Compare commits
48 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
95f567a62b | ||
|
|
c05003f184 | ||
|
|
c5ccafa21f | ||
|
|
5ea61bd508 | ||
|
|
a99d93f41f | ||
|
|
278919eade | ||
|
|
66cd1a599f | ||
|
|
e069f38cb5 | ||
|
|
f5e278fbbf | ||
|
|
9cb672cf34 | ||
|
|
325aad49da | ||
|
|
38219249b3 | ||
|
|
6c81ba0080 | ||
|
|
c14d74050f | ||
|
|
3dd3c12537 | ||
|
|
d86bc2fbc5 | ||
|
|
7ad5c5f4b1 | ||
|
|
38a357ee64 | ||
|
|
5b2c6b9967 | ||
|
|
950c1a5c51 | ||
|
|
f1043df2da | ||
|
|
a148491f95 | ||
|
|
987e9e3a7f | ||
|
|
50cee9c4d3 | ||
|
|
80da663600 | ||
|
|
c470dacee3 | ||
|
|
ab7611fc7e | ||
|
|
fc9e75945a | ||
|
|
84c51343f9 | ||
|
|
396702429f | ||
|
|
800718737d | ||
|
|
e88027ffa6 | ||
|
|
798648e85d | ||
|
|
e09067365f | ||
|
|
9a8a80328a | ||
|
|
11fbf26d6d | ||
|
|
4e7757b7b4 | ||
|
|
8b6133a81a | ||
|
|
106b5d450d | ||
|
|
b98d3f6ab2 | ||
|
|
7868779771 | ||
|
|
b14e342955 | ||
|
|
d6a830db05 | ||
|
|
0d0b2cc5f8 | ||
|
|
3fb27a9e53 | ||
|
|
d57fcf8229 | ||
|
|
edd357ba72 | ||
|
|
c7b749fd09 |
@ -87,9 +87,9 @@ spec:
|
|||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
vault.hashicorp.com/role: attachments
|
vault.hashicorp.com/role: attachments
|
||||||
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/postgresql/apps/attachments
|
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres
|
||||||
vault.hashicorp.com/agent-inject-template-attachments-db: |-
|
vault.hashicorp.com/agent-inject-template-attachments-db: |-
|
||||||
{{- with secret "secrets/data/postgresql/apps/attachments" -}}
|
{{- with secret "secrets/data/apps/attachments/postgres" -}}
|
||||||
DATABASE_HOST={{ index .Data.data "host" }}
|
DATABASE_HOST={{ index .Data.data "host" }}
|
||||||
DATABASE_PORT={{ index .Data.data "port" }}
|
DATABASE_PORT={{ index .Data.data "port" }}
|
||||||
DATABASE_NAME={{ index .Data.data "database" }}
|
DATABASE_NAME={{ index .Data.data "database" }}
|
||||||
|
|||||||
@ -3,4 +3,5 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
namespace: attachments
|
namespace: attachments
|
||||||
resources:
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
- helmrelease.yaml
|
- helmrelease.yaml
|
||||||
|
|||||||
8
apps/attachments/base/namespace.yaml
Normal file
8
apps/attachments/base/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: attachments
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -11,10 +11,10 @@ spec:
|
|||||||
podAnnotations:
|
podAnnotations:
|
||||||
_default:
|
_default:
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
vault.hashicorp.com/role: attachments-vault
|
vault.hashicorp.com/role: attachments
|
||||||
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/postgresql/apps/attachments
|
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres
|
||||||
vault.hashicorp.com/agent-inject-template-attachments-db: |-
|
vault.hashicorp.com/agent-inject-template-attachments-db: |-
|
||||||
{{- with secret "secrets/data/postgresql/apps/attachments" -}}
|
{{- with secret "secrets/data/apps/attachments/postgres" -}}
|
||||||
DATABASE_HOST={{ index .Data.data "host" }}
|
DATABASE_HOST={{ index .Data.data "host" }}
|
||||||
DATABASE_PORT={{ index .Data.data "port" }}
|
DATABASE_PORT={{ index .Data.data "port" }}
|
||||||
DATABASE_NAME={{ index .Data.data "database" }}
|
DATABASE_NAME={{ index .Data.data "database" }}
|
||||||
|
|||||||
@ -4,5 +4,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: auth-flow
|
name: auth-flow
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -1,108 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: backend
|
|
||||||
namespace: bim
|
|
||||||
labels:
|
|
||||||
app: backend
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: backend
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: backend
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: bim
|
|
||||||
vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/postgresql/apps/bim
|
|
||||||
vault.hashicorp.com/agent-inject-template-bim-postgresql: |-
|
|
||||||
{{- with secret "secrets/data/postgresql/apps/bim" -}}
|
|
||||||
POSTGRES_ADDRESS=postgresql.bim.svc.cluster.local
|
|
||||||
POSTGRES_ADDRESS_2=postgresql.bim.svc.cluster.local
|
|
||||||
POSTGRES_ADDRESS_3=postgresql.bim.svc.cluster.local
|
|
||||||
POSTGRES_ADDRESS_4=postgresql.bim.svc.cluster.local
|
|
||||||
POSTGRES_PORT=5432
|
|
||||||
POSTGRES_PORT_2=5432
|
|
||||||
POSTGRES_PORT_3=5432
|
|
||||||
POSTGRES_PORT_4=5432
|
|
||||||
POSTGRES_DB=bim_db
|
|
||||||
POSTGRES_DB_2=bim_db
|
|
||||||
POSTGRES_DB_3=bim_db
|
|
||||||
POSTGRES_DB_4=bim_db
|
|
||||||
POSTGRES_USER={{ index .Data.data "username" }}
|
|
||||||
POSTGRES_USER_2={{ index .Data.data "username" }}
|
|
||||||
POSTGRES_USER_3={{ index .Data.data "username" }}
|
|
||||||
POSTGRES_USER_4={{ index .Data.data "username" }}
|
|
||||||
POSTGRES_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
POSTGRES_PASSWORD_2={{ index .Data.data "password" }}
|
|
||||||
POSTGRES_PASSWORD_3={{ index .Data.data "password" }}
|
|
||||||
POSTGRES_PASSWORD_4={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
|
||||||
serviceAccountName: bim-vault
|
|
||||||
containers:
|
|
||||||
- name: backend
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command: ["/bin/sh", "-ec"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
set -a
|
|
||||||
[ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql
|
|
||||||
set +a
|
|
||||||
exec ./httpserver
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: LAST_MASTER_BIM
|
|
||||||
value: "100000"
|
|
||||||
- name: LAST_MASTER_BIM_V3
|
|
||||||
value: "100000"
|
|
||||||
- name: DB_CERT_PATH_4
|
|
||||||
value: /root/yandex_pg.pem
|
|
||||||
- name: DB_CERT_PATH_3
|
|
||||||
value: /root/yandex_pg.pem
|
|
||||||
- name: DB_CERT_PATH_2
|
|
||||||
value: /root/yandex_pg.pem
|
|
||||||
- name: LAST_SLAVE_1_BIM
|
|
||||||
value: "1000000"
|
|
||||||
- name: POSTGRES_POOL_SIZE
|
|
||||||
value: "30"
|
|
||||||
- name: API_ADDRESS
|
|
||||||
value: 0.0.0.0:8000
|
|
||||||
- name: DJANGO_HOST
|
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
|
||||||
- name: ENABLE_SQL_QUERY
|
|
||||||
value: "0"
|
|
||||||
- name: ENABLE_SSL
|
|
||||||
value: "0"
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 25m
|
|
||||||
memory: 100Mi
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /ping
|
|
||||||
port: 8000
|
|
||||||
initialDelaySeconds: 10
|
|
||||||
periodSeconds: 60
|
|
||||||
failureThreshold: 10
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /ping
|
|
||||||
port: 8000
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 5
|
|
||||||
failureThreshold: 20
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: backend-svc
|
|
||||||
namespace: bim
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: backend
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
217
apps/bim/base/backend.yaml
Normal file
217
apps/bim/base/backend.yaml
Normal file
@ -0,0 +1,217 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: bim
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: bim-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-api:contour_3d704fef
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/bim-postgresql ] && . /vault/secrets/bim-postgresql
|
||||||
|
set +a
|
||||||
|
exec ./httpserver
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /ping
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 60
|
||||||
|
failureThreshold:
|
||||||
|
_default: 10
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /ping
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 5
|
||||||
|
periodSeconds:
|
||||||
|
_default: 5
|
||||||
|
failureThreshold:
|
||||||
|
_default: 20
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "100000"
|
||||||
|
|
||||||
|
- name: LAST_MASTER_BIM_V3
|
||||||
|
value:
|
||||||
|
_default: "100000"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_4
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_3
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_2
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "1000000"
|
||||||
|
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0:8000"
|
||||||
|
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.django.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: bim
|
||||||
|
vault.hashicorp.com/agent-inject-secret-bim-postgresql: secrets/data/apps/bim/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-bim-postgresql: |-
|
||||||
|
{{- with secret "secrets/data/apps/bim/postgres" -}}
|
||||||
|
POSTGRES_ADDRESS={{ index .Data.data "host" }}
|
||||||
|
POSTGRES_ADDRESS_2={{ index .Data.data "host" }}
|
||||||
|
POSTGRES_ADDRESS_3={{ index .Data.data "host" }}
|
||||||
|
POSTGRES_ADDRESS_4={{ index .Data.data "host" }}
|
||||||
|
POSTGRES_PORT={{ index .Data.data "port" }}
|
||||||
|
POSTGRES_PORT_2={{ index .Data.data "port" }}
|
||||||
|
POSTGRES_PORT_3={{ index .Data.data "port" }}
|
