Commit Graph

750 Commits

Author SHA1 Message Date
ivan
64fe3c00fb control-interface/admin-frontend: drop explicit podAnnotations
universal-chart already injects proxy.istio.io/config and
traffic.sidecar.istio.io/excludeOutboundPorts by default for every
service — explicitly setting them too produced a duplicate-key YAML
error in Flux's post-render step:

  error while running post render on files: ... yaml: unmarshal errors:
    line 42: mapping key "traffic.sidecar.istio.io/excludeOutboundPorts" already defined at line 25
    line 41: mapping key "proxy.istio.io/config" already defined at line 26

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:40:19 +05:00
ivan
5564778337 control-interface: add admin-frontend (universal-chart) to base, route it in vad istio-config
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.

Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.

infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:34:54 +05:00
ivan
0bd15c6ae5 ++ 2026-10-02 14:57:19 +05:00
ivan
e00a7905fb ++ 2026-10-02 14:51:30 +05:00
ivan
7531341438 ++ 2026-10-02 12:33:16 +05:00
ivan
6251cfed5c brusnika-stage: bring images and env vars up to wb level
Missing env vars copied from wb for ams-sync, attachments, bi/frontend,
checklists, django (celery, export-project, sarex-backend), documentations
(api, filestream, pdm), eav, flows (backend, celery, frontend), iam,
inspections, issues (backend, celery), rfi, transmittal/worker.

Image tags updated to match wb for flows (backend/celery/frontend), iam.

Known issue, not yet fixed in this commit: several of the copied env
values are wb-specific hosts (*.wb.ru, one uralmine.com) that don't apply
to brusnika-stage — ZITADEL_HOST/ZITADEL_DOMAIN (django, documentations,
iam), DATABASE_HOST/FLOWS_DB_HOST/ISSUES_DB_HOST (checklists, flows),
SUPERSET_HOST (bi), DJANGO_BASE_HOST/SAREX_BACKEND_URL (flows,
inspections), RESOURCES_INTERNAL_HOST/RESOURCE_URL (ams-sync, django,
flows, notes-related). To be corrected in a follow-up commit.

bi/backend.yaml, bim/backend.yaml and notes/backend.yaml were reverted
before this commit (image-tag updates for bi-backend/bim/notes and bi's
SUPERSET_* env additions are not included).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:04:55 +05:00
ivan
e4c3294bb8 ++ 2026-10-01 17:43:58 +05:00
diamondrigido
7cac4ff295 fix: update brusnika for copy 2026-09-30 17:17:53 +02:00
ivan
979e5c2a51 uralkal: clear CPU/memory requests for all 36 business apps
Every services.<svc>.deployment.resources.requests.{cpu,memory} across the
36 uralkal apps (69 HelmRelease/service entries total) is now nulled via a
kustomize patch, so Helm never renders a requests block for these pods on
uralkal — Kubernetes won't reserve CPU/memory for them there.

Where a uralkal patch already existed for that service (13 cases:
documentations api/filestream/pdf-markings-amqp, django backend, flows
backend/celery, pm backend/celery, transmittal backend/worker, bi,
document-link, stamp-verification, message-hub), the null block was added
into that same file. Where no uralkal patch existed yet (55 cases,
including all 13 cde workers and every plain frontend), a new minimal
patch file was added and wired into that app's kustomization.yaml.

