Compare commits

...

38 Commits
aero ... master

Author SHA1 Message Date
ivan
325aad49da ++ 2026-08-02 00:50:33 +05:00
ivan
38219249b3 ++ 2026-08-02 00:44:21 +05:00
ivan
6c81ba0080 ++ 2026-08-02 00:41:18 +05:00
ivan
c14d74050f ++ 2026-08-02 00:36:36 +05:00
ivan
3dd3c12537 ++ 2026-08-01 15:13:48 +05:00
ivan
d86bc2fbc5 ++ 2026-08-01 14:49:07 +05:00
ivan
7ad5c5f4b1 ++ 2026-08-01 14:41:41 +05:00
ivan
38a357ee64 ++ 2026-08-01 14:21:30 +05:00
ivan
5b2c6b9967 ++ 2026-08-01 14:08:35 +05:00
ivan
950c1a5c51 ++ 2026-08-01 14:00:43 +05:00
ivan
f1043df2da ++ 2026-08-01 13:53:41 +05:00
ivan
a148491f95 ++ 2026-08-01 13:07:29 +05:00
ivan
987e9e3a7f ++ 2026-08-01 12:50:10 +05:00
ivan
50cee9c4d3 ++ 2026-07-31 18:40:52 +05:00
ivan
80da663600 ++ 2026-07-31 17:53:50 +05:00
ivan
c470dacee3 ++ 2026-07-31 17:48:17 +05:00
ivan
ab7611fc7e ++ 2026-07-31 17:47:56 +05:00
ivan
fc9e75945a ++ 2026-07-31 17:42:37 +05:00
ivan
84c51343f9 ++ 2026-07-31 17:32:56 +05:00
ivan
396702429f ++ 2026-07-31 17:10:00 +05:00
ivan
800718737d ++ 2026-07-31 17:01:48 +05:00
ivan
e88027ffa6 ++ 2026-07-31 16:56:56 +05:00
ivan
798648e85d ++ 2026-07-31 16:53:33 +05:00
ivan
e09067365f ++ 2026-07-31 16:26:47 +05:00
ivan
9a8a80328a ++ 2026-07-31 16:22:27 +05:00
ivan
11fbf26d6d ++ 2026-07-31 16:12:24 +05:00
ivan
4e7757b7b4 ++ 2026-07-31 16:08:52 +05:00
ivan
8b6133a81a ++ 2026-07-31 16:07:34 +05:00
ivan
106b5d450d ++ 2026-07-31 15:46:58 +05:00
ivan
b98d3f6ab2 ++ 2026-07-31 15:27:24 +05:00
ivan
7868779771 ++ 2026-07-31 15:12:16 +05:00
ivan
b14e342955 ++ 2026-07-31 14:57:31 +05:00
ivan
d6a830db05 ++ 2026-07-31 14:54:33 +05:00
ivan
0d0b2cc5f8 ++ 2026-07-31 14:45:28 +05:00
ivan
3fb27a9e53 ++ 2026-07-31 14:13:51 +05:00
ivan
d57fcf8229 ++ 2026-07-31 13:59:05 +05:00
ivan
edd357ba72 ++ 2026-07-31 13:55:22 +05:00
ivan
c7b749fd09 ++ 2026-07-31 12:55:03 +05:00
153 changed files with 7296 additions and 3217 deletions

View File

@ -87,9 +87,9 @@ spec:
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: attachments
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/postgresql/apps/attachments
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres
vault.hashicorp.com/agent-inject-template-attachments-db: |-
{{- with secret "secrets/data/postgresql/apps/attachments" -}}
{{- with secret "secrets/data/apps/attachments/postgres" -}}
DATABASE_HOST={{ index .Data.data "host" }}
DATABASE_PORT={{ index .Data.data "port" }}
DATABASE_NAME={{ index .Data.data "database" }}

View File

@ -3,4 +3,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
namespace: attachments
resources:
- namespace.yaml
- helmrelease.yaml

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: attachments
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -11,10 +11,10 @@ spec:
podAnnotations:
_default:
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: attachments-vault
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/postgresql/apps/attachments
vault.hashicorp.com/role: attachments
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres
vault.hashicorp.com/agent-inject-template-attachments-db: |-
{{- with secret "secrets/data/postgresql/apps/attachments" -}}
{{- with secret "secrets/data/apps/attachments/postgres" -}}
DATABASE_HOST={{ index .Data.data "host" }}
DATABASE_PORT={{ index .Data.data "port" }}
DATABASE_NAME={{ index .Data.data "database" }}

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: auth-flow
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,108 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: bim
labels:
app: backend
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: bim
vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim
vault.hashicorp.com/agent-inject-template-bim-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/bim" -}}
POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local
POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local
POSTGRES_PORT=5432
POSTGRES_PORT_2=5432
POSTGRES_PORT_3=5432
POSTGRES_PORT_4=5432
POSTGRES_DB=bim_db
POSTGRES_DB_2=bim_db
POSTGRES_DB_3=bim_db
POSTGRES_DB_4=bim_db
POSTGRES_USER={{ index .Data.data "username" }}
POSTGRES_USER_2={{ index .Data.data "username" }}
POSTGRES_USER_3={{ index .Data.data "username" }}
POSTGRES_USER_4={{ index .Data.data "username" }}
POSTGRES_PASSWORD={{ index .Data.data "password" }}
POSTGRES_PASSWORD_2={{ index .Data.data "password" }}
POSTGRES_PASSWORD_3={{ index .Data.data "password" }}
POSTGRES_PASSWORD_4={{ index .Data.data "password" }}
{{- end -}}
spec:
serviceAccountName: bim-vault
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql
set +a
exec ./httpserver
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: LAST_MASTER_BIM
value: "100000"
- name: LAST_MASTER_BIM_V3
value: "100000"
- name: DB_CERT_PATH_4
value: /root/yandex_pg.pem
- name: DB_CERT_PATH_3
value: /root/yandex_pg.pem
- name: DB_CERT_PATH_2
value: /root/yandex_pg.pem
- name: LAST_SLAVE_1_BIM
value: "1000000"
- name: POSTGRES_POOL_SIZE
value: "30"
- name: API_ADDRESS
value: 0.0.0.0:8000
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000
- name: ENABLE_SQL_QUERY
value: "0"
- name: ENABLE_SSL
value: "0"
resources:
requests:
cpu: 25m
memory: 100Mi
livenessProbe:
httpGet:
path: /ping
port: 8000
initialDelaySeconds: 10
periodSeconds: 60
failureThreshold: 10
readinessProbe:
httpGet:
path: /ping
port: 8000
initialDelaySeconds: 5
periodSeconds: 5
failureThreshold: 20
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: bim
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

217
apps/bim/base/backend.yaml Normal file
View File

@ -0,0 +1,217 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: bim
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: bim-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql
set +a
exec ./httpserver
resources:
requests:
cpu:
_default: 25m
memory:
_default: 100Mi
probes:
liveness:
enabled:
_default: true
type:
_default: httpGet
httpGet:
path:
_default: /ping
port:
_default: 8000
initialDelaySeconds:
_default: 10
periodSeconds:
_default: 60
failureThreshold:
_default: 10
readiness:
enabled:
_default: true
type:
_default: httpGet
httpGet:
path:
_default: /ping
port:
_default: 8000
initialDelaySeconds:
_default: 5
periodSeconds:
_default: 5
failureThreshold:
_default: 20
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: LAST_MASTER_BIM
value:
_default: "100000"
- name: LAST_MASTER_BIM_V3
value:
_default: "100000"
- name: DB_CERT_PATH_4
value:
_default: "/root/yandex_pg.pem"
- name: DB_CERT_PATH_3
value:
_default: "/root/yandex_pg.pem"
- name: DB_CERT_PATH_2
value:
_default: "/root/yandex_pg.pem"
- name: LAST_SLAVE_1_BIM
value:
_default: "1000000"
- name: POSTGRES_POOL_SIZE
value:
_default: "30"
- name: API_ADDRESS
value:
_default: "0.0.0.0:8000"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: ENABLE_SQL_QUERY
value:
_default: "0"
- name: ENABLE_SSL
value:
_default: "0"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: bim
vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/apps/bim/postgres
vault.hashicorp.com/agent-inject-template-bim-postgresql: |-
{{- with secret "secrets/data/apps/bim/postgres" -}}
POSTGRES_ADDRESS={{ index .Data.data "host" }}
POSTGRES_ADDRESS_2={{ index .Data.data "host" }}
POSTGRES_ADDRESS_3={{ index .Data.data "host" }}
POSTGRES_ADDRESS_4={{ index .Data.data "host" }}
POSTGRES_PORT={{ index .Data.data "port" }}
POSTGRES_PORT_2={{ index .Data.data "port" }}
POSTGRES_PORT_3={{ index .Data.data "port" }}
POSTGRES_PORT_4={{ index .Data.data "port" }}
POSTGRES_DB={{ index .Data.data "database" }}
POSTGRES_DB_2={{ index .Data.data "database" }}
POSTGRES_DB_3={{ index .Data.data "database" }}
POSTGRES_DB_4={{ index .Data.data "database" }}
POSTGRES_USER={{ index .Data.data "username" }}
POSTGRES_USER_2={{ index .Data.data "username" }}
POSTGRES_USER_3={{ index .Data.data "username" }}
POSTGRES_USER_4={{ index .Data.data "username" }}
POSTGRES_PASSWORD={{ index .Data.data "password" }}
POSTGRES_PASSWORD_2={{ index .Data.data "password" }}
POSTGRES_PASSWORD_3={{ index .Data.data "password" }}
POSTGRES_PASSWORD_4={{ index .Data.data "password" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,6 +4,4 @@ kind: Kustomization
namespace: bim
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- backend-service.yaml
- backend.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: bim-vault
namespace: bim