||||||
|
POSTGRES_PORT_4={{ index .Data.data "port" }}
|
||||||
|
POSTGRES_DB={{ index .Data.data "database" }}
|
||||||
|
POSTGRES_DB_2={{ index .Data.data "database" }}
|
||||||
|
POSTGRES_DB_3={{ index .Data.data "database" }}
|
||||||
|
POSTGRES_DB_4={{ index .Data.data "database" }}
|
||||||
|
POSTGRES_USER={{ index .Data.data "username" }}
|
||||||
|
POSTGRES_USER_2={{ index .Data.data "username" }}
|
||||||
|
POSTGRES_USER_3={{ index .Data.data "username" }}
|
||||||
|
POSTGRES_USER_4={{ index .Data.data "username" }}
|
||||||
|
POSTGRES_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
POSTGRES_PASSWORD_2={{ index .Data.data "password" }}
|
||||||
|
POSTGRES_PASSWORD_3={{ index .Data.data "password" }}
|
||||||
|
POSTGRES_PASSWORD_4={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -4,6 +4,4 @@ kind: Kustomization
|
|||||||
namespace: bim
|
namespace: bim
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- serviceaccount.yaml
|
- backend.yaml
|
||||||
- backend-deployment.yaml
|
|
||||||
- backend-service.yaml
|
|
||||||
|
|||||||
@ -1,5 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: bim-vault
|
|
||||||
namespace: bim
|
|
||||||
10
apps/bim/d8-ugmk-prod/kustomization.yaml
Normal file
10
apps/bim/d8-ugmk-prod/kustomization.yaml
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: namespace.yaml
|
||||||
|
target:
|
||||||
|
kind: Namespace
|
||||||
|
name: bim
|
||||||
8
apps/bim/d8-ugmk-prod/namespace.yaml
Normal file
8
apps/bim/d8-ugmk-prod/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: bim
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -1,53 +1,98 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: backend
|
name: backend
|
||||||
namespace: bim
|
namespace: bim
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
backend:
|
||||||
- name: backend
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc
|
name:
|
||||||
env:
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:1d961a7b125ae0e69bd5717658d927091d8c05cc
|
||||||
- name: LAST_MASTER_BIM
|
|
||||||
value: '100000'
|
envs:
|
||||||
- name: LAST_SLAVE_1_BIM
|
- name: LAST_MASTER_BIM
|
||||||
value: '94015'
|
value:
|
||||||
- name: LAST_MASTER_BIM_V3
|
_default: "100000"
|
||||||
value: '100000'
|
|
||||||
- name: LAST_SLAVE_1_BIM_V3
|
- name: LAST_SLAVE_1_BIM
|
||||||
value: '0'
|
value:
|
||||||
- name: DB_CERT_PATH_3
|
_default: "94015"
|
||||||
value: /root/yandex_pg.pem
|
|
||||||
- name: POSTGRES_ADDRESS_3
|
- name: LAST_MASTER_BIM_V3
|
||||||
value: postgres-service
|
value:
|
||||||
- name: POSTGRES_PORT_3
|
_default: "100000"
|
||||||
value: '5432'
|
|
||||||
- name: POSTGRES_DB_3
|
- name: LAST_SLAVE_1_BIM_V3
|
||||||
value: bimapidb
|
value:
|
||||||
- name: DB_CERT_PATH_2
|
_default: "0"
|
||||||
value: /root/yandex_pg.pem
|
|
||||||
- name: POSTGRES_ADDRESS_2
|
- name: DB_CERT_PATH_3
|
||||||
value: postgres-service
|
value:
|
||||||
- name: POSTGRES_PORT_2
|
_default: "/root/yandex_pg.pem"
|
||||||
value: '5432'
|
|
||||||
- name: POSTGRES_DB_2
|
- name: POSTGRES_ADDRESS_3
|
||||||
value: bimapidb
|
value:
|
||||||
- name: POSTGRES_ADDRESS
|
_default: "postgres-service"
|
||||||
value: postgres-service
|
|
||||||
- name: POSTGRES_PORT
|
- name: POSTGRES_PORT_3
|
||||||
value: '5432'
|
value:
|
||||||
- name: POSTGRES_DB
|
_default: "5432"
|
||||||
value: bimapidb
|
|
||||||
- name: POSTGRES_POOL_SIZE
|
- name: POSTGRES_DB_3
|
||||||
value: '30'
|
value:
|
||||||
- name: API_ADDRESS
|
_default: "bimapidb"
|
||||||
value: 0.0.0.0:8000
|
|
||||||
- name: DJANGO_HOST
|
- name: DB_CERT_PATH_2
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
value:
|
||||||
- name: ENABLE_SQL_QUERY
|
_default: "/root/yandex_pg.pem"
|
||||||
value: '0'
|
|
||||||
- name: ENABLE_SSL
|
- name: POSTGRES_ADDRESS_2
|
||||||
value: '0'
|
value:
|
||||||
|
_default: "postgres-service"
|
||||||
|
|
||||||
|
- name: POSTGRES_PORT_2
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: POSTGRES_DB_2
|
||||||
|
value:
|
||||||
|
_default: "bimapidb"
|
||||||
|
|
||||||
|
- name: POSTGRES_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "postgres-service"
|
||||||
|
|
||||||
|
- name: POSTGRES_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value:
|
||||||
|
_default: "bimapidb"
|
||||||
|
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0:8000"
|
||||||
|
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_4
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|||||||
@ -9,5 +9,5 @@ resources:
|
|||||||
patches:
|
patches:
|
||||||
- path: backend.yaml
|
- path: backend.yaml
|
||||||
target:
|
target:
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
name: backend
|
name: backend
|
||||||
|
|||||||
@ -7,5 +7,5 @@ resources:
|
|||||||
patches:
|
patches:
|
||||||
- path: replicas.yaml
|
- path: replicas.yaml
|
||||||
target:
|
target:
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
name: backend
|
name: backend
|
||||||
|
|||||||
@ -1,8 +1,13 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: backend
|
name: backend
|
||||||
namespace: bim
|
namespace: bim
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
values:
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
deployment:
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: cde-svc
|
|
||||||
namespace: faas
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: cde
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-flowscallback
|
name: cde-flowscallback
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-flowscallback
|
|
||||||
service: cde-flowscallback
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-flowscallback
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-flowscallback
|
|
||||||
service: cde-flowscallback
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-flowscallback
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-flowscallback:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flowscallback-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-flowscallback
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-splitpdf
|
name: cde-splitpdf
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-splitpdf
|
|
||||||
service: cde-splitpdf
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-splitpdf
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-splitpdf
|
|
||||||
service: cde-splitpdf
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-splitpdf
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-splitpdf:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/splitpdf-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-splitpdf
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
120
apps/cde/base/cde-worker-alert.yaml
Normal file
120
apps/cde/base/cde-worker-alert.yaml
Normal file
@ -0,0 +1,120 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: cde-worker-alert
|
||||||
|
namespace: cde
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-alert:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/orchestrator:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-alert
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/bash", "-lc"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
source /vault/secrets/cde-env
|
||||||
|
exec /worker
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 500m
|
||||||
|
memory:
|
||||||
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-worker-copy
|
name: cde-worker-copy
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-worker-copy
|
|
||||||
service: cde-worker-copy
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-worker-copy
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-worker-copy
|
|
||||||
service: cde-worker-copy
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-worker-copy
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-copy:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/copy-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-copy
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: "1"
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
120
apps/cde/base/cde-worker-copyv2.yaml
Normal file
120
apps/cde/base/cde-worker-copyv2.yaml
Normal file
@ -0,0 +1,120 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: cde-worker-copyv2
|
||||||
|
namespace: cde
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-copyv2:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/copyv2-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-copyv2
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/bash", "-lc"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
source /vault/secrets/cde-env
|
||||||
|
exec /worker
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: "1"
|
||||||
|
memory:
|
||||||
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-worker-create-versions
|
name: cde-worker-create-versions
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-worker-create-versions
