Compare commits

...

48 Commits

Author SHA1 Message Date
247a753f5d ++ camunda processing nodes 2026-10-07 15:06:31 +03:00
ivan
53f4886b29 ++ 2026-10-07 16:16:15 +05:00
ivan
da188eef04 ++ 2026-10-07 15:40:40 +05:00
ivan
2bc78aa7fb ++ 2026-10-07 13:51:10 +05:00
ivan
1099f45a75 ++ 2026-10-06 23:23:56 +05:00
ivan
0d6d6d826b uralkal: pm and message-hub accept flat kafka secret format
KAFKA_SASL_MECHANISM is read from auth.sasl_mechanism when the nested auth
map exists and from the top-level sasl_mechanism otherwise, so the pods start
both before and after kafka/apps/pm switches to creds delivered from the
kafka-topics terraform stack.
2026-10-06 22:40:16 +05:00
emelinda
252a716c03 Merge remote-tracking branch 'origin/master' 2026-10-06 20:30:02 +03:00
emelinda
4f66b55d10 Enable allowCredentials in CORS settings for multiple services in brusnika-prod Istio configuration 2026-10-06 20:29:33 +03:00
ivan
90e684d0a9 uralkal: take Kafka CA from the kafka-kafka-contour-tls secret
flows, issues, pm and message-hub read ca.crt from a copy of the Kafka TLS
secret in their own namespace instead of an inline PEM (flows) or a
per-namespace kafka-ca-cert ConfigMap (issues, pm, message-hub). Mount paths
and env names are unchanged. The secret must exist in each namespace before
the pods restart.
2026-10-06 21:59:43 +05:00
ivan
b1bfb8049a ++ 2026-10-06 18:24:47 +05:00
ivan
8c8a646e03 ++ 2026-10-06 18:19:18 +05:00
ivan
df45eca99f ++ 2026-10-06 17:53:40 +05:00
ivan
563ccefe83 documentations/uralkal: use prod_179e518c_uralkali images for api and filestream 2026-10-06 16:50:50 +05:00
ivan
4117728329 ++ 2026-10-06 16:07:47 +05:00
ivan
47943a4420 ++ 2026-10-06 13:22:11 +05:00
emelinda
2564167f27 Update S3 proxy image reference to stable in brusnika-prod configuration 2026-10-06 00:01:12 +03:00
emelinda
7301e50947 Update AWS_API_ENDPOINT value in brusnika-prod S3 proxy configuration 2026-10-05 23:56:47 +03:00
emelinda
bee959edee Add CORS and routes for cde, pdm-api-api, and documentations services in brusnika-prod Istio configuration 2026-10-05 23:42:24 +03:00
emelinda
bb144b1563 Add CORS and routes for new backend services in brusnika-prod Istio configuration 2026-10-05 23:31:51 +03:00
emelinda
2fa77d717e Add CORS and routes for transmittal-api, inspections-backend, workflows-api, and workspaces-api in brusnika-prod Istio configuration 2026-10-05 23:17:03 +03:00
emelinda
ef5ae0c01d Add CORS and routes for multiple frontend services in brusnika-prod Istio configuration 2026-10-05 22:46:57 +03:00
emelinda
3e9b539f45 Update replicaCount default value to 1 in brusnika-prod backend configuration 2026-10-05 22:09:34 +03:00
emelinda
445336e721 Add TLS and routes for MinIO Console in brusnika-prod Istio configuration 2026-10-05 21:21:30 +03:00
emelinda
6b2cf9b208 Update MinIO routes and CORS settings in brusnika-prod Istio configuration 2026-10-05 20:58:21 +03:00
emelinda
8cf5b3e056 Add routes for checklist and issues services in brusnika-prod Istio configuration 2026-10-05 20:28:46 +03:00
emelinda
6f44ecf79e Update openobserve-web service reference in brusnika-prod Istio configuration 2026-10-05 19:14:45 +03:00
emelinda
02d96adcec Update openobserve-web service reference in brusnika-prod Istio configuration 2026-10-05 19:13:39 +03:00
emelinda
5e40cbd08b Restructure brusnika-prod infrastructure by splitting component configurations into dedicated directories and adding respective kustomizations. 2026-10-05 19:02:52 +03:00
emelinda
dfab98373f Add HelmRelease patch and kustomization for failed-pod-cleanup in brusnika-prod configuration. 2026-10-05 18:57:50 +03:00
emelinda
1c4d9cf1a9 Update replicaCount default value to 2 in brusnika-prod backend configuration. 2026-10-05 14:32:32 +03:00
ivan
2bc3f59580 ++ 2026-10-05 13:28:37 +05:00
ivan
2924e7da5b ++ 2026-10-05 13:25:39 +05:00
ivan
d340ea58aa ++ 2026-10-05 13:03:24 +05:00
ivan
64fe3c00fb control-interface/admin-frontend: drop explicit podAnnotations
universal-chart already injects proxy.istio.io/config and
traffic.sidecar.istio.io/excludeOutboundPorts by default for every
service — explicitly setting them too produced a duplicate-key YAML
error in Flux's post-render step:

  error while running post render on files: ... yaml: unmarshal errors:
    line 42: mapping key "traffic.sidecar.istio.io/excludeOutboundPorts" already defined at line 25
    line 41: mapping key "proxy.istio.io/config" already defined at line 26

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:40:19 +05:00
ivan
5564778337 control-interface: add admin-frontend (universal-chart) to base, route it in vad istio-config
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.

Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.

infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-02 15:34:54 +05:00
ivan
0bd15c6ae5 ++ 2026-10-02 14:57:19 +05:00
ivan
e00a7905fb ++ 2026-10-02 14:51:30 +05:00
ivan
7531341438 ++ 2026-10-02 12:33:16 +05:00
ivan
d44378a432 brusnika-stage: route checklists/inspections/workflows/workspaces/comparisons/etc. through Istio instead of the global-ingress nginx proxy
Adds 13 new VirtualServices on the existing test.sarex.brusnika.tech host
and ingress-nginx/main-gateway, matching the active (non-commented)
location blocks in global-ingress's nginx-configmap (fetched live from the
cluster and cross-checked service/port/namespace names against what's
actually running). The root path (/) stays routed to
nginx-service.global-ingress as a fallback for anything not covered here.

Two deliberate deviations from literally replaying the nginx config:
- /comparisons/api/: nginx proxies to port 8080, but the real
  backend-service.comparisons Service listens on 80 (targetPort 8080) —
  used 80.
- /orchestrator/: nginx declares 4 location blocks, but the first
  (bare ~^/orchestrator/) shadows the other three for any non-empty
  path (nginx picks the first matching regex location, not the most
  specific), so only one route (no rewrite) was ported, matching what
  nginx actually does today.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:50:27 +05:00
ivan
6251cfed5c brusnika-stage: bring images and env vars up to wb level
Missing env vars copied from wb for ams-sync, attachments, bi/frontend,
checklists, django (celery, export-project, sarex-backend), documentations
(api, filestream, pdm), eav, flows (backend, celery, frontend), iam,
inspections, issues (backend, celery), rfi, transmittal/worker.

Image tags updated to match wb for flows (backend/celery/frontend), iam.

Known issue, not yet fixed in this commit: several of the copied env
values are wb-specific hosts (*.wb.ru, one uralmine.com) that don't apply
to brusnika-stage — ZITADEL_HOST/ZITADEL_DOMAIN (django, documentations,
iam), DATABASE_HOST/FLOWS_DB_HOST/ISSUES_DB_HOST (checklists, flows),
SUPERSET_HOST (bi), DJANGO_BASE_HOST/SAREX_BACKEND_URL (flows,
inspections), RESOURCES_INTERNAL_HOST/RESOURCE_URL (ams-sync, django,
flows, notes-related). To be corrected in a follow-up commit.

bi/backend.yaml, bim/backend.yaml and notes/backend.yaml were reverted
before this commit (image-tag updates for bi-backend/bim/notes and bi's
SUPERSET_* env additions are not included).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-10-01 18:04:55 +05:00
ivan
e4c3294bb8 ++ 2026-10-01 17:43:58 +05:00
0c54886814 Merge branch 'pdm/update_for_brusnika_copy' into 'master'
fix: update brusnika for copy

See merge request infra/iac!4
2026-09-30 15:25:45 +00:00
diamondrigido
7cac4ff295 fix: update brusnika for copy 2026-09-30 17:17:53 +02:00
emelinda
a438f5bd6b Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:55:40 +03:00
emelinda
8244e56f02 Comment out vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:52:55 +03:00
emelinda
70e4b24eee Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:42:18 +03:00
emelinda
474298459a comment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 17:35:11 +03:00
emelinda
c471cf39e0 Uncomment vs-resources-admin configuration in brusnika-stage Istio settings. 2026-09-30 15:20:40 +03:00
92 changed files with 1566 additions and 362 deletions

