universal-chart already injects proxy.istio.io/config and
traffic.sidecar.istio.io/excludeOutboundPorts by default for every
service — explicitly setting them too produced a duplicate-key YAML
error in Flux's post-render step:
error while running post render on files: ... yaml: unmarshal errors:
line 42: mapping key "traffic.sidecar.istio.io/excludeOutboundPorts" already defined at line 25
line 41: mapping key "proxy.istio.io/config" already defined at line 26
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.
Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.
infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>