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: bim

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: bim
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,53 +1,98 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: bim
spec:
template:
spec:
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc
env:
- name: LAST_MASTER_BIM
value: '100000'
- name: LAST_SLAVE_1_BIM
value: '94015'
- name: LAST_MASTER_BIM_V3
value: '100000'
- name: LAST_SLAVE_1_BIM_V3
value: '0'
- name: DB_CERT_PATH_3
value: /root/yandex_pg.pem
- name: POSTGRES_ADDRESS_3
value: postgres-service
- name: POSTGRES_PORT_3
value: '5432'
- name: POSTGRES_DB_3
value: bimapidb
- name: DB_CERT_PATH_2
value: /root/yandex_pg.pem
- name: POSTGRES_ADDRESS_2
value: postgres-service
- name: POSTGRES_PORT_2
value: '5432'
- name: POSTGRES_DB_2
value: bimapidb
- name: POSTGRES_ADDRESS
value: postgres-service
- name: POSTGRES_PORT
value: '5432'
- name: POSTGRES_DB
value: bimapidb
- name: POSTGRES_POOL_SIZE
value: '30'
- name: API_ADDRESS
value: 0.0.0.0:8000
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000
- name: ENABLE_SQL_QUERY
value: '0'
- name: ENABLE_SSL
value: '0'
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc
envs:
- name: LAST_MASTER_BIM
value:
_default: "100000"
- name: LAST_SLAVE_1_BIM
value:
_default: "94015"
- name: LAST_MASTER_BIM_V3
value:
_default: "100000"
- name: LAST_SLAVE_1_BIM_V3
value:
_default: "0"
- name: DB_CERT_PATH_3
value:
_default: "/root/yandex_pg.pem"
- name: POSTGRES_ADDRESS_3
value:
_default: "postgres-service"
- name: POSTGRES_PORT_3
value:
_default: "5432"
- name: POSTGRES_DB_3
value:
_default: "bimapidb"
- name: DB_CERT_PATH_2
value:
_default: "/root/yandex_pg.pem"
- name: POSTGRES_ADDRESS_2
value:
_default: "postgres-service"
- name: POSTGRES_PORT_2
value:
_default: "5432"
- name: POSTGRES_DB_2
value:
_default: "bimapidb"
- name: POSTGRES_ADDRESS
value:
_default: "postgres-service"
- name: POSTGRES_PORT
value:
_default: "5432"
- name: POSTGRES_DB
value:
_default: "bimapidb"
- name: POSTGRES_POOL_SIZE
value:
_default: "30"
- name: API_ADDRESS
value:
_default: "0.0.0.0:8000"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: ENABLE_SQL_QUERY
value:
_default: "0"
- name: ENABLE_SSL
value:
_default: "0"
- name: DB_CERT_PATH_4
value:
_default: "/root/yandex_pg.pem"

View File

@ -9,5 +9,5 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend

View File

@ -7,5 +7,5 @@ resources:
patches:
- path: replicas.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend

View File

@ -1,8 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: bim
spec:
replicas: 1
values:
services:
backend:
deployment:
replicaCount:
_default: 1

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: cde-svc
namespace: faas
spec:
type: ClusterIP
selector:
app: cde
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-flowscallback
namespace: cde
labels:
app: cde-flowscallback
service: cde-flowscallback
spec:
replicas: 1
selector:
matchLabels:
app: cde-flowscallback
template:
metadata:
labels:
app: cde-flowscallback
service: cde-flowscallback
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-flowscallback
image: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-flowscallback:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-flowscallback
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 1Gi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-splitpdf
namespace: cde
labels:
app: cde-splitpdf
service: cde-splitpdf
spec:
replicas: 1
selector:
matchLabels:
app: cde-splitpdf
template:
metadata:
labels:
app: cde-splitpdf
service: cde-splitpdf
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-splitpdf
image: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-splitpdf:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-splitpdf
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 1Gi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -0,0 +1,120 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-alert
namespace: cde
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-alert:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/orchestrator:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-alert
replicaCount:
_default: 1
port:
_default: 8080
command:
_default: ["/bin/bash", "-lc"]
args:
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu:
_default: 500m
memory:
_default: 1Gi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-copy
namespace: cde
labels:
app: cde-worker-copy
service: cde-worker-copy
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-copy
template:
metadata:
labels:
app: cde-worker-copy
service: cde-worker-copy
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-copy
image: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-copy:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-copy
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: "1"
memory:
_default: 1Gi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -0,0 +1,120 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-copyv2
namespace: cde
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-copyv2:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/copyv2-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-copyv2
replicaCount:
_default: 1
port:
_default: 8080
command:
_default: ["/bin/bash", "-lc"]
args:
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu:
_default: "1"
memory:
_default: 1Gi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-create-versions
namespace: cde
labels:
app: cde-worker-create-versions
service: cde-worker-create-versions
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-create-versions
template:
metadata:
labels:
app: cde-worker-create-versions
service: cde-worker-create-versions
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-create-versions
image: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-create-versions:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-create-versions
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -0,0 +1,120 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-create-versionsv2
namespace: cde
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-create-versionsv2:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/createversionsv2-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-create-versionsv2
replicaCount:
_default: 1
port:
_default: 8080
command:
_default: ["/bin/bash", "-lc"]
args:
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-markings
namespace: cde
labels:
app: cde-worker-markings
service: cde-worker-markings
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-markings
template:
metadata:
labels:
app: cde-worker-markings
service: cde-worker-markings
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-markings
image: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-markings:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-markings
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -0,0 +1,120 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-markingsv2
namespace: cde
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-markingsv2:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/markingsv2-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-markingsv2
replicaCount:
_default: 1
port:
_default: 8080
command:
_default: ["/bin/bash", "-lc"]
args:
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-sign
namespace: cde
labels:
app: cde-worker-sign
service: cde-worker-sign
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-sign
template:
metadata:
labels:
app: cde-worker-sign
service: cde-worker-sign
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-sign
image: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-sign:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-sign
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -0,0 +1,120 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-signv2
namespace: cde
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-signv2:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/signv2-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-signv2
replicaCount:
_default: 1
port:
_default: 8080
command:
_default: ["/bin/bash", "-lc"]
args:
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,120 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde-worker-update-bundles
namespace: cde
labels:
app: cde-worker-update-bundles
service: cde-worker-update-bundles
spec:
replicas: 1
selector:
matchLabels:
app: cde-worker-update-bundles
template:
metadata:
labels:
app: cde-worker-update-bundles
service: cde-worker-update-bundles
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: cde-worker-update-bundles
image: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde-worker-update-bundles:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde-worker-update-bundles
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /worker
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /worker
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,60 +1,139 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: cde
namespace: cde
labels:
app: cde
service: cde
spec:
replicas: 1
selector:
matchLabels:
app: cde
template:
metadata:
labels:
app: cde
service: cde
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
interval: 10m
chart:
spec:
serviceAccountName: cde-vault
containers:
- name: api
image: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a
imagePullPolicy: IfNotPresent
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
cde:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: cde-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/cde:preprod_4302d8f3
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: cde
replicaCount:
_default: 1
port:
_default: 8080
command:
- /bin/bash
- -lc
_default: ["/bin/bash", "-lc"]
args:
- |
set -e
source /vault/secrets/cde-env
exec /http
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: S3_IS_CONTOUR
value: "true"
_default:
- |
set -e
source /vault/secrets/cde-env
exec /http
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred
cpu:
_default: 500m
memory:
_default: 512Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: cde-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8080
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: SAREX_BACKEND_BASE_URL
value:
_default: "https://lk.sarex.io"
- name: S3_IS_CONTOUR
value:
_default: "true"
- name: IS_CONTOUR
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: cde
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
vault.hashicorp.com/agent-inject-template-cde-env: |-
{{- with secret "secrets/data/vault/apps/cde" -}}
{{- range $k, $v := .Data.data }}
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
{{- end }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,13 +4,16 @@ kind: Kustomization
namespace: cde
resources:
- namespace.yaml
- serviceaccount.yaml
- cde.yaml
- cde-splitpdf.yaml
- backend-service.yaml
- cde-flowscallback.yaml
- cde-worker-alert.yaml
- cde-worker-copy.yaml
- cde-worker-copyv2.yaml
- cde-worker-create-versions.yaml
- cde-worker-create-versionsv2.yaml
- cde-worker-markings.yaml
- cde-worker-markingsv2.yaml
- cde-worker-sign.yaml
- cde-worker-signv2.yaml
- cde-worker-update-bundles.yaml

View File

@ -5,3 +5,4 @@ metadata:
name: cde
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: cde-vault
namespace: cde

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: cde

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: cde
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -244,17 +244,17 @@ spec:
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: comparisons
vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/postgresql/apps/comparisons
vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/apps/comparisons/postgres
vault.hashicorp.com/agent-inject-template-comparisons-db: |-
{{- with secret "secrets/data/postgresql/apps/comparisons" -}}
DATABASE_HOST=postgresql.comparisons.svc.cluster.local
DATABASE_PORT=5432
DATABASE_DB=comparisons_db
{{- with secret "secrets/data/apps/comparisons/postgres" -}}
DATABASE_HOST={{ index .Data.data "host" }}
DATABASE_PORT={{ index .Data.data "port" }}
DATABASE_DB={{ index .Data.data "database" }}
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
POSTGRES_ADDRESS=postgresql.comparisons.svc.cluster.local
POSTGRES_PORT=5432
POSTGRES_DB=comparisons_db
POSTGRES_ADDRESS={{ index .Data.data "host" }}
POSTGRES_PORT={{ index .Data.data "port" }}
POSTGRES_DB={{ index .Data.data "database" }}
POSTGRES_USER={{ index .Data.data "username" }}
POSTGRES_PASSWORD={{ index .Data.data "password" }}
{{- end -}}

