ --- apps/documentations/base/filestream.yaml | 2 +- apps/documentations/d8-ugmk-prod/filestream.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/documentations/base/filestream.yaml b/apps/documentations/base/filestream.yaml index c72314d..3b5d94a 100644 --- a/apps/documentations/base/filestream.yaml +++ b/apps/documentations/base/filestream.yaml @@ -96,7 +96,7 @@ spec: _default: zitadel-srx.wb.ru - name: USE_ZITADEL value: - _default: "0" + _default: "1" - name: FLOWS_URL value: _default: http://backend-svc.flows.svc.cluster.local:80 diff --git a/apps/documentations/d8-ugmk-prod/filestream.yaml b/apps/documentations/d8-ugmk-prod/filestream.yaml index 815c6f3..a4892b9 100644 --- a/apps/documentations/d8-ugmk-prod/filestream.yaml +++ b/apps/documentations/d8-ugmk-prod/filestream.yaml @@ -20,7 +20,7 @@ spec: _default: sarex-login.uralmine.com - name: USE_ZITADEL value: - _default: "0" + _default: "1" - name: FLOWS_URL value: _default: http://backend-svc.flows.svc.cluster.local:80 From 5ea61bd5081a51697af1b5c001563c1ee46938ce Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:52:18 +0500 Subject: [PATCH 45/51] ++ --- apps/documentations/base/api.yaml | 3 +++ apps/documentations/d8-ugmk-prod/api.yaml | 3 +++ apps/workspaces/base/frontend.yaml | 2 +- 3 files changed, 7 insertions(+), 1 deletion(-) diff --git a/apps/documentations/base/api.yaml b/apps/documentations/base/api.yaml index 09d3372..20d21b2 100644 --- a/apps/documentations/base/api.yaml +++ b/apps/documentations/base/api.yaml @@ -88,6 +88,9 @@ spec: - name: POSTGRES_POOL_SIZE value: _default: "20" + - name: USE_LEGACY_BIM_FLOW + value: + _default: "true" - name: ZITADEL_ACCOUNT value: _default: /vault/secrets/documentations-zitadel-account-json diff --git a/apps/documentations/d8-ugmk-prod/api.yaml b/apps/documentations/d8-ugmk-prod/api.yaml index c5b7350..316e7fc 100644 --- a/apps/documentations/d8-ugmk-prod/api.yaml +++ b/apps/documentations/d8-ugmk-prod/api.yaml @@ -30,6 +30,9 @@ spec: - name: API_ADDRESS value: _default: 0.0.0.0:8080 + - name: USE_LEGACY_BIM_FLOW + value: + _default: "true" - name: API_ADDRESS_FILE value: _default: 0.0.0.0:8080 diff --git a/apps/workspaces/base/frontend.yaml b/apps/workspaces/base/frontend.yaml index 84bb622..a96f0da 100644 --- a/apps/workspaces/base/frontend.yaml +++ b/apps/workspaces/base/frontend.yaml @@ -29,7 +29,7 @@ spec: enabled: true image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/workspaces-v2-frontend:contour_7f95769f + _default: cr.yandex/crp3ccidau046kdj8g9q/workspaces-v2-frontend:contour_2a4ce3fd pullPolicy: _default: IfNotPresent deployment: From c5ccafa21ff661a1d40090bfe85964e36111209b Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 01:53:05 +0500 Subject: [PATCH 46/51] ++ --- apps/bim/base/backend.