Commit Graph

559 Commits

Author SHA1 Message Date
1fe6cb2eba ++ first contour pipeline 2026-09-30 11:22:55 +03:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
e23783997e ++ uralkal istio-config domains 2026-09-28 11:02:53 +03:00
emelinda
15d1f11d8a Remove HelmRelease configurations (failed-pod-cleanup.yaml, goalert.yaml, and istio-config.yaml) from brusnika-stage cluster. 2026-09-25 18:04:55 +03:00
4703b77906 ++ uralkal bundled postgres 2026-09-25 17:27:14 +03:00
69c45fc7f1 ++ uralkal apps 2026-09-25 16:46:07 +03:00
e8ebed3689 ++ uralkal flux ca 2026-09-25 13:06:50 +03:00
26f4d13d47 ++ uralkal kafka rabbitmq 2026-09-25 12:07:57 +03:00
ivan
f6df384388 added asterus 2026-09-23 23:36:27 +05:00
6ec7167c04 ++ uralkal vault istio-base istio-pilot istio-gateway 2026-09-23 17:48:37 +03:00
5ba220fb33 ++ uralkal flux bootstrap manifests 2026-09-23 17:26:15 +03:00
ivan
5ae853bbf2 asterus: deploy auth-flow
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 14:34:14 +05:00
ivan
0a5eeafece asterus: add cluster entry point
Flux self-managed bootstrap files copied from ugok (controller images
already mirrored to cr.yandex), GitRepository/Kustomization pointed at
gitlab.sarex.io directly since the cluster has outbound internet access.
Starts with just flux-system + helm-repositories, infra/apps to be added
incrementally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 14:25:17 +05:00
ivan
f62dfb037d vad: pm, message-hub, cde
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:37:49 +05:00
ivan
4edb8d1274 vad: faas, iam
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:07:13 +05:00
ivan
b0b6b65ec7 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal, cross-section, document-link, prescriptions, projects, stamp-verification
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:01:20 +05:00
ivan
11007c0bc6 vad: processing, flows, issues, bim
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:49:38 +05:00
ivan
d17d2548c2 vad: django, documentations
django's nginx-configmap is patched for vad: pm and processing aren't
deployed there yet (kept commented out), documentations is enabled
since it's going in alongside django this time.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:26:27 +05:00
ivan
82f12762fc vad: notes, rfi, checklists, contracts (postgres ready; S3 pending stage 2 for notes/rfi/contracts)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:52:31 +05:00
ivan
a10ee6b6d5 vad: eav (postgres ready, S3 secret pending stage 2 in terraform repo)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:17:35 +05:00
ivan
b5bd5b7dc4 vad: workspaces
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:22:47 +05:00
ivan
169e2294aa vad: reviews, remarks, auth-flow, control-interface
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 16:45:19 +05:00
ivan
8098edcc42 sarex-contour: bim, comparisons, drawings, inspections, mapper, measurements, notes, rfi, subscriptions, system-log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:17:33 +05:00
ivan
41fe17ee7f sarex-contour: cross-section, prescriptions, projects, remarks, reviews, stamp-verification
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 14:45:20 +05:00
ivan
0c354f6d2f sarex-contour: attachments, documentations
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:34:56 +05:00
ivan
2ecfbb6e94 sarex-contour: flows, issues, checklists, contracts
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:53:27 +05:00
ivan
04da33f73e ++ sarex-contour: eav, bi, auth-flow, document-link
Все 4 — чистое наследование base:
- eav, bi — vault-зависимости (postgres [+ eav также minio]) заведены
  через terraform (live/database, live/s3, applications-блок).
- auth-flow, document-link — чистые статические фронтенды без бэкенда
  (см. CLAUDE.md), вообще без vault-зависимостей.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:29:28 +05:00
ivan
1ff52d0442 ++ sarex-contour: django
apps/django/sarex-contour — чистое наследование base (backend, celery,
frontend, srx-admin, s3-proxy, redis, конфигмапы). Все vault-пути
(apps/django/postgres, rabbitmq/apps/django, minio/apps/django,
kafka/apps/django, vault/common/{rsa_keys,django_auth}) заведены через
terraform в infra/terraform. S3-эндпоинт в манифестах base захардкожен
на несуществующий домен — деплою как есть, патчить по факту если
помешает подняться (как с rabbitmq/zitadel).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 13:08:02 +05:00
ivan
075472c4f1 ++ sarex-contour: workspaces
apps/workspaces/sarex-contour — чистое наследование base (backend +
frontend), replicaCount уже 1 в base, патчей не нужно. БД внешняя
(111.88.255.180) — заказана через terraform live/database, секрет
apps/workspaces/postgres заведён через vault-secrets applications-блок.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:36:23 +05:00
d15eb8ace9 ++ bump rabbitmq-exporter memory limit 2026-09-15 10:16:35 +03:00
ivan
9baaa3d7f1 ++ sarex-contour: zitadel
infrastructure/zitadel/sarex-contour (chart idp-contour 4.12.13), по
образцу overlay vad: без dependsOn на postgresql (БД внешняя, отдельная
машина 111.88.255.180 — заказана через terraform live/database, не
in-cluster HelmRelease), postRenderer снимает nodeSelector с Deployment
+ 2 Job'ов и подменяет vault-agent template на свой (кладёт
Admin.Password/FirstInstance.Org.Human.Password из
secrets/data/zitadel/postgresql).