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: comparisons
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -90,9 +90,9 @@ spec:
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: contracts
vault.hashicorp.com/agent-inject-secret-contracts-db: secrets/data/postgresql/apps/contracts
vault.hashicorp.com/agent-inject-secret-contracts-db: secrets/data/apps/contracts/postgres
vault.hashicorp.com/agent-inject-template-contracts-db: |-
{{- with secret "secrets/data/postgresql/apps/contracts" -}}
{{- with secret "secrets/data/apps/contracts/postgres" -}}
DB_URL=postgresql://{{ index .Data.data "username" }}:{{ index .Data.data "password" }}@postgresql.contracts.svc.cluster.local:5432/contracts_db?sslmode=disable
{{- end -}}
vault.hashicorp.com/agent-inject-secret-contracts-jwt-public: secrets/data/vault/common/rsa_keys

View File

@ -3,5 +3,5 @@ kind: Namespace
metadata:
name: control-interface
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: cross-section
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -296,6 +296,11 @@ data:
"name": "Запросы",
"uri": "/rfi"
},
{
"name": "Управление проектами",
"uri": "/management/projects"
},
# {
# "name": "Обзор",
# "uri": "/projects"

View File

@ -62,11 +62,13 @@ data:
if_modified_since off;
expires off;
}
# location ~^/api/pm/ {
# #rewrite /api/(.+) /$1 break;
# proxy_set_header Host $host;
# proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
# }
location ~^/api/pm/ {
#rewrite /api/(.+) /$1 break;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
}
# location ~^/api/v1/documents/ {
# #rewrite /api/(.+) /$1 break;
@ -74,25 +76,27 @@ data:
# proxy_pass http://backend-filestream-svc.documentations.svc.cluster.local:80;
# }
# location ~^/(api|admin)/ {
# proxy_set_header Host $host;
# proxy_pass http://backend-svc.django.svc.cluster.local:80;
# }
location ~^/(api|admin)/ {
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_pass http://backend-svc.django.svc.cluster.local:80;
}
# location ~^/workspaces-v2/(.+).js {
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# rewrite /workspaces-v2/(.+) /$1 break;
# proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
# }
location ~^/workspaces-v2/(.+).js {
proxy_http_version 1.1;
proxy_set_header Connection "";
rewrite /workspaces-v2/(.+) /$1 break;
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
}
# location ~^/workspaces-v2/(.+)\.wasm$ {
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# rewrite ^/workspaces-v2/(.+) /$1 break;
# proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
# }
location ~^/workspaces-v2/(.+)\.wasm$ {
proxy_http_version 1.1;
proxy_set_header Connection "";
rewrite ^/workspaces-v2/(.+) /$1 break;
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
}
location @index {
add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';
@ -101,10 +105,12 @@ data:
try_files /static/index.html =404;
}
# location ~^/workflows/(.+).js {
# rewrite /workflows/(.+) /$1 break;
# proxy_pass http://frontend-svc.processing.svc.cluster.local:80;
# }
location ~^/workflows/(.+).js {
proxy_http_version 1.1;
proxy_set_header Connection "";
rewrite /workflows/(.+) /$1 break;
proxy_pass http://frontend-svc.processing.svc.cluster.local:80;
}
location /service-worker.js {
try_files /static/$uri @index;
}

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: document-link
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -0,0 +1,163 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: documentations-hasher
namespace: documentations
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: documentations-vault
deployment:
enabled: true
name:
_default: hasher
replicaCount:
_default: 1
port:
_default: 8080
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/documentations-hasher-rabbitmq ] && . /vault/secrets/documentations-hasher-rabbitmq
[ -f /vault/secrets/documentations-hasher-s3 ] && . /vault/secrets/documentations-hasher-s3
set +a
exec ./server
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/hasher:production_3f853d3a
pullPolicy:
_default: IfNotPresent
service:
enabled: true
name:
_default: hasher-service
type:
_default: ClusterIP
port:
_default: 8080
targetPort:
_default: 8080
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: HASHER_APP__LOG_LEVEL
value:
_default: INFO
- name: HASHER_APP__NUM_WORKERS
value:
_default: "4"
- name: HASHER_AMQP__ROUTING__TASK_INPUT_QUEUE
value:
_default: hash.compute.normal.tasks
- name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE
value:
_default: hash.compute
- name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE_TYPE
value:
_default: direct
- name: HASHER_AMQP__ROUTING__TASK_INPUT_ROUTING_KEY
value:
_default: hash.compute.normal
- name: HASHER_S3__MAX_POOL_CONNECTIONS
value:
_default: "10"
- name: HASHER_S3__CONNECT_TIMEOUT
value:
_default: "10"
- name: HASHER_S3__READ_TIMEOUT
value:
_default: "30"
- name: HASHER_S3__REGION_NAME
value:
_default: ru-central1
- name: HASHER_S3__USE_SSL
value:
_default: "true"
- name: HASHER_S3__VERIFY
value:
_default: "true"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411,8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: documentations
vault.hashicorp.com/agent-inject-secret-documentations-hasher-rabbitmq: secrets/data/apps/documentations/hasher/rabbitmq
vault.hashicorp.com/agent-inject-template-documentations-hasher-rabbitmq: |-
{{- with secret "secrets/data/apps/documentations/hasher/rabbitmq" -}}
HASHER_AMQP__HOST={{ index .Data.data "host" }}
HASHER_AMQP__PORT={{ index .Data.data "port" }}
HASHER_AMQP__USERNAME={{ index .Data.data "username" }}
HASHER_AMQP__PASSWORD={{ index .Data.data "password" }}
HASHER_AMQP__VHOST={{ index .Data.data "vhost" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-documentations-hasher-s3: secrets/data/apps/documentations/hasher/s3
vault.hashicorp.com/agent-inject-template-documentations-hasher-s3: |-
{{- with secret "secrets/data/apps/documentations/hasher/s3" -}}
HASHER_S3__ENDPOINT={{ index .Data.data "endpoint" }}
HASHER_S3__ACCESS_KEY={{ index .Data.data "access_key" }}
HASHER_S3__SECRET_KEY={{ index .Data.data "secret_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -8,5 +8,7 @@ resources:
- filestream.yaml
- frontend.yaml
- pdm.yaml
- pdf-markings-amqp.yaml
- hasher.yaml
- redis-deployment.yaml
- redis-service.yaml

View File

@ -0,0 +1,172 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: documentations-pdf-markings-amqp
namespace: documentations
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: documentations-vault
deployment:
enabled: true
name:
_default: pdf-markings-amqp
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/documentations-marks-db ] && . /vault/secrets/documentations-marks-db
[ -f /vault/secrets/documentations-marks-rabbitmq ] && . /vault/secrets/documentations-marks-rabbitmq
[ -f /vault/secrets/documentations-marks-s3 ] && . /vault/secrets/documentations-marks-s3
set +a
exec ./server
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/pdf-markings-amqp:prod_3ab263be
pullPolicy:
_default: IfNotPresent
service:
enabled: true
name:
_default: marks-service
type:
_default: ClusterIP
port:
_default: 8000
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: MARKS_APP__LOG_LEVEL
value:
_default: INFO
- name: MARKS_CRYPTO__HASHING_ALGO
value:
_default: md_gost12_256
- name: MARKS_QR__REDIRECT_URL
value:
_default: "https://stamp-verification.srx.wb.ru/"
- name: MARKS_QR__BASE_DOCUMENT_URL
value:
_default: "https://srx.wb.ru"
- name: MARKS_S3__REGION
value:
_default: ru-central1
- name: MARKS_S3__USE_SSL
value:
_default: "true"
- name: MARKS_S3__SSL_VERIFY
value:
_default: "true"
- name: MARKS_S3__DEFAULT_BUCKET
value:
_default: documentations-marks
- name: MARKS_RABBITMQ__ROUTING__INPUT_QUEUE
value:
_default: pdf_markings_input
- name: MARKS_RABBITMQ__HOST
value:
_default: rabbitmq.rabbitmq.svc.cluster.local
- name: MARKS_RABBITMQ__PORT
value:
_default: "5672"
- name: MARKS_RABBITMQ__HEARTBEAT_SECONDS
value:
_default: "60"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411,8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: documentations
vault.hashicorp.com/agent-inject-secret-documentations-marks-db: secrets/data/apps/documentations/postgres
vault.hashicorp.com/agent-inject-template-documentations-marks-db: |-
{{- with secret "secrets/data/apps/documentations/postgres" -}}
MARKS_DOCUMENTS_DB__HOST={{ index .Data.data "host" }}
MARKS_DOCUMENTS_DB__PORT={{ index .Data.data "port" }}
MARKS_DOCUMENTS_DB__DATABASE={{ index .Data.data "database" }}
MARKS_DOCUMENTS_DB__USERNAME={{ index .Data.data "username" }}
MARKS_DOCUMENTS_DB__PASSWORD={{ index .Data.data "password" }}
MARKS_DOCUMENTS_DB__SSLMODE=disable
{{- end -}}
vault.hashicorp.com/agent-inject-secret-documentations-marks-rabbitmq: secrets/data/rabbitmq/apps/documentations
vault.hashicorp.com/agent-inject-template-documentations-marks-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/documentations" -}}
MARKS_RABBITMQ__USERNAME={{ index .Data.data "username" }}
MARKS_RABBITMQ__PASSWORD={{ index .Data.data "password" }}
MARKS_RABBITMQ__VHOST={{ index .Data.data "vhost" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-documentations-marks-s3: secrets/data/apps/documentations/marks-s3
vault.hashicorp.com/agent-inject-template-documentations-marks-s3: |-
{{- with secret "secrets/data/apps/documentations/marks-s3" -}}
MARKS_S3__URL={{ index .Data.data "endpoint_url" }}
MARKS_S3__ACCESS_KEY={{ index .Data.data "access_key" }}
MARKS_S3__SECRET_KEY={{ index .Data.data "secret_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -119,11 +119,11 @@ spec:
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: drawings
vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/postgresql/apps/drawings
vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/apps/drawings/postgres
vault.hashicorp.com/agent-inject-template-drawings-db: |-
{{- with secret "secrets/data/postgresql/apps/drawings" -}}
POSTGRES_ADDRESS=postgresql.drawings.svc.cluster.local:5432
POSTGRES_DB=drawings_db
{{- with secret "secrets/data/apps/drawings/postgres" -}}
POSTGRES_ADDRESS={{ index .Data.data "host" }}:{{ index .Data.data "port" }}
POSTGRES_DB={{ index .Data.data "database" }}
POSTGRES_USER={{ index .Data.data "username" }}
POSTGRES_PASSWORD={{ index .Data.data "password" }}
{{- end -}}

