ivan
b9154da622
++ sarex-contour: vault — снять nodeSelector dedicated=sts
...
chart vault-contour 0.2.3 прибивает server-под к нодам dedicated=sts,
в кластере их нет → под висел Pending. postRenderer + values обнуляют
nodeSelector/tolerations на StatefulSet и injector.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:17:47 +05:00
ivan
b4f3fc6851
++ sarex-contour: vault под управление flux
...
vault уже стоял в кластере (helm CLI, chart 0.1.0, standalone/raft,
инициализирован, данных нет). Overlay infrastructure/vault/sarex-contour:
values как у прочих свежих контуров (regcred, backup off, standalone),
namespace istio-injection: disabled. helm-controller перенимает релиз
`vault` и апгрейдит до 0.2.3 (base). StatefulSet updateStrategy: OnDelete —
под не дёргается автоматически.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:15:57 +05:00
ivan
5d5fde4374
++ sarex-contour: ingressgateway replicaCount=1
...
base-чарт istio-gateway прибит к control-plane нодам и просит 3 реплики
с hostPort — в sarex-contour одна control-plane нода, 2 пода висли Pending.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:27:36 +05:00
ivan
ea759acd09
++ sarex-contour: flux entrypoint + istio rollout
...
Новый кластер clusters/sarex-contour: flux-system (bootstrap на
gitlab.sarex.io, path ./clusters/sarex-contour), helm-repositories
(yc-oci-charts), раскатка istio-base/istiod/ingressgateway.
Gateway опубликован через NodePort 30080/30443 — в контуре нет
облачного LoadBalancer.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:18:46 +05:00
d37c229249
++ default local-path storage class to retain
2026-09-01 18:21:48 +03:00
ivan
9591d770be
++
2026-08-31 16:55:22 +05:00
ivan
1ffe61ea88
feat(bi/d8-ugmk-prod): istio-маршруты для bi на sarex-bi.uralmine.com
...
/analytics-v2/api/ -> /api/ -> bi-backend-service.bi:80
/analytics-v2/static/, /analytics-v2/ -> / -> bi-frontend-frontend-svc.bi:80
Префиксы уже, чем catch-all `/` -> superset на том же хосте.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:54:09 +05:00
bd62e7c153
++ force empty nodeselector and tolerations for ugok vault
2026-08-28 13:21:49 +03:00
75cecf0321
++ add vault install for ugok
2026-08-28 13:14:11 +03:00
b911b7ea50
++ deploy dedicated in-cluster postgres for zitadel, point zitadel at it
2026-08-26 14:22:02 +03:00
2bbf786aa6
++ revert keycloak db password to allowed vault path
2026-08-26 14:17:25 +03:00
7b5f249581
++ read identity password from canonical vault key, drop staging secret
2026-08-26 14:03:22 +03:00
09b0d4e8d1
++ point keycloak db password at its own vault path
2026-08-26 12:53:12 +03:00
30e58fdc30
++ fix gateway wildcard and drop foreign domains
2026-08-26 12:32:46 +03:00
9e66a1e31d
++ route s3 domain through ingressgateway to nginx service
2026-08-26 12:20:56 +03:00
8bbc158e49
++ add s3-proxy nginx service for vad
2026-08-26 12:15:11 +03:00
d2df6afaa4
++ add istio-config for vad with self-signed tls
2026-08-26 12:06:00 +03:00
f051fd67b8
++ zitadel admin password reads same key as user
2026-08-26 11:58:30 +03:00
4420efb5a1
++ match ugmk zitadel admin username pattern
2026-08-26 11:51:32 +03:00
c38032e64e
++ add kafka camunda zitadel overlays for vad
2026-08-26 11:32:23 +03:00
9db6db713a
++ nest ingressgateway service override under internal defaults key
2026-08-25 18:43:38 +03:00
b5acdf28b5
++ fix vad ingressgateway values schema, expose 30080/30443
2026-08-25 18:40:55 +03:00
e2c3079ab1
