Missing env vars copied from wb for ams-sync, attachments, bi/frontend,
checklists, django (celery, export-project, sarex-backend), documentations
(api, filestream, pdm), eav, flows (backend, celery, frontend), iam,
inspections, issues (backend, celery), rfi, transmittal/worker.
Image tags updated to match wb for flows (backend/celery/frontend), iam.
Known issue, not yet fixed in this commit: several of the copied env
values are wb-specific hosts (*.wb.ru, one uralmine.com) that don't apply
to brusnika-stage — ZITADEL_HOST/ZITADEL_DOMAIN (django, documentations,
iam), DATABASE_HOST/FLOWS_DB_HOST/ISSUES_DB_HOST (checklists, flows),
SUPERSET_HOST (bi), DJANGO_BASE_HOST/SAREX_BACKEND_URL (flows,
inspections), RESOURCES_INTERNAL_HOST/RESOURCE_URL (ams-sync, django,
flows, notes-related). To be corrected in a follow-up commit.
bi/backend.yaml, bim/backend.yaml and notes/backend.yaml were reverted
before this commit (image-tag updates for bi-backend/bim/notes and bi's
SUPERSET_* env additions are not included).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Every services.<svc>.deployment.resources.requests.{cpu,memory} across the
36 uralkal apps (69 HelmRelease/service entries total) is now nulled via a
kustomize patch, so Helm never renders a requests block for these pods on
uralkal — Kubernetes won't reserve CPU/memory for them there.
Where a uralkal patch already existed for that service (13 cases:
documentations api/filestream/pdf-markings-amqp, django backend, flows
backend/celery, pm backend/celery, transmittal backend/worker, bi,
document-link, stamp-verification, message-hub), the null block was added
into that same file. Where no uralkal patch existed yet (55 cases,
including all 13 cde workers and every plain frontend), a new minimal
patch file was added and wired into that app's kustomization.yaml.
vad and the other clusters are untouched — only apps/*/uralkal/* changed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).
infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.
clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.
infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.
apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
django's nginx-configmap is patched for vad: pm and processing aren't
deployed there yet (kept commented out), documentations is enabled
since it's going in alongside django this time.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/control-interface/base has no namespace.yaml (unlike reviews,
remarks, auth-flow), so Flux failed applying the HelmRelease into a
namespace that was never created.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Все 4 — чистое наследование base:
- eav, bi — vault-зависимости (postgres [+ eav также minio]) заведены
через terraform (live/database, live/s3, applications-блок).
- auth-flow, document-link — чистые статические фронтенды без бэкенда
(см. CLAUDE.md), вообще без vault-зависимостей.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
По просьбе: неподнятые в контуре сервисы (pm, documentations,
processing) остаются в конфиге закомментированными, а не вырезанными —
видно, что временно выключено, легко раскомментировать когда появятся.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
nginx падал в CrashLoopBackOff: "host not found in upstream
backend-svc.pm.svc.cluster.local" — proxy_pass резолвится один раз при
старте, приложений pm/documentations/processing в sarex-contour нет.
Убраны location-блоки /api/pm/, /api/v1/documents/, /workflows/;
django и workspaces (оба раскатаны) — оставлены.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/django/sarex-contour — чистое наследование base (backend, celery,
frontend, srx-admin, s3-proxy, redis, конфигмапы). Все vault-пути
(apps/django/postgres, rabbitmq/apps/django, minio/apps/django,
kafka/apps/django, vault/common/{rsa_keys,django_auth}) заведены через
terraform в infra/terraform. S3-эндпоинт в манифестах base захардкожен
на несуществующий домен — деплою как есть, патчить по факту если
помешает подняться (как с rabbitmq/zitadel).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>