vad and the other clusters are untouched — only apps/*/uralkal/* changed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-30 15:06:51 +03:00
ivan
b32e4667c1 ++ 2026-09-30 14:11:08 +03:00
ivan
f48a81f5c2 ++ 2026-09-30 11:10:45 +03:00
ivan
33664b0afb ++ 2026-09-30 11:10:45 +03:00
emelinda
4947d8b675 Merge remote-tracking branch 'origin/master'
# Conflicts:
#	apps/documentations/ugok/filestream.yaml
2026-09-29 10:44:18 +03:00
emelinda
f7ee2ab1af Update image versions for ugok services in api.yaml and filestream.yaml. 2026-09-29 10:43:48 +03:00
ivan
92efab2ecd ++ 2026-09-28 15:57:47 +03:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
ivan
6e8151fed6 ++ 2026-09-27 22:34:07 +03:00
ivan
954e0a7231 ++ 2026-09-27 21:44:39 +03:00
emelinda
cdaf20f7cc Add "Справочники" section to django-configmap navigation menu. 2026-09-24 21:26:42 +03:00
emelinda
380986659e Update backend worker image version in celery.yaml. 2026-09-24 21:17:39 +03:00
emelinda
21dcac2d1d Update frontend and backend image versions in deployment configurations. 2026-09-24 21:07:59 +03:00
ivan
f6df384388 added asterus 2026-09-23 23:36:27 +05:00
ivan
5ae853bbf2 asterus: deploy auth-flow
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 14:34:14 +05:00
ivan
a3f9fb5ee9 vad: pdf-markings-amqp hosts/bucket override, stamp-verification and document-link frontend images
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 13:03:29 +05:00
ivan
40f5552951 ++ 2026-09-22 12:00:31 +05:00
ivan
a5750ed220 ++ 2026-09-22 01:47:43 +05:00
ivan
48924262aa vad: contracts DB_URL from the Vault postgres secret (external database)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 17:31:50 +05:00
ivan
5c7369ed70 vad: replace kafka CA with the vad kafka-kafka-contour CA in flows, issues, pm, message-hub
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 15:54:05 +05:00
ivan
be6e8b26fb ++ 2026-09-21 15:28:12 +05:00
ivan
f648d01629 vad: iam zitadel org rules with the vad default org id
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:18:54 +05:00
ivan
a1afea5ae3 ++ 2026-09-18 17:56:09 +05:00
ivan
f62dfb037d vad: pm, message-hub, cde
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:37:49 +05:00
ivan
410fd96439 ++ 2026-09-17 21:08:16 +05:00
ivan
4edb8d1274 vad: faas, iam
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:07:13 +05:00
ivan
b0b6b65ec7 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal, cross-section, document-link, prescriptions, projects, stamp-verification
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:01:20 +05:00
ivan
11007c0bc6 vad: processing, flows, issues, bim
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:49:38 +05:00
ivan
d17d2548c2 vad: django, documentations
django's nginx-configmap is patched for vad: pm and processing aren't
deployed there yet (kept commented out), documentations is enabled
since it's going in alongside django this time.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:26:27 +05:00
ivan
82f12762fc vad: notes, rfi, checklists, contracts (postgres ready; S3 pending stage 2 for notes/rfi/contracts)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:52:31 +05:00
ivan
a10ee6b6d5 vad: eav (postgres ready, S3 secret pending stage 2 in terraform repo)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:17:35 +05:00
ivan
b5bd5b7dc4 vad: workspaces
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:22:47 +05:00
ivan
dabf7e1256 vad: add missing control-interface namespace
apps/control-interface/base has no namespace.yaml (unlike reviews,
remarks, auth-flow), so Flux failed applying the HelmRelease into a
namespace that was never created.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:02:00 +05:00
ivan
169e2294aa vad: reviews, remarks, auth-flow, control-interface
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 16:45:19 +05:00
ivan
8098edcc42 sarex-contour: bim, comparisons, drawings, inspections, mapper, measurements, notes, rfi, subscriptions, system-log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:17:33 +05:00
ivan
41fe17ee7f sarex-contour: cross-section, prescriptions, projects, remarks, reviews, stamp-verification
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 14:45:20 +05:00
ivan
0c354f6d2f sarex-contour: attachments, documentations
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:34:56 +05:00
ivan
2ecfbb6e94 sarex-contour: flows, issues, checklists, contracts
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:53:27 +05:00
ivan
24fa9db719 sarex-contour: remove explanatory comments
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:40:46 +05:00
ivan
04da33f73e ++ sarex-contour: eav, bi, auth-flow, document-link
Все 4 — чистое наследование base:
- eav, bi — vault-зависимости (postgres [+ eav также minio]) заведены
  через terraform (live/database, live/s3, applications-блок).
- auth-flow, document-link — чистые статические фронтенды без бэкенда
  (см. CLAUDE.md), вообще без vault-зависимостей.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:29:28 +05:00
4222cb164e ++ create bi namespace on brusnika-prod 2026-09-15 11:12:51 +03:00
ivan
b9a870618e ++ sarex-contour: django/frontend — закомментировать, не удалять
По просьбе: неподнятые в контуре сервисы (pm, documentations,
processing) остаются в конфиге закомментированными, а не вырезанными —
видно, что временно выключено, легко раскомментировать когда появятся.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 13:10:55 +05:00