Commit Graph

9 Commits

Author SHA1 Message Date
ivan
9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00
ivan
5ae853bbf2 asterus: deploy auth-flow
First business app on asterus, overlay copied from brusnika-prod
(no namespace.yaml — ns and regcred created manually, out of band).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 14:34:14 +05:00
ivan
169e2294aa vad: reviews, remarks, auth-flow, control-interface
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 16:45:19 +05:00
ivan
04da33f73e ++ sarex-contour: eav, bi, auth-flow, document-link
Все 4 — чистое наследование base:
- eav, bi — vault-зависимости (postgres [+ eav также minio]) заведены
  через terraform (live/database, live/s3, applications-блок).
- auth-flow, document-link — чистые статические фронтенды без бэкенда
  (см. CLAUDE.md), вообще без vault-зависимостей.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:29:28 +05:00
ivan
c7b749fd09 ++ 2026-07-31 12:55:03 +05:00
emelinda
a8aeb7df0e Migrate auth-flow app from raw manifest definitions to HelmRelease and add to d8-ugmk-prod kustomization. Remove deprecated deployment and service resources and update related configurations. 2026-07-15 18:04:32 +03:00
emelinda
28478d9c86 Add example .env files and configuration documentation for ams-sync, auth-flow, bim, cde, comparisons, django, document-link, flows, iam, inspections services. 2026-07-14 19:23:02 +03:00
ivan
21052884cb ++ 2026-06-29 14:38:29 +05:00
ivan
ef69ec43a5 ++ 2026-06-11 15:19:51 +05:00