Commit Graph

1360 Commits

Author SHA1 Message Date
ivan
92efab2ecd ++ 2026-09-28 15:57:47 +03:00
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
e23783997e ++ uralkal istio-config domains 2026-09-28 11:02:53 +03:00
dcab7c00ed ++ uralkal superset image with deps 2026-09-28 11:02:53 +03:00
ivan
2595d174aa vad: allow cross-origin credentialed requests to documentations-api (document-link, stamp-verification)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 22:41:17 +03:00
ivan
6e8151fed6 ++ 2026-09-27 22:34:07 +03:00
ivan
3dcf6ef89f vad: istio path routing for pm (/pm/api/, /pm/)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 21:44:39 +03:00
ivan
954e0a7231 ++ 2026-09-27 21:44:39 +03:00
emelinda
15d1f11d8a Remove HelmRelease configurations (failed-pod-cleanup.yaml, goalert.yaml, and istio-config.yaml) from brusnika-stage cluster. 2026-09-25 18:04:55 +03:00
4703b77906 ++ uralkal bundled postgres 2026-09-25 17:27:14 +03:00
692647f4ec ++ uralkal trino node 2026-09-25 16:47:46 +03:00
69c45fc7f1 ++ uralkal apps 2026-09-25 16:46:07 +03:00
e8ebed3689 ++ uralkal flux ca 2026-09-25 13:06:50 +03:00
da2472438d Merge branch 'master' of https://gitlab.sarex.io/infra/iac 2026-09-25 12:55:16 +03:00
26f4d13d47 ++ uralkal kafka rabbitmq 2026-09-25 12:07:57 +03:00
emelinda
cdaf20f7cc Add "Справочники" section to django-configmap navigation menu. 2026-09-24 21:26:42 +03:00
emelinda
380986659e Update backend worker image version in celery.yaml. 2026-09-24 21:17:39 +03:00
emelinda
21dcac2d1d Update frontend and backend image versions in deployment configurations. 2026-09-24 21:07:59 +03:00
98dc78d4a9 Merge branch 'master' of https://gitlab.sarex.io/infra/iac 2026-09-24 11:26:36 +03:00
b053237833 ++ pin uralkal ingressgateway to 1 replica 2026-09-24 11:23:36 +03:00
ivan
f6df384388 added asterus 2026-09-23 23:36:27 +05:00
6ec7167c04 ++ uralkal vault istio-base istio-pilot istio-gateway 2026-09-23 17:48:37 +03:00
b9114a5033 ++ push latest tag alongside versioned iac-offline image 2026-09-23 17:36:22 +03:00
5ba220fb33 ++ uralkal flux bootstrap manifests 2026-09-23 17:26:15 +03:00
emelinda
8fe6445be8 Expand architecture documentation: enhance preview.html with an application layer component registry, update tooltips, refine SVG rendering, and adjust Archimate model structure. 2026-09-23 16:32:43 +03:00
ivan
5ae853bbf2 asterus: deploy auth-flow
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 14:34:14 +05:00
ivan
0a5eeafece asterus: add cluster entry point
Flux self-managed bootstrap files copied from ugok (controller images
already mirrored to cr.yandex), GitRepository/Kustomization pointed at
gitlab.sarex.io directly since the cluster has outbound internet access.
Starts with just flux-system + helm-repositories, infra/apps to be added
incrementally.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 14:25:17 +05:00
ivan
a3f9fb5ee9 vad: pdf-markings-amqp hosts/bucket override, stamp-verification and document-link frontend images
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 13:03:29 +05:00
ivan
40f5552951 ++ 2026-09-22 12:00:31 +05:00
ivan
a5750ed220 ++ 2026-09-22 01:47:43 +05:00
ivan
48924262aa vad: contracts DB_URL from the Vault postgres secret (external database)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 17:31:50 +05:00
ivan
5c7369ed70 vad: replace kafka CA with the vad kafka-kafka-contour CA in flows, issues, pm, message-hub
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 15:54:05 +05:00
ivan
be6e8b26fb ++ 2026-09-21 15:28:12 +05:00
ivan
f648d01629 vad: iam zitadel org rules with the vad default org id
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:18:54 +05:00
ivan
a1afea5ae3 ++ 2026-09-18 17:56:09 +05:00
ivan
ef3120352e vad: fix zitadel ExternalDomain to match the actual istio host
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 15:55:01 +05:00
ivan
f62dfb037d vad: pm, message-hub, cde
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:37:49 +05:00
ivan
c75d178fb5 vad: istio path-routing for sarex.vadroad.ru
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:16:07 +05:00
ivan
410fd96439 ++ 2026-09-17 21:08:16 +05:00
ivan
4edb8d1274 vad: faas, iam
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:07:13 +05:00
ivan
b0b6b65ec7 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal, cross-section, document-link, prescriptions, projects, stamp-verification
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:01:20 +05:00
ivan
11007c0bc6 vad: processing, flows, issues, bim
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:49:38 +05:00
ivan
d17d2548c2 vad: django, documentations
django's nginx-configmap is patched for vad: pm and processing aren't
deployed there yet (kept commented out), documentations is enabled
since it's going in alongside django this time.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:26:27 +05:00
ivan
82f12762fc vad: notes, rfi, checklists, contracts (postgres ready; S3 pending stage 2 for notes/rfi/contracts)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:52:31 +05:00
ivan
a10ee6b6d5 vad: eav (postgres ready, S3 secret pending stage 2 in terraform repo)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:17:35 +05:00
ivan
b5bd5b7dc4 vad: workspaces
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:22:47 +05:00
ivan
dabf7e1256 vad: add missing control-interface namespace
apps/control-interface/base has no namespace.yaml (unlike reviews,
remarks, auth-flow), so Flux failed applying the HelmRelease into a
namespace that was never created.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:02:00 +05:00
ivan
169e2294aa vad: reviews, remarks, auth-flow, control-interface
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 16:45:19 +05:00
d14b072432 ++ vad camunda identity urls to flat sarex- scheme 2026-09-17 13:28:24 +03:00
ivan
8098edcc42 sarex-contour: bim, comparisons, drawings, inspections, mapper, measurements, notes, rfi, subscriptions, system-log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:17:33 +05:00