View File

@ -39,7 +39,8 @@
**Кластер.** `clusters/<cluster>/kustomization.yaml` — плоский список `../../apps/<app>/<cluster>`. Инфраструктура подключается двумя разными способами: **Кластер.** `clusters/<cluster>/kustomization.yaml` — плоский список `../../apps/<app>/<cluster>`. Инфраструктура подключается двумя разными способами:
- `d8-ugmk-prod` — прямо в корневом kustomization как `../../infrastructure/<comp>/d8-ugmk-prod`; - `d8-ugmk-prod` — прямо в корневом kustomization как `../../infrastructure/<comp>/d8-ugmk-prod`;
- `brusnika-prod`, `brusnika-stage`, `wb` — через `clusters/<c>/infrastructure/kustomization.yaml`, который ссылается на `../../../infrastructure/<comp>` (резолвится в `base`), а различия лежат в `clusters/<c>/infrastructure/patches/*.yaml`. - `brusnika-prod`, `brusnika-stage` — через `clusters/<c>/infrastructure/kustomization.yaml`, который ссылается на оверлеи `../../../infrastructure/<comp>/<c>` (`base` + патч HelmRelease + сопутствующие манифесты компонента);
- `wb` — через `clusters/wb/infrastructure/kustomization.yaml`, который ссылается на `../../../infrastructure/<comp>` (резолвится в `base`), а различия лежат в `clusters/wb/infrastructure/patches/*.yaml`.
Кластеры: `brusnika-prod`, `brusnika-stage`, `d8-ugmk-prod`, `wb`, `yc-cps-prod`, `yc-ecp`, `yc-infra-prod`, `yc-k8s-test`, `yc-k8s-test-02`, `contour`. Кластеры: `brusnika-prod`, `brusnika-stage`, `d8-ugmk-prod`, `wb`, `yc-cps-prod`, `yc-ecp`, `yc-infra-prod`, `yc-k8s-test`, `yc-k8s-test-02`, `contour`.

View File

@ -138,6 +138,10 @@ spec:
- name: KAFKA_SASL_MECHANISM - name: KAFKA_SASL_MECHANISM
value: value:
_default: "SCRAM-SHA-512" _default: "SCRAM-SHA-512"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://iams.iam.svc.cluster.local:8080"
secretEnvs: secretEnvs:
- name: TELEGRAM_TOKEN - name: TELEGRAM_TOKEN
secretName: secretName:

View File

@ -110,6 +110,10 @@ spec:
- name: YANDEX_S3_VERIFY - name: YANDEX_S3_VERIFY
value: value:
_default: "false" _default: "false"
- name: YANDEX_S3_USE_SSL
value:
_default: "false"
secretEnvs: secretEnvs:
- name: DATABASE_HOST - name: DATABASE_HOST
secretName: secretName:

View File

@ -71,9 +71,9 @@ spec:
resources: resources:
requests: requests:
cpu: cpu:
_default: 500m _default: 25m
memory: memory:
_default: 1Gi _default: 128Mi
probes: probes:
liveness: liveness:

View File

@ -37,7 +37,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-frontend:production_afb137d4 _default: cr.yandex/crp3ccidau046kdj8g9q/bi-frontend:contour_9cfd1a0b
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent

View File

@ -71,9 +71,9 @@ spec:
resources: resources:
requests: requests:
cpu: cpu:
_default: 500m _default: 25m
memory: memory:
_default: 1Gi _default: 128Mi
probes: probes:
liveness: liveness:

View File

@ -71,9 +71,9 @@ spec:
resources: resources:
requests: requests:
cpu: cpu:
_default: "1" _default: 25m
memory: memory:
_default: 1Gi _default: 228Mi
probes: probes:
liveness: liveness:

View File

@ -71,7 +71,7 @@ spec:
resources: resources:
requests: requests:
cpu: cpu:
_default: 500m _default: 250m
memory: memory:
_default: 512Mi _default: 512Mi

View File

@ -0,0 +1,94 @@
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: admin-frontend
namespace: control-interface
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.7"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
admin-frontend:
enabled: true
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/admin-frontend:contour_9dc27b40
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: admin-frontend
replicaCount:
_default: 1
port:
_default: 80
resources:
requests:
cpu:
_default: 100m
memory:
_default: 100Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: admin-frontend-svc
type:
_default: ClusterIP
port:
_default: 8080
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,4 +4,5 @@ kind: Kustomization
namespace: control-interface namespace: control-interface
resources: resources:
- helmrelease.yaml - helmrelease.yaml
- admin-frontend.yaml

View File

@ -3,3 +3,4 @@ kind: Kustomization
resources: resources:
- ../base - ../base
- namespace.yaml - namespace.yaml
- psql-tools-debug.yaml

View File

@ -0,0 +1,27 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: psql-tools-debug
namespace: control-interface
labels:
app: psql-tools-debug
spec:
replicas: 1
selector:
matchLabels:
app: psql-tools-debug
template:
metadata:
labels:
app: psql-tools-debug
spec:
containers:
- name: debug
image: cr.yandex/crp3ccidau046kdj8g9q/mc-files:latest
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-c"]
args:
- while true; do sleep 3600; done
imagePullSecrets:
- name: regcred

View File

@ -35,7 +35,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/export-project:prod_37a48176 _default: cr.yandex/crp3ccidau046kdj8g9q/s3-proxy:stable
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent
@ -89,7 +89,7 @@ spec:
envs: envs:
- name: AWS_API_ENDPOINT - name: AWS_API_ENDPOINT
value: value:
_default: "http://minio-svc.minio.svc.cluster.local:9000" _default: "https://obs.ru-moscow-1.hc.sbercloud.ru"
- name: APP_PORT - name: APP_PORT
value: value:
_default: "8000" _default: "8000"

View File

@ -330,6 +330,14 @@ spec:
- name: KC_USE_REDIRECT_LOGOUT - name: KC_USE_REDIRECT_LOGOUT
value: value:
_default: "True" _default: "True"
- name: CACHE_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://iams.iam.svc.cluster.local:8080"
secretEnvs: secretEnvs:
- name: SERVER_SUPERSET_JWT_SECRET - name: SERVER_SUPERSET_JWT_SECRET
secretName: secretName:

View File

@ -88,6 +88,11 @@ spec:
labels: labels:
monitoring: prometheus monitoring: prometheus
envs:
- name: TIMEOUT
value:
_default: "180"
commitSha: "" commitSha: ""
gitlabUri: "" gitlabUri: ""
gitlabJobUrl: "" gitlabJobUrl: ""

View File

@ -313,6 +313,18 @@ spec:
- name: KC_USE_REDIRECT_LOGOUT - name: KC_USE_REDIRECT_LOGOUT
value: value:
_default: "True" _default: "True"
- name: RESOURCES_INTERNAL_HOST
value:
_default: "http://iams.iam.svc.cluster.local:8080"
- name: SERVER_EXTERNAL_FIND_BY_USERNAME_ENABLED
value:
_default: "True"
- name: SERVER_EXTERNAL_FIND_BY_EMAIL_ENABLED
value:
_default: "True"
secretEnvs: secretEnvs:
- name: SERVER_SUPERSET_JWT_SECRET - name: SERVER_SUPERSET_JWT_SECRET
secretName: secretName:

View File

@ -60,12 +60,12 @@ data:
expires off; expires off;
} }
# location ~^/api/pm/ { location ~^/api/pm/ {
# proxy_http_version 1.1; proxy_http_version 1.1;
# proxy_set_header Connection ""; proxy_set_header Connection "";
# proxy_set_header Host $host; proxy_set_header Host $host;
# proxy_pass http://backend-svc.pm.svc.cluster.local:8000; proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
# } }
location ~^/api/v1/documents/ { location ~^/api/v1/documents/ {
proxy_http_version 1.1; proxy_http_version 1.1;

View File

@ -60,12 +60,12 @@ data:
expires off; expires off;
} }
# location ~^/api/pm/ { location ~^/api/pm/ {
# proxy_http_version 1.1; proxy_http_version 1.1;
# proxy_set_header Connection ""; proxy_set_header Connection "";
# proxy_set_header Host $host; proxy_set_header Host $host;
# proxy_pass http://backend-svc.pm.svc.cluster.local:8000; proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
# } }
location ~^/api/v1/documents/ { location ~^/api/v1/documents/ {
proxy_http_version 1.1; proxy_http_version 1.1;

