Commit Graph

71 Commits

Author SHA1 Message Date
ivan
5564778337 control-interface: add admin-frontend (universal-chart) to base, route it in vad istio-config
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.

Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.

infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:34:54 +05:00
ivan
d44378a432 brusnika-stage: route checklists/inspections/workflows/workspaces/comparisons/etc. through Istio instead of the global-ingress nginx proxy
Adds 13 new VirtualServices on the existing test.sarex.brusnika.tech host
and ingress-nginx/main-gateway, matching the active (non-commented)
location blocks in global-ingress's nginx-configmap (fetched live from the
cluster and cross-checked service/port/namespace names against what's
actually running). The root path (/) stays routed to
nginx-service.global-ingress as a fallback for anything not covered here.

Two deliberate deviations from literally replaying the nginx config:
- /comparisons/api/: nginx proxies to port 8080, but the real
  backend-service.comparisons Service listens on 80 (targetPort 8080) —
  used 80.
- /orchestrator/: nginx declares 4 location blocks, but the first
  (bare ~^/orchestrator/) shadows the other three for any non-empty
  path (nginx picks the first matching regex location, not the most
  specific), so only one route (no rewrite) was ported, matching what
  nginx actually does today.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:50:27 +05:00
emelinda
a438f5bd6b Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:55:40 +03:00
emelinda
8244e56f02 Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:52:55 +03:00
emelinda
70e4b24eee Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:42:18 +03:00
emelinda
474298459a comment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:35:11 +03:00
emelinda
c471cf39e0 Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 15:20:40 +03:00
emelinda
809febe4dc Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 14:06:07 +03:00
emelinda
c602ca904a Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 09:38:28 +03:00
emelinda
9ea8ab675e Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 09:23:04 +03:00
emelinda
e04fc5b850 Update Istio route prefix for resource-management in brusnika-stage configuration. 2026-09-29 17:47:23 +03:00
a204213979 ++ uralkal camunda domains 2026-09-28 18:23:45 +03:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
e23783997e ++ uralkal istio-config domains 2026-09-28 11:02:53 +03:00
ivan
2595d174aa vad: allow cross-origin credentialed requests to documentations-api (document-link, stamp-verification)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 22:41:17 +03:00
ivan
3dcf6ef89f vad: istio path routing for pm (/pm/api/, /pm/)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 21:44:39 +03:00
emelinda
15d1f11d8a Remove HelmRelease configurations (failed-pod-cleanup.yaml, goalert.yaml, and istio-config.yaml) from brusnika-stage cluster. 2026-09-25 18:04:55 +03:00
ivan
c75d178fb5 vad: istio path-routing for sarex.vadroad.ru
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:16:07 +05:00
5f48671f0e ++ vad istio hosts to flat sarex- scheme 2026-09-17 12:54:40 +03:00
ivan
9591d770be ++ 2026-08-31 16:55:22 +05:00
ivan
1ffe61ea88 feat(bi/d8-ugmk-prod): istio-маршруты для bi на sarex-bi.uralmine.com
/analytics-v2/api/ -> /api/  -> bi-backend-service.bi:80
/analytics-v2/static/, /analytics-v2/ -> / -> bi-frontend-frontend-svc.bi:80
Префиксы уже, чем catch-all `/` -> superset на том же хосте.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:54:09 +05:00
30e58fdc30 ++ fix gateway wildcard and drop foreign domains 2026-08-26 12:32:46 +03:00
9e66a1e31d ++ route s3 domain through ingressgateway to nginx service 2026-08-26 12:20:56 +03:00
d2df6afaa4 ++ add istio-config for vad with self-signed tls 2026-08-26 12:06:00 +03:00
fb1a36c2fd ++ switch superset domain to sarex-bi.uralmine.com 2026-08-20 15:48:55 +03:00
34c05548f6 ++ add superset trino ugmk 2026-08-20 13:19:52 +03:00
emelinda
8447ab76bb Add frontend HelmRelease to d8-ugmk-prod and configure Istio route for s3-proxy in Istio config 2026-08-05 15:33:56 +03:00
emelinda
af6135f2b0 Re-enable and configure multiple virtual services in yc-ecp Istio configuration for main-gateway. 2026-08-05 02:16:35 +03:00
emelinda
db0b8988f1 Refactor yc-ecp configuration: update HelmRelease affinity settings for frontend and re-enable commented Istio routes for main-gateway. 2026-08-05 02:06:17 +03:00
emelinda
218d233eb7 Add Django frontend app to yc-ecp: define namespace, configure HelmRelease with chart and deployment details, update Istio configuration, and include in cluster Kustomization 2026-08-05 01:58:35 +03:00
emelinda
d46ba48d22 Update yc-ecp Istio configuration: add main-gateway and TLS settings for aero.invest.sarex.io 2026-08-05 01:05:11 +03:00
emelinda
c7c244e95d Update yc-ecp Istio configuration: add imagePullSecrets for cert-manager and enforce HTTPS for dashboard bindings 2026-08-05 00:11:41 +03:00
emelinda
3a5b3b07e6 Add Measurements app to yc-ecp: define HelmRelease, configure Istio certificates, and update cluster Kustomization 2026-08-05 00:00:06 +03:00
emelinda
172e889f00 Add Kubernetes Dashboard configuration to yc-ecp: define HelmRelease, update Istio Gateway and VirtualService, and include in cluster Kustomization 2026-08-04 23:34:53 +03:00
emelinda
e491466a37 Refactor yc-ecp Istio and cert-manager configurations: adjust ClusterIssuer specs, update certificate and VirtualService keys, and add port names. 2026-08-04 23:27:13 +03:00
emelinda
6b107c872a Remove deprecated Let's Encrypt ClusterIssuer configurations and update dependencies in yc-ecp cert-manager and Istio configuration. 2026-08-04 23:14:05 +03:00
emelinda
6e94f826c3 Migrate Istio and Vault configurations to separate yc-ecp infrastructure directories with updated HelmRelease and Kustomization files. 2026-08-04 22:34:42 +03:00
ivan
1e1280d74e ++ 2026-08-04 18:54:52 +05:00
ivan
27327f2c9c ++ 2026-08-04 14:36:19 +05:00
ivan
0703f6a7ea ++ 2026-08-04 14:07:53 +05:00
ivan
0c04c357dc ++ 2026-08-04 13:29:50 +05:00
ivan
ebe1bbfd08 ++ 2026-08-04 13:19:31 +05:00
ivan
fb765a9cf9 ++ 2026-08-04 12:41:10 +05:00
ivan
8a0eee6538 ++ 2026-08-03 20:41:38 +05:00
fb30bab0b8 ++ prefix uralmine service domains with sarex 2026-08-03 11:06:10 +03:00
a4f1424403 ++ move uralmine service domains up one level 2026-08-03 10:56:18 +03:00
ivan
9cb672cf34 ++ 2026-08-02 01:10:27 +05:00
ivan
325aad49da ++ 2026-08-02 00:50:33 +05:00
ivan
6c81ba0080 ++ 2026-08-02 00:41:18 +05:00
ivan
3dd3c12537 ++ 2026-08-01 15:13:48 +05:00