Commit Graph

17 Commits

Author SHA1 Message Date
ivan
6251cfed5c brusnika-stage: bring images and env vars up to wb level
Missing env vars copied from wb for ams-sync, attachments, bi/frontend,
checklists, django (celery, export-project, sarex-backend), documentations
(api, filestream, pdm), eav, flows (backend, celery, frontend), iam,
inspections, issues (backend, celery), rfi, transmittal/worker.

Image tags updated to match wb for flows (backend/celery/frontend), iam.

Known issue, not yet fixed in this commit: several of the copied env
values are wb-specific hosts (*.wb.ru, one uralmine.com) that don't apply
to brusnika-stage — ZITADEL_HOST/ZITADEL_DOMAIN (django, documentations,
iam), DATABASE_HOST/FLOWS_DB_HOST/ISSUES_DB_HOST (checklists, flows),
SUPERSET_HOST (bi), DJANGO_BASE_HOST/SAREX_BACKEND_URL (flows,
inspections), RESOURCES_INTERNAL_HOST/RESOURCE_URL (ams-sync, django,
flows, notes-related). To be corrected in a follow-up commit.

bi/backend.yaml, bim/backend.yaml and notes/backend.yaml were reverted
before this commit (image-tag updates for bi-backend/bim/notes and bi's
SUPERSET_* env additions are not included).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:04:55 +05:00
ivan
979e5c2a51 uralkal: clear CPU/memory requests for all 36 business apps
Every services.<svc>.deployment.resources.requests.{cpu,memory} across the
36 uralkal apps (69 HelmRelease/service entries total) is now nulled via a
kustomize patch, so Helm never renders a requests block for these pods on
uralkal — Kubernetes won't reserve CPU/memory for them there.

Where a uralkal patch already existed for that service (13 cases:
documentations api/filestream/pdf-markings-amqp, django backend, flows
backend/celery, pm backend/celery, transmittal backend/worker, bi,
document-link, stamp-verification, message-hub), the null block was added
into that same file. Where no uralkal patch existed yet (55 cases,
including all 13 cde workers and every plain frontend), a new minimal
patch file was added and wired into that app's kustomization.yaml.

vad and the other clusters are untouched — only apps/*/uralkal/* changed.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-30 15:06:51 +03:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
ivan
410fd96439 ++ 2026-09-17 21:08:16 +05:00
ivan
b0b6b65ec7 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal, cross-section, document-link, prescriptions, projects, stamp-verification
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:01:20 +05:00
ivan
04da33f73e ++ sarex-contour: eav, bi, auth-flow, document-link
Все 4 — чистое наследование base:
- eav, bi — vault-зависимости (postgres [+ eav также minio]) заведены
  через terraform (live/database, live/s3, applications-блок).
- auth-flow, document-link — чистые статические фронтенды без бэкенда
  (см. CLAUDE.md), вообще без vault-зависимостей.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:29:28 +05:00
4222cb164e ++ create bi namespace on brusnika-prod 2026-09-15 11:12:51 +03:00
ivan
7bb62c8665 ++ 2026-09-14 16:40:55 +05:00
ivan
2b4f3af18e ++ 2026-09-10 13:23:12 +05:00
ivan
310835285a ++ 2026-09-10 13:07:22 +05:00
ivan
b441d1c913 ++ 2026-08-31 23:46:11 +05:00
ivan
37063d38e1 feat(bi): standalone-оверлеи bi для ugok, brusnika-stage, brusnika-prod
Не наследуют base (vault-native) — отдельные HelmRelease на universal-chart
с обычными secretEnvs, как остальные сервисы этих контуров. Свои хосты,
имена сервисов и kafka-bootstrap на контур; KAFKA_ENABLE=0, поэтому kafka
без секретов. Подключены к соответствующим clusters/*/kustomization.yaml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 19:51:23 +05:00
ivan
0cfb386c90 fix(bi): bi-backend слушает :8000, не :80
Приложение (gunicorn/uvicorn) биндится на 0.0.0.0:8000. Service targetPort
и containerPort были 80 -> istio -> svc:80 -> pod:80 (никто не слушает) -> 503.
targetPort и deployment.port -> 8000, service.port остаётся 80 (в него бьёт VS).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 17:04:23 +05:00
ivan
0c7f1f63e9 ++ 2026-08-31 16:56:22 +05:00
ivan
ce5280bef1 ++ 2026-08-31 16:33:57 +05:00
ivan
55156efab2 ++ 2026-08-31 16:23:28 +05:00
ivan
d3a973adea feat(bi): новое приложение bi (ns bi) на universal-chart + подключение к d8-ugmk-prod
apps/bi/base — bi-backend (vault-native, SA bi-vault) и bi-frontend.
apps/bi/d8-ugmk-prod — патч env под контур УГМК (хосты issues/eav/pm,
AUTH_HOST, kafka), namespace с deckhouse pod-policy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:08:29 +05:00