View File

@ -37,7 +37,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations:prod_b34286a7 _default: cr.yandex/crp3ccidau046kdj8g9q/documentations:prod_98a23ef5
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent
@ -267,6 +267,15 @@ spec:
- name: USE_CACHE_IN_FILE_STREAMER - name: USE_CACHE_IN_FILE_STREAMER
value: value:
_default: "1" _default: "1"
- name: USE_LEGACY_BIM_FLOW
value:
_default: "true"
- name: PUBLIC_LINK_FOLDER_CONNECTOR_ENABLED
value:
_default: "true"
secretEnvs: secretEnvs:
- name: PUBLIC_KEY - name: PUBLIC_KEY
secretName: secretName:

View File

@ -255,6 +255,34 @@ spec:
- name: USE_CACHE_IN_FILE_STREAMER - name: USE_CACHE_IN_FILE_STREAMER
value: value:
_default: "1" _default: "1"
- name: USE_LEGACY_BIM_FLOW
value:
_default: "true"
- name: USE_ZITADEL
value:
_default: "0"
- name: LAST_SLAVE_1_BIM
value:
_default: "1000000"
- name: ENABLE_SMTP
value:
_default: "True"
- name: ENABLE_MAILGUN
value:
_default: "False"
- name: ENABLE_AUTH_JWT_IN_URL
value:
_default: "false"
- name: ENABLE_SIGNATURE_IN_URL
value:
_default: "true"
secretEnvs: secretEnvs:
- name: PUBLIC_KEY - name: PUBLIC_KEY
secretName: secretName:

View File

@ -255,6 +255,19 @@ spec:
- name: USE_CACHE_IN_FILE_STREAMER - name: USE_CACHE_IN_FILE_STREAMER
value: value:
_default: "1" _default: "1"
- name: USE_ZITADEL
value:
_default: "0"
- name: ENABLE_AUTH_JWT_IN_URL
value:
_default: "false"
- name: ENABLE_SIGNATURE_IN_URL
value:
_default: "true"
secretEnvs: secretEnvs:
- name: PUBLIC_KEY - name: PUBLIC_KEY
secretName: secretName:

View File

@ -308,6 +308,14 @@ spec:
- name: WORKSPACE_URL - name: WORKSPACE_URL
value: value:
_default: "http://workspaces-service.workspaces.svc.cluster.local:8000/" _default: "http://workspaces-service.workspaces.svc.cluster.local:8000/"
- name: BUCKET_NAME
value:
_default: "attachments-storage"
- name: PERMISSIONS_FILTER_COMPANIES
value:
_default: "[1]"
secretEnvs: secretEnvs:
- name: RELEASES_TOKEN - name: RELEASES_TOKEN
secretName: secretName:

View File

@ -13,6 +13,9 @@ spec:
requests: requests:
cpu: null cpu: null
memory: null memory: null
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations-api:contour_8631bb0e
envs: envs:
- name: POSTGRES_POOL_SIZE - name: POSTGRES_POOL_SIZE
value: value:
@ -23,6 +26,9 @@ spec:
- name: ZITADEL_DOMAIN - name: ZITADEL_DOMAIN
value: value:
_default: login.sarex.local.uralkali.com _default: login.sarex.local.uralkali.com
- name: ZITADEL_INSECURE_SKIP_VERIFY
value:
_default: "true"
- name: USE_ZITADEL - name: USE_ZITADEL
value: value:
_default: "1" _default: "1"

View File

@ -13,10 +13,16 @@ spec:
requests: requests:
cpu: null cpu: null
memory: null memory: null
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations-api-files:contour_8631bb0e
envs: envs:
- name: POSTGRES_POOL_SIZE - name: POSTGRES_POOL_SIZE
value: value:
_default: "20" _default: "20"
- name: ZITADEL_INSECURE_SKIP_VERIFY
value:
_default: "true"
- name: ZITADEL_ACCOUNT - name: ZITADEL_ACCOUNT
value: value:
_default: /vault/secrets/documentations-zitadel-account-json _default: /vault/secrets/documentations-zitadel-account-json

View File

@ -166,6 +166,10 @@ spec:
- name: YC_S3_BUCKET_NAME - name: YC_S3_BUCKET_NAME
value: value:
_default: "eav" _default: "eav"
- name: KAFKA_ENABLED
value:
_default: "False"
secretEnvs: secretEnvs:
- name: KAFKA_PASSWORD - name: KAFKA_PASSWORD
secretName: secretName:

View File

@ -35,7 +35,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a7dc8216 _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_e8a366a3
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent
@ -225,6 +225,22 @@ spec:
- name: DOCUMENTATION_TIMEOUT - name: DOCUMENTATION_TIMEOUT
value: value:
_default: "60" _default: "60"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: PROXY_PATH_PREFIX
value:
_default: "/flows"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
secretEnvs: secretEnvs:
- name: ADMIN_PANEL_SECRET_KEY - name: ADMIN_PANEL_SECRET_KEY
secretName: secretName:

View File

@ -35,7 +35,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a7dc8216 _default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_e8a366a3
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent
@ -223,6 +223,34 @@ spec:
- name: DOCUMENTATION_TIMEOUT - name: DOCUMENTATION_TIMEOUT
value: value:
_default: "60" _default: "60"
- name: FLOWS_HOST
value:
_default: "http://backend-service.flows.svc.cluster.local:8000"
- name: RESOURCES_HOST
value:
_default: "http://iams.iam.svc.cluster.local:8080"
- name: FLOWS_DB_HOST
value:
_default: "192.168.2.45"
- name: FLOWS_DB_PORT
value:
_default: "5432"
- name: ISSUES_DB_PORT
value:
_default: "5432"
- name: ISSUES_DB_HOST
value:
_default: "192.168.2.45"
- name: DJANGO_BASE_HOST
value:
_default: "https://test.sarex.brusnika.tech"
secretEnvs: secretEnvs:
- name: ADMIN_PANEL_SECRET_KEY - name: ADMIN_PANEL_SECRET_KEY
secretName: secretName:

View File

@ -35,7 +35,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_dcc5b5e6 _default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_ed219085
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent

View File

@ -83,6 +83,10 @@ spec:
value: value:
_default: "0" _default: "0"
- name: ENABLE_EVENTS
value:
_default: "0"
- name: ENABLE_METRICS - name: ENABLE_METRICS
value: value:
_default: "0" _default: "0"
@ -139,28 +143,11 @@ spec:
value: value:
_default: "kafka-kafka-contour.kafka.svc.cluster.local:9092" _default: "kafka-kafka-contour.kafka.svc.cluster.local:9092"
secretEnvs:
- name: KAFKA_SSL_CERT - name: KAFKA_SSL_CERT
value: secretName:
_default: | _default: kafka-kafka-contour-tls
-----BEGIN CERTIFICATE----- secretKey: "ca.crt"
MIIDETCCAfmgAwIBAgIQNhHkZWgkcMSiuRD9FD3SKjANBgkqhkiG9w0BAQsFADAT
MREwDwYDVQQDEwhrYWZrYS1jYTAeFw0yNjA4MjYwOTM4MzFaFw0yNzA4MjYwOTM4
MzFaMBMxETAPBgNVBAMTCGthZmthLWNhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7Vvs1386xYZrKJ4qr/LwiibuhyoIHZm6AnjubChLKUSulP0+TIYC
tDgfSiEQsmASCkJKrvrpg2o0TGxj+LUTVnBCDWwBL3wXWSrbHTmpo9y2n0MH/SiN
h0n43/ReuXXGzuP+s4WF4Z6EkQyCqqGXZkqYx3PsiqQv2DYmnU/s6jdEqXBhDyU9
k6KGjMGxCmDN07E8iElfZp58KvZSISFNi2X5QWa3CIiPo7EKOyW20Hw8xVyQ8/SX
GE/Rt2I4G/LC+EhUBKrRB4UgHY1UcifO0EMvKeh8lLRBT5+yqQvkA2/cXYKmeEKc
zICZw5ve1DiImjQKvHoM257t6lf5yj9h+wIDAQABo2EwXzAOBgNVHQ8BAf8EBAMC
AqQwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMB
Af8wHQYDVR0OBBYEFAANdtqbrWPSSQqiCh1Wii2jxHO5MA0GCSqGSIb3DQEBCwUA
A4IBAQBJOea+5wxUNQuWX+E1m3GA5WJz+mAyt8J37w1ZpFVSpOX9r/ptSjyGoNY2
vgP0G8bJH30s25D4kRHuvvPeeCGnOR3PKPceeNIa4CQYvHnYT2bf7WBP8rLd0TyS
OV/ApxvxipKjl0OQc+95xAxm2z0qWIeOh1dkurvyhdLasIhqyhuUguW8APB2U3dU
fIvJ/R992Hy/MYvW7cw1CMWoaoBX90TEl6JNCHQvfBxaQzvPRvSEWwnRgbGwSZwz
ZS6GaNGN7C70WCxP4gmmkWfUC9lphnFb0IMGxXr/nTu5Ez5PKqRG56THkW5vd45i
0FC16VuidLG0HUCCawFjRiAg9rIA
-----END CERTIFICATE-----
podAnnotations: podAnnotations:
_default: _default:

View File

@ -1,11 +1,4 @@
--- ---
# Патч celery для контура УГМК — подключение к Kafka.
#
# ВНИМАНИЕ: envs — список, kustomize заменяет его ЦЕЛИКОМ (JSON merge patch),
# поэтому здесь продублирован весь набор из apps/flows/base/celery.yaml.
# args — тоже список, продублирован весь скрипт с добавленным sourcing flows-kafka.
# podAnnotations — map, мержится по ключам, поэтому переопределён только
# один ключ agent-inject-template-flows-kafka; остальные vault-аннотации берутся из base.
apiVersion: helm.toolkit.fluxcd.io/v2 apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease kind: HelmRelease
metadata: metadata:
@ -140,28 +133,11 @@ spec:
value: value:
_default: "kafka-kafka-contour.kafka.svc.cluster.local:9092" _default: "kafka-kafka-contour.kafka.svc.cluster.local:9092"
secretEnvs:
- name: KAFKA_SSL_CERT - name: KAFKA_SSL_CERT
value: secretName:
_default: | _default: kafka-kafka-contour-tls
-----BEGIN CERTIFICATE----- secretKey: "ca.crt"
MIIDETCCAfmgAwIBAgIQNhHkZWgkcMSiuRD9FD3SKjANBgkqhkiG9w0BAQsFADAT
MREwDwYDVQQDEwhrYWZrYS1jYTAeFw0yNjA4MjYwOTM4MzFaFw0yNzA4MjYwOTM4
MzFaMBMxETAPBgNVBAMTCGthZmthLWNhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7Vvs1386xYZrKJ4qr/LwiibuhyoIHZm6AnjubChLKUSulP0+TIYC
tDgfSiEQsmASCkJKrvrpg2o0TGxj+LUTVnBCDWwBL3wXWSrbHTmpo9y2n0MH/SiN
h0n43/ReuXXGzuP+s4WF4Z6EkQyCqqGXZkqYx3PsiqQv2DYmnU/s6jdEqXBhDyU9
k6KGjMGxCmDN07E8iElfZp58KvZSISFNi2X5QWa3CIiPo7EKOyW20Hw8xVyQ8/SX
GE/Rt2I4G/LC+EhUBKrRB4UgHY1UcifO0EMvKeh8lLRBT5+yqQvkA2/cXYKmeEKc
zICZw5ve1DiImjQKvHoM257t6lf5yj9h+wIDAQABo2EwXzAOBgNVHQ8BAf8EBAMC
AqQwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMB
Af8wHQYDVR0OBBYEFAANdtqbrWPSSQqiCh1Wii2jxHO5MA0GCSqGSIb3DQEBCwUA
A4IBAQBJOea+5wxUNQuWX+E1m3GA5WJz+mAyt8J37w1ZpFVSpOX9r/ptSjyGoNY2
vgP0G8bJH30s25D4kRHuvvPeeCGnOR3PKPceeNIa4CQYvHnYT2bf7WBP8rLd0TyS
OV/ApxvxipKjl0OQc+95xAxm2z0qWIeOh1dkurvyhdLasIhqyhuUguW8APB2U3dU
fIvJ/R992Hy/MYvW7cw1CMWoaoBX90TEl6JNCHQvfBxaQzvPRvSEWwnRgbGwSZwz
ZS6GaNGN7C70WCxP4gmmkWfUC9lphnFb0IMGxXr/nTu5Ez5PKqRG56THkW5vd45i
0FC16VuidLG0HUCCawFjRiAg9rIA
-----END CERTIFICATE-----
podAnnotations: podAnnotations:
_default: _default:

View File

@ -42,7 +42,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/iams:contour_dada80a8 _default: cr.yandex/crp3ccidau046kdj8g9q/iams:contour_29754513
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent

View File

@ -35,7 +35,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/iams:production_786e19c3 _default: cr.yandex/crp3ccidau046kdj8g9q/iams:contour_dada80a8
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent
@ -158,6 +158,22 @@ spec:
- name: KAFKA_TOPIC_COMPANY_RESOURCE_PERMISSIONS - name: KAFKA_TOPIC_COMPANY_RESOURCE_PERMISSIONS
value: value:
_default: "company_resource_permissions" _default: "company_resource_permissions"
- name: AUTH_ENABLED
value:
_default: "true"
- name: ZITADEL_ENABLED
value:
_default: "false"
- name: ZITADEL_ORG_RULES_FILE
value:
_default: "config/zitadel/org-rules-prod.json"
- name: KAFKA_TOPIC_LEGACY_AMS_SYNC
value:
_default: "ams-sync"
secretEnvs: secretEnvs:
- name: DB_DSN - name: DB_DSN
secretName: secretName:

View File

@ -57,6 +57,10 @@ spec:
value: value:
_default: "iam" _default: "iam"
- name: ZITADEL_TLS_INSECURE_SKIP_VERIFY
value:
_default: "true"
- name: S3_REGION - name: S3_REGION
value: value:
_default: "ru-central1" _default: "ru-central1"

View File

@ -130,6 +130,94 @@ spec:
- name: API_ADDRESS - name: API_ADDRESS
value: value:
_default: "8000" _default: "8000"
- name: DEBUG
value:
_default: "false"
- name: HTTP_APP_HOST
value:
_default: "0.0.0.0"
- name: HTTP_APP_PORT
value:
_default: "8000"
- name: HTTP_APP_ROOT_PATH
value:
_default: "/inspections"
- name: HTTP_APP_WORKERS
value:
_default: "3"
- name: HTTP_APP_ADMIN_ENABLE
value:
_default: "true"
- name: KAFKA_SSL_CAFILE
value:
_default: "/usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt"
- name: KAFKA_EAV_ASSETS_TOPIC
value:
_default: "assets_broadcast"
- name: JWT_AUTH_ENABLE
value:
_default: "true"
- name: NOTIFICATIONS_ENABLE
value:
_default: "true"
- name: NOTIFICATIONS_EMAIL_FROM
value:
_default: "hello@sarex.io"
- name: SAREX_BACKEND_URL
value:
_default: "https://test.sarex.brusnika.tech"
- name: SAREX_BACKEND_TIMEOUT
value:
_default: "30"
- name: EAV_URL
value:
_default: "http://eav-service.eav"
- name: EAV_TIMEOUT
value:
_default: "30"
- name: WORKFLOWS_TIMEOUT
value:
_default: "30"
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q/notification:email"
- name: MOBILE_APP_CURRENT_VERSION
value:
_default: "1.0.0"
- name: MOBILE_APP_RECOMMENDED_VERSION
value:
_default: "1.0.0"
- name: MOBILE_APP_REQUIRED_VERSION
value:
_default: "1.0.0"
- name: MAILER_URL
value:
_default: "http://mailer-service.mailer:8000"
- name: MAILER_TIMEOUT
value:
_default: "30"
secretEnvs: secretEnvs:
- name: DATABASE_USER - name: DATABASE_USER
secretName: secretName:

View File

@ -176,6 +176,10 @@ spec:
- name: API_ADDRESS - name: API_ADDRESS
value: value:
_default: "8000" _default: "8000"
- name: RABBITMQ_HOSTNAME
value:
_default: "rabbitmq.rabbitmq.svc.cluster.local:5672"
secretEnvs: secretEnvs:
- name: YC_S3_ACCESS_KEY_ID - name: YC_S3_ACCESS_KEY_ID
secretName: secretName:

View File

@ -187,6 +187,18 @@ spec:
- name: API_ADDRESS - name: API_ADDRESS
value: value:
_default: "8000" _default: "8000"
- name: USE_NOTIFICATIONS
value:
_default: "True"
- name: ENABLE_MAILGUN
value:
_default: "False"
- name: RABBITMQ_HOSTNAME
value:
_default: "rabbitmq.rabbitmq.svc.cluster.local:5672"
secretEnvs: secretEnvs:
- name: YC_S3_ACCESS_KEY_ID - name: YC_S3_ACCESS_KEY_ID
secretName: secretName:

View File

@ -49,11 +49,11 @@ spec:
_default: kafka.crt _default: kafka.crt
readOnly: readOnly:
_default: true _default: true
configMap: secret:
name: secretName:
_default: kafka-ca-cert _default: kafka-kafka-contour-tls
items: items:
- key: kafka.crt - key: ca.crt
path: path:
_default: kafka.crt _default: kafka.crt

View File

@ -49,11 +49,11 @@ spec:
_default: kafka.crt _default: kafka.crt
readOnly: readOnly:
_default: true _default: true
configMap: secret:
name: secretName:
_default: kafka-ca-cert _default: kafka-kafka-contour-tls
items: items:
- key: kafka.crt - key: ca.crt
path: path:
_default: kafka.crt _default: kafka.crt

