Commit Graph

276 Commits

Author SHA1 Message Date
ivan
5564778337 control-interface: add admin-frontend (universal-chart) to base, route it in vad istio-config
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.

Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.

infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:34:54 +05:00
ivan
d44378a432 brusnika-stage: route checklists/inspections/workflows/workspaces/comparisons/etc. through Istio instead of the global-ingress nginx proxy
Adds 13 new VirtualServices on the existing test.sarex.brusnika.tech host
and ingress-nginx/main-gateway, matching the active (non-commented)
location blocks in global-ingress's nginx-configmap (fetched live from the
cluster and cross-checked service/port/namespace names against what's
actually running). The root path (/) stays routed to
nginx-service.global-ingress as a fallback for anything not covered here.

Two deliberate deviations from literally replaying the nginx config:
- /comparisons/api/: nginx proxies to port 8080, but the real
  backend-service.comparisons Service listens on 80 (targetPort 8080) —
  used 80.
- /orchestrator/: nginx declares 4 location blocks, but the first
  (bare ~^/orchestrator/) shadows the other three for any non-empty
  path (nginx picks the first matching regex location, not the most
  specific), so only one route (no rewrite) was ported, matching what
  nginx actually does today.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:50:27 +05:00
emelinda
a438f5bd6b Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:55:40 +03:00
emelinda
8244e56f02 Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:52:55 +03:00
emelinda
70e4b24eee Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:42:18 +03:00
emelinda
474298459a comment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:35:11 +03:00
emelinda
c471cf39e0 Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 15:20:40 +03:00
emelinda
809febe4dc Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 14:06:07 +03:00
emelinda
c602ca904a Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 09:38:28 +03:00
emelinda
9ea8ab675e Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 09:23:04 +03:00
emelinda
e04fc5b850 Update Istio route prefix for resource-management in brusnika-stage configuration. 2026-09-29 17:47:23 +03:00
a204213979 ++ uralkal camunda domains 2026-09-28 18:23:45 +03:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
e23783997e ++ uralkal istio-config domains 2026-09-28 11:02:53 +03:00
dcab7c00ed ++ uralkal superset image with deps 2026-09-28 11:02:53 +03:00
ivan
2595d174aa vad: allow cross-origin credentialed requests to documentations-api (document-link, stamp-verification)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 22:41:17 +03:00
ivan
3dcf6ef89f vad: istio path routing for pm (/pm/api/, /pm/)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 21:44:39 +03:00
emelinda
15d1f11d8a Remove HelmRelease configurations (failed-pod-cleanup.yaml, goalert.yaml, and istio-config.yaml) from brusnika-stage cluster. 2026-09-25 18:04:55 +03:00
4703b77906 ++ uralkal bundled postgres 2026-09-25 17:27:14 +03:00
692647f4ec ++ uralkal trino node 2026-09-25 16:47:46 +03:00
69c45fc7f1 ++ uralkal apps 2026-09-25 16:46:07 +03:00
26f4d13d47 ++ uralkal kafka rabbitmq 2026-09-25 12:07:57 +03:00
b053237833 ++ pin uralkal ingressgateway to 1 replica 2026-09-24 11:23:36 +03:00
6ec7167c04 ++ uralkal vault istio-base istio-pilot istio-gateway 2026-09-23 17:48:37 +03:00
ivan
ef3120352e vad: fix zitadel ExternalDomain to match the actual istio host
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 15:55:01 +05:00
ivan
c75d178fb5 vad: istio path-routing for sarex.vadroad.ru
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:16:07 +05:00
d14b072432 ++ vad camunda identity urls to flat sarex- scheme 2026-09-17 13:28:24 +03:00
5f48671f0e ++ vad istio hosts to flat sarex- scheme 2026-09-17 12:54:40 +03:00
ivan
24fa9db719 sarex-contour: remove explanatory comments
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:40:46 +05:00
ivan
9baaa3d7f1 ++ sarex-contour: zitadel
infrastructure/zitadel/sarex-contour (chart idp-contour 4.12.13), по
образцу overlay vad: без dependsOn на postgresql (БД внешняя, отдельная
машина 111.88.255.180 — заказана через terraform live/database, не
in-cluster HelmRelease), postRenderer снимает nodeSelector с Deployment
+ 2 Job'ов и подменяет vault-agent template на свой (кладёт
Admin.Password/FirstInstance.Org.Human.Password из
secrets/data/zitadel/postgresql).