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: drawings
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -103,10 +103,11 @@ data:
"django_filters.rest_framework.DjangoFilterBackend"
],
"DEFAULT_AUTHENTICATION_CLASSES": [
"core.auth.ZitadelJWTAuthentication",
"rest_framework_simplejwt.authentication.JWTAuthentication",
"rest_framework.authentication.SessionAuthentication",
"rest_framework.authentication.BasicAuthentication",
#"core.auth.ZitadelJWTAuthentication",
"rest_framework_simplejwt.authentication.JWTStatelessUserAuthentication",
#"rest_framework_simplejwt.authentication.JWTAuthentication",
#"rest_framework.authentication.SessionAuthentication",
#"rest_framework.authentication.BasicAuthentication",
],
"DEFAULT_PERMISSION_CLASSES": [
"rest_framework.permissions.AllowAny",
@ -125,7 +126,7 @@ data:
return default
raise ImproperlyConfigured(error_msg)
SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="django")
SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="default_issuer")
SIMPLE_JWT = {

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: faas
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,137 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: flows
labels:
app: backend
service: backend
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
service: backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/flows" -}}
PG_DB=flows_db
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST=postgresql.flows.svc.cluster.local
PG_PORT=5432
PG_PASSWORD={{ index .Data.data "password" }}
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
DOCUMENTATION_PG_PORT=5432
DOCUMENTATION_PG_DATABASE=flows_db
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: flows-vault
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec /opt/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: LOG_LEVEL
value: DEBUG
- name: BASE_HOST
value: https://srx.wb.ru
- name: CELERY_QUEUE
value: flow
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: DJANGO_HOST
value: http://backend-svc.django.svc.cluster.local:80/api
- name: PLANNING_HOST
value: http://backend-svc.pm.svc.cluster.local:80/api/pm/msp
- name: PLANNING_USE
value: "True"
- name: DOCUMENTATION_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1
- name: DOCUMENTATION_EXTERNAL_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1
- name: ENABLE_ANALYTICS
value: "1"
- name: ENABLE_CELERY
value: "1"
- name: ENABLE_MAILGUN
value: "0"
- name: ENABLE_METRICS
value: "0"
- name: FROM_EMAIL
value: sarex@rwb.ru
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080
- name: RESOURCE_URL
value: http://resources-service.resources.svc.cluster.local:8000
- name: SERVICE_HOST
value: https://srx.wb.ru/flows/api/v1
- name: SMTP_HOST
value: mail.rwb.ru
- name: CHECKLIST_HOST
value: http://checklists-backend-service.checklists.svc.cluster.local:80
- name: SMTP_PORT
value: "465"
- name: SYNC_RESOURCE_ID
value: "1"
- name: TIMEOUT
value: "120"
- name: WORKFLOWS_HOST
value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1
- name: WORKFLOWS_TIMEOUT
value: "60"
- name: DOCUMENTATION_TIMEOUT
value: "60"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: flows
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -0,0 +1,262 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: flows
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: flows-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-documentations-db ] && . /vault/secrets/flows-documentations-db
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec /opt/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://srx.wb.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: DJANGO_HOST
value:
_default: "http://backend-svc.django.svc.cluster.local:80/api"
- name: PLANNING_HOST
value:
_default: "http://backend-svc.pm.svc.cluster.local:80/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@rwb.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: SERVICE_HOST
value:
_default: "https://srx.wb.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "mail.rwb.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "465"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "120"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "60"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "60"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/apps/flows/postgres" -}}
PG_DB={{ index .Data.data "database" }}
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST={{ index .Data.data "host" }}
PG_PORT={{ index .Data.data "port" }}
PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres
vault.hashicorp.com/agent-inject-template-flows-documentations-db: |-
{{- with secret "secrets/data/apps/documentations/postgres" -}}
DOCUMENTATION_PG_HOST={{ index .Data.data "host" }}
DOCUMENTATION_PG_PORT={{ index .Data.data "port" }}
DOCUMENTATION_PG_DATABASE={{ index .Data.data "database" }}
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,137 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: celery
namespace: flows
labels:
app: celery
service: celery
spec:
replicas: 1
selector:
matchLabels:
app: celery
template:
metadata:
labels:
app: celery
service: celery
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/postgresql/apps/flows" -}}
PG_DB=flows_db
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST=postgresql.flows.svc.cluster.local
PG_PORT=5432
PG_PASSWORD={{ index .Data.data "password" }}
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
DOCUMENTATION_PG_PORT=5432
DOCUMENTATION_PG_DATABASE=flows_db
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: flows-vault
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: LOG_LEVEL
value: DEBUG
- name: BASE_HOST
value: https://srx.wb.ru
- name: CELERY_QUEUE
value: flow
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: DJANGO_HOST
value: http://backend-svc.django.svc.cluster.local:80/api
- name: PLANNING_HOST
value: http://backend-service.pm.svc.cluster.local:80/api/pm/msp
- name: PLANNING_USE
value: "True"
- name: DOCUMENTATION_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1
- name: DOCUMENTATION_EXTERNAL_HOST
value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1
- name: ENABLE_ANALYTICS
value: "1"
- name: ENABLE_CELERY
value: "1"
- name: ENABLE_MAILGUN
value: "0"
- name: ENABLE_METRICS
value: "0"
- name: FROM_EMAIL
value: sarex@rwb.ru
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080
- name: RESOURCE_URL
value: http://resources-service.resources.svc.cluster.local:8000
- name: SERVICE_HOST
value: https://srx.wb.ru/flows/api/v1
- name: SMTP_HOST
value: mail.rwb.ru
- name: CHECKLIST_HOST
value: http://checklists-backend-service.checklists.svc.cluster.local:80
- name: SMTP_PORT
value: "465"
- name: SYNC_RESOURCE_ID
value: "1"
- name: TIMEOUT
value: "120"
- name: WORKFLOWS_HOST
value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1
- name: WORKFLOWS_TIMEOUT
value: "60"
- name: DOCUMENTATION_TIMEOUT
value: "60"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

248
apps/flows/base/celery.yaml Normal file
View File

@ -0,0 +1,248 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: flows
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
celery:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: flows-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: celery
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
[ -f /vault/secrets/flows-documentations-db ] && . /vault/secrets/flows-documentations-db
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
set +a
exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://srx.wb.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: DJANGO_HOST
value:
_default: "http://backend-svc.django.svc.cluster.local:80/api"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:80/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@rwb.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: SERVICE_HOST
value:
_default: "https://srx.wb.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "mail.rwb.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "465"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "120"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "60"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "60"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: flows
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
{{- with secret "secrets/data/apps/flows/postgres" -}}
PG_DB={{ index .Data.data "database" }}
PG_LOGIN={{ index .Data.data "username" }}
PG_HOST={{ index .Data.data "host" }}
PG_PORT={{ index .Data.data "port" }}
PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres
vault.hashicorp.com/agent-inject-template-flows-documentations-db: |-
{{- with secret "secrets/data/apps/documentations/postgres" -}}
DOCUMENTATION_PG_HOST={{ index .Data.data "host" }}
DOCUMENTATION_PG_PORT={{ index .Data.data "port" }}
DOCUMENTATION_PG_DATABASE={{ index .Data.data "database" }}
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PORT=5672
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,32 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontend
namespace: flows
labels:
app: frontend
spec:
replicas: 1
selector:
matchLabels:
app: frontend
template:
metadata:
labels:
app: frontend
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 80
protocol: TCP
resources:
requests:
cpu: 25m
memory: 100Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: frontend-svc
namespace: flows
spec:
type: ClusterIP
selector:
app: frontend
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP

View File

@ -0,0 +1,90 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: flows
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
frontend:
enabled: true
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: frontend
replicaCount:
_default: 1
port:
_default: 80
resources:
requests:
cpu:
_default: 25m
memory:
_default: 100Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: frontend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred

View File

@ -4,9 +4,6 @@ kind: Kustomization
namespace: flows
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- celery-deployment.yaml
- frontend-deployment.yaml
- backend-service.yaml
- frontend-service.yaml
- backend.yaml
- celery.yaml
- frontend.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: flows-vault
namespace: flows