|
|
||||||
service: cde-worker-create-versions
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-worker-create-versions
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-worker-create-versions
|
|
||||||
service: cde-worker-create-versions
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-worker-create-versions
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-create-versions:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/createversions-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-create-versions
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
120
apps/cde/base/cde-worker-create-versionsv2.yaml
Normal file
120
apps/cde/base/cde-worker-create-versionsv2.yaml
Normal file
@ -0,0 +1,120 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: cde-worker-create-versionsv2
|
||||||
|
namespace: cde
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-create-versionsv2:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/createversionsv2-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-create-versionsv2
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/bash", "-lc"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
source /vault/secrets/cde-env
|
||||||
|
exec /worker
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 500m
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-worker-markings
|
name: cde-worker-markings
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-worker-markings
|
|
||||||
service: cde-worker-markings
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-worker-markings
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-worker-markings
|
|
||||||
service: cde-worker-markings
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-worker-markings
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-markings:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/markings-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-markings
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
120
apps/cde/base/cde-worker-markingsv2.yaml
Normal file
120
apps/cde/base/cde-worker-markingsv2.yaml
Normal file
@ -0,0 +1,120 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: cde-worker-markingsv2
|
||||||
|
namespace: cde
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-markingsv2:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/markingsv2-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-markingsv2
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/bash", "-lc"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
source /vault/secrets/cde-env
|
||||||
|
exec /worker
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 500m
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-worker-sign
|
name: cde-worker-sign
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-worker-sign
|
|
||||||
service: cde-worker-sign
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-worker-sign
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-worker-sign
|
|
||||||
service: cde-worker-sign
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-worker-sign
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-sign:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/sign-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-sign
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
120
apps/cde/base/cde-worker-signv2.yaml
Normal file
120
apps/cde/base/cde-worker-signv2.yaml
Normal file
@ -0,0 +1,120 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: cde-worker-signv2
|
||||||
|
namespace: cde
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-signv2:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/signv2-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-signv2
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/bash", "-lc"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -e
|
||||||
|
source /vault/secrets/cde-env
|
||||||
|
exec /worker
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 500m
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,60 +1,120 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde-worker-update-bundles
|
name: cde-worker-update-bundles
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde-worker-update-bundles
|
|
||||||
service: cde-worker-update-bundles
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde-worker-update-bundles
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde-worker-update-bundles
|
|
||||||
service: cde-worker-update-bundles
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: cde-worker-update-bundles
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde-worker-update-bundles:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/updatebundles-worker:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-worker-update-bundles
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /worker
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /worker
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
@ -1,60 +1,139 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: cde
|
name: cde
|
||||||
namespace: cde
|
namespace: cde
|
||||||
labels:
|
|
||||||
app: cde
|
|
||||||
service: cde
|
|
||||||
spec:
|
spec:
|
||||||
replicas: 1
|
interval: 10m
|
||||||
selector:
|
|
||||||
matchLabels:
|
chart:
|
||||||
app: cde
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: cde
|
|
||||||
service: cde
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: cde
|
|
||||||
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
|
||||||
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
|
||||||
{{- with secret "secrets/data/vault/apps/cde" -}}
|
|
||||||
{{- range $k, $v := .Data.data }}
|
|
||||||
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
|
||||||
{{- end }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
spec:
|
||||||
serviceAccountName: cde-vault
|
chart: universal-chart
|
||||||
containers:
|
version: "0.1.9"
|
||||||
- name: api
|
sourceRef:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/cde:prod_9f3c1d2a
|
kind: HelmRepository
|
||||||
imagePullPolicy: IfNotPresent
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
cde:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: cde-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/cde:preprod_4302d8f3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
command:
|
command:
|
||||||
- /bin/bash
|
_default: ["/bin/bash", "-lc"]
|
||||||
- -lc
|
|
||||||
args:
|
args:
|
||||||
- |
|
_default:
|
||||||
set -e
|
- |
|
||||||
source /vault/secrets/cde-env
|
set -e
|
||||||
exec /http
|
source /vault/secrets/cde-env
|
||||||
ports:
|
exec /http
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: S3_IS_CONTOUR
|
|
||||||
value: "true"
|
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
cpu: "25m"
|
cpu:
|
||||||
memory: 128Mi
|
_default: 500m
|
||||||
imagePullSecrets:
|
memory:
|
||||||
- name: regcred
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: cde-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: SAREX_BACKEND_BASE_URL
|
||||||
|
value:
|
||||||
|
_default: "https://lk.sarex.io"
|
||||||
|
|
||||||
|
- name: S3_IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: IS_CONTOUR
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: cde
|
||||||
|
vault.hashicorp.com/agent-inject-secret-cde-env: secrets/data/vault/apps/cde
|
||||||
|
vault.hashicorp.com/agent-inject-template-cde-env: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/cde" -}}
|
||||||
|
{{- range $k, $v := .Data.data }}
|
||||||
|
export {{ $k }}=$(printf '%b' {{ printf "%q" (printf "%v" $v) }})
|
||||||
|
{{- end }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
|
|||||||
@ -4,13 +4,16 @@ kind: Kustomization
|
|||||||
namespace: cde
|
namespace: cde
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- serviceaccount.yaml
|
|
||||||
- cde.yaml
|
- cde.yaml
|
||||||
- cde-splitpdf.yaml
|
- cde-splitpdf.yaml
|
||||||
- backend-service.yaml
|
|
||||||
- cde-flowscallback.yaml
|
- cde-flowscallback.yaml
|
||||||
|
- cde-worker-alert.yaml
|
||||||
- cde-worker-copy.yaml
|
- cde-worker-copy.yaml
|
||||||
|
- cde-worker-copyv2.yaml
|
||||||
- cde-worker-create-versions.yaml
|
- cde-worker-create-versions.yaml
|
||||||
|
- cde-worker-create-versionsv2.yaml
|
||||||
- cde-worker-markings.yaml
|
- cde-worker-markings.yaml
|
||||||
|
- cde-worker-markingsv2.yaml
|
||||||
- cde-worker-sign.yaml
|
- cde-worker-sign.yaml
|
||||||
|
- cde-worker-signv2.yaml
|
||||||
- cde-worker-update-bundles.yaml
|
- cde-worker-update-bundles.yaml
|
||||||
|
|||||||
@ -5,3 +5,4 @@ metadata:
|
|||||||
name: cde
|
name: cde
|
||||||
labels:
|
labels:
|
||||||
istio-injection: enabled
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -1,5 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: cde-vault
|
|
||||||
namespace: cde
|
|
||||||
10
apps/cde/d8-ugmk-prod/kustomization.yaml
Normal file
10