ExternalDomain — заглушка zitadel.sarex-contour.internal, istio-config
для внешнего доступа ещё не заведён.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:15:12 +05:00
ivan
48f7934699 ++ sarex-contour: rabbitmq — вырезать Certificate/Gateway/VirtualService
cert-manager в sarex-contour не раскатан, chart рендерит Certificate/
Gateway/VirtualService для ingress несмотря на values:null (как и в
vad/d8-ugmk-prod) — install падал на "no matches for kind Certificate".
Тот же postRenderer $patch:delete, что у vad.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:18:05 +05:00
ivan
0c882d76c2 ++ sarex-contour: kafka + rabbitmq
infrastructure/kafka/sarex-contour, infrastructure/rabbitmq/sarex-contour
(values по образцу yc-k8s-test, controller-only kafka KRaft, rabbitmq
1 реплика, local-path). Vault для них уже заведён отдельно (terraform
environments.sarex-contour.vault, kafka/rabbitmq policy+role+kv).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:17:00 +05:00
ivan
e37507aa6c ++ sarex-contour: vault ha.replicas=1
chart всегда рендерит raft HA; для контура держим одну ноду вместо
дефолтных трёх — меньше unseal-операций и PVC.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:48:30 +05:00
ivan
b98b4b6ee3 ++ sarex-contour: vault dataStorage.size 10Gi
chart 0.2.3 дефолтит 20Gi, живой StatefulSet с 0.1.0 — 10Gi, поле
volumeClaimTemplates иммутабельно → helm upgrade падал Forbidden.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:44:14 +05:00
ivan
f3e2f84947 ++ sarex-contour: vault — values по образцу ugok
chart 0.2.3 игнорирует server.standalone/ha.enabled и рендерит raft;
не воюем с ним — values только regcred + backup off, как в overlay ugok.
postRenderer снимает nodeSelector dedicated=sts.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:28:10 +05:00
ivan
b9154da622 ++ sarex-contour: vault — снять nodeSelector dedicated=sts
chart vault-contour 0.2.3 прибивает server-под к нодам dedicated=sts,
в кластере их нет → под висел Pending. postRenderer + values обнуляют
nodeSelector/tolerations на StatefulSet и injector.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:17:47 +05:00
ivan
b4f3fc6851 ++ sarex-contour: vault под управление flux
vault уже стоял в кластере (helm CLI, chart 0.1.0, standalone/raft,
инициализирован, данных нет). Overlay infrastructure/vault/sarex-contour:
values как у прочих свежих контуров (regcred, backup off, standalone),
namespace istio-injection: disabled. helm-controller перенимает релиз
`vault` и апгрейдит до 0.2.3 (base). StatefulSet updateStrategy: OnDelete —
под не дёргается автоматически.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:15:57 +05:00
ivan
5d5fde4374 ++ sarex-contour: ingressgateway replicaCount=1
base-чарт istio-gateway прибит к control-plane нодам и просит 3 реплики
с hostPort — в sarex-contour одна control-plane нода, 2 пода висли Pending.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:27:36 +05:00
ivan
ea759acd09 ++ sarex-contour: flux entrypoint + istio rollout
Новый кластер clusters/sarex-contour: flux-system (bootstrap на
gitlab.sarex.io, path ./clusters/sarex-contour), helm-repositories
(yc-oci-charts), раскатка istio-base/istiod/ingressgateway.
Gateway опубликован через NodePort 30080/30443 — в контуре нет
облачного LoadBalancer.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:18:46 +05:00
d37c229249 ++ default local-path storage class to retain 2026-09-01 18:21:48 +03:00
ivan
9591d770be ++ 2026-08-31 16:55:22 +05:00
ivan
1ffe61ea88 feat(bi/d8-ugmk-prod): istio-маршруты для bi на sarex-bi.uralmine.com
/analytics-v2/api/ -> /api/  -> bi-backend-service.bi:80
/analytics-v2/static/, /analytics-v2/ -> / -> bi-frontend-frontend-svc.bi:80
Префиксы уже, чем catch-all `/` -> superset на том же хосте.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:54:09 +05:00
bd62e7c153 ++ force empty nodeselector and tolerations for ugok vault 2026-08-28 13:21:49 +03:00
75cecf0321 ++ add vault install for ugok 2026-08-28 13:14:11 +03:00
b911b7ea50 ++ deploy dedicated in-cluster postgres for zitadel, point zitadel at it 2026-08-26 14:22:02 +03:00
2bbf786aa6 ++ revert keycloak db password to allowed vault path 2026-08-26 14:17:25 +03:00
7b5f249581 ++ read identity password from canonical vault key, drop staging secret 2026-08-26 14:03:22 +03:00
09b0d4e8d1 ++ point keycloak db password at its own vault path 2026-08-26 12:53:12 +03:00
30e58fdc30 ++ fix gateway wildcard and drop foreign domains 2026-08-26 12:32:46 +03:00
9e66a1e31d ++ route s3 domain through ingressgateway to nginx service 2026-08-26 12:20:56 +03:00