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/apps/bim/base/backend.yaml b/apps/bim/base/backend.yaml index bb212b2..de46d82 100644 --- a/apps/bim/base/backend.yaml +++ b/apps/bim/base/backend.yaml @@ -168,7 +168,7 @@ spec: - name: DJANGO_HOST value: - _default: "http://backend.django.svc.cluster.local:8000" + _default: "http://backend-svc.django.svc.cluster.local:80" - name: ENABLE_SQL_QUERY value: From c05003f1842e27f13ff08741e76e0d6ec383f5f1 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 02:05:07 +0500 Subject: [PATCH 47/51] ++ --- apps/documentations/base/api.yaml | 4 ++-- apps/documentations/base/filestream.yaml | 4 ++-- apps/documentations/d8-ugmk-prod/api.yaml | 4 ++-- apps/documentations/d8-ugmk-prod/filestream.yaml | 4 ++-- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/apps/documentations/base/api.yaml b/apps/documentations/base/api.yaml index 20d21b2..10657cd 100644 --- a/apps/documentations/base/api.yaml +++ b/apps/documentations/base/api.yaml @@ -153,10 +153,10 @@ spec: _default: http://backend-svc.workspaces.svc.cluster.local:80/ - name: BIM_API_URL value: - _default: http://bim-api-service.bim.svc.cluster.local:8080/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: BIM_API_V2_URL value: - _default: http://backend-service.bim.svc.cluster.local:8000/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: WORKSPACE_BUNDLE_VERSION value: _default: v1 diff --git a/apps/documentations/base/filestream.yaml b/apps/documentations/base/filestream.yaml index 3b5d94a..ffbd568 100644 --- a/apps/documentations/base/filestream.yaml +++ b/apps/documentations/base/filestream.yaml @@ -150,10 +150,10 @@ spec: _default: http://backend-svc.workspaces.svc.cluster.local:80/ - name: BIM_API_URL value: - _default: http://bim-api-service.bim.svc.cluster.local:8080/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: BIM_API_V2_URL value: - _default: http://backend-service.bim.svc.cluster.local:8000/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: WORKSPACE_BUNDLE_VERSION value: _default: v1 diff --git a/apps/documentations/d8-ugmk-prod/api.yaml b/apps/documentations/d8-ugmk-prod/api.yaml index 316e7fc..5b2e0ff 100644 --- a/apps/documentations/d8-ugmk-prod/api.yaml +++ b/apps/documentations/d8-ugmk-prod/api.yaml @@ -77,10 +77,10 @@ spec: _default: http://backend-svc.workspaces.svc.cluster.local:80/ - name: BIM_API_URL value: - _default: http://bim-api-service.bim.svc.cluster.local:8080/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: BIM_API_V2_URL value: - _default: http://backend-service.bim.svc.cluster.local:8000/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: WORKSPACE_BUNDLE_VERSION value: _default: v1 diff --git a/apps/documentations/d8-ugmk-prod/filestream.yaml b/apps/documentations/d8-ugmk-prod/filestream.yaml index a4892b9..a9ecae9 100644 --- a/apps/documentations/d8-ugmk-prod/filestream.yaml +++ b/apps/documentations/d8-ugmk-prod/filestream.yaml @@ -74,10 +74,10 @@ spec: _default: http://backend-svc.workspaces.svc.cluster.local:80/ - name: BIM_API_URL value: - _default: http://bim-api-service.bim.svc.cluster.local:8080/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: BIM_API_V2_URL value: - _default: http://backend-service.bim.svc.cluster.local:8000/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: WORKSPACE_BUNDLE_VERSION value: _default: v1 From 95f567a62b7af5366d20ad3740bf861879d88cd3 Mon Sep 17 00:00:00 2001 From: ivan Date: Sun, 2 Aug 2026 02:06:58 +0500 Subject: [PATCH 48/51] ++ --- apps/documentations/base/pdm.