apps/cde/d8-ugmk-prod/kustomization.yaml
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: namespace.yaml
|
||||||
|
target:
|
||||||
|
kind: Namespace
|
||||||
|
name: cde
|
||||||
8
apps/cde/d8-ugmk-prod/namespace.yaml
Normal file
8
apps/cde/d8-ugmk-prod/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: cde
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -244,17 +244,17 @@ spec:
|
|||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
vault.hashicorp.com/role: comparisons
|
vault.hashicorp.com/role: comparisons
|
||||||
vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/postgresql/apps/comparisons
|
vault.hashicorp.com/agent-inject-secret-comparisons-db: secrets/data/apps/comparisons/postgres
|
||||||
vault.hashicorp.com/agent-inject-template-comparisons-db: |-
|
vault.hashicorp.com/agent-inject-template-comparisons-db: |-
|
||||||
{{- with secret "secrets/data/postgresql/apps/comparisons" -}}
|
{{- with secret "secrets/data/apps/comparisons/postgres" -}}
|
||||||
DATABASE_HOST=postgresql.comparisons.svc.cluster.local
|
DATABASE_HOST={{ index .Data.data "host" }}
|
||||||
DATABASE_PORT=5432
|
DATABASE_PORT={{ index .Data.data "port" }}
|
||||||
DATABASE_DB=comparisons_db
|
DATABASE_DB={{ index .Data.data "database" }}
|
||||||
DATABASE_USER={{ index .Data.data "username" }}
|
DATABASE_USER={{ index .Data.data "username" }}
|
||||||
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
||||||
POSTGRES_ADDRESS=postgresql.comparisons.svc.cluster.local
|
POSTGRES_ADDRESS={{ index .Data.data "host" }}
|
||||||
POSTGRES_PORT=5432
|
POSTGRES_PORT={{ index .Data.data "port" }}
|
||||||
POSTGRES_DB=comparisons_db
|
POSTGRES_DB={{ index .Data.data "database" }}
|
||||||
POSTGRES_USER={{ index .Data.data "username" }}
|
POSTGRES_USER={{ index .Data.data "username" }}
|
||||||
POSTGRES_PASSWORD={{ index .Data.data "password" }}
|
POSTGRES_PASSWORD={{ index .Data.data "password" }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|||||||
@ -4,5 +4,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: comparisons
|
name: comparisons
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -90,9 +90,9 @@ spec:
|
|||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
vault.hashicorp.com/role: contracts
|
vault.hashicorp.com/role: contracts
|
||||||
vault.hashicorp.com/agent-inject-secret-contracts-db: secrets/data/postgresql/apps/contracts
|
vault.hashicorp.com/agent-inject-secret-contracts-db: secrets/data/apps/contracts/postgres
|
||||||
vault.hashicorp.com/agent-inject-template-contracts-db: |-
|
vault.hashicorp.com/agent-inject-template-contracts-db: |-
|
||||||
{{- with secret "secrets/data/postgresql/apps/contracts" -}}
|
{{- with secret "secrets/data/apps/contracts/postgres" -}}
|
||||||
DB_URL=postgresql://{{ index .Data.data "username" }}:{{ index .Data.data "password" }}@postgresql.contracts.svc.cluster.local:5432/contracts_db?sslmode=disable
|
DB_URL=postgresql://{{ index .Data.data "username" }}:{{ index .Data.data "password" }}@postgresql.contracts.svc.cluster.local:5432/contracts_db?sslmode=disable
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
vault.hashicorp.com/agent-inject-secret-contracts-jwt-public: secrets/data/vault/common/rsa_keys
|
vault.hashicorp.com/agent-inject-secret-contracts-jwt-public: secrets/data/vault/common/rsa_keys
|
||||||
|
|||||||
@ -3,5 +3,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: control-interface
|
name: control-interface
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -4,5 +4,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: cross-section
|
name: cross-section
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -296,6 +296,11 @@ data:
|
|||||||
"name": "Запросы",
|
"name": "Запросы",
|
||||||
"uri": "/rfi"
|
"uri": "/rfi"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"name": "Управление проектами",
|
||||||
|
"uri": "/management/projects"
|
||||||
|
},
|
||||||
|
|
||||||
# {
|
# {
|
||||||
# "name": "Обзор",
|
# "name": "Обзор",
|
||||||
# "uri": "/projects"
|
# "uri": "/projects"
|
||||||
|
|||||||
@ -62,11 +62,13 @@ data:
|
|||||||
if_modified_since off;
|
if_modified_since off;
|
||||||
expires off;
|
expires off;
|
||||||
}
|
}
|
||||||
# location ~^/api/pm/ {
|
location ~^/api/pm/ {
|
||||||
# #rewrite /api/(.+) /$1 break;
|
#rewrite /api/(.+) /$1 break;
|
||||||
# proxy_set_header Host $host;
|
proxy_http_version 1.1;
|
||||||
# proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
|
proxy_set_header Connection "";
|
||||||
# }
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
|
||||||
|
}
|
||||||
|
|
||||||
# location ~^/api/v1/documents/ {
|
# location ~^/api/v1/documents/ {
|
||||||
# #rewrite /api/(.+) /$1 break;
|
# #rewrite /api/(.+) /$1 break;
|
||||||
@ -74,25 +76,27 @@ data:
|
|||||||
# proxy_pass http://backend-filestream-svc.documentations.svc.cluster.local:80;
|
# proxy_pass http://backend-filestream-svc.documentations.svc.cluster.local:80;
|
||||||
# }
|
# }
|
||||||
|
|
||||||
# location ~^/(api|admin)/ {
|
location ~^/(api|admin)/ {
|
||||||
# proxy_set_header Host $host;
|
proxy_http_version 1.1;
|
||||||
# proxy_pass http://backend-svc.django.svc.cluster.local:80;
|
proxy_set_header Connection "";
|
||||||
# }
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://backend-svc.django.svc.cluster.local:80;
|
||||||
|
}
|
||||||
|
|
||||||
# location ~^/workspaces-v2/(.+).js {
|
location ~^/workspaces-v2/(.+).js {
|
||||||
# proxy_http_version 1.1;
|
proxy_http_version 1.1;
|
||||||
# proxy_set_header Connection "";
|
proxy_set_header Connection "";
|
||||||
# rewrite /workspaces-v2/(.+) /$1 break;
|
rewrite /workspaces-v2/(.+) /$1 break;
|
||||||
# proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
|
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
|
||||||
# }
|
}
|
||||||
|
|
||||||
|
|
||||||
# location ~^/workspaces-v2/(.+)\.wasm$ {
|
location ~^/workspaces-v2/(.+)\.wasm$ {
|
||||||
# proxy_http_version 1.1;
|
proxy_http_version 1.1;
|
||||||
# proxy_set_header Connection "";
|
proxy_set_header Connection "";
|
||||||
# rewrite ^/workspaces-v2/(.+) /$1 break;
|
rewrite ^/workspaces-v2/(.+) /$1 break;
|
||||||
# proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
|
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
|
||||||
# }
|
}
|
||||||
|
|
||||||
location @index {
|
location @index {
|
||||||
add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
||||||
@ -101,10 +105,12 @@ data:
|
|||||||
try_files /static/index.html =404;
|
try_files /static/index.html =404;
|
||||||
}
|
}
|
||||||
|
|
||||||
# location ~^/workflows/(.+).js {
|
location ~^/workflows/(.+).js {
|
||||||
# rewrite /workflows/(.+) /$1 break;
|
proxy_http_version 1.1;
|
||||||
# proxy_pass http://frontend-svc.processing.svc.cluster.local:80;
|
proxy_set_header Connection "";
|
||||||
# }
|
rewrite /workflows/(.+) /$1 break;
|
||||||
|
proxy_pass http://frontend-svc.processing.svc.cluster.local:80;
|
||||||
|
}
|
||||||
location /service-worker.js {
|
location /service-worker.js {
|
||||||
try_files /static/$uri @index;
|
try_files /static/$uri @index;
|
||||||
}
|
}
|
||||||
|
|||||||
@ -8,8 +8,8 @@ data:
|
|||||||
{
|
{
|
||||||
"auth_type": "zitadel",
|
"auth_type": "zitadel",
|
||||||
"zitadel": {
|
"zitadel": {
|
||||||
"client_id": "383923818340615274",
|
"client_id": "379557107642492501",
|
||||||
"host": "https://sarex-login.uralmine.com"
|
"host": "https://zitadel.contour.infra.sarex.tech"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
140
apps/django/d8-ugmk-prod/backend.yaml
Normal file
140
apps/django/d8-ugmk-prod/backend.yaml
Normal file
@ -0,0 +1,140 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: django
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
envs:
|
||||||
|
- name: ALLOWED_HOSTS
|
||||||
|
value:
|
||||||
|
_default: "*"
|
||||||
|
- name: SERVER_USE_CHANGELOG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_ZITADEL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: config.settings.production
|
||||||
|
- name: CELERY_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: redis
|
||||||
|
- name: CELERY_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
- name: DJANGO_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: redis
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_USERNAME_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_EMAIL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: DJANGO_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
- name: BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://bim-backend-v2-service.bim-api
|
||||||
|
- name: BIMV2_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
- name: JWT_KID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: PDM_SYNC
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: KC_SYNC_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: MEASUREMENTS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://measurements-service.measurements.svc.cluster.local:8000/api