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: flows

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: flows
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,92 +1,182 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: flows
spec:
replicas: 2
template:
spec:
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0
env:
- name: DEBUG
value: 'false'
- name: PLANNING_HOST
value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp
- name: PLANNING_USE
value: 'True'
- name: PG_PORT
value: '5432'
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: PROXY_PATH_PREFIX
value: /flows
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000/api
- name: DOCUMENTATION_TIMEOUT
value: '240'
- name: DOCUMENTATION_HOST
value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1
- name: DOCUMENTATION_EXTERNAL_HOST
value: http://documentations-service.documentations.svc.cluster.local:8080/api/v1
- name: BASE_HOST
value: https://sarex.dsinv.ru
- name: DOCUMENTATION_PG_PORT
value: '5432'
- name: DOCUMENTATION_PG_DATABASE
value: documentations
- name: DOCUMENTATION_PG_HOST
value: postgres-service.documentations.svc.cluster.local
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value: cr.yandex/crp3ccidau046kdj8g9q
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value: relay.dsinv.ru
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value: '25'
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value: sarex@dsinv.ru
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value: '0'
- name: RESOURCES_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: ENABLE_METRICS
value: '0'
- name: ENABLE_MAILGUN
value: '0'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: FROM_EMAIL
value: sarex@dsinv.ru
- name: TIMEOUT
value: '240'
- name: WORKFLOWS_TIMEOUT
value: '20'
- name: RESOURCE_URL
value: http://resources-service.resources.svc.cluster.local:8000/
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080/
- name: SYNC_RESOURCE_ID
value: '1'
- name: SERVICE_HOST
value: https://sarex.dsinv.ru/flows/api/v1
- name: ENABLE_ANALYTICS
value: '1'
- name: ENABLE_CELERY
value: '1'
- name: CELERY_QUEUE
value: flow
- name: RABBITMQ_HOST
value: rabbitmq-service.flows.svc
- name: RABBITMQ_PORT
value: '5672'
- name: RABBITMQ_VHOST
value: flow
- name: PG_HOST
value: postgres-service.flows.svc.cluster.local
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0
deployment:
replicaCount:
_default: 2
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000/api"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://documentations-service.documentations.svc.cluster.local:8080/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@dsinv.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080/"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources.svc.cluster.local:8000/"
- name: SERVICE_HOST
value:
_default: "https://sarex.dsinv.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "25"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "240"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "20"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "240"
- name: DEBUG
value:
_default: "false"
- name: PG_PORT
value:
_default: "5432"
- name: PROXY_PATH_PREFIX
value:
_default: "/flows"
- name: DOCUMENTATION_PG_PORT
value:
_default: "5432"
- name: DOCUMENTATION_PG_DATABASE
value:
_default: "documentations"
- name: DOCUMENTATION_PG_HOST
value:
_default: "postgres-service.documentations.svc.cluster.local"
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value:
_default: "25"
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value:
_default: "sarex@dsinv.ru"
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value:
_default: "0"
- name: RESOURCES_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: RABBITMQ_HOST
value:
_default: "rabbitmq-service.flows.svc"
- name: RABBITMQ_PORT
value:
_default: "5672"
- name: RABBITMQ_VHOST
value:
_default: "flow"
- name: PG_HOST
value:
_default: "postgres-service.flows.svc.cluster.local"

View File

@ -1,93 +1,198 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: flows
spec:
template:
spec:
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0
env:
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL
value: sarex@dsinv.ru
- name: ENABLE_METRICS
value: '0'
- name: ENABLE_MAILGUN
value: '0'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: FROM_EMAIL
value: sarex@dsinv.ru
- name: MAILGUN_HOST
value: http:localhost:8000
- name: MAILGUN_API_KEY
value: empty
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value: '0'
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1
- name: FLOWS_HOST
value: http://backend-service.flows.svc.cluster.local:8000
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value: cr.yandex/crp3ccidau046kdj8g9q
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value: relay.dsinv.ru
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value: '25'
- name: PLANNING_HOST
value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp
- name: PLANNING_USE
value: 'True'
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value: sarex@dsinv.ru
- name: FLOWS_DB_HOST
value: postgres-service.flows.svc.cluster.local
- name: ISSUES_DB_HOST
value: postgres-service.issues.svc.cluster.local
- name: DEBUG
value: '0'
- name: PG_PORT
value: '5432'
- name: FLOWS_DB_PORT
value: '5432'
- name: ISSUES_DB_PORT
value: '5432'
- name: DJANGO_HOST
value: http://backend.django.svc.cluster.local:8000/api
- name: DJANGO_BASE_HOST
value: https://sarex.dsinv.ru
- name: DOCUMENTATION_HOST
value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1
- name: BASE_HOST
value: https://sarex.dsinv.ru
- name: RESOURCES_HOST
value: http://resources-service.resources.svc.cluster.local:8000/
- name: TIMEOUT
value: '120'
- name: RESOURCE_URL
value: http://resources-service.resources/api/v1
- name: GATEWAY_URL
value: http://pdm-api.documentations.svc.cluster.local:8080/api/v1
- name: SYNC_RESOURCE_ID
value: '1'
- name: SERVICE_HOST
value: https://sarex.dsinv.ru/flows/api/v1
- name: ENABLE_ANALYTICS
value: '1'
- name: ENABLE_CELERY
value: '1'
- name: CELERY_QUEUE
value: flow
- name: RABBITMQ_HOST
value: rabbitmq-service.flows.svc
- name: RABBITMQ_PORT
value: '5672'
- name: RABBITMQ_VHOST
value: flow
- name: PG_HOST
value: postgres-service.flows.svc.cluster.local
values:
services:
celery:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0
envs:
- name: LOG_LEVEL
value:
_default: "DEBUG"
- name: BASE_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: CELERY_QUEUE
value:
_default: "flow"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: DJANGO_HOST
value:
_default: "http://backend.django.svc.cluster.local:8000/api"
- name: PLANNING_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
- name: PLANNING_USE
value:
_default: "True"
- name: DOCUMENTATION_HOST
value:
_default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1"
- name: DOCUMENTATION_EXTERNAL_HOST
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
- name: ENABLE_ANALYTICS
value:
_default: "1"
- name: ENABLE_CELERY
value:
_default: "1"
- name: ENABLE_MAILGUN
value:
_default: "0"
- name: ENABLE_METRICS
value:
_default: "0"
- name: FROM_EMAIL
value:
_default: "sarex@dsinv.ru"
- name: GATEWAY_URL
value:
_default: "http://pdm-api.documentations.svc.cluster.local:8080/api/v1"
- name: RESOURCE_URL
value:
_default: "http://resources-service.resources/api/v1"
- name: SERVICE_HOST
value:
_default: "https://sarex.dsinv.ru/flows/api/v1"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: CHECKLIST_HOST
value:
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
- name: SMTP_PORT
value:
_default: "25"
- name: SYNC_RESOURCE_ID
value:
_default: "1"
- name: TIMEOUT
value:
_default: "120"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1"
- name: WORKFLOWS_TIMEOUT
value:
_default: "60"
- name: DOCUMENTATION_TIMEOUT
value:
_default: "60"
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL
value:
_default: "sarex@dsinv.ru"
- name: MAILGUN_HOST
value:
_default: "http:localhost:8000"
- name: MAILGUN_API_KEY
value:
_default: "empty"
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
value:
_default: "0"
- name: FLOWS_HOST
value:
_default: "http://backend-service.flows.svc.cluster.local:8000"
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
value:
_default: "25"
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
value:
_default: "sarex@dsinv.ru"
- name: FLOWS_DB_HOST
value:
_default: "postgres-service.flows.svc.cluster.local"
- name: ISSUES_DB_HOST
value:
_default: "postgres-service.issues.svc.cluster.local"
- name: DEBUG
value:
_default: "0"
- name: PG_PORT
value:
_default: "5432"
- name: FLOWS_DB_PORT
value:
_default: "5432"
- name: ISSUES_DB_PORT
value:
_default: "5432"
- name: DJANGO_BASE_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: RESOURCES_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000/"
- name: RABBITMQ_HOST
value:
_default: "rabbitmq-service.flows.svc"
- name: RABBITMQ_PORT
value:
_default: "5672"
- name: RABBITMQ_VHOST
value:
_default: "flow"
- name: PG_HOST
value:
_default: "postgres-service.flows.svc.cluster.local"

View File

@ -1,12 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: flows
spec:
template:
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2
values:
services:
frontend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2

View File

@ -10,13 +10,13 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend
- path: celery.yaml
target:
kind: Deployment
kind: HelmRelease
name: celery
- path: frontend.yaml
target:
kind: Deployment
kind: HelmRelease
name: frontend

