apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).
infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.
clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.
infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.
apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Flux self-managed bootstrap files copied from ugok (controller images
already mirrored to cr.yandex), GitRepository/Kustomization pointed at
gitlab.sarex.io directly since the cluster has outbound internet access.
Starts with just flux-system + helm-repositories, infra/apps to be added
incrementally.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
django's nginx-configmap is patched for vad: pm and processing aren't
deployed there yet (kept commented out), documentations is enabled
since it's going in alongside django this time.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/control-interface/base has no namespace.yaml (unlike reviews,
remarks, auth-flow), so Flux failed applying the HelmRelease into a
namespace that was never created.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>