|
||||||
|
- name: MEASUREMENTS_USE_MEASUREMENTS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_API_HOST
|
||||||
|
value:
|
||||||
|
_default: https://sarex.uralmine.com
|
||||||
|
- name: SERVER_HOST
|
||||||
|
value:
|
||||||
|
_default: https://sarex.uralmine.com
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.processing.svc.cluster.local:80
|
||||||
|
- name: WORKFLOWS_BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.django.svc.cluster.local:80
|
||||||
|
- name: WORKFLOWS_PREFIX
|
||||||
|
value:
|
||||||
|
_default: /internal/v1
|
||||||
|
- name: WORKFLOWS_USE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_S3_STREAM_IMPORT
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_SAVE_DIFF_DEM
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_USE_CLICKHOUSE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_DJANGO_STORAGE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_USE_METASHAPE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_CHANGELOG_MODE_SYSTEM_LOG
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHANGELOG_MODE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_DJANGO_URLS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: EAV_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHUNKED_PATH
|
||||||
|
value:
|
||||||
|
_default: /tmp/chunked_uploads/%Y/%m/%d
|
||||||
|
- name: SERVER_HIDE_USER_SCROLL_PERMISSIONS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_WRORKFLOW_STATUS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: ZITADEL_HOST
|
||||||
|
value:
|
||||||
|
_default: https://sarex-login.uralmine.com
|
||||||
|
- name: SERVER_KAFKA_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}'
|
||||||
|
- name: KAFKA_SSL_CAFILE
|
||||||
|
value:
|
||||||
|
_default: /usr/local/share/ca-certificates/kafka.crt
|
||||||
|
- name: KC_USE_REDIRECT_LOGOUT
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
@ -3,4 +3,13 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
namespace: django
|
namespace: django
|
||||||
resources:
|
resources:
|
||||||
- ../base
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: backend.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: backend
|
||||||
|
- path: zitadel-configmap.yaml
|
||||||
|
target:
|
||||||
|
kind: ConfigMap
|
||||||
|
name: zitadel-configmap
|
||||||
14
apps/django/d8-ugmk-prod/zitadel-configmap.yaml
Normal file
14
apps/django/d8-ugmk-prod/zitadel-configmap.yaml
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: zitadel-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
config.json: |
|
||||||
|
{
|
||||||
|
"auth_type": "zitadel",
|
||||||
|
"zitadel": {
|
||||||
|
"client_id": "383923818340615274",
|
||||||
|
"host": "https://sarex-login.uralmine.com"
|
||||||
|
}
|
||||||
|
}
|
||||||
@ -4,5 +4,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: document-link
|
name: document-link
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -88,6 +88,9 @@ spec:
|
|||||||
- name: POSTGRES_POOL_SIZE
|
- name: POSTGRES_POOL_SIZE
|
||||||
value:
|
value:
|
||||||
_default: "20"
|
_default: "20"
|
||||||
|
- name: USE_LEGACY_BIM_FLOW
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
- name: ZITADEL_ACCOUNT
|
- name: ZITADEL_ACCOUNT
|
||||||
value:
|
value:
|
||||||
_default: /vault/secrets/documentations-zitadel-account-json
|
_default: /vault/secrets/documentations-zitadel-account-json
|
||||||
@ -96,7 +99,7 @@ spec:
|
|||||||
_default: zitadel-srx.wb.ru
|
_default: zitadel-srx.wb.ru
|
||||||
- name: USE_ZITADEL
|
- name: USE_ZITADEL
|
||||||
value:
|
value:
|
||||||
_default: "0"
|
_default: "1"
|
||||||
- name: FLOWS_URL
|
- name: FLOWS_URL
|
||||||
value:
|
value:
|
||||||
_default: http://backend-svc.flows.svc.cluster.local:80
|
_default: http://backend-svc.flows.svc.cluster.local:80
|
||||||
@ -150,10 +153,10 @@ spec:
|
|||||||
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
||||||
- name: BIM_API_URL
|
- name: BIM_API_URL
|
||||||
value:
|
value:
|
||||||
_default: http://bim-api-service.bim.svc.cluster.local:8080/
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
- name: BIM_API_V2_URL
|
- name: BIM_API_V2_URL
|
||||||
value:
|
value:
|
||||||
_default: http://backend-service.bim.svc.cluster.local:8000/
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
- name: WORKSPACE_BUNDLE_VERSION
|
- name: WORKSPACE_BUNDLE_VERSION
|
||||||
value:
|
value:
|
||||||
_default: v1
|
_default: v1
|
||||||
|
|||||||
@ -96,7 +96,7 @@ spec:
|
|||||||
_default: zitadel-srx.wb.ru
|
_default: zitadel-srx.wb.ru
|
||||||
- name: USE_ZITADEL
|
- name: USE_ZITADEL
|
||||||
value:
|
value:
|
||||||
_default: "0"
|
_default: "1"
|
||||||
- name: FLOWS_URL
|
- name: FLOWS_URL
|
||||||
value:
|
value:
|
||||||
_default: http://backend-svc.flows.svc.cluster.local:80
|
_default: http://backend-svc.flows.svc.cluster.local:80
|
||||||
@ -150,10 +150,10 @@ spec:
|
|||||||
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
||||||
- name: BIM_API_URL
|
- name: BIM_API_URL
|
||||||
value:
|
value:
|
||||||
_default: http://bim-api-service.bim.svc.cluster.local:8080/
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
- name: BIM_API_V2_URL
|
- name: BIM_API_V2_URL
|
||||||
value:
|
value:
|
||||||
_default: http://backend-service.bim.svc.cluster.local:8000/
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
- name: WORKSPACE_BUNDLE_VERSION
|
- name: WORKSPACE_BUNDLE_VERSION
|
||||||
value:
|
value:
|
||||||
_default: v1
|
_default: v1
|
||||||
|
|||||||
163
apps/documentations/base/hasher.yaml
Normal file
163
apps/documentations/base/hasher.yaml
Normal file
@ -0,0 +1,163 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: documentations-hasher
|
||||||
|
namespace: documentations
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: documentations-vault
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
name:
|
||||||
|
_default: hasher
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/documentations-hasher-rabbitmq ] && . /vault/secrets/documentations-hasher-rabbitmq
|
||||||
|
[ -f /vault/secrets/documentations-hasher-s3 ] && . /vault/secrets/documentations-hasher-s3
|
||||||
|
set +a
|
||||||
|
exec ./server
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/hasher:production_3f853d3a
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
name:
|
||||||
|
_default: hasher-service
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
targetPort:
|
||||||
|
_default: 8080
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
envs:
|
||||||
|
- name: HASHER_APP__LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: INFO
|
||||||
|
|
||||||
|
- name: HASHER_APP__NUM_WORKERS
|
||||||
|
value:
|
||||||
|
_default: "4"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_QUEUE
|
||||||
|
value:
|
||||||
|
_default: hash.compute.normal.tasks
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE
|
||||||
|
value:
|
||||||
|
_default: hash.compute
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE_TYPE
|
||||||
|
value:
|
||||||
|
_default: direct
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_ROUTING_KEY
|
||||||
|
value:
|
||||||
|
_default: hash.compute.normal
|
||||||
|
|
||||||
|
- name: HASHER_S3__MAX_POOL_CONNECTIONS
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
|
||||||
|
- name: HASHER_S3__CONNECT_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
|
||||||
|
- name: HASHER_S3__READ_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: HASHER_S3__REGION_NAME
|
||||||
|
value:
|
||||||
|
_default: ru-central1
|
||||||
|
|
||||||
|
- name: HASHER_S3__USE_SSL
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: HASHER_S3__VERIFY
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411,8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: documentations
|
||||||
|
vault.hashicorp.com/agent-inject-secret-documentations-hasher-rabbitmq: secrets/data/apps/documentations/hasher/rabbitmq
|
||||||
|
vault.hashicorp.com/agent-inject-template-documentations-hasher-rabbitmq: |-
|
||||||
|
{{- with secret "secrets/data/apps/documentations/hasher/rabbitmq" -}}
|
||||||
|
HASHER_AMQP__HOST={{ index .Data.data "host" }}
|
||||||
|
HASHER_AMQP__PORT={{ index .Data.data "port" }}
|
||||||
|
HASHER_AMQP__USERNAME={{ index .Data.data "username" }}
|
||||||
|
HASHER_AMQP__PASSWORD={{ index .Data.data "password" }}
|
||||||
|
HASHER_AMQP__VHOST={{ index .Data.data "vhost" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-documentations-hasher-s3: secrets/data/apps/documentations/hasher/s3
|
||||||
|
vault.hashicorp.com/agent-inject-template-documentations-hasher-s3: |-
|
||||||
|
{{- with secret "secrets/data/apps/documentations/hasher/s3" -}}
|
||||||
|
HASHER_S3__ENDPOINT={{ index .Data.data "endpoint" }}
|
||||||
|
HASHER_S3__ACCESS_KEY={{ index .Data.data "access_key" }}