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/apps/documentations/base/pdm.yaml b/apps/documentations/base/pdm.yaml index b86f0ba..128c9c5 100644 --- a/apps/documentations/base/pdm.yaml +++ b/apps/documentations/base/pdm.yaml @@ -129,10 +129,10 @@ spec: _default: http://attachments-service.attachments.svc.cluster.local:8000 - name: BIM_API_V2_URL value: - _default: http://backend-service.bim.svc.cluster.local:8000/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: BIM_V2_HOST value: - _default: http://backend-service.bim.svc.cluster.local:8000/ + _default: http://backend-svc.bim.svc.cluster.local:80/ - name: CACHE_CLEANUP_INTERVAL value: _default: 60s From a4f1424403cb4e6fdadffef6e54dc57c9944bece Mon Sep 17 00:00:00 2001 From: Kochetkov S Date: Mon, 3 Aug 2026 10:56:18 +0300 Subject: [PATCH 49/51] ++ move uralmine service domains up one level --- .../istio-ingress/certificate.yaml | 3 +-- .../camunda/d8-ugmk-prod/camunda.yaml | 10 ++++---- .../d8-ugmk-prod/istio-config.yaml | 24 +++++++++---------- 3 files changed, 18 insertions(+), 19 deletions(-) diff --git a/clusters/d8-ugmk-prod/istio-ingress/certificate.yaml b/clusters/d8-ugmk-prod/istio-ingress/certificate.yaml index 6fb5625..d95d380 100644 --- a/clusters/d8-ugmk-prod/istio-ingress/certificate.yaml +++ b/clusters/d8-ugmk-prod/istio-ingress/certificate.yaml @@ -4,9 +4,8 @@ metadata: name: sarex-wildcard namespace: d8-ingress-istio spec: - commonName: "*.sarex-k8s.uralmine.com" + commonName: "*.uralmine.com" dnsNames: - - "*.sarex-k8s.uralmine.com" - "*.uralmine.com" issuerRef: group: cert-manager.io diff --git a/infrastructure/camunda/d8-ugmk-prod/camunda.yaml b/infrastructure/camunda/d8-ugmk-prod/camunda.yaml index 30d0764..19a4cf5 100644 --- a/infrastructure/camunda/d8-ugmk-prod/camunda.yaml +++ b/infrastructure/camunda/d8-ugmk-prod/camunda.yaml @@ -164,15 +164,15 @@ spec: - name: regcred identity: auth: - publicIssuerUrl: "https://camunda-keycloak.sarex-k8s.uralmine.com/auth/realms/camunda-platform" + publicIssuerUrl: "https://camunda-keycloak.uralmine.com/auth/realms/camunda-platform" identity: - redirectUrl: "https://camunda-identity.sarex-k8s.uralmine.com" + redirectUrl: "https://camunda-identity.uralmine.com" operate: - redirectUrl: "https://camunda-operate.sarex-k8s.uralmine.com" + redirectUrl: "https://camunda-operate.uralmine.com" tasklist: - redirectUrl: "https://camunda-tasklist.sarex-k8s.uralmine.com" + redirectUrl: "https://camunda-tasklist.uralmine.com" optimize: - redirectUrl: "https://camunda-optimize.sarex-k8s.uralmine.com" + redirectUrl: "https://camunda-optimize.uralmine.com" webModeler: redirectUrl: "https://camunda-web-modeler.contour.infra.sarex.tech" console: diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index b181dd6..7acc76b 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -23,12 +23,12 @@ spec: - hosts: - sarex.uralmine.com - sarex-login.uralmine.com - - rabbitmq.sarex-k8s.uralmine.com - - camunda-keycloak.sarex-k8s.uralmine.com - - camunda-identity.sarex-k8s.uralmine.com - - camunda-operate.sarex-k8s.uralmine.com - - camunda-tasklist.sarex-k8s.uralmine.com - - camunda-optimize.sarex-k8s.uralmine.com + - rabbitmq.uralmine.com + - camunda-keycloak.uralmine.com + - camunda-identity.uralmine.com + - camunda-operate.uralmine.com + - camunda-tasklist.uralmine.com + - camunda-optimize.uralmine.com tls: credentialName: istio-ingress-tls virtualServices: @@ -383,7 +383,7 @@ spec: camunda-keycloak: namespace: default hosts: - - camunda-keycloak.sarex-k8s.uralmine.com + - camunda-keycloak.uralmine.com gateways: - default/platform-gateway routes: @@ -394,7 +394,7 @@ spec: camunda-identity: namespace: default hosts: - - camunda-identity.sarex-k8s.uralmine.com + - camunda-identity.uralmine.com gateways: - default/platform-gateway routes: @@ -405,7 +405,7 @@ spec: camunda-operate: namespace: default hosts: - - camunda-operate.sarex-k8s.uralmine.com + - camunda-operate.uralmine.com gateways: - default/platform-gateway routes: @@ -416,7 +416,7 @@ spec: camunda-tasklist: namespace: default hosts: - - camunda-tasklist.sarex-k8s.uralmine.com + - camunda-tasklist.uralmine.com gateways: - default/platform-gateway routes: @@ -427,7 +427,7 @@ spec: camunda-optimize: namespace: default hosts: - - camunda-optimize.sarex-k8s.uralmine.com + - camunda-optimize.uralmine.com gateways: - default/platform-gateway routes: @@ -438,7 +438,7 @@ spec: rabbitmq: namespace: default hosts: - - rabbitmq.sarex-k8s.uralmine.com + - rabbitmq.uralmine.com gateways: - default/platform-gateway routes: From fb30bab0b8abc63cd3880dbe62e4ea3778c3bc14 Mon Sep 17 00:00:00 2001 From: Kochetkov S Date: Mon, 3 Aug 2026 11:06:10 +0300 Subject: [PATCH 50/51] ++ prefix uralmine service domains with sarex --- .../camunda/d8-ugmk-prod/camunda.yaml | 10 ++++---- .../d8-ugmk-prod/istio-config.yaml | 24 +++++++++---------- 2 files changed, 17 insertions(+), 17 deletions(-) diff --git a/infrastructure/camunda/d8-ugmk-prod/camunda.yaml b/infrastructure/camunda/d8-ugmk-prod/camunda.yaml index 19a4cf5..2601400 100644 --- a/infrastructure/camunda/d8-ugmk-prod/camunda.yaml +++ b/infrastructure/camunda/d8-ugmk-prod/camunda.yaml @@ -164,15 +164,15 @@ spec: - name: regcred identity: auth: - publicIssuerUrl: "https://camunda-keycloak.uralmine.com/auth/realms/camunda-platform" + publicIssuerUrl: "https://sarex-camunda-keycloak.uralmine.com/auth/realms/camunda-platform" identity: - redirectUrl: "https://camunda-identity.uralmine.com" + redirectUrl: "https://sarex-camunda-identity.uralmine.com" operate: - redirectUrl: "https://camunda-operate.uralmine.com" + redirectUrl: "https://sarex-camunda-operate.uralmine.com" tasklist: - redirectUrl: "https://camunda-tasklist.uralmine.com" + redirectUrl: "https://sarex-camunda-tasklist.uralmine.com" optimize: - redirectUrl: "https://camunda-optimize.uralmine.com" + redirectUrl: "https://sarex-camunda-optimize.uralmine.com" webModeler: redirectUrl: "https://camunda-web-modeler.contour.infra.sarex.tech" console: diff --git a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml index 7acc76b..f50c455 100644 --- a/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml +++ b/infrastructure/istio-config/d8-ugmk-prod/istio-config.yaml @@ -23,12 +23,12 @@ spec: - hosts: - sarex.uralmine.com - sarex-login.uralmine.com - - rabbitmq.uralmine.com - - camunda-keycloak.uralmine.com - - camunda-identity.uralmine.com - - camunda-operate.uralmine.com - - camunda-tasklist.uralmine.com - - camunda-optimize.uralmine.com + - sarex-rabbitmq.uralmine.com + - sarex-camunda-keycloak.uralmine.com + - sarex-camunda-identity.uralmine.com + - sarex-camunda-operate.uralmine.com + - sarex-camunda-tasklist.uralmine.com + - sarex-camunda-optimize.uralmine.com tls: credentialName: istio-ingress-tls virtualServices: @@ -383,7 +383,7 @@ spec: camunda-keycloak: namespace: default hosts: - - camunda-keycloak.uralmine.com + - sarex-camunda-keycloak.uralmine.com gateways: - default/platform-gateway routes: @@ -394,7 +394,7 @@ spec: camunda-identity: namespace: default hosts: - - camunda-identity.uralmine.com + - sarex-camunda-identity.uralmine.com gateways: - default/platform-gateway routes: @@ -405,7 +405,7 @@ spec: camunda-operate: namespace: default hosts: - - camunda-operate.uralmine.com + - sarex-camunda-operate.uralmine.com gateways: - default/platform-gateway routes: @@ -416,7 +416,7 @@ spec: camunda-tasklist: namespace: default hosts: - - camunda-tasklist.uralmine.com + - sarex-camunda-tasklist.uralmine.com gateways: - default/platform-gateway routes: @@ -427,7 +427,7 @@ spec: camunda-optimize: namespace: default hosts: - - camunda-optimize.uralmine.com + - sarex-camunda-optimize.uralmine.com gateways: - default/platform-gateway routes: @@ -438,7 +438,7 @@ spec: rabbitmq: namespace: default hosts: - - rabbitmq.uralmine.com + - sarex-rabbitmq.uralmine.com gateways: - default/platform-gateway routes: From 4e59c76096524035bc02b7d580876cc97710b232 Mon Sep 17 00:00:00 2001 From: ivan Date: Mon, 3 Aug 2026 13:55:20 +0500 Subject: [PATCH 51/51] ++ --- apps/bim/base/backend.yaml | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/apps/bim/base/backend.yaml b/apps/bim/base/backend.yaml index de46d82..dc5c8e0 100644 --- a/apps/bim/base/backend.yaml +++ b/apps/bim/base/backend.yaml @@ -42,7 +42,7 @@ spec: image: name: - _default: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef + _default: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_f9f2a39 pullPolicy: _default: IfNotPresent @@ -193,22 +193,27 @@ spec: POSTGRES_ADDRESS_2={{ index .Data.data "host" }} POSTGRES_ADDRESS_3={{ index .Data.data "host" }} POSTGRES_ADDRESS_4={{ index .Data.data "host" }} + POSTGRES_ADDRESS_5={{ index .Data.data "host" }} POSTGRES_PORT={{ index .Data.data "port" }} POSTGRES_PORT_2={{ index .Data.data "port" }} POSTGRES_PORT_3={{ index .Data.data "port" }} POSTGRES_PORT_4={{ index .Data.data "port" }} + POSTGRES_PORT_5={{ index .Data.data "port" }} POSTGRES_DB={{ index .Data.data "database" }} POSTGRES_DB_2={{ index .Data.data "database" }} POSTGRES_DB_3={{ index .Data.data "database" }} POSTGRES_DB_4={{ index .Data.data "database" }} + POSTGRES_DB_5={{ index .Data.data "database" }} POSTGRES_USER={{ index .Data.data "username" }} POSTGRES_USER_2={{ index .Data.data "username" }} POSTGRES_USER_3={{ index .Data.data "username" }} POSTGRES_USER_4={{ index .Data.data "username" }} + POSTGRES_USER_5={{ index .Data.data "username" }} POSTGRES_PASSWORD={{ index .Data.data "password" }} POSTGRES_PASSWORD_2={{ index .Data.data "password" }} POSTGRES_PASSWORD_3={{ index .Data.data "password" }} POSTGRES_PASSWORD_4={{ index .Data.data "password" }} + POSTGRES_PASSWORD_5={{ index .Data.data "password" }} {{- end -}} commitSha: ""