View File

@ -1,120 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: inspections-backend
namespace: inspections
labels:
app: inspections-backend
spec:
replicas: 1
selector:
matchLabels:
app: inspections-backend
template:
metadata:
labels:
app: inspections-backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: inspections
vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/postgresql/apps/inspections
vault.hashicorp.com/agent-inject-template-inspections-db: |-
{{- with secret "secrets/data/postgresql/apps/inspections" -}}
DATABASE_HOST=postgresql.inspections.svc.cluster.local
DATABASE_PORT=5432
DATABASE_NAME=inspections_db
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections
vault.hashicorp.com/agent-inject-template-inspections-kafka: |-
{{- with secret "secrets/data/kafka/apps/inspections" -}}
KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-inspections-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
SAREX_BACKEND_AUTH={{ index .Data.data "key" }}
{{- end -}}
spec:
serviceAccountName: inspections-vault
containers:
- name: inspections-backend
image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db
[ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka
[ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth
set +a
exec ./entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: DEBUG
value: "false"
- name: SERVICE_URL
value: https://srx.wb.ru
- name: HTTP_APP_HOST
value: 0.0.0.0
- name: HTTP_APP_PORT
value: "8000"
- name: HTTP_APP_ROOT_PATH
value: /inspections
- name: HTTP_APP_WORKERS
value: "3"
- name: HTTP_APP_ADMIN_ENABLE
value: "true"
- name: KAFKA_SSL_CAFILE
value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt
- name: KAFKA_EAV_ASSETS_TOPIC
value: assets_broadcast
- name: JWT_AUTH_ENABLE
value: "true"
- name: NOTIFICATIONS_ENABLE
value: "true"
- name: NOTIFICATIONS_EMAIL_FROM
value: hello@sarex.io
- name: SAREX_BACKEND_URL
value: https://srx.wb.ru
- name: SAREX_BACKEND_TIMEOUT
value: "30"
- name: EAV_URL
value: http://eav-service.eav
- name: EAV_TIMEOUT
value: "30"
- name: WORKFLOWS_URL
value: http://workflows-service.processing-prod
- name: WORKFLOWS_TIMEOUT
value: "30"
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
value: cr.yandex/crp3ccidau046kdj8g9q/notification:email
- name: MOBILE_APP_CURRENT_VERSION
value: 1.0.0
- name: MOBILE_APP_RECOMMENDED_VERSION
value: 1.0.0
- name: MOBILE_APP_REQUIRED_VERSION
value: 1.0.0
- name: MAILER_URL
value: http://mailer-service.mailer:8000
- name: MAILER_TIMEOUT
value: "30"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: rfi-backend-api-svc
namespace: rfi
spec:
type: ClusterIP
selector:
app: rfi-backend-api
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -0,0 +1,240 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: inspections
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: inspections-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: inspections-backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/bash", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db
[ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka
[ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth
set +a
exec ./entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: DEBUG
value:
_default: "false"
- name: SERVICE_URL
value:
_default: "https://srx.wb.ru"
- name: HTTP_APP_HOST
value:
_default: "0.0.0.0"
- name: HTTP_APP_PORT
value:
_default: "8000"
- name: HTTP_APP_ROOT_PATH
value:
_default: "/inspections"
- name: HTTP_APP_WORKERS
value:
_default: "3"
- name: HTTP_APP_ADMIN_ENABLE
value:
_default: "true"
- name: KAFKA_SSL_CAFILE
value:
_default: "/usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt"
- name: KAFKA_EAV_ASSETS_TOPIC
value:
_default: "assets_broadcast"
- name: JWT_AUTH_ENABLE
value:
_default: "true"
- name: NOTIFICATIONS_ENABLE
value:
_default: "true"
- name: NOTIFICATIONS_EMAIL_FROM
value:
_default: "hello@sarex.io"
- name: SAREX_BACKEND_URL
value:
_default: "https://srx.wb.ru"
- name: SAREX_BACKEND_TIMEOUT
value:
_default: "30"
- name: EAV_URL
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: EAV_TIMEOUT
value:
_default: "30"
- name: WORKFLOWS_URL
value:
_default: "http://backend-svc.processing.svc.cluster.local:80"
- name: WORKFLOWS_TIMEOUT
value:
_default: "30"
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
value:
_default: "cr.yandex/crp3ccidau046kdj8g9q/notification:email"
- name: MOBILE_APP_CURRENT_VERSION
value:
_default: "1.0.0"
- name: MOBILE_APP_RECOMMENDED_VERSION
value:
_default: "1.0.0"
- name: MOBILE_APP_REQUIRED_VERSION
value:
_default: "1.0.0"
- name: MAILER_URL
value:
_default: "http://mailer-service.mailer:8000"
- name: MAILER_TIMEOUT
value:
_default: "30"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: inspections
vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/apps/inspections/postgres
vault.hashicorp.com/agent-inject-template-inspections-db: |-
{{- with secret "secrets/data/apps/inspections/postgres" -}}
DATABASE_HOST={{ index .Data.data "host" }}
DATABASE_PORT={{ index .Data.data "port" }}
DATABASE_NAME={{ index .Data.data "database" }}
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections
vault.hashicorp.com/agent-inject-template-inspections-kafka: |-
{{- with secret "secrets/data/kafka/apps/inspections" -}}
KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-inspections-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
SAREX_BACKEND_AUTH={{ index .Data.data "key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -4,6 +4,4 @@ kind: Kustomization
namespace: inspections
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- backend-service.yaml
- backend.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: inspections-vault
namespace: inspections

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: inspections

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: inspections
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,61 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: inspections-backend
name: backend
namespace: inspections
spec:
template:
spec:
containers:
- name: inspections-backend
image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d
env:
- name: DEBUG
value: 'false'
- name: SERVICE_URL
value: https://srx.wb.ru
- name: HTTP_APP_HOST
value: 0.0.0.0
- name: HTTP_APP_PORT
value: '8000'
- name: HTTP_APP_ROOT_PATH
value: /inspections
- name: HTTP_APP_WORKERS
value: '3'
- name: HTTP_APP_ADMIN_ENABLE
value: 'true'
- name: KAFKA_SSL_CAFILE
value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt
- name: KAFKA_EAV_ASSETS_TOPIC
value: assets_broadcast
- name: JWT_AUTH_ENABLE
value: 'true'
- name: NOTIFICATIONS_ENABLE
value: 'true'
- name: NOTIFICATIONS_EMAIL_FROM
value: hello@sarex.io
- name: SAREX_BACKEND_URL
value: https://srx.wb.ru
- name: SAREX_BACKEND_TIMEOUT
value: '30'
- name: EAV_URL
value: http://eav-service.eav
- name: EAV_TIMEOUT
value: '30'
- name: WORKFLOWS_URL
value: http://workflows-service.processing-prod
- name: WORKFLOWS_TIMEOUT
value: '30'
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
value: cr.yandex/crp3ccidau046kdj8g9q/notification:email
- name: MOBILE_APP_CURRENT_VERSION
value: 1.0.0
- name: MOBILE_APP_RECOMMENDED_VERSION
value: 1.0.0
- name: MOBILE_APP_REQUIRED_VERSION
value: 1.0.0
- name: MAILER_URL
value: http://mailer-service.mailer:8000
- name: MAILER_TIMEOUT
value: '30'
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d

View File

@ -9,5 +9,5 @@ resources:
patches:
- path: inspections-backend.yaml
target:
kind: Deployment
name: inspections-backend
kind: HelmRelease
name: backend

View File

@ -1,135 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: backend
namespace: issues
labels:
app: backend
service: backend
spec:
replicas: 1
selector:
matchLabels:
app: backend
template:
metadata:
labels:
app: backend
service: backend
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/postgresql/apps/issues" -}}
DATABASE_PORT=5432
DATABASE_HOST=postgresql.issues.svc.cluster.local
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME=issues_db
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: issues-vault
volumes:
- name: production-configmap
configMap:
name: production-configmap
items:
- key: production.py
path: production.py
defaultMode: 420
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec /src/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: ENVIRONMENT
value: production
- name: AERO_PUBLIC_HOST
value: https://sarex.contour.infra.sarex.tech
- name: AERO_HOST
value: https://sarex.contour.infra.sarex.tech
- name: BASE_AERO_URL
value: https://sarex.contour.infra.sarex.tech
- name: BASE_AUTH_URL
value: http://backend-svc.django.svc.cluster.local:80
- name: WORKFLOWS_HOST
value: http://backend-svc.workflow.svc.cluster.local:80
- name: WORKFLOWS_URL
value: http://backend-svc.workflow.svc.cluster.local:80
- name: RESOURCES_API_HOST
value: http://backend-svc.resources.svc.cluster.local:80
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: SAREX_API
value: https://sarex.contour.infra.sarex.tech
- name: DOCUMENTATIONS_URL
value: http://documentations-api-svc.documentations.svc.cluster.local:80
- name: DJANGO_SETTINGS_MODULE
value: config.settings.production
- name: API_ADDRESS
value: "8000"
resources:
requests:
cpu: "25m"
memory: 128Mi
volumeMounts:
- name: production-configmap
mountPath: /src/config/settings/production.py
subPath: production.py
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: backend-svc
namespace: issues
spec:
type: ClusterIP
selector:
app: backend
ports:
- name: http
port: 80
targetPort: 8000
protocol: TCP

View File

@ -0,0 +1,237 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: issues
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: issues-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: backend
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec /src/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: backend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 8000
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
volumes:
_default:
- name: production-configmap
mountPath:
_default: /src/config/settings/production.py
subPath:
_default: production.py
readOnly:
_default: true
configMap:
name:
_default: production-configmap
items:
- key: production.py
path:
_default: production.py
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: AERO_HOST
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: BASE_AERO_URL
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: BASE_AUTH_URL
value:
_default: "http://backend-svc.django.svc.cluster.local:80"
- name: WORKFLOWS_HOST
value:
_default: "http://backend-svc.workflow.svc.cluster.local:80"
- name: WORKFLOWS_URL
value:
_default: "http://backend-svc.workflow.svc.cluster.local:80"
- name: RESOURCES_API_HOST
value:
_default: "http://iam-backend.iam.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: SAREX_API
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: DOCUMENTATIONS_URL
value:
_default: "http://documentations-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/apps/issues/postgres" -}}
DATABASE_PORT={{ index .Data.data "port" }}
DATABASE_HOST={{ index .Data.data "host" }}
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME={{ index .Data.data "database" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,135 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: celery
namespace: issues
labels:
app: celery
service: celery
spec:
replicas: 1
selector:
matchLabels:
app: celery
template:
metadata:
labels:
app: celery
service: celery
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/postgresql/apps/issues" -}}
DATABASE_PORT=5432
DATABASE_HOST=postgresql.issues.svc.cluster.local
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME=issues_db
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
spec:
serviceAccountName: issues-vault
volumes:
- name: production-configmap
configMap:
name: production-configmap
items:
- key: production.py
path: production.py
defaultMode: 420
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
imagePullPolicy: IfNotPresent
command: ["/bin/sh", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec celery -A config worker -l info -E
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: ENVIRONMENT
value: production
- name: AERO_PUBLIC_HOST
value: https://srx.wb.ru
- name: AERO_HOST
value: https://srx.wb.ru
- name: BASE_AERO_URL
value: https://srx.wb.ru
- name: BASE_AUTH_URL
value: http://backend-svc.django.svc.cluster.local:80
- name: WORKFLOWS_HOST
value: http://workflows-api-service.workflow.svc.cluster.local:8000
- name: WORKFLOWS_URL
value: http://workflows-api-service.workflow.svc.cluster.local:8000
- name: RESOURCES_API_HOST
value: http://backend-svc.resources.svc.cluster.local:80
- name: EAV_HOST
value: http://backend-svc.eav.svc.cluster.local:80
- name: SAREX_API
value: https://srx.wb.ru
- name: DOCUMENTATIONS_URL
value: http://backend-api-svc.documentations.svc.cluster.local:80
- name: DJANGO_SETTINGS_MODULE
value: config.settings.production
- name: API_ADDRESS
value: "8000"
resources:
requests:
cpu: "25m"
memory: 128Mi
volumeMounts:
- name: production-configmap
mountPath: /src/config/settings/production.py
subPath: production.py
imagePullSecrets:
- name: regcred