|
||||||
|
HASHER_S3__SECRET_KEY={{ index .Data.data "secret_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -8,5 +8,7 @@ resources:
|
|||||||
- filestream.yaml
|
- filestream.yaml
|
||||||
- frontend.yaml
|
- frontend.yaml
|
||||||
- pdm.yaml
|
- pdm.yaml
|
||||||
|
- pdf-markings-amqp.yaml
|
||||||
|
- hasher.yaml
|
||||||
- redis-deployment.yaml
|
- redis-deployment.yaml
|
||||||
- redis-service.yaml
|
- redis-service.yaml
|
||||||
|
|||||||
172
apps/documentations/base/pdf-markings-amqp.yaml
Normal file
172
apps/documentations/base/pdf-markings-amqp.yaml
Normal file
@ -0,0 +1,172 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: documentations-pdf-markings-amqp
|
||||||
|
namespace: documentations
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: documentations-vault
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
name:
|
||||||
|
_default: pdf-markings-amqp
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/documentations-marks-db ] && . /vault/secrets/documentations-marks-db
|
||||||
|
[ -f /vault/secrets/documentations-marks-rabbitmq ] && . /vault/secrets/documentations-marks-rabbitmq
|
||||||
|
[ -f /vault/secrets/documentations-marks-s3 ] && . /vault/secrets/documentations-marks-s3
|
||||||
|
set +a
|
||||||
|
exec ./server
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/pdf-markings-amqp:prod_3ab263be
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
name:
|
||||||
|
_default: marks-service
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
envs:
|
||||||
|
- name: MARKS_APP__LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: INFO
|
||||||
|
|
||||||
|
- name: MARKS_CRYPTO__HASHING_ALGO
|
||||||
|
value:
|
||||||
|
_default: md_gost12_256
|
||||||
|
|
||||||
|
- name: MARKS_QR__REDIRECT_URL
|
||||||
|
value:
|
||||||
|
_default: "https://stamp-verification.srx.wb.ru/"
|
||||||
|
|
||||||
|
- name: MARKS_QR__BASE_DOCUMENT_URL
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: MARKS_S3__REGION
|
||||||
|
value:
|
||||||
|
_default: ru-central1
|
||||||
|
|
||||||
|
- name: MARKS_S3__USE_SSL
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: MARKS_S3__SSL_VERIFY
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: MARKS_S3__DEFAULT_BUCKET
|
||||||
|
value:
|
||||||
|
_default: documentations-marks
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ__ROUTING__INPUT_QUEUE
|
||||||
|
value:
|
||||||
|
_default: pdf_markings_input
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ__HOST
|
||||||
|
value:
|
||||||
|
_default: rabbitmq.rabbitmq.svc.cluster.local
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ__PORT
|
||||||
|
value:
|
||||||
|
_default: "5672"
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ__HEARTBEAT_SECONDS
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "4317,4318,9411,8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: documentations
|
||||||
|
vault.hashicorp.com/agent-inject-secret-documentations-marks-db: secrets/data/apps/documentations/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-documentations-marks-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/documentations/postgres" -}}
|
||||||
|
MARKS_DOCUMENTS_DB__HOST={{ index .Data.data "host" }}
|
||||||
|
MARKS_DOCUMENTS_DB__PORT={{ index .Data.data "port" }}
|
||||||
|
MARKS_DOCUMENTS_DB__DATABASE={{ index .Data.data "database" }}
|
||||||
|
MARKS_DOCUMENTS_DB__USERNAME={{ index .Data.data "username" }}
|
||||||
|
MARKS_DOCUMENTS_DB__PASSWORD={{ index .Data.data "password" }}
|
||||||
|
MARKS_DOCUMENTS_DB__SSLMODE=disable
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-documentations-marks-rabbitmq: secrets/data/rabbitmq/apps/documentations
|
||||||
|
vault.hashicorp.com/agent-inject-template-documentations-marks-rabbitmq: |-
|
||||||
|
{{- with secret "secrets/data/rabbitmq/apps/documentations" -}}
|
||||||
|
MARKS_RABBITMQ__USERNAME={{ index .Data.data "username" }}
|
||||||
|
MARKS_RABBITMQ__PASSWORD={{ index .Data.data "password" }}
|
||||||
|
MARKS_RABBITMQ__VHOST={{ index .Data.data "vhost" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-documentations-marks-s3: secrets/data/apps/documentations/marks-s3
|
||||||
|
vault.hashicorp.com/agent-inject-template-documentations-marks-s3: |-
|
||||||
|
{{- with secret "secrets/data/apps/documentations/marks-s3" -}}
|
||||||
|
MARKS_S3__URL={{ index .Data.data "endpoint_url" }}
|
||||||
|
MARKS_S3__ACCESS_KEY={{ index .Data.data "access_key" }}
|
||||||
|
MARKS_S3__SECRET_KEY={{ index .Data.data "secret_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -129,10 +129,10 @@ spec:
|
|||||||
_default: http://attachments-service.attachments.svc.cluster.local:8000
|
_default: http://attachments-service.attachments.svc.cluster.local:8000
|
||||||
- name: BIM_API_V2_URL
|
- name: BIM_API_V2_URL
|
||||||
value:
|
value:
|
||||||
_default: http://backend-service.bim.svc.cluster.local:8000/
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
- name: BIM_V2_HOST
|
- name: BIM_V2_HOST
|
||||||
value:
|
value:
|
||||||
_default: http://backend-service.bim.svc.cluster.local:8000/
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
- name: CACHE_CLEANUP_INTERVAL
|
- name: CACHE_CLEANUP_INTERVAL
|
||||||
value:
|
value:
|
||||||
_default: 60s
|
_default: 60s
|
||||||
|
|||||||
149
apps/documentations/d8-ugmk-prod/api.yaml
Normal file
149
apps/documentations/d8-ugmk-prod/api.yaml
Normal file
@ -0,0 +1,149 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: documentations-api
|
||||||
|
namespace: documentations
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
envs:
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "20"
|
||||||
|
- name: ZITADEL_ACCOUNT
|
||||||
|
value:
|
||||||
|
_default: /vault/secrets/documentations-zitadel-account-json
|
||||||
|
- name: ZITADEL_DOMAIN
|
||||||
|
value:
|
||||||
|
_default: sarex-login.uralmine.com
|
||||||
|
- name: USE_ZITADEL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: FLOWS_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.flows.svc.cluster.local:80
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "36311"
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8080
|
||||||
|
- name: USE_LEGACY_BIM_FLOW
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: API_ADDRESS_FILE
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8080
|
||||||
|
- name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES
|
||||||
|
value:
|
||||||
|
_default: "5"
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: WORKSPACE_V2_EXTERNAL_URL
|
||||||
|
value:
|
||||||
|
_default: https://sarex.uralmine.com/workspaces-v2/
|
||||||
|
- name: ENABLE_S3
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: CONTAINER_REGISTRY
|
||||||
|
value:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q
|
||||||
|
- name: ENVIRONMENT
|
||||||
|
value:
|
||||||
|
_default: production
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "1000000"
|
||||||
|
- name: HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-api-svc.documentations.svc.cluster.local:80
|
||||||
|
- name: FILE_STREAM_HOST
|
||||||
|
value:
|
||||||
|
_default: sarex.uralmine.com
|
||||||
|
- name: DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: http://documentations-api.documentations.svc.cluster.local:80/
|
||||||
|
- name: WORKFLOW_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.processing.svc.cluster.local:80/
|
||||||
|
- name: WORKSPACE_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
||||||
|
- name: BIM_API_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
|
- name: BIM_API_V2_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
|
- name: WORKSPACE_BUNDLE_VERSION
|
||||||
|
value:
|
||||||
|
_default: v1
|
||||||
|
- name: SYSTEM_LOG_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.system-log.svc.cluster.local:80
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.django.svc.cluster.local:80
|
||||||
|
- name: MARKS_PROCESSING_URL
|
||||||
|
value:
|
||||||
|
_default: http://marks-service:8000
|
||||||
|
- name: PUBLIC_LINK_HOST
|
||||||
|
value:
|
||||||
|
_default: https://document-link-srx.wb.ru
|
||||||
|
- name: NAMESPACE
|
||||||
|
value:
|
||||||
|
_default: documentations
|
||||||
|
- name: DJANGO_ORIGINATOR
|
||||||
|
value:
|
||||||
|
_default: docs_prod
|
||||||
|
- name: WORKFLOW_IMAGES_VERSION
|
||||||
|
value:
|
||||||
|
_default: master
|
||||||
|
- name: WORKFLOWS_IMAGES_VERSION
|
||||||
|
value:
|
||||||
|
_default: master
|
||||||
|
- name: S3_SERVICE_ACCOUNT
|
||||||
|
value:
|
||||||
|
_default: /vault/secrets/documentations-s3-account-json
|
||||||
|
- name: READ_WRITE_TIMEOUT_FILE_STREAM
|
||||||
|
value:
|
||||||
|
_default: 6h
|
||||||
|
- name: CACHE_DEFAULT_EXPIRATION
|
||||||
|
value:
|
||||||
|
_default: 60s
|
||||||
|
- name: ENABLE_SMTP
