Commit Graph

1424 Commits

Author SHA1 Message Date
ivan
fb614030e7 ++ 2026-10-08 00:09:41 +05:00
ivan
5341c355c9 ++ 2026-10-07 23:25:06 +05:00
emelinda
add56bbe3f ++ wb: flows production_81d0fa17, processing MAX_WORKFLOWS_LIMIT 10 2026-10-07 18:58:46 +03:00
247a753f5d ++ camunda processing nodes 2026-10-07 15:06:31 +03:00
ivan
53f4886b29 ++ 2026-10-07 16:16:15 +05:00
ivan
da188eef04 ++ 2026-10-07 15:40:40 +05:00
ivan
2bc78aa7fb ++ 2026-10-07 13:51:10 +05:00
ivan
1099f45a75 ++ 2026-10-06 23:23:56 +05:00
ivan
0d6d6d826b uralkal: pm and message-hub accept flat kafka secret format
KAFKA_SASL_MECHANISM is read from auth.sasl_mechanism when the nested auth
map exists and from the top-level sasl_mechanism otherwise, so the pods start
both before and after kafka/apps/pm switches to creds delivered from the
kafka-topics terraform stack.
2026-10-06 22:40:16 +05:00
emelinda
252a716c03 Merge remote-tracking branch 'origin/master' 2026-10-06 20:30:02 +03:00
emelinda
4f66b55d10 Enable allowCredentials in CORS settings for multiple services in brusnika-prod Istio configuration 2026-10-06 20:29:33 +03:00
ivan
90e684d0a9 uralkal: take Kafka CA from the kafka-kafka-contour-tls secret
flows, issues, pm and message-hub read ca.crt from a copy of the Kafka TLS
secret in their own namespace instead of an inline PEM (flows) or a
per-namespace kafka-ca-cert ConfigMap (issues, pm, message-hub). Mount paths
and env names are unchanged. The secret must exist in each namespace before
the pods restart.
2026-10-06 21:59:43 +05:00
ivan
b1bfb8049a ++ 2026-10-06 18:24:47 +05:00
ivan
8c8a646e03 ++ 2026-10-06 18:19:18 +05:00
ivan
df45eca99f ++ 2026-10-06 17:53:40 +05:00
ivan
563ccefe83 documentations/uralkal: use prod_179e518c_uralkali images for api and filestream 2026-10-06 16:50:50 +05:00
ivan
4117728329 ++ 2026-10-06 16:07:47 +05:00
ivan
47943a4420 ++ 2026-10-06 13:22:11 +05:00
emelinda
2564167f27 Update S3 proxy image reference to stable in brusnika-prod configuration 2026-10-06 00:01:12 +03:00
emelinda
7301e50947 Update AWS_API_ENDPOINT value in brusnika-prod S3 proxy configuration 2026-10-05 23:56:47 +03:00
emelinda
bee959edee Add CORS and routes for cde, pdm-api-api, and documentations services in brusnika-prod Istio configuration 2026-10-05 23:42:24 +03:00
emelinda
bb144b1563 Add CORS and routes for new backend services in brusnika-prod Istio configuration 2026-10-05 23:31:51 +03:00
emelinda
2fa77d717e Add CORS and routes for transmittal-api, inspections-backend, workflows-api, and workspaces-api in brusnika-prod Istio configuration 2026-10-05 23:17:03 +03:00
emelinda
ef5ae0c01d Add CORS and routes for multiple frontend services in brusnika-prod Istio configuration 2026-10-05 22:46:57 +03:00
emelinda
3e9b539f45 Update replicaCount default value to 1 in brusnika-prod backend configuration 2026-10-05 22:09:34 +03:00
emelinda
445336e721 Add TLS and routes for MinIO Console in brusnika-prod Istio configuration 2026-10-05 21:21:30 +03:00
emelinda
6b2cf9b208 Update MinIO routes and CORS settings in brusnika-prod Istio configuration 2026-10-05 20:58:21 +03:00
emelinda
8cf5b3e056 Add routes for checklist and issues services in brusnika-prod Istio configuration 2026-10-05 20:28:46 +03:00
emelinda
6f44ecf79e Update openobserve-web service reference in brusnika-prod Istio configuration 2026-10-05 19:14:45 +03:00
emelinda
02d96adcec Update openobserve-web service reference in brusnika-prod Istio configuration 2026-10-05 19:13:39 +03:00
emelinda
5e40cbd08b Restructure brusnika-prod infrastructure by splitting component configurations into dedicated directories and adding respective kustomizations. 2026-10-05 19:02:52 +03:00
emelinda
dfab98373f Add HelmRelease patch and kustomization for failed-pod-cleanup in brusnika-prod configuration. 2026-10-05 18:57:50 +03:00
emelinda
1c4d9cf1a9 Update replicaCount default value to 2 in brusnika-prod backend configuration. 2026-10-05 14:32:32 +03:00
ivan
2bc3f59580 ++ 2026-10-05 13:28:37 +05:00
ivan
2924e7da5b ++ 2026-10-05 13:25:39 +05:00
ivan
d340ea58aa ++ 2026-10-05 13:03:24 +05:00
ivan
64fe3c00fb control-interface/admin-frontend: drop explicit podAnnotations
universal-chart already injects proxy.istio.io/config and
traffic.sidecar.istio.io/excludeOutboundPorts by default for every
service — explicitly setting them too produced a duplicate-key YAML
error in Flux's post-render step:

