Commit Graph

249 Commits

Author SHA1 Message Date
5f48671f0e ++ vad istio hosts to flat sarex- scheme 2026-09-17 12:54:40 +03:00
ivan
24fa9db719 sarex-contour: remove explanatory comments
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:40:46 +05:00
ivan
9baaa3d7f1 ++ sarex-contour: zitadel
infrastructure/zitadel/sarex-contour (chart idp-contour 4.12.13), по
образцу overlay vad: без dependsOn на postgresql (БД внешняя, отдельная
машина 111.88.255.180 — заказана через terraform live/database, не
in-cluster HelmRelease), postRenderer снимает nodeSelector с Deployment
+ 2 Job'ов и подменяет vault-agent template на свой (кладёт
Admin.Password/FirstInstance.Org.Human.Password из
secrets/data/zitadel/postgresql).

ExternalDomain — заглушка zitadel.sarex-contour.internal, istio-config
для внешнего доступа ещё не заведён.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:15:12 +05:00
ivan
48f7934699 ++ sarex-contour: rabbitmq — вырезать Certificate/Gateway/VirtualService
cert-manager в sarex-contour не раскатан, chart рендерит Certificate/
Gateway/VirtualService для ingress несмотря на values:null (как и в
vad/d8-ugmk-prod) — install падал на "no matches for kind Certificate".
Тот же postRenderer $patch:delete, что у vad.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:18:05 +05:00
ivan
0c882d76c2 ++ sarex-contour: kafka + rabbitmq
infrastructure/kafka/sarex-contour, infrastructure/rabbitmq/sarex-contour
(values по образцу yc-k8s-test, controller-only kafka KRaft, rabbitmq
1 реплика, local-path). Vault для них уже заведён отдельно (terraform
environments.sarex-contour.vault, kafka/rabbitmq policy+role+kv).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:17:00 +05:00
ivan
e37507aa6c ++ sarex-contour: vault ha.replicas=1
chart всегда рендерит raft HA; для контура держим одну ноду вместо
дефолтных трёх — меньше unseal-операций и PVC.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:48:30 +05:00
ivan
b98b4b6ee3 ++ sarex-contour: vault dataStorage.size 10Gi
chart 0.2.3 дефолтит 20Gi, живой StatefulSet с 0.1.0 — 10Gi, поле
volumeClaimTemplates иммутабельно → helm upgrade падал Forbidden.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:44:14 +05:00
ivan
f3e2f84947 ++ sarex-contour: vault — values по образцу ugok
chart 0.2.3 игнорирует server.standalone/ha.enabled и рендерит raft;
не воюем с ним — values только regcred + backup off, как в overlay ugok.
postRenderer снимает nodeSelector dedicated=sts.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:28:10 +05:00
ivan
b9154da622 ++ sarex-contour: vault — снять nodeSelector dedicated=sts
chart vault-contour 0.2.3 прибивает server-под к нодам dedicated=sts,
в кластере их нет → под висел Pending. postRenderer + values обнуляют
nodeSelector/tolerations на StatefulSet и injector.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:17:47 +05:00
ivan
b4f3fc6851 ++ sarex-contour: vault под управление flux
vault уже стоял в кластере (helm CLI, chart 0.1.0, standalone/raft,
инициализирован, данных нет). Overlay infrastructure/vault/sarex-contour:
values как у прочих свежих контуров (regcred, backup off, standalone),
namespace istio-injection: disabled. helm-controller перенимает релиз
`vault` и апгрейдит до 0.2.3 (base). StatefulSet updateStrategy: OnDelete —
под не дёргается автоматически.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:15:57 +05:00
ivan
5d5fde4374 ++ sarex-contour: ingressgateway replicaCount=1
base-чарт istio-gateway прибит к control-plane нодам и просит 3 реплики
с hostPort — в sarex-contour одна control-plane нода, 2 пода висли Pending.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:27:36 +05:00
ivan
ea759acd09 ++ sarex-contour: flux entrypoint + istio rollout
Новый кластер clusters/sarex-contour: flux-system (bootstrap на
gitlab.sarex.io, path ./clusters/sarex-contour), helm-repositories
(yc-oci-charts), раскатка istio-base/istiod/ingressgateway.
Gateway опубликован через NodePort 30080/30443 — в контуре нет
облачного LoadBalancer.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:18:46 +05:00