View File

@ -1,27 +0,0 @@
---
apiVersion: v1
kind: ConfigMap
metadata:
name: kafka-ca-cert
namespace: issues
data:
kafka.crt: |
-----BEGIN CERTIFICATE-----
MIIDETCCAfmgAwIBAgIQNhHkZWgkcMSiuRD9FD3SKjANBgkqhkiG9w0BAQsFADAT
MREwDwYDVQQDEwhrYWZrYS1jYTAeFw0yNjA4MjYwOTM4MzFaFw0yNzA4MjYwOTM4
MzFaMBMxETAPBgNVBAMTCGthZmthLWNhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7Vvs1386xYZrKJ4qr/LwiibuhyoIHZm6AnjubChLKUSulP0+TIYC
tDgfSiEQsmASCkJKrvrpg2o0TGxj+LUTVnBCDWwBL3wXWSrbHTmpo9y2n0MH/SiN
h0n43/ReuXXGzuP+s4WF4Z6EkQyCqqGXZkqYx3PsiqQv2DYmnU/s6jdEqXBhDyU9
k6KGjMGxCmDN07E8iElfZp58KvZSISFNi2X5QWa3CIiPo7EKOyW20Hw8xVyQ8/SX
GE/Rt2I4G/LC+EhUBKrRB4UgHY1UcifO0EMvKeh8lLRBT5+yqQvkA2/cXYKmeEKc
zICZw5ve1DiImjQKvHoM257t6lf5yj9h+wIDAQABo2EwXzAOBgNVHQ8BAf8EBAMC
AqQwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMB
Af8wHQYDVR0OBBYEFAANdtqbrWPSSQqiCh1Wii2jxHO5MA0GCSqGSIb3DQEBCwUA
A4IBAQBJOea+5wxUNQuWX+E1m3GA5WJz+mAyt8J37w1ZpFVSpOX9r/ptSjyGoNY2
vgP0G8bJH30s25D4kRHuvvPeeCGnOR3PKPceeNIa4CQYvHnYT2bf7WBP8rLd0TyS
OV/ApxvxipKjl0OQc+95xAxm2z0qWIeOh1dkurvyhdLasIhqyhuUguW8APB2U3dU
fIvJ/R992Hy/MYvW7cw1CMWoaoBX90TEl6JNCHQvfBxaQzvPRvSEWwnRgbGwSZwz
ZS6GaNGN7C70WCxP4gmmkWfUC9lphnFb0IMGxXr/nTu5Ez5PKqRG56THkW5vd45i
0FC16VuidLG0HUCCawFjRiAg9rIA
-----END CERTIFICATE-----

View File

@ -2,7 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- ../base - ../base
- kafka-ca-configmap.yaml
patches: patches:
- path: backend-s3.yaml - path: backend-s3.yaml
target: target:

View File

@ -1,27 +0,0 @@
---
apiVersion: v1
kind: ConfigMap
metadata:
name: kafka-ca-cert
namespace: message-hub
data:
kafka.crt: |
-----BEGIN CERTIFICATE-----
MIIDETCCAfmgAwIBAgIQNhHkZWgkcMSiuRD9FD3SKjANBgkqhkiG9w0BAQsFADAT
MREwDwYDVQQDEwhrYWZrYS1jYTAeFw0yNjA4MjYwOTM4MzFaFw0yNzA4MjYwOTM4
MzFaMBMxETAPBgNVBAMTCGthZmthLWNhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7Vvs1386xYZrKJ4qr/LwiibuhyoIHZm6AnjubChLKUSulP0+TIYC
tDgfSiEQsmASCkJKrvrpg2o0TGxj+LUTVnBCDWwBL3wXWSrbHTmpo9y2n0MH/SiN
h0n43/ReuXXGzuP+s4WF4Z6EkQyCqqGXZkqYx3PsiqQv2DYmnU/s6jdEqXBhDyU9
k6KGjMGxCmDN07E8iElfZp58KvZSISFNi2X5QWa3CIiPo7EKOyW20Hw8xVyQ8/SX
GE/Rt2I4G/LC+EhUBKrRB4UgHY1UcifO0EMvKeh8lLRBT5+yqQvkA2/cXYKmeEKc
zICZw5ve1DiImjQKvHoM257t6lf5yj9h+wIDAQABo2EwXzAOBgNVHQ8BAf8EBAMC
AqQwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMB
Af8wHQYDVR0OBBYEFAANdtqbrWPSSQqiCh1Wii2jxHO5MA0GCSqGSIb3DQEBCwUA
A4IBAQBJOea+5wxUNQuWX+E1m3GA5WJz+mAyt8J37w1ZpFVSpOX9r/ptSjyGoNY2
vgP0G8bJH30s25D4kRHuvvPeeCGnOR3PKPceeNIa4CQYvHnYT2bf7WBP8rLd0TyS
OV/ApxvxipKjl0OQc+95xAxm2z0qWIeOh1dkurvyhdLasIhqyhuUguW8APB2U3dU
fIvJ/R992Hy/MYvW7cw1CMWoaoBX90TEl6JNCHQvfBxaQzvPRvSEWwnRgbGwSZwz
ZS6GaNGN7C70WCxP4gmmkWfUC9lphnFb0IMGxXr/nTu5Ez5PKqRG56THkW5vd45i
0FC16VuidLG0HUCCawFjRiAg9rIA
-----END CERTIFICATE-----

View File

@ -2,7 +2,6 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization kind: Kustomization
resources: resources:
- ../base - ../base
- kafka-ca-configmap.yaml
patches: patches:
- path: message-hub.yaml - path: message-hub.yaml
target: target:

View File

@ -91,11 +91,11 @@ spec:
_default: kafka.crt _default: kafka.crt
readOnly: readOnly:
_default: true _default: true
configMap: secret:
name: secretName:
_default: kafka-ca-cert _default: kafka-kafka-contour-tls
items: items:
- key: kafka.crt - key: ca.crt
path: path:
_default: kafka.crt _default: kafka.crt
@ -106,5 +106,5 @@ spec:
{{- with secret "secrets/data/kafka/apps/pm" -}} {{- with secret "secrets/data/kafka/apps/pm" -}}
KAFKA_USERNAME={{ index .Data.data "username" }} KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }} KAFKA_PASSWORD={{ index .Data.data "password" }}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }} KAFKA_SASL_MECHANISM={{ if .Data.data.auth }}{{ index .Data.data.auth "sasl_mechanism" }}{{ else }}{{ index .Data.data "sasl_mechanism" }}{{ end }}
{{- end -}} {{- end -}}

View File

@ -182,11 +182,11 @@ spec:
_default: kafka.crt _default: kafka.crt
readOnly: readOnly:
_default: true _default: true
configMap: secret:
name: secretName:
_default: kafka-ca-cert _default: kafka-kafka-contour-tls
items: items:
- key: kafka.crt - key: ca.crt
path: path:
_default: kafka.crt _default: kafka.crt
@ -204,7 +204,7 @@ spec:
vault.hashicorp.com/agent-inject-secret-pm-kafka: secrets/data/kafka/apps/pm vault.hashicorp.com/agent-inject-secret-pm-kafka: secrets/data/kafka/apps/pm
vault.hashicorp.com/agent-inject-template-pm-kafka: |- vault.hashicorp.com/agent-inject-template-pm-kafka: |-
{{- with secret "secrets/data/kafka/apps/pm" -}} {{- with secret "secrets/data/kafka/apps/pm" -}}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }} KAFKA_SASL_MECHANISM={{ if .Data.data.auth }}{{ index .Data.data.auth "sasl_mechanism" }}{{ else }}{{ index .Data.data "sasl_mechanism" }}{{ end }}
KAFKA_SASL_PLAIN_USERNAME={{ index .Data.data "username" }} KAFKA_SASL_PLAIN_USERNAME={{ index .Data.data "username" }}
KAFKA_SASL_PLAIN_PASSWORD={{ index .Data.data "password" }} KAFKA_SASL_PLAIN_PASSWORD={{ index .Data.data "password" }}
{{- end -}} {{- end -}}

