Commit Graph

21 Commits

Author SHA1 Message Date
ivan
e00a7905fb ++ 2026-10-02 14:51:30 +05:00
ivan
7531341438 ++ 2026-10-02 12:33:16 +05:00
ivan
6251cfed5c brusnika-stage: bring images and env vars up to wb level
Missing env vars copied from wb for ams-sync, attachments, bi/frontend,
checklists, django (celery, export-project, sarex-backend), documentations
(api, filestream, pdm), eav, flows (backend, celery, frontend), iam,
inspections, issues (backend, celery), rfi, transmittal/worker.

Image tags updated to match wb for flows (backend/celery/frontend), iam.

Known issue, not yet fixed in this commit: several of the copied env
values are wb-specific hosts (*.wb.ru, one uralmine.com) that don't apply
to brusnika-stage — ZITADEL_HOST/ZITADEL_DOMAIN (django, documentations,
iam), DATABASE_HOST/FLOWS_DB_HOST/ISSUES_DB_HOST (checklists, flows),
SUPERSET_HOST (bi), DJANGO_BASE_HOST/SAREX_BACKEND_URL (flows,
inspections), RESOURCES_INTERNAL_HOST/RESOURCE_URL (ams-sync, django,
flows, notes-related). To be corrected in a follow-up commit.

bi/backend.yaml, bim/backend.yaml and notes/backend.yaml were reverted
before this commit (image-tag updates for bi-backend/bim/notes and bi's
SUPERSET_* env additions are not included).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:04:55 +05:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
ivan
f6df384388 added asterus 2026-09-23 23:36:27 +05:00
ivan
f648d01629 vad: iam zitadel org rules with the vad default org id
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:18:54 +05:00
ivan
410fd96439 ++ 2026-09-17 21:08:16 +05:00
ivan
4edb8d1274 vad: faas, iam
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:07:13 +05:00
ivan
96e42f9899 ++ 2026-08-31 14:49:47 +05:00
ivan
935f8fa372 Revert "brusnika-stage: align images with wb, add missing backend envs"
This reverts commit e18124c73a.
2026-08-28 19:03:00 +05:00
ivan
e18124c73a brusnika-stage: align images with wb, add missing backend envs
Образы подтянуты под теги wb там, где это один и тот же сервис.
В backend-файлах добавлены недостающие env-переменные — с адаптацией
доменов под конвенцию brusnika-stage (test.sarex.brusnika.tech), без
слепого копирования wb-специфичных значений (доменов/секретов).

Не тронуты apps/comparisons/brusnika-stage/backend.yaml,
apps/faas/brusnika-stage/backend.yaml, apps/notes/brusnika-stage/backend.yaml —
по содержимому принадлежат другим приложениям/клиенту, требуют отдельного
разбора.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-28 16:00:24 +05:00
ivan
dff652819a wb: set requests/limits from 14d VictoriaMetrics utilization
Проставлены requests и limits в apps/*/wb на основе p95/max
потребления CPU и памяти за 14 дней (scripts/wb-resource-utilization.sh).
request ~ p95*1.2, limit ~ max*1.5-2, с полом 10m/20m CPU и 32Mi/48Mi
памяти. documentations/pdf-markings: request урезан до пола (10m/32Mi),
limit оставлен на исходном уровне (2 CPU/8Gi) — редко используется, но
при вызове может понадобиться весь объём.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-27 15:36:59 +05:00
ivan
fbdad7f412 ++ 2026-08-12 16:35:37 +05:00
ivan
a8a4f5e50d ++ 2026-08-04 18:33:39 +05:00
ivan
f8a16fe423 ++ 2026-08-03 16:32:47 +05:00
ivan
55c9f573c3 ++ 2026-08-03 15:30:37 +05:00
ivan
582028b65e ++ 2026-07-29 17:45:16 +05:00
ivan
c1aa11b922 ++ 2026-07-29 17:38:58 +05:00
ivan
73ec054bba ++ 2026-07-29 17:34:10 +05:00
emelinda
28478d9c86 Add example .env files and configuration documentation for ams-sync, auth-flow, bim, cde, comparisons, django, document-link, flows, iam, inspections services. 2026-07-14 19:23:02 +03:00
ivan
ef69ec43a5 ++ 2026-06-11 15:19:51 +05:00