ExternalDomain — заглушка zitadel.sarex-contour.internal, istio-config
для внешнего доступа ещё не заведён.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:15:12 +05:00
ivan
0c882d76c2 ++ sarex-contour: kafka + rabbitmq
infrastructure/kafka/sarex-contour, infrastructure/rabbitmq/sarex-contour
(values по образцу yc-k8s-test, controller-only kafka KRaft, rabbitmq
1 реплика, local-path). Vault для них уже заведён отдельно (terraform
environments.sarex-contour.vault, kafka/rabbitmq policy+role+kv).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:17:00 +05:00
ivan
49342404c0 ++ sarex-contour: control-interface
apps/control-interface/sarex-contour наследует base (по образцу
d8-ugmk-prod), namespace control-interface, istio-injection: enabled.
Оверлей yc-k8s-test для control-interface не копировали — там
namespace: django и патч на несуществующий HelmRelease srx-admin,
похоже на скопипащенный мёртвый код из apps/django/yc-k8s-test.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 12:00:45 +05:00
ivan
b4f3fc6851 ++ sarex-contour: vault под управление flux
vault уже стоял в кластере (helm CLI, chart 0.1.0, standalone/raft,
инициализирован, данных нет). Overlay infrastructure/vault/sarex-contour:
values как у прочих свежих контуров (regcred, backup off, standalone),
namespace istio-injection: disabled. helm-controller перенимает релиз
`vault` и апгрейдит до 0.2.3 (base). StatefulSet updateStrategy: OnDelete —
под не дёргается автоматически.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:15:57 +05:00
ivan
ea759acd09 ++ sarex-contour: flux entrypoint + istio rollout
Новый кластер clusters/sarex-contour: flux-system (bootstrap на
gitlab.sarex.io, path ./clusters/sarex-contour), helm-repositories
(yc-oci-charts), раскатка istio-base/istiod/ingressgateway.
Gateway опубликован через NodePort 30080/30443 — в контуре нет
облачного LoadBalancer.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:18:46 +05:00
7c2cc383c1 ++ istio solver for stuck cert domains 2026-09-02 13:13:22 +03:00
d37c229249 ++ default local-path storage class to retain 2026-09-01 18:21:48 +03:00
da34ec0bdf ++ exclude jwt-secret from flux-managed superset render 2026-09-01 11:28:33 +03:00
ivan
b441d1c913 ++ 2026-08-31 23:46:11 +05:00
ivan
6efd29da18 fix(brusnika-stage): битые внутрикластерные ссылки + чистка мусорных оверлеев
- django/s3-proxy: образ export-project -> s3-proxy:stable
- message-hub: backend-service.pm -> backend-svc.pm
- processing: documentations-filestream-service -> documentations-filestream
- resources: minio-service -> minio-svc
- documentations: bim-api-service -> backend-service.bim:8000;
  inspections-service -> backend-service.inspections:8000;
  remarks-static-service.remarks -> remarks-static.issues:80
- notes: sarex-* namespace -> реальные, documentations-service -> documentations-api,
  sarex-processing -> ns workflow / workflows-api-service,
  BASE_HOST уралхим -> test.sarex.brusnika.tech/notes
- подключён inspections в clusters/brusnika-stage/kustomization.yaml
- удалены мёртвые копипаст-оверлеи cross-section/faas/prescriptions/comparisons
  (нигде не подключены, побайтовые копии documentations/drawings)

brusnika-prod не трогаем.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 20:51:07 +05:00
ivan
37063d38e1 feat(bi): standalone-оверлеи bi для ugok, brusnika-stage, brusnika-prod
Не наследуют base (vault-native) — отдельные HelmRelease на universal-chart
с обычными secretEnvs, как остальные сервисы этих контуров. Свои хосты,
имена сервисов и kafka-bootstrap на контур; KAFKA_ENABLE=0, поэтому kafka
без секретов. Подключены к соответствующим clusters/*/kustomization.yaml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 19:51:23 +05:00
ivan
d3a973adea feat(bi): новое приложение bi (ns bi) на universal-chart + подключение к d8-ugmk-prod
apps/bi/base — bi-backend (vault-native, SA bi-vault) и bi-frontend.
apps/bi/d8-ugmk-prod — патч env под контур УГМК (хосты issues/eav/pm,
AUTH_HOST, kafka), namespace с deckhouse pod-policy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:08:29 +05:00
ivan
43e8fd5408 ++ 2026-08-29 04:07:08 +05:00
ivan
2233069ce1 ++ 2026-08-29 04:00:37 +05:00
ivan
068badbe0b ++ 2026-08-29 03:57:01 +05:00
ivan
b757fa5452 ++ 2026-08-29 03:52:37 +05:00
ivan
9cab91c074 ++ 2026-08-29 03:12:46 +05:00
ivan
3a6ee99866 ++ 2026-08-29 02:41:33 +05:00
ivan
60218f2306 ++ 2026-08-29 01:53:29 +05:00
ivan
2077174ef6 ++ 2026-08-29 01:37:04 +05:00