View File

@ -191,11 +191,11 @@ spec:
_default: kafka.crt _default: kafka.crt
readOnly: readOnly:
_default: true _default: true
configMap: secret:
name: secretName:
_default: kafka-ca-cert _default: kafka-kafka-contour-tls
items: items:
- key: kafka.crt - key: ca.crt
path: path:
_default: kafka.crt _default: kafka.crt
@ -215,7 +215,7 @@ spec:
vault.hashicorp.com/agent-inject-secret-pm-kafka: secrets/data/kafka/apps/pm vault.hashicorp.com/agent-inject-secret-pm-kafka: secrets/data/kafka/apps/pm
vault.hashicorp.com/agent-inject-template-pm-kafka: |- vault.hashicorp.com/agent-inject-template-pm-kafka: |-
{{- with secret "secrets/data/kafka/apps/pm" -}} {{- with secret "secrets/data/kafka/apps/pm" -}}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }} KAFKA_SASL_MECHANISM={{ if .Data.data.auth }}{{ index .Data.data.auth "sasl_mechanism" }}{{ else }}{{ index .Data.data "sasl_mechanism" }}{{ end }}
KAFKA_SASL_PLAIN_USERNAME={{ index .Data.data "username" }} KAFKA_SASL_PLAIN_USERNAME={{ index .Data.data "username" }}
KAFKA_SASL_PLAIN_PASSWORD={{ index .Data.data "password" }} KAFKA_SASL_PLAIN_PASSWORD={{ index .Data.data "password" }}
{{- end -}} {{- end -}}

View File

@ -1,27 +0,0 @@
---
apiVersion: v1
kind: ConfigMap
metadata:
name: kafka-ca-cert
namespace: pm
data:
kafka.crt: |
-----BEGIN CERTIFICATE-----
MIIDETCCAfmgAwIBAgIQNhHkZWgkcMSiuRD9FD3SKjANBgkqhkiG9w0BAQsFADAT
MREwDwYDVQQDEwhrYWZrYS1jYTAeFw0yNjA4MjYwOTM4MzFaFw0yNzA4MjYwOTM4
MzFaMBMxETAPBgNVBAMTCGthZmthLWNhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA7Vvs1386xYZrKJ4qr/LwiibuhyoIHZm6AnjubChLKUSulP0+TIYC
tDgfSiEQsmASCkJKrvrpg2o0TGxj+LUTVnBCDWwBL3wXWSrbHTmpo9y2n0MH/SiN
h0n43/ReuXXGzuP+s4WF4Z6EkQyCqqGXZkqYx3PsiqQv2DYmnU/s6jdEqXBhDyU9
k6KGjMGxCmDN07E8iElfZp58KvZSISFNi2X5QWa3CIiPo7EKOyW20Hw8xVyQ8/SX
GE/Rt2I4G/LC+EhUBKrRB4UgHY1UcifO0EMvKeh8lLRBT5+yqQvkA2/cXYKmeEKc
zICZw5ve1DiImjQKvHoM257t6lf5yj9h+wIDAQABo2EwXzAOBgNVHQ8BAf8EBAMC
AqQwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMA8GA1UdEwEB/wQFMAMB
Af8wHQYDVR0OBBYEFAANdtqbrWPSSQqiCh1Wii2jxHO5MA0GCSqGSIb3DQEBCwUA
A4IBAQBJOea+5wxUNQuWX+E1m3GA5WJz+mAyt8J37w1ZpFVSpOX9r/ptSjyGoNY2
vgP0G8bJH30s25D4kRHuvvPeeCGnOR3PKPceeNIa4CQYvHnYT2bf7WBP8rLd0TyS
OV/ApxvxipKjl0OQc+95xAxm2z0qWIeOh1dkurvyhdLasIhqyhuUguW8APB2U3dU
fIvJ/R992Hy/MYvW7cw1CMWoaoBX90TEl6JNCHQvfBxaQzvPRvSEWwnRgbGwSZwz
ZS6GaNGN7C70WCxP4gmmkWfUC9lphnFb0IMGxXr/nTu5Ez5PKqRG56THkW5vd45i
0FC16VuidLG0HUCCawFjRiAg9rIA
-----END CERTIFICATE-----

View File

@ -3,7 +3,6 @@ kind: Kustomization
resources: resources:
- ../base - ../base
- redis.yaml - redis.yaml
- kafka-ca-configmap.yaml
patches: patches:
- path: backend.yaml - path: backend.yaml
target: target:

View File

@ -35,7 +35,7 @@ spec:
image: image:
name: name:
_default: cr.yandex/crp3ccidau046kdj8g9q/rfi-backend:dev4 _default: cr.yandex/crp3ccidau046kdj8g9q/rfi-backend:production_d1e2e80d
pullPolicy: pullPolicy:
_default: IfNotPresent _default: IfNotPresent
@ -102,7 +102,7 @@ spec:
- name: NOTIFICATIONS_SERVICE_URL - name: NOTIFICATIONS_SERVICE_URL
value: value:
_default: "https://lk.srx.wb.ru:30443/rfi" _default: "https://test.sarex.brusnika.tech"
- name: SAREX_BACKEND_URL - name: SAREX_BACKEND_URL
value: value:
@ -131,6 +131,10 @@ spec:
- name: DB_PORT - name: DB_PORT
value: value:
_default: "5432" _default: "5432"
- name: RESOURCES_API_HOST
value:
_default: "http://iams.iam.svc.cluster.local:8080"
secretEnvs: secretEnvs:
- name: DJANGO_SECRET_KEY - name: DJANGO_SECRET_KEY
secretName: secretName:

View File

@ -343,7 +343,7 @@ spec:
- name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL
value: value:
_default: "hello@wb.io" _default: "smtp-relay.gmail.com"
secretEnvs: secretEnvs:
- name: TRANSMITTAL_SERVICE_DATABASE__USER - name: TRANSMITTAL_SERVICE_DATABASE__USER
secretName: secretName:

View File

@ -334,7 +334,23 @@ spec:
- name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL - name: TRANSMITTAL_SERVICE_MAILGUN__EMAIL
value: value:
_default: "hello@wb.io" _default: "smtp-relay.gmail.com"
- name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__BASE_URL
value:
_default: "http://backend-service.flows.svc.cluster.local:8000"
- name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_CONNECTIONS
value:
_default: "10"
- name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__MAX_KEEPALIVE_CONNECTIONS
value:
_default: "5"
- name: TRANSMITTAL_SERVICE_FLOWS_REPOSITORY__TIMEOUT
value:
_default: "30"
secretEnvs: secretEnvs:
- name: TRANSMITTAL_SERVICE_DATABASE__USER - name: TRANSMITTAL_SERVICE_DATABASE__USER
secretName: secretName:

View File

@ -20,6 +20,7 @@ spec:
- identity.camunda.cde.brusnika.ru - identity.camunda.cde.brusnika.ru
- jupyter.brusnika.onprem.sarex.io - jupyter.brusnika.onprem.sarex.io
- keycloak.camunda.cde.brusnika.ru - keycloak.camunda.cde.brusnika.ru
- minio-console.brusnika.onprem.sarex.io
- minio.brusnika.onprem.sarex.io - minio.brusnika.onprem.sarex.io
- openobserve.brusnika.onprem.sarex.io - openobserve.brusnika.onprem.sarex.io
- operate.camunda.cde.brusnika.ru - operate.camunda.cde.brusnika.ru

View File

@ -3,134 +3,21 @@ kind: Kustomization
resources: resources:
- ../../../infrastructure/istio-base - ../../../infrastructure/istio-base
- ../../../infrastructure/istio-pilot - ../../../infrastructure/istio-pilot
- ../../../infrastructure/istio-gateway - ../../../infrastructure/istio-gateway/brusnika-prod
- ../../../infrastructure/istio-config - ../../../infrastructure/istio-config/brusnika-prod
- ../../../infrastructure/vault - ../../../infrastructure/vault/brusnika-prod
- ../../../infrastructure/zitadel - ../../../infrastructure/zitadel/brusnika-prod
- ../../../infrastructure/minio - ../../../infrastructure/minio/brusnika-prod
- ../../../infrastructure/openobserve - ../../../infrastructure/openobserve/brusnika-prod
- ../../../infrastructure/vmstack - ../../../infrastructure/vmstack/brusnika-prod
- ../../../infrastructure/prometheus-stack - ../../../infrastructure/prometheus-stack/brusnika-prod
- ../../../infrastructure/opentelemetry-operator - ../../../infrastructure/opentelemetry-operator/brusnika-prod
- ../../../infrastructure/opentelemetry-collector - ../../../infrastructure/opentelemetry-collector/brusnika-prod
- ../../../infrastructure/goalert - ../../../infrastructure/goalert/brusnika-prod
- ../../../infrastructure/kafka-exporter - ../../../infrastructure/kafka-exporter/brusnika-prod
- ../../../infrastructure/postgres-exporter - ../../../infrastructure/postgres-exporter/brusnika-prod
- ../../../infrastructure/pgbouncer - ../../../infrastructure/pgbouncer/brusnika-prod
- ./vault-ingress.yaml
- ./clusterissuer-letsencrypt.yaml - ./clusterissuer-letsencrypt.yaml
- ./node-exporter-vmnodescrape.yaml
- ./istio-gateway-stats-scrape.yaml
- ./istio-dashboard-compat-vmrule.yaml
- ./camunda-servicemonitors.yaml - ./camunda-servicemonitors.yaml
- ./rabbitmq-exporter.yaml - ./rabbitmq-exporter.yaml
- ./kafka-exporter-yc.yaml - ../../../infrastructure/failed-pod-cleanup/brusnika-prod
- ./kafka-exporter-yc-rules.yaml
- ./kafka-exporter-yc-dashboard.yaml
- ../../../infrastructure/failed-pod-cleanup
patches:
- path: ./patches/istio-gateway.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: ingressgateway
namespace: istio-system
- path: ./patches/istio-config.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: istio-config
namespace: default
- path: ./patches/vault.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: vault
namespace: vault
- path: ./patches/zitadel.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: zitadel
namespace: zitadel
- path: ./patches/minio.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: minio
namespace: minio
- path: ./patches/openobserve.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: openobserve
namespace: openobserve
- path: ./patches/vmstack.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: vmstack
namespace: vmstack
- path: ./patches/prometheus-stack.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: prometheus-stack
namespace: prometheus-stack
- path: ./patches/opentelemetry-operator.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: opentelemetry-operator
namespace: opentelemetry-operator
- path: ./patches/opentelemetry-collector.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: opentelemetry-collector
namespace: opentelemetry-collector
- path: ./patches/goalert.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: goalert
namespace: goalert
- path: ./patches/kafka-exporter.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: kafka-exporter
namespace: kafka-exporter
- path: ./patches/postgres-exporter.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: postgres-exporter
namespace: postgres-exporter
- path: ./patches/failed-pod-cleanup.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: failed-pod-cleanup
namespace: default
- path: ./patches/pgbouncer.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: pgbouncer
namespace: pgbouncer