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: ENABLE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
- name: CACHE_CLEANUP_INTERVAL
|
||||||
|
value:
|
||||||
|
_default: 60s
|
||||||
|
- name: DOCUMENT_PUBLIC_LINK_JWT_SECRET
|
||||||
|
value:
|
||||||
|
_default: "mock"
|
||||||
|
- name: ENABLE_AUTH_JWT_IN_URL
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: ENABLE_SIGNATURE_IN_URL
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
- name: USE_CACHE_IN_FILE_STREAMER
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: VALKEY_ADDR
|
||||||
|
value:
|
||||||
|
_default: redis:6379
|
||||||
|
- name: VALKEY_HOST
|
||||||
|
value:
|
||||||
|
_default: redis
|
||||||
|
- name: VALKEY_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
146
apps/documentations/d8-ugmk-prod/filestream.yaml
Normal file
146
apps/documentations/d8-ugmk-prod/filestream.yaml
Normal file
@ -0,0 +1,146 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: documentations-filestream
|
||||||
|
namespace: documentations
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
envs:
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "20"
|
||||||
|
- name: ZITADEL_ACCOUNT
|
||||||
|
value:
|
||||||
|
_default: /vault/secrets/documentations-zitadel-account-json
|
||||||
|
- name: ZITADEL_DOMAIN
|
||||||
|
value:
|
||||||
|
_default: sarex-login.uralmine.com
|
||||||
|
- name: USE_ZITADEL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: FLOWS_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.flows.svc.cluster.local:80
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "36311"
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8080
|
||||||
|
- name: API_ADDRESS_FILE
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8080
|
||||||
|
- name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES
|
||||||
|
value:
|
||||||
|
_default: "5"
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: WORKSPACE_V2_EXTERNAL_URL
|
||||||
|
value:
|
||||||
|
_default: https://sarex.uralmine.com/workspaces-v2/
|
||||||
|
- name: ENABLE_S3
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: CONTAINER_REGISTRY
|
||||||
|
value:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q
|
||||||
|
- name: ENVIRONMENT
|
||||||
|
value:
|
||||||
|
_default: production
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "1000000"
|
||||||
|
- name: HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-api-svc.documentations.svc.cluster.local:80
|
||||||
|
- name: FILE_STREAM_HOST
|
||||||
|
value:
|
||||||
|
_default: sarex.uralmine.com
|
||||||
|
- name: DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-api-svc.documentations.svc.cluster.local:80/
|
||||||
|
- name: WORKFLOW_URL
|
||||||
|
value:
|
||||||
|
_default: http://workflows-api-service.workflow.svc.cluster.local:8000/
|
||||||
|
- name: WORKSPACE_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
||||||
|
- name: BIM_API_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
|
- name: BIM_API_V2_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
||||||
|
- name: WORKSPACE_BUNDLE_VERSION
|
||||||
|
value:
|
||||||
|
_default: v1
|
||||||
|
- name: SYSTEM_LOG_URL
|
||||||
|
value:
|
||||||
|
_default: http://api-service.system-log.svc.cluster.local:80
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.django.svc.cluster.local:80
|
||||||
|
- name: MARKS_PROCESSING_URL
|
||||||
|
value:
|
||||||
|
_default: http://marks-service:8000
|
||||||
|
- name: PUBLIC_LINK_HOST
|
||||||
|
value:
|
||||||
|
_default: https://document-link-srx.wb.ru
|
||||||
|
- name: NAMESPACE
|
||||||
|
value:
|
||||||
|
_default: documentations
|
||||||
|
- name: DJANGO_ORIGINATOR
|
||||||
|
value:
|
||||||
|
_default: docs_prod
|
||||||
|
- name: WORKFLOW_IMAGES_VERSION
|
||||||
|
value:
|
||||||
|
_default: master
|
||||||
|
- name: WORKFLOWS_IMAGES_VERSION
|
||||||
|
value:
|
||||||
|
_default: master
|
||||||
|
- name: S3_SERVICE_ACCOUNT
|
||||||
|
value:
|
||||||
|
_default: /vault/secrets/documentations-s3-account-json
|
||||||
|
- name: READ_WRITE_TIMEOUT_FILE_STREAM
|
||||||
|
value:
|
||||||
|
_default: 6h
|
||||||
|
- name: CACHE_DEFAULT_EXPIRATION
|
||||||
|
value:
|
||||||
|
_default: 60s
|
||||||
|
- name: ENABLE_SMTP
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: ENABLE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
- name: CACHE_CLEANUP_INTERVAL
|
||||||
|
value:
|
||||||
|
_default: 60s
|
||||||
|
- name: ENABLE_AUTH_JWT_IN_URL
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
- name: ENABLE_SIGNATURE_IN_URL
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: DOCUMENT_PUBLIC_LINK_JWT_SECRET
|
||||||
|
value:
|
||||||
|
_default: "mock"
|
||||||
|
- name: USE_CACHE_IN_FILE_STREAMER
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: VALKEY_ADDR
|
||||||
|
value:
|
||||||
|
_default: redis:6379
|
||||||
|
- name: VALKEY_HOST
|
||||||
|
value:
|
||||||
|
_default: redis
|
||||||
|
- name: VALKEY_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
@ -3,4 +3,13 @@ apiVersion: kustomize.config.k8s.io/v1beta1
|
|||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
namespace: documentations
|
namespace: documentations
|
||||||
resources:
|
resources:
|
||||||
- ../base
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: api.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: documentations-api
|
||||||
|
- path: filestream.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: documentations-filestream
|
||||||
@ -119,11 +119,11 @@ spec:
|
|||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
vault.hashicorp.com/role: drawings
|
vault.hashicorp.com/role: drawings
|
||||||
vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/postgresql/apps/drawings
|
vault.hashicorp.com/agent-inject-secret-drawings-db: secrets/data/apps/drawings/postgres
|
||||||
vault.hashicorp.com/agent-inject-template-drawings-db: |-
|
vault.hashicorp.com/agent-inject-template-drawings-db: |-
|
||||||
{{- with secret "secrets/data/postgresql/apps/drawings" -}}
|
{{- with secret "secrets/data/apps/drawings/postgres" -}}
|
||||||
POSTGRES_ADDRESS=postgresql.drawings.svc.cluster.local:5432
|
POSTGRES_ADDRESS={{ index .Data.data "host" }}:{{ index .Data.data "port" }}
|
||||||
POSTGRES_DB=drawings_db
|
POSTGRES_DB={{ index .Data.data "database" }}
|
||||||
POSTGRES_USER={{ index .Data.data "username" }}
|
POSTGRES_USER={{ index .Data.data "username" }}
|
||||||
POSTGRES_PASSWORD={{ index .Data.data "password" }}
|
POSTGRES_PASSWORD={{ index .Data.data "password" }}
|
||||||
{{- end -}}
|
{{- end -}}
|
||||||
|
|||||||
@ -4,5 +4,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: drawings
|
name: drawings
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -104,9 +104,10 @@ data:
|
|||||||
],
|
],
|
||||||
"DEFAULT_AUTHENTICATION_CLASSES": [
|
"DEFAULT_AUTHENTICATION_CLASSES": [
|
||||||
"core.auth.ZitadelJWTAuthentication",
|
"core.auth.ZitadelJWTAuthentication",
|
||||||
"rest_framework_simplejwt.authentication.JWTAuthentication",
|
"rest_framework_simplejwt.authentication.JWTStatelessUserAuthentication",
|
||||||
"rest_framework.authentication.SessionAuthentication",
|
#"rest_framework_simplejwt.authentication.JWTAuthentication",
|
||||||
"rest_framework.authentication.BasicAuthentication",
|
#"rest_framework.authentication.SessionAuthentication",
|
||||||
|
#"rest_framework.authentication.BasicAuthentication",
|
||||||
],
|
],
|
||||||
"DEFAULT_PERMISSION_CLASSES": [
|
"DEFAULT_PERMISSION_CLASSES": [
|
||||||
"rest_framework.permissions.AllowAny",
|
"rest_framework.permissions.AllowAny",
|
||||||
@ -125,7 +126,7 @@ data:
|
|||||||
return default
|
return default
|
||||||
raise ImproperlyConfigured(error_msg)
|
raise ImproperlyConfigured(error_msg)
|
||||||
|
|
||||||
SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="django")
|
SIMPLE_JWT_ISSUER = get_env_variable("SIMPLE_JWT_ISSUER", default="default_issuer")
|
||||||
|
|
||||||
|
|
||||||
SIMPLE_JWT = {
|
SIMPLE_JWT = {
|
||||||
|
|||||||
@ -4,5 +4,5 @@ kind: Namespace
|
|||||||
metadata:
|
metadata:
|
||||||
name: faas
|
name: faas
|
||||||
labels:
|
labels:
|
||||||
istio-injection: disabled
|
istio-injection: enabled
|
||||||
security.deckhouse.io/pod-policy: privileged
|
security.deckhouse.io/pod-policy: privileged
|
||||||
|
|||||||
@ -1,137 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: backend
|
|
||||||
namespace: flows
|
|
||||||
labels:
|
|
||||||
app: backend
|
|
||||||
service: backend
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: backend
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: backend
|
|
||||||
service: backend
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: flows
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
|
|
||||||
{{- with secret "secrets/data/postgresql/apps/flows" -}}
|
|
||||||
PG_DB=flows_db
|
|
||||||
PG_LOGIN={{ index .Data.data "username" }}
|
|
||||||