d37c229249 ++ default local-path storage class to retain 2026-09-01 18:21:48 +03:00
ivan
9591d770be ++ 2026-08-31 16:55:22 +05:00
ivan
1ffe61ea88 feat(bi/d8-ugmk-prod): istio-маршруты для bi на sarex-bi.uralmine.com
/analytics-v2/api/ -> /api/  -> bi-backend-service.bi:80
/analytics-v2/static/, /analytics-v2/ -> / -> bi-frontend-frontend-svc.bi:80
Префиксы уже, чем catch-all `/` -> superset на том же хосте.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:54:09 +05:00
bd62e7c153 ++ force empty nodeselector and tolerations for ugok vault 2026-08-28 13:21:49 +03:00
75cecf0321 ++ add vault install for ugok 2026-08-28 13:14:11 +03:00
b911b7ea50 ++ deploy dedicated in-cluster postgres for zitadel, point zitadel at it 2026-08-26 14:22:02 +03:00
2bbf786aa6 ++ revert keycloak db password to allowed vault path 2026-08-26 14:17:25 +03:00
7b5f249581 ++ read identity password from canonical vault key, drop staging secret 2026-08-26 14:03:22 +03:00
09b0d4e8d1 ++ point keycloak db password at its own vault path 2026-08-26 12:53:12 +03:00
30e58fdc30 ++ fix gateway wildcard and drop foreign domains 2026-08-26 12:32:46 +03:00
9e66a1e31d ++ route s3 domain through ingressgateway to nginx service 2026-08-26 12:20:56 +03:00
8bbc158e49 ++ add s3-proxy nginx service for vad 2026-08-26 12:15:11 +03:00
d2df6afaa4 ++ add istio-config for vad with self-signed tls 2026-08-26 12:06:00 +03:00
f051fd67b8 ++ zitadel admin password reads same key as user 2026-08-26 11:58:30 +03:00
4420efb5a1 ++ match ugmk zitadel admin username pattern 2026-08-26 11:51:32 +03:00
c38032e64e ++ add kafka camunda zitadel overlays for vad 2026-08-26 11:32:23 +03:00
9db6db713a ++ nest ingressgateway service override under internal defaults key 2026-08-25 18:43:38 +03:00
b5acdf28b5 ++ fix vad ingressgateway values schema, expose 30080/30443 2026-08-25 18:40:55 +03:00
e2c3079ab1 ++ fix vad rabbitmq gateway crd and istio image pull secrets 2026-08-25 18:28:13 +03:00
83262697c0 ++ add vault, rabbitmq and istio for vad 2026-08-25 18:22:55 +03:00
98f8ad1635 ++ null out sarex_db and resources_db chart defaults in trino catalogs 2026-08-25 14:57:43 +03:00
88b58158de ++ point trino at django_db, drop dead resources_db catalog 2026-08-21 15:56:15 +03:00
b5efcc378c ++ bump pgbouncer chart to 1.0.12 2026-08-21 14:45:05 +03:00
29cc95ef33 ++ add pgbouncer backup pooler to brusnika-prod 2026-08-21 14:21:13 +03:00
fb1a36c2fd ++ switch superset domain to sarex-bi.uralmine.com 2026-08-20 15:48:55 +03:00
c45150bc98 ++ fix trino worker node selector render 2026-08-20 15:48:55 +03:00
1cb049ba9b ++ place trino worker on processing node 2026-08-20 14:16:49 +03:00
327212ea6f ++ use mirrored ugmk superset trino images 2026-08-20 14:09:26 +03:00
3b5a6ddcc0 ++ fix ugmk superset trino contour charts 2026-08-20 14:09:26 +03:00
34c05548f6 ++ add superset trino ugmk 2026-08-20 13:19:52 +03:00
e9c582800e ++ use wb superset jwt k8s secret 2026-08-17 17:19:21 +03:00
1827903c41 ++ fix wb superset guest token secret delivery 2026-08-17 17:00:33 +03:00
c10d84861f fix identity.fullURL for ugmk, was falling back to chart default identity.camunda.sarex.io instead of camunda-identity.sarex-k8s.uralmine.com 2026-08-07 14:43:35 +03:00
emelinda
8447ab76bb Add frontend HelmRelease to d8-ugmk-prod and configure Istio route for s3-proxy in Istio config 2026-08-05 15:33:56 +03:00
emelinda
af6135f2b0 Re-enable and configure multiple virtual services in yc-ecp Istio configuration for main-gateway. 2026-08-05 02:16:35 +03:00
emelinda
db0b8988f1 Refactor yc-ecp configuration: update HelmRelease affinity settings for frontend and re-enable commented Istio routes for main-gateway. 2026-08-05 02:06:17 +03:00
emelinda
218d233eb7 Add Django frontend app to yc-ecp: define namespace, configure HelmRelease with chart and deployment details, update Istio configuration, and include in cluster Kustomization 2026-08-05 01:58:35 +03:00
emelinda
d46ba48d22 Update yc-ecp Istio configuration: add main-gateway and TLS settings for aero.invest.sarex.io 2026-08-05 01:05:11 +03:00