View File

@ -0,0 +1,222 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: issues
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
celery:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: issues-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: celery
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/sh", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
set +a
exec celery -A config worker -l info -E
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: false
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
volumes:
_default:
- name: production-configmap
mountPath:
_default: /src/config/settings/production.py
subPath:
_default: production.py
readOnly:
_default: true
configMap:
name:
_default: production-configmap
items:
- key: production.py
path:
_default: production.py
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://srx.wb.ru"
- name: AERO_HOST
value:
_default: "https://srx.wb.ru"
- name: BASE_AERO_URL
value:
_default: "https://srx.wb.ru"
- name: BASE_AUTH_URL
value:
_default: "http://backend-svc.django.svc.cluster.local:80"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000"
- name: WORKFLOWS_URL
value:
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000"
- name: RESOURCES_API_HOST
value:
_default: "http://iam-backend.iam.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: SAREX_API
value:
_default: "https://srx.wb.ru"
- name: DOCUMENTATIONS_URL
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: issues
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres
vault.hashicorp.com/agent-inject-template-issues-db: |-
{{- with secret "secrets/data/apps/issues/postgres" -}}
DATABASE_PORT={{ index .Data.data "port" }}
DATABASE_HOST={{ index .Data.data "host" }}
DATABASE_USER={{ index .Data.data "username" }}
DATABASE_PASSWORD={{ index .Data.data "password" }}
DATABASE_NAME={{ index .Data.data "database" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
RABBITMQ_USERNAME={{ index .Data.data "username" }}
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
vault.hashicorp.com/agent-inject-template-issues-s3: |-
{{- with secret "secrets/data/minio/apps/issues" -}}
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
YC_S3_BUCKET_NAME=rfi
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
{{- with secret "secrets/data/vault/common/django_auth" -}}
DJANGO_TOKEN={{ index .Data.data "key" }}
SAREX_USERNAME={{ index .Data.data "username" }}
SAREX_PASSWORD={{ index .Data.data "password" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "private_key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
{{ index .Data.data "public_key" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,32 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: frontend
namespace: issues
labels:
app: frontend
spec:
replicas: 1
selector:
matchLabels:
app: frontend
template:
metadata:
labels:
app: frontend
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73
imagePullPolicy: IfNotPresent
ports:
- name: http
containerPort: 80
protocol: TCP
resources:
requests:
cpu: 25m
memory: 100Mi
imagePullSecrets:
- name: regcred

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: frontend-svc
namespace: issues
spec:
type: ClusterIP
selector:
app: frontend
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP

View File

@ -0,0 +1,90 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: issues
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
frontend:
enabled: true
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: frontend
replicaCount:
_default: 1
port:
_default: 80
resources:
requests:
cpu:
_default: 25m
memory:
_default: 100Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: frontend-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred

View File

@ -4,10 +4,7 @@ kind: Kustomization
namespace: issues
resources:
- namespace.yaml
- serviceaccount.yaml
- backend-deployment.yaml
- celery-deployment.yaml
- frontend-deployment.yaml
- backend-service.yaml
- frontend-service.yaml
- backend.yaml
- celery.yaml
- frontend.yaml
- production-configmap.yaml

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: issues-vault
namespace: issues

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: issues

View File

@ -0,0 +1,8 @@
---
apiVersion: v1
kind: Namespace
metadata:
name: issues
labels:
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,53 +1,102 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: backend
namespace: issues
spec:
template:
spec:
containers:
- name: backend
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
env:
- name: ENABLE_MAILGUN
value: 'False'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: EMAIL_FROM
value: sarex@dsinv.ru
- name: USE_NOTIFICATIONS
value: 'True'
- name: DJANGO_SETTINGS_MODULE
value: config.settings.production
- name: REDIS_HOST
value: redis-service.issues.svc.cluster.local
- name: DATABASE_HOST
value: postgres-service.issues.svc.cluster.local
- name: DATABASE_PORT
value: '5432'
- name: DATABASE_NAME
value: issues
- name: API_ADDRESS
value: '8000'
- name: ENVIRONMENT
value: production
- name: AERO_PUBLIC_HOST
value: https://sarex.dsinv.ru
- name: BASE_AERO_URL
value: http://backend.django.svc.cluster.local:8000
- name: BASE_AUTH_URL
value: http://backend.django.svc.cluster.local:8000
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000
- name: WORKFLOWS_URL
value: https://sarex.dsinv.ru
- name: RESOURCES_API_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: SAREX_API
value: http://backend.django.svc.cluster.local:8000
values:
services:
backend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: AERO_HOST
value:
_default: "https://sarex.contour.infra.sarex.tech"
- name: BASE_AERO_URL
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: BASE_AUTH_URL
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000"
- name: WORKFLOWS_URL
value:
_default: "https://sarex.dsinv.ru"
- name: RESOURCES_API_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: SAREX_API
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: DOCUMENTATIONS_URL
value:
_default: "http://documentations-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
- name: ENABLE_MAILGUN
value:
_default: "False"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: SMTP_PORT
value:
_default: "25"
- name: EMAIL_FROM
value:
_default: "sarex@dsinv.ru"
- name: USE_NOTIFICATIONS
value:
_default: "True"
- name: REDIS_HOST
value:
_default: "redis-service.issues.svc.cluster.local"
- name: DATABASE_HOST
value:
_default: "postgres-service.issues.svc.cluster.local"
- name: DATABASE_PORT
value:
_default: "5432"
- name: DATABASE_NAME
value:
_default: "issues"

View File

@ -1,57 +1,110 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: celery
namespace: issues
spec:
template:
spec:
containers:
- name: celery
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
env:
- name: KAFKA_EAV_ASSETS_TOPIC
value: sarex
- name: AERO_PUBLIC_HOST
value: https://sarex.dsinv.ru
- name: ENABLE_MAILGUN
value: 'False'
- name: SMTP_HOST
value: relay.dsinv.ru
- name: SMTP_PORT
value: '25'
- name: EMAIL_FROM
value: sarex@dsinv.ru
- name: REDIS_HOST
value: redis-service.issues.svc.cluster.local
- name: DATABASE_HOST
value: postgres-service.issues.svc.cluster.local
- name: DATABASE_PORT
value: '5432'
- name: DATABASE_NAME
value: issues
- name: USE_NOTIFICATIONS
value: 'True'
- name: API_ADDRESS
value: '8000'
- name: YC_S3_VERIFY
value: 'False'
- name: ENVIRONMENT
value: production
- name: AERO_HOST
value: https://sarex.dsinv.ru
- name: BASE_AERO_URL
value: http://backend.django.svc.cluster.local:8000
- name: BASE_AUTH_URL
value: https://sarex.dsinv.ru
- name: WORKFLOWS_HOST
value: http://workflows-service.workflow.svc.cluster.local:8000
- name: WORKFLOWS_URL
value: https://sarex.dsinv.ru
- name: RESOURCES_API_HOST
value: http://resources-service.resources.svc.cluster.local:8000
- name: EAV_HOST
value: http://eav-service.eav.svc.cluster.local:8000
- name: SAREX_API
value: http://backend.django.svc.cluster.local:8000
values:
services:
celery:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
envs:
- name: ENVIRONMENT
value:
_default: "production"
- name: AERO_PUBLIC_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: AERO_HOST
value:
_default: "https://sarex.dsinv.ru"
- name: BASE_AERO_URL
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: BASE_AUTH_URL
value:
_default: "https://sarex.dsinv.ru"
- name: WORKFLOWS_HOST
value:
_default: "http://workflows-service.workflow.svc.cluster.local:8000"
- name: WORKFLOWS_URL
value:
_default: "https://sarex.dsinv.ru"
- name: RESOURCES_API_HOST
value:
_default: "http://resources-service.resources.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://eav-service.eav.svc.cluster.local:8000"
- name: SAREX_API
value:
_default: "http://backend.django.svc.cluster.local:8000"
- name: DOCUMENTATIONS_URL
value:
_default: "http://backend-api-svc.documentations.svc.cluster.local:80"
- name: DJANGO_SETTINGS_MODULE
value:
_default: "config.settings.production"
- name: API_ADDRESS
value:
_default: "8000"
- name: KAFKA_EAV_ASSETS_TOPIC
value:
_default: "sarex"
- name: ENABLE_MAILGUN
value:
_default: "False"
- name: SMTP_HOST
value:
_default: "relay.dsinv.ru"
- name: SMTP_PORT
value:
_default: "25"
- name: EMAIL_FROM
value:
_default: "sarex@dsinv.ru"
- name: REDIS_HOST
value:
_default: "redis-service.issues.svc.cluster.local"
- name: DATABASE_HOST
value:
_default: "postgres-service.issues.svc.cluster.local"
- name: DATABASE_PORT
value:
_default: "5432"
- name: DATABASE_NAME
value:
_default: "issues"
- name: USE_NOTIFICATIONS
value:
_default: "True"
- name: YC_S3_VERIFY
value:
_default: "False"