++ fix vad rabbitmq gateway crd and istio image pull secrets
2026-08-25 18:28:13 +03:00
83262697c0
++ add vault, rabbitmq and istio for vad
2026-08-25 18:22:55 +03:00
98f8ad1635
++ null out sarex_db and resources_db chart defaults in trino catalogs
2026-08-25 14:57:43 +03:00
88b58158de
++ point trino at django_db, drop dead resources_db catalog
2026-08-21 15:56:15 +03:00
b5efcc378c
++ bump pgbouncer chart to 1.0.12
2026-08-21 14:45:05 +03:00
29cc95ef33
++ add pgbouncer backup pooler to brusnika-prod
2026-08-21 14:21:13 +03:00
fb1a36c2fd
++ switch superset domain to sarex-bi.uralmine.com
2026-08-20 15:48:55 +03:00
c45150bc98
++ fix trino worker node selector render
2026-08-20 15:48:55 +03:00
1cb049ba9b
++ place trino worker on processing node
2026-08-20 14:16:49 +03:00
327212ea6f
++ use mirrored ugmk superset trino images
2026-08-20 14:09:26 +03:00
3b5a6ddcc0
++ fix ugmk superset trino contour charts
2026-08-20 14:09:26 +03:00
34c05548f6
++ add superset trino ugmk
2026-08-20 13:19:52 +03:00
e9c582800e
++ use wb superset jwt k8s secret
2026-08-17 17:19:21 +03:00
1827903c41
++ fix wb superset guest token secret delivery
2026-08-17 17:00:33 +03:00
c10d84861f
fix identity.fullURL for ugmk, was falling back to chart default identity.camunda.sarex.io instead of camunda-identity.sarex-k8s.uralmine.com
2026-08-07 14:43:35 +03:00
emelinda
8447ab76bb
Add frontend HelmRelease to d8-ugmk-prod and configure Istio route for s3-proxy in Istio config
2026-08-05 15:33:56 +03:00
emelinda
af6135f2b0
Re-enable and configure multiple virtual services in yc-ecp Istio configuration for main-gateway.
2026-08-05 02:16:35 +03:00
emelinda
db0b8988f1
Refactor yc-ecp configuration: update HelmRelease affinity settings for frontend and re-enable commented Istio routes for main-gateway.
2026-08-05 02:06:17 +03:00
emelinda
218d233eb7
Add Django frontend app to yc-ecp: define namespace, configure HelmRelease with chart and deployment details, update Istio configuration, and include in cluster Kustomization
2026-08-05 01:58:35 +03:00
emelinda
d46ba48d22
Update yc-ecp Istio configuration: add main-gateway and TLS settings for aero.invest.sarex.io
2026-08-05 01:05:11 +03:00
emelinda
c7c244e95d
Update yc-ecp Istio configuration: add imagePullSecrets for cert-manager and enforce HTTPS for dashboard bindings
2026-08-05 00:11:41 +03:00
emelinda
3a5b3b07e6
Add Measurements app to yc-ecp: define HelmRelease, configure Istio certificates, and update cluster Kustomization
2026-08-05 00:00:06 +03:00
emelinda
172e889f00
Add Kubernetes Dashboard configuration to yc-ecp: define HelmRelease, update Istio Gateway and VirtualService, and include in cluster Kustomization
2026-08-04 23:34:53 +03:00
emelinda
e491466a37
Refactor yc-ecp Istio and cert-manager configurations: adjust ClusterIssuer specs, update certificate and VirtualService keys, and add port names.
2026-08-04 23:27:13 +03:00
emelinda
6b107c872a
Remove deprecated Let's Encrypt ClusterIssuer configurations and update dependencies in yc-ecp cert-manager and Istio configuration.
2026-08-04 23:14:05 +03:00
emelinda
9e4a27f898
Remove unused Let's Encrypt ClusterIssuer configurations from yc-ecp cert-manager directory.
2026-08-04 23:07:06 +03:00
emelinda
da36ac822f
Remove unused ClusterIssuer references from yc-ecp cert-manager kustomization
2026-08-04 23:06:33 +03:00
emelinda
4cd9a8b4d5
Add imagePullSecrets to Let's Encrypt ClusterIssuer for DockerHub authentication
2026-08-04 22:58:10 +03:00