apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).
infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.
clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.
infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.
apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/control-interface/base has no namespace.yaml (unlike reviews,
remarks, auth-flow), so Flux failed applying the HelmRelease into a
namespace that was never created.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
apps/control-interface/sarex-contour наследует base (по образцу
d8-ugmk-prod), namespace control-interface, istio-injection: enabled.
Оверлей yc-k8s-test для control-interface не копировали — там
namespace: django и патч на несуществующий HelmRelease srx-admin,
похоже на скопипащенный мёртвый код из apps/django/yc-k8s-test.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds apps/<app>/ugok overlays for 31 applications, derived strictly from
a live cluster dump (kubectl get deployment/service/configmap/secret),
following the wb overlay pattern (standalone HelmRelease patches on
universal-chart, plain k8s Secret + secretKeyRef instead of Vault Agent
since the ugok cluster has zero Vault usage cluster-wide).
- processing (workflow namespace) does not extend base: base is
vault-native, ugok is not, so it's four standalone HelmReleases
modeled on apps/processing/wb/*.
- issues/redis and django/redis are raw Deployments patched via JSON6902.
- documentations/pdf-markings and django/auth-flow-frontend,
export-project are copied in as standalone files (base has no
HelmRelease for them, and kustomize forbids cross-overlay references
outside a directory's own tree).
- Images and images-with-registry updated to match wb where the same
build lineage applies; left as-is where the wb tag carries a distinct
client/cluster name (donstroi1, brusnika_*, dev4, UGOK_*, ugok1_*) or
points at a different image repository entirely.
- Missing backend envs backfilled from wb where safe (internal
svc.cluster.local refs, feature flags, already-established ugok
domains); skipped where wb-specific (external DB/Kafka hosts, TLS CA
content, features not deployed in ugok like gatekeeper/Superset).
- message-hub patch was missing its entire env block from the original
bootstrap; rebuilt from the raw dump (not wb, whose Kafka/DB config is
incompatible) plus a handful of small env gaps found while
cross-checking every ugok app's rendered envs against the raw dump.
clusters/ugok/kustomization.yaml keeps the apps section commented out —
not wired into the Flux Kustomization yet, pending review.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>