View File

@ -1,12 +1,13 @@
---
apiVersion: apps/v1
kind: Deployment
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: frontend
namespace: issues
spec:
template:
spec:
containers:
- name: frontend
image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b
values:
services:
frontend:
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b

View File

@ -7,13 +7,13 @@ resources:
patches:
- path: backend.yaml
target:
kind: Deployment
kind: HelmRelease
name: backend
- path: celery.yaml
target:
kind: Deployment
kind: HelmRelease
name: celery
- path: frontend.yaml
target:
kind: Deployment
kind: HelmRelease
name: frontend

View File

@ -147,14 +147,14 @@ spec:
{{- with secret "secrets/data/vault/common/django_auth" -}}
MAPPER_DJANGO_TOKEN={{ index .Data.data "key" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-mapper-db: secrets/data/postgresql/apps/mapper
vault.hashicorp.com/agent-inject-secret-mapper-db: secrets/data/apps/mapper/postgres
vault.hashicorp.com/agent-inject-template-mapper-db: |-
{{- with secret "secrets/data/postgresql/apps/mapper" -}}
{{- with secret "secrets/data/apps/mapper/postgres" -}}
MAPPER_DB_USER={{ index .Data.data "username" }}
MAPPER_DB_PASSWORD={{ index .Data.data "password" }}
MAPPER_DB_HOST=postgresql.mapper.svc.cluster.local
MAPPER_DB_PORT=5432
MAPPER_DB_NAME=mapper_db
MAPPER_DB_HOST={{ index .Data.data "host" }}
MAPPER_DB_PORT={{ index .Data.data "port" }}
MAPPER_DB_NAME={{ index .Data.data "database" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-mapper-rabbitmq: secrets/data/rabbitmq/apps/mapper
vault.hashicorp.com/agent-inject-template-mapper-rabbitmq: |-

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: mapper
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -4,5 +4,5 @@ kind: Namespace
metadata:
name: measurements
labels:
istio-injection: disabled
istio-injection: enabled
security.deckhouse.io/pod-policy: privileged

View File

@ -1,96 +0,0 @@
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: message-hub
namespace: message-hub
labels:
app: message-hub
service: message-hub
spec:
replicas: 1
selector:
matchLabels:
app: message-hub
template:
metadata:
labels:
app: message-hub
service: message-hub
annotations:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: message-hub
vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/postgresql/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-db: |-
{{- with secret "secrets/data/postgresql/apps/message-hub" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE=pm_db
DB_HOST=postgresql.pm.svc.cluster.local
DB_PORT=5432
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-s3: |-
{{- with secret "secrets/data/minio/apps/message-hub" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}rfi{{- end -}}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-kafka: |-
{{- with secret "secrets/data/kafka/apps/message-hub" -}}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
KAFKA_HOST=kafka-kafka-contour-controller-headless.kafka.svc.cluster.local
KAFKA_PORT=9094
KAFKA_SECURITY_PROTOCOL={{ index .Data.data.auth "security_protocol" }}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }}
{{- end -}}
spec:
serviceAccountName: message-hub-vault
containers:
- name: message-hub
image: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_24425472
imagePullPolicy: IfNotPresent
command: ["/bin/bash", "-ec"]
args:
- |
set -a
[ -f /vault/secrets/message-hub-db ] && . /vault/secrets/message-hub-db
[ -f /vault/secrets/message-hub-s3 ] && . /vault/secrets/message-hub-s3
[ -f /vault/secrets/message-hub-kafka ] && . /vault/secrets/message-hub-kafka
set +a
exec /opt/entrypoint.sh
ports:
- name: http
containerPort: 8000
protocol: TCP
env:
- name: WORKER_TIMEOUT
value: "60"
- name: PYTHONPATH
value: src
- name: SETTINGS_MAX_RETRIES
value: "1"
- name: SETTINGS_TOPICS
value: '{"planning": "pm", "assets": "assets_broadcast", "project_entity": "issues_broadcast"}'
- name: SETTINGS_PDF_CONVERTER_HOST
value: http://export-project-service.django.svc.cluster.local:8000
- name: SAREX_BASE_HOST
value: http://backend-service.pm.svc.cluster.local:8000
- name: CACHE_HOST
value: redis.pm.svc.cluster.local
- name: CACHE_PORT
value: "6379"
resources:
requests:
cpu: "25m"
memory: 128Mi
imagePullSecrets:
- name: regcred

View File

@ -4,6 +4,4 @@ kind: Kustomization
namespace: message-hub
resources:
- namespace.yaml
- serviceaccount.yaml
- deployment.yaml
- service.yaml
- message-hub.yaml

View File

@ -0,0 +1,183 @@
---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: message-hub
namespace: message-hub
spec:
interval: 10m
chart:
spec:
chart: universal-chart
version: "0.1.9"
sourceRef:
kind: HelmRepository
name: yc-oci-charts
namespace: flux-system
interval: 10m
install:
remediation:
retries: 3
upgrade:
remediation:
retries: 3
values:
global:
env: _default
services:
backend:
enabled: true
serviceAccount:
enabled:
_default: true
name:
_default: message-hub-vault
image:
name:
_default: cr.yandex/crp3ccidau046kdj8g9q/message-hub:production_24425472
pullPolicy:
_default: IfNotPresent
deployment:
enabled: true
name:
_default: message-hub
replicaCount:
_default: 1
port:
_default: 8000
command:
_default: ["/bin/bash", "-ec"]
args:
_default:
- |
set -a
[ -f /vault/secrets/message-hub-db ] && . /vault/secrets/message-hub-db
[ -f /vault/secrets/message-hub-s3 ] && . /vault/secrets/message-hub-s3
[ -f /vault/secrets/message-hub-kafka ] && . /vault/secrets/message-hub-kafka
set +a
exec /opt/entrypoint.sh
resources:
requests:
cpu:
_default: 25m
memory:
_default: 128Mi
probes:
liveness:
enabled: false
readiness:
enabled: false
service:
enabled: true
name:
_default: message-hub-svc
type:
_default: ClusterIP
port:
_default: 80
targetPort:
_default: 80
portName:
_default: http
imagePullSecrets:
enabled:
_default: true
name:
_default: regcred
envs:
- name: WORKER_TIMEOUT
value:
_default: "60"
- name: PYTHONPATH
value:
_default: "src"
- name: SETTINGS_MAX_RETRIES
value:
_default: "1"
- name: SETTINGS_TOPICS
value:
_default: '{"planning": "pm", "assets": "assets_broadcast", "project_entity": "issues_broadcast"}'
- name: SETTINGS_PDF_CONVERTER_HOST
value:
_default: "http://export-project-service.django.svc.cluster.local:8000"
- name: SAREX_BASE_HOST
value:
_default: "http://backend-service.pm.svc.cluster.local:8000"
- name: CACHE_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: CACHE_PORT
value:
_default: "6379"
podAnnotations:
_default:
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
vault.hashicorp.com/agent-init-first: "true"
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/agent-pre-populate-only: "true"
vault.hashicorp.com/auth-path: auth/kubernetes
vault.hashicorp.com/role: message-hub
vault.hashicorp.com/agent-inject-secret-message-hub-db: secrets/data/apps/message-hub/postgres
vault.hashicorp.com/agent-inject-template-message-hub-db: |-
{{- with secret "secrets/data/apps/message-hub/postgres" -}}
DB_USERNAME={{ index .Data.data "username" }}
DB_PASSWORD={{ index .Data.data "password" }}
DB_DATABASE={{ index .Data.data "database" }}
DB_HOST={{ index .Data.data "host" }}
DB_PORT={{ index .Data.data "port" }}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-s3: secrets/data/minio/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-s3: |-
{{- with secret "secrets/data/minio/apps/message-hub" -}}
S3_HOST={{ index .Data.data.client "endpoint" }}
S3_LOGIN={{ index .Data.data "access_key" }}
S3_PASSWORD={{ index .Data.data "secret_key" }}
{{- $buckets := index .Data.data "buckets" }}
S3_BUCKET={{- if gt (len $buckets) 0 -}}{{ index (index $buckets 0) "name" }}{{- else -}}rfi{{- end -}}
{{- end -}}
vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/message-hub
vault.hashicorp.com/agent-inject-template-message-hub-kafka: |-
{{- with secret "secrets/data/kafka/apps/message-hub" -}}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
KAFKA_HOST=kafka-kafka-contour-controller-headless.kafka.svc.cluster.local
KAFKA_PORT=9094
KAFKA_SECURITY_PROTOCOL={{ index .Data.data.auth "security_protocol" }}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }}
{{- end -}}
commitSha: ""
gitlabUri: ""
gitlabJobUrl: ""
owner: ""

View File

@ -1,15 +0,0 @@
---
apiVersion: v1
kind: Service
metadata:
name: message-hub-svc
namespace: message-hub
spec:
type: ClusterIP
selector:
app: message-hub
ports:
- name: http
port: 80
targetPort: 80
protocol: TCP

View File

@ -1,5 +0,0 @@
apiVersion: v1
kind: ServiceAccount
metadata:
name: message-hub-vault
namespace: message-hub

View File

@ -0,0 +1,10 @@
---
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../base
patches:
- path: namespace.yaml
target:
kind: Namespace
name: message-hub

Some files were not shown because too many files have changed in this diff Show More