  error while running post render on files: ... yaml: unmarshal errors:
    line 42: mapping key "traffic.sidecar.istio.io/excludeOutboundPorts" already defined at line 25
    line 41: mapping key "proxy.istio.io/config" already defined at line 26

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:40:19 +05:00
ivan
5564778337 control-interface: add admin-frontend (universal-chart) to base, route it in vad istio-config
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.

Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.

infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:34:54 +05:00
ivan
0bd15c6ae5 ++ 2026-10-02 14:57:19 +05:00
ivan
e00a7905fb ++ 2026-10-02 14:51:30 +05:00
ivan
7531341438 ++ 2026-10-02 12:33:16 +05:00
ivan
d44378a432 brusnika-stage: route checklists/inspections/workflows/workspaces/comparisons/etc. through Istio instead of the global-ingress nginx proxy
Adds 13 new VirtualServices on the existing test.sarex.brusnika.tech host
and ingress-nginx/main-gateway, matching the active (non-commented)
location blocks in global-ingress's nginx-configmap (fetched live from the
cluster and cross-checked service/port/namespace names against what's
actually running). The root path (/) stays routed to
nginx-service.global-ingress as a fallback for anything not covered here.

Two deliberate deviations from literally replaying the nginx config:
- /comparisons/api/: nginx proxies to port 8080, but the real
  backend-service.comparisons Service listens on 80 (targetPort 8080) —
  used 80.
- /orchestrator/: nginx declares 4 location blocks, but the first
  (bare ~^/orchestrator/) shadows the other three for any non-empty
  path (nginx picks the first matching regex location, not the most
  specific), so only one route (no rewrite) was ported, matching what
  nginx actually does today.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:50:27 +05:00
ivan
6251cfed5c brusnika-stage: bring images and env vars up to wb level
Missing env vars copied from wb for ams-sync, attachments, bi/frontend,
checklists, django (celery, export-project, sarex-backend), documentations
(api, filestream, pdm), eav, flows (backend, celery, frontend), iam,
inspections, issues (backend, celery), rfi, transmittal/worker.

Image tags updated to match wb for flows (backend/celery/frontend), iam.

Known issue, not yet fixed in this commit: several of the copied env
values are wb-specific hosts (*.wb.ru, one uralmine.com) that don't apply
to brusnika-stage — ZITADEL_HOST/ZITADEL_DOMAIN (django, documentations,
iam), DATABASE_HOST/FLOWS_DB_HOST/ISSUES_DB_HOST (checklists, flows),
SUPERSET_HOST (bi), DJANGO_BASE_HOST/SAREX_BACKEND_URL (flows,
inspections), RESOURCES_INTERNAL_HOST/RESOURCE_URL (ams-sync, django,
flows, notes-related). To be corrected in a follow-up commit.

bi/backend.yaml, bim/backend.yaml and notes/backend.yaml were reverted
before this commit (image-tag updates for bi-backend/bim/notes and bi's
SUPERSET_* env additions are not included).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:04:55 +05:00
ivan
e4c3294bb8 ++ 2026-10-01 17:43:58 +05:00
0c54886814 Merge branch 'pdm/update_for_brusnika_copy' into 'master'
fix: update brusnika for copy

See merge request infra/iac!4
2026-09-30 15:25:45 +00:00
diamondrigido
7cac4ff295 fix: update brusnika for copy 2026-09-30 17:17:53 +02:00
emelinda
a438f5bd6b Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:55:40 +03:00
emelinda
8244e56f02 Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:52:55 +03:00
emelinda
70e4b24eee Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:42:18 +03:00
emelinda
474298459a comment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:35:11 +03:00