View File

@ -14,139 +14,169 @@ spec:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: StatefulSet kind: StatefulSet
namespace: camunda
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: batch group: batch
version: v1 version: v1
kind: Job kind: Job
namespace: camunda
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
name: camunda-connectors name: camunda-connectors
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
name: camunda-identity name: camunda-identity
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
name: camunda-operate name: camunda-operate
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
name: camunda-optimize name: camunda-optimize
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
name: camunda-tasklist name: camunda-tasklist
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: Deployment kind: Deployment
namespace: camunda
name: camunda-zeebe-gateway name: camunda-zeebe-gateway
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
- target: - target:
group: apps group: apps
version: v1 version: v1
kind: StatefulSet kind: StatefulSet
namespace: camunda
name: camunda-zeebe name: camunda-zeebe
patch: |- patch: |-
- op: add - op: add
path: /spec/template/spec/nodeSelector path: /spec/template/spec/nodeSelector
value: value:
dedicated: generic dedicated: processing
- op: add - op: add
path: /spec/template/spec/tolerations path: /spec/template/spec/tolerations
value: [] value:
- key: dedicated
operator: Equal
value: processing
effect: NoSchedule
values: values:
global: global:
vault: vault:

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./failed-pod-cleanup.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: failed-pod-cleanup
namespace: default

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./goalert.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: goalert
namespace: goalert

View File

@ -103,6 +103,13 @@ spec:
issuerRef: issuerRef:
name: letsencrypt name: letsencrypt
kind: ClusterIssuer kind: ClusterIssuer
minio-console-tls:
namespace: ingress-nginx
dnsNames:
- minio-console.brusnika.onprem.sarex.io
issuerRef:
name: letsencrypt
kind: ClusterIssuer
projects-secret-name: projects-secret-name:
namespace: ingress-nginx namespace: ingress-nginx
dnsNames: dnsNames:
@ -278,6 +285,16 @@ spec:
- minio.brusnika.onprem.sarex.io - minio.brusnika.onprem.sarex.io
tls: tls:
credentialName: brusnika-secret-name credentialName: brusnika-secret-name
minio-console:
name: minio-console-gw
namespace: ingress-nginx
selector:
istio: ingressgateway
servers:
- hosts:
- minio-console.brusnika.onprem.sarex.io
tls:
credentialName: minio-console-tls
sso-check: sso-check:
name: sso-check-gw name: sso-check-gw
namespace: ingress-nginx namespace: ingress-nginx
@ -526,10 +543,554 @@ spec:
prefix: /integration/ prefix: /integration/
service: yet-another-nginx-service.global-ingress.svc.cluster.local service: yet-another-nginx-service.global-ingress.svc.cluster.local
port: 80 port: 80
- path:
prefix: /checklists/admin/
service: backend-service.checklist.svc.cluster.local
port: 8000
- path:
prefix: /checklists/api/
rewrite: /api/
service: backend-service.checklist.svc.cluster.local
port: 8000
- path: - path:
prefix: / prefix: /
service: nginx-service.global-ingress.svc.cluster.local service: nginx-service.global-ingress.svc.cluster.local
port: 80 port: 80
projects-frontend:
namespace: projects
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /projects/static/
rewrite: /
service: frontend-service.projects.svc.cluster.local
port: 8000
transmittal-frontend-static:
namespace: transmittal
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /transmittal/static/
rewrite: /
service: transmittal-frontend-static.transmittal.svc.cluster.local
port: 80
flows-frontend:
namespace: flows
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /flows/static/
rewrite: /
service: frontend-service.flows.svc.cluster.local
port: 80
reviews-frontend:
namespace: reviews
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /reviews/static/
rewrite: /
service: frontend-service.reviews.svc.cluster.local
port: 80
documentation-frontend-static:
namespace: documentations
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /documentations/static/
rewrite: /
service: documentation-frontend-static-service.documentations.svc.cluster.local
port: 80
inspections-frontend:
namespace: inspections
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /inspections/static/
rewrite: /
service: frontend-service.inspections.svc.cluster.local
port: 80
comparisons-static:
namespace: comparisons
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /comparisons/static/
rewrite: /
service: comparisons-service.comparisons.svc.cluster.local
port: 8080
notes-frontend:
namespace: notes
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /notes/static/
rewrite: /
service: frontend-service.notes.svc.cluster.local
port: 8080
transmittal-api-virt-service:
namespace: transmittal
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /transmittals/api/
rewrite: /api/
service: transmittal-service.transmittal.svc.cluster.local
port: 80
inspections-backend:
namespace: inspections
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /inspections/api/
rewrite: /api/
service: backend-service.inspections.svc.cluster.local
port: 8000
workflows-api:
namespace: workflow
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /workflows/api/
rewrite: /api/
service: workflows-api-service.workflow.svc.cluster.local
port: 8000
workspaces-api:
namespace: workspaces
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /workspaces/api/
rewrite: /api/
service: workspaces-service.workspaces.svc.cluster.local
port: 8000
bim-backend-v2:
namespace: bim
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /bimv2/api/
rewrite: /api/
service: backend-service.bim.svc.cluster.local
port: 8000
notes-backend:
namespace: notes
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /notes/api/
rewrite: /api/
service: backend-service.notes.svc.cluster.local
port: 8000
mapper-backend:
namespace: mapper
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /mapper/api/
rewrite: /api/
service: backend-service.mapper.svc.cluster.local
port: 8000
eav:
namespace: eav
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /eav/api/
rewrite: /api/
service: eav-service.eav.svc.cluster.local
port: 8000
- path:
prefix: /eav/admin/
service: eav-service.eav.svc.cluster.local
port: 8000
comparisons-backend:
namespace: comparisons
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /comparisons/api/
rewrite: /api/
service: backend-service.comparisons.svc.cluster.local
port: 80
django-media:
namespace: django
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /media/
rewrite: /
service: s3-proxy-service.django.svc.cluster.local
port: 80
resources:
namespace: resources
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /resources/
rewrite: /
service: resources-service.resources.svc.cluster.local
port: 8000
- path:
prefix: /res-admin/
service: resources-service.resources.svc.cluster.local
port: 8000
- path:
prefix: /resource-management/
service: resources-service.resources.svc.cluster.local
port: 8000
srx-admin:
namespace: django
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /control-interface/
rewrite: /
service: srx-admin-svc.django.svc.cluster.local
port: 8080
administration-users:
namespace: django
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /administration/users
service: frontend-service.django.svc.cluster.local
port: 80
cde:
namespace: orchestrator
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
routes:
- path:
prefix: /orchestrator/
rewrite: /api/
service: cde.orchestrator.svc.cluster.local
port: 8080
pdm-api-api:
namespace: documentations
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
headers:
request:
remove:
- Cookie
routes:
- path:
prefix: /gateway/api/
rewrite: /api/
service: pdm-api.documentations.svc.cluster.local
port: 8080
documentations:
namespace: documentations
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
extraAllowMethods:
- HEAD
extraAllowHeaders:
- Range
- Cache-Control
routes:
- path:
prefix: /documentations/api/
rewrite: /api/
service: documentations-api.documentations.svc.cluster.local
port: 8080
- path:
prefix: /files/api/
rewrite: /api/
service: documentations-filestream.documentations.svc.cluster.local
port: 8080
issues-vs:
namespace: issues
hosts:
- cde.brusnika.ru
gateways:
- ingress-nginx/global-cde-gw
cors:
allowCredentials: true
allowOrigins:
- exact: https://cde.brusnika.ru
- exact: https://stamp-verification.cde.brusnika.ru
- exact: https://document-link.cde.brusnika.ru
routes:
- path:
prefix: /issues-management/
service: issues-service.issues.svc.cluster.local
port: 80
- path:
prefix: /issues/api/
rewrite: /api/
service: issues-service.issues.svc.cluster.local
port: 80
- path:
prefix: /issues/static/
rewrite: /
service: static-service.issues.svc.cluster.local
port: 80
- path:
prefix: /remarks/static/
rewrite: /
service: remarks-static.issues.svc.cluster.local
port: 80
jupyter-vs: jupyter-vs:
namespace: jupyter namespace: jupyter
hosts: hosts:
@ -580,7 +1141,28 @@ spec:
- ingress-nginx/minio-gw - ingress-nginx/minio-gw
cors: cors:
allowOrigins: allowOrigins:
- regex: ".*" - exact: https://minio.brusnika.onprem.sarex.io
routes:
- match:
- port: 80
uri:
prefix: /
redirect:
scheme: https
redirectCode: 308
- path:
prefix: /
service: minio.minio.svc.cluster.local
port: 9000
minio-console-vs:
namespace: minio
hosts:
- minio-console.brusnika.onprem.sarex.io
gateways:
- ingress-nginx/minio-console-gw
cors:
allowOrigins:
- exact: https://minio-console.brusnika.onprem.sarex.io
routes: routes:
- match: - match:
- port: 80 - port: 80

