apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).
infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.
clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.
infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.
apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Flux self-managed bootstrap files copied from ugok (controller images
already mirrored to cr.yandex), GitRepository/Kustomization pointed at
gitlab.sarex.io directly since the cluster has outbound internet access.
Starts with just flux-system + helm-repositories, infra/apps to be added
incrementally.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
django's nginx-configmap is patched for vad: pm and processing aren't
deployed there yet (kept commented out), documentations is enabled
since it's going in alongside django this time.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Все 4 — чистое наследование base:
- eav, bi — vault-зависимости (postgres [+ eav также minio]) заведены
через terraform (live/database, live/s3, applications-блок).
- auth-flow, document-link — чистые статические фронтенды без бэкенда
(см. CLAUDE.md), вообще без vault-зависимостей.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/django/sarex-contour — чистое наследование base (backend, celery,
frontend, srx-admin, s3-proxy, redis, конфигмапы). Все vault-пути
(apps/django/postgres, rabbitmq/apps/django, minio/apps/django,
kafka/apps/django, vault/common/{rsa_keys,django_auth}) заведены через
terraform в infra/terraform. S3-эндпоинт в манифестах base захардкожен
на несуществующий домен — деплою как есть, патчить по факту если
помешает подняться (как с rabbitmq/zitadel).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/workspaces/sarex-contour — чистое наследование base (backend +
frontend), replicaCount уже 1 в base, патчей не нужно. БД внешняя
(111.88.255.180) — заказана через terraform live/database, секрет
apps/workspaces/postgres заведён через vault-secrets applications-блок.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
infrastructure/zitadel/sarex-contour (chart idp-contour 4.12.13), по
образцу overlay vad: без dependsOn на postgresql (БД внешняя, отдельная
машина 111.88.255.180 — заказана через terraform live/database, не
in-cluster HelmRelease), postRenderer снимает nodeSelector с Deployment
+ 2 Job'ов и подменяет vault-agent template на свой (кладёт
Admin.Password/FirstInstance.Org.Human.Password из
secrets/data/zitadel/postgresql).
ExternalDomain — заглушка zitadel.sarex-contour.internal, istio-config
для внешнего доступа ещё не заведён.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
infrastructure/kafka/sarex-contour, infrastructure/rabbitmq/sarex-contour
(values по образцу yc-k8s-test, controller-only kafka KRaft, rabbitmq
1 реплика, local-path). Vault для них уже заведён отдельно (terraform
environments.sarex-contour.vault, kafka/rabbitmq policy+role+kv).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/control-interface/sarex-contour наследует base (по образцу
d8-ugmk-prod), namespace control-interface, istio-injection: enabled.
Оверлей yc-k8s-test для control-interface не копировали — там
namespace: django и патч на несуществующий HelmRelease srx-admin,
похоже на скопипащенный мёртвый код из apps/django/yc-k8s-test.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
vault уже стоял в кластере (helm CLI, chart 0.1.0, standalone/raft,
инициализирован, данных нет). Overlay infrastructure/vault/sarex-contour:
values как у прочих свежих контуров (regcred, backup off, standalone),
namespace istio-injection: disabled. helm-controller перенимает релиз
`vault` и апгрейдит до 0.2.3 (base). StatefulSet updateStrategy: OnDelete —
под не дёргается автоматически.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Новый кластер clusters/sarex-contour: flux-system (bootstrap на
gitlab.sarex.io, path ./clusters/sarex-contour), helm-repositories
(yc-oci-charts), раскатка istio-base/istiod/ingressgateway.
Gateway опубликован через NodePort 30080/30443 — в контуре нет
облачного LoadBalancer.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Не наследуют base (vault-native) — отдельные HelmRelease на universal-chart
с обычными secretEnvs, как остальные сервисы этих контуров. Свои хосты,
имена сервисов и kafka-bootstrap на контур; KAFKA_ENABLE=0, поэтому kafka
без секретов. Подключены к соответствующим clusters/*/kustomization.yaml.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>