PG_HOST=postgresql.flows.svc.cluster.local
|
|
||||||
PG_PORT=5432
|
|
||||||
PG_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
|
|
||||||
DOCUMENTATION_PG_PORT=5432
|
|
||||||
DOCUMENTATION_PG_DATABASE=flows_db
|
|
||||||
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
|
|
||||||
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
|
|
||||||
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
|
|
||||||
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
|
||||||
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
|
||||||
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
|
|
||||||
RABBITMQ_PORT=5672
|
|
||||||
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
|
||||||
DJANGO_TOKEN={{ index .Data.data "key" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
|
||||||
{{ index .Data.data "public_key" }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
|
||||||
serviceAccountName: flows-vault
|
|
||||||
containers:
|
|
||||||
- name: backend
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command: ["/bin/sh", "-ec"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
set -a
|
|
||||||
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
|
|
||||||
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
|
|
||||||
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
|
|
||||||
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
|
|
||||||
set +a
|
|
||||||
exec /opt/entrypoint.sh
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: LOG_LEVEL
|
|
||||||
value: DEBUG
|
|
||||||
- name: BASE_HOST
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: CELERY_QUEUE
|
|
||||||
value: flow
|
|
||||||
- name: EAV_HOST
|
|
||||||
value: http://backend-svc.eav.svc.cluster.local:80
|
|
||||||
- name: DJANGO_HOST
|
|
||||||
value: http://backend-svc.django.svc.cluster.local:80/api
|
|
||||||
- name: PLANNING_HOST
|
|
||||||
value: http://backend-svc.pm.svc.cluster.local:80/api/pm/msp
|
|
||||||
- name: PLANNING_USE
|
|
||||||
value: "True"
|
|
||||||
- name: DOCUMENTATION_HOST
|
|
||||||
value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1
|
|
||||||
- name: DOCUMENTATION_EXTERNAL_HOST
|
|
||||||
value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1
|
|
||||||
- name: ENABLE_ANALYTICS
|
|
||||||
value: "1"
|
|
||||||
- name: ENABLE_CELERY
|
|
||||||
value: "1"
|
|
||||||
- name: ENABLE_MAILGUN
|
|
||||||
value: "0"
|
|
||||||
- name: ENABLE_METRICS
|
|
||||||
value: "0"
|
|
||||||
- name: FROM_EMAIL
|
|
||||||
value: sarex@rwb.ru
|
|
||||||
- name: GATEWAY_URL
|
|
||||||
value: http://pdm-api.documentations.svc.cluster.local:8080
|
|
||||||
- name: RESOURCE_URL
|
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000
|
|
||||||
- name: SERVICE_HOST
|
|
||||||
value: https://srx.wb.ru/flows/api/v1
|
|
||||||
- name: SMTP_HOST
|
|
||||||
value: mail.rwb.ru
|
|
||||||
- name: CHECKLIST_HOST
|
|
||||||
value: http://checklists-backend-service.checklists.svc.cluster.local:80
|
|
||||||
- name: SMTP_PORT
|
|
||||||
value: "465"
|
|
||||||
- name: SYNC_RESOURCE_ID
|
|
||||||
value: "1"
|
|
||||||
- name: TIMEOUT
|
|
||||||
value: "120"
|
|
||||||
- name: WORKFLOWS_HOST
|
|
||||||
value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1
|
|
||||||
- name: WORKFLOWS_TIMEOUT
|
|
||||||
value: "60"
|
|
||||||
- name: DOCUMENTATION_TIMEOUT
|
|
||||||
value: "60"
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: "25m"
|
|
||||||
memory: 128Mi
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: backend-svc
|
|
||||||
namespace: flows
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: backend
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
262
apps/flows/base/backend.yaml
Normal file
262
apps/flows/base/backend.yaml
Normal file
@ -0,0 +1,262 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: flows
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: flows-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_2a439111
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
|
||||||
|
[ -f /vault/secrets/flows-documentations-db ] && . /vault/secrets/flows-documentations-db
|
||||||
|
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
|
||||||
|
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
|
||||||
|
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
|
||||||
|
set +a
|
||||||
|
exec /opt/entrypoint.sh
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: "DEBUG"
|
||||||
|
|
||||||
|
- name: BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: CELERY_QUEUE
|
||||||
|
value:
|
||||||
|
_default: "flow"
|
||||||
|
|
||||||
|
- name: EAV_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.eav.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.django.svc.cluster.local:80/api"
|
||||||
|
|
||||||
|
- name: PLANNING_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.pm.svc.cluster.local:80/api/pm/msp"
|
||||||
|
|
||||||
|
- name: PLANNING_USE
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_EXTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
|
||||||
|
|
||||||
|
- name: ENABLE_ANALYTICS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: ENABLE_CELERY
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: ENABLE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: ENABLE_METRICS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: FROM_EMAIL
|
||||||
|
value:
|
||||||
|
_default: "sarex@rwb.ru"
|
||||||
|
|
||||||
|
- name: GATEWAY_URL
|
||||||
|
value:
|
||||||
|
_default: "http://pdm-api.documentations.svc.cluster.local:8080"
|
||||||
|
|
||||||
|
- name: RESOURCE_URL
|
||||||
|
value:
|
||||||
|
_default: "http://resources-service.resources.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru/flows/api/v1"
|
||||||
|
|
||||||
|
- name: SMTP_HOST
|
||||||
|
value:
|
||||||
|
_default: "mail.rwb.ru"
|
||||||
|
|
||||||
|
- name: CHECKLIST_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "465"
|
||||||
|
|
||||||
|
- name: SYNC_RESOURCE_ID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: flows
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
|
||||||
|
{{- with secret "secrets/data/apps/flows/postgres" -}}
|
||||||
|
PG_DB={{ index .Data.data "database" }}
|
||||||
|
PG_LOGIN={{ index .Data.data "username" }}
|
||||||
|
PG_HOST={{ index .Data.data "host" }}
|
||||||
|
PG_PORT={{ index .Data.data "port" }}
|
||||||
|
PG_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-documentations-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/documentations/postgres" -}}
|
||||||
|
DOCUMENTATION_PG_HOST={{ index .Data.data "host" }}
|
||||||
|
DOCUMENTATION_PG_PORT={{ index .Data.data "port" }}
|
||||||
|
DOCUMENTATION_PG_DATABASE={{ index .Data.data "database" }}
|
||||||
|
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
|
||||||
|
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
|
||||||
|
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
|
||||||
|
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
||||||
|
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
||||||
|
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
|
||||||
|
RABBITMQ_PORT=5672
|
||||||
|
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
||||||
|
DJANGO_TOKEN={{ index .Data.data "key" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
||||||
|
{{ index .Data.data "public_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,137 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: celery
|
|
||||||
namespace: flows
|
|
||||||
labels:
|
|
||||||
app: celery
|
|
||||||
service: celery
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: celery
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: celery
|
|
||||||
service: celery
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: flows
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/postgresql/apps/flows
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
|
|
||||||
{{- with secret "secrets/data/postgresql/apps/flows" -}}
|
|
||||||
PG_DB=flows_db
|
|
||||||
PG_LOGIN={{ index .Data.data "username" }}
|
|
||||||
PG_HOST=postgresql.flows.svc.cluster.local
|
|
||||||
PG_PORT=5432
|
|
||||||
PG_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
DOCUMENTATION_PG_HOST=postgresql.flows.svc.cluster.local
|
|
||||||
DOCUMENTATION_PG_PORT=5432
|
|
||||||
DOCUMENTATION_PG_DATABASE=flows_db
|
|
||||||
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
|
|
||||||
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
|
|
||||||
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
|
|
||||||
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
|
||||||
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
|
||||||
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
|
|
||||||
RABBITMQ_PORT=5672
|
|
||||||
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
|
||||||
DJANGO_TOKEN={{ index .Data.data "key" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
|