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./istio-config.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: istio-config
namespace: default

View File

@ -469,6 +469,212 @@ spec:
prefix: / prefix: /
service: gitea.gitea.svc.cluster.local service: gitea.gitea.svc.cluster.local
port: 3000 port: 3000
workflows-static-vs:
namespace: workflow
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /static/workflows/
rewrite: /
service: frontend-service.workflow.svc.cluster.local
port: 8080
workspaces-v2-static-vs:
namespace: workspaces
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /static/workspaces-v2/
rewrite: /
service: workspaces-v2-frontend-static-service.workspaces.svc.cluster.local
port: 8080
checklists-vs:
namespace: checklist
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /checklists/admin/
service: backend-service.checklist.svc.cluster.local
port: 8000
- path:
prefix: /checklists/api/
rewrite: /api/
service: backend-service.checklist.svc.cluster.local
port: 8000
res-admin-vs:
namespace: resources
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /res-admin/
service: resources-service.resources.svc.cluster.local
port: 8000
inspections-vs:
namespace: inspections
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /inspections/static/
rewrite: /
service: frontend-service.inspections.svc.cluster.local
port: 80
- path:
prefix: /inspections/api/
rewrite: /api/
service: inspections-service.inspections.svc.cluster.local
port: 80
workflows-api-vs:
namespace: workflow
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /workflows/api/
rewrite: /api/
service: workflows-api-service.workflow.svc.cluster.local
port: 8000
workspaces-api-vs:
namespace: workspaces
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /workspaces/api/
rewrite: /api/
service: workspaces-service.workspaces.svc.cluster.local
port: 8000
global-media-vs:
namespace: django
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /media/
rewrite: /
service: s3-proxy-service.django.svc.cluster.local
port: 80
remarks-static-vs:
namespace: issues
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /remarks/static/
rewrite: /
service: remarks-static.issues.svc.cluster.local
port: 80
global-resources-vs:
namespace: resources
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /resources/
rewrite: /
service: resources-service.resources.svc.cluster.local
port: 8000
comparisons-vs:
namespace: comparisons
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /comparisons/static/
rewrite: /
service: comparisons-service.comparisons.svc.cluster.local
port: 8080
- path:
prefix: /comparisons/api/
rewrite: /api/
service: backend-service.comparisons.svc.cluster.local
port: 80
administration-users-vs:
namespace: django
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /administration/users
service: frontend-service.django.svc.cluster.local
port: 80
orchestrator-vs:
namespace: orchestrator
hosts:
- test.sarex.brusnika.tech
gateways:
- ingress-nginx/main-gateway
cors:
allowOrigins:
- regex: ".*"
routes:
- path:
prefix: /orchestrator/
service: cde.orchestrator.svc.cluster.local
port: 8080
global-test-vs: global-test-vs:
namespace: global-ingress namespace: global-ingress
hosts: hosts:
@ -982,19 +1188,19 @@ spec:
service: workspaces-service.workspaces.svc.cluster.local service: workspaces-service.workspaces.svc.cluster.local
port: 8000 port: 8000
# vs-resources-admin: vs-resources-admin:
# namespace: ingress-nginx namespace: ingress-nginx
# hosts: hosts:
# - test.sarex.brusnika.tech - test.sarex.brusnika.tech
# gateways: gateways:
# - ingress-nginx/main-gateway - ingress-nginx/main-gateway
# routes: routes:
# - match: - match:
# - uri: - uri:
# prefix: /resource-management prefix: /resource-management
# rewrite: /resource-management rewrite: /resource-management
# service: resources-service.resources.svc.cluster.local service: resources-service.resources.svc.cluster.local
# port: 8000 port: 8000
# vs-workspaces-frontend-v2: # vs-workspaces-frontend-v2:
# namespace: ingress-nginx # namespace: ingress-nginx

View File

@ -399,6 +399,19 @@ spec:
rewrite: / rewrite: /
service: frontend-svc.control-interface.svc.cluster.local service: frontend-svc.control-interface.svc.cluster.local
port: 8080 port: 8080
admin-frontend:
name: admin-frontend-virt-service
namespace: default
hosts:
- sarex.vadroad.ru
gateways:
- default/platform-gateway
routes:
- path:
prefix: /admin-frontend/static/
rewrite: /
service: admin-frontend-svc.control-interface.svc.cluster.local
port: 8080
s3-proxy-media: s3-proxy-media:
name: s3-proxy-media-virt-service name: s3-proxy-media-virt-service
namespace: default namespace: default

View File

@ -0,0 +1,14 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
- ./istio-gateway-stats-scrape.yaml
- ./istio-dashboard-compat-vmrule.yaml
patches:
- path: ./istio-gateway.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: ingressgateway
namespace: istio-system

View File

@ -0,0 +1,15 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
- ./kafka-exporter-yc.yaml
- ./kafka-exporter-yc-rules.yaml
- ./kafka-exporter-yc-dashboard.yaml
patches:
- path: ./kafka-exporter.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: kafka-exporter
namespace: kafka-exporter

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./minio.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: minio
namespace: minio

View File

@ -11,7 +11,7 @@ spec:
mode: standalone mode: standalone
environment: environment:
MINIO_SERVER_URL: "https://minio.brusnika.onprem.sarex.io" MINIO_SERVER_URL: "https://minio.brusnika.onprem.sarex.io"
MINIO_BROWSER_REDIRECT_URL: "https://minio.brusnika.onprem.sarex.io/console/" MINIO_BROWSER_REDIRECT_URL: "https://minio-console.brusnika.onprem.sarex.io"
MINIO_API_CORS_ALLOW_ORIGIN: "https://minio.brusnika.onprem.sarex.io" MINIO_API_CORS_ALLOW_ORIGIN: "https://minio.brusnika.onprem.sarex.io"
imagePullSecrets: imagePullSecrets:
- name: regcred - name: regcred

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./openobserve.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: openobserve
namespace: openobserve

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./opentelemetry-collector.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: opentelemetry-collector
namespace: opentelemetry-collector

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./opentelemetry-operator.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: opentelemetry-operator
namespace: opentelemetry-operator

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./pgbouncer.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: pgbouncer
namespace: pgbouncer

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./postgres-exporter.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: postgres-exporter
namespace: postgres-exporter

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./prometheus-stack.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: prometheus-stack
namespace: prometheus-stack

View File

@ -0,0 +1,13 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
- ./vault-ingress.yaml
patches:
- path: ./vault.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: vault
namespace: vault

View File

@ -0,0 +1,13 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
- ./node-exporter-vmnodescrape.yaml
patches:
- path: ./vmstack.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: vmstack
namespace: vmstack

View File

@ -0,0 +1,12 @@
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: ./zitadel.yaml
target:
group: helm.toolkit.fluxcd.io
version: v2
kind: HelmRelease
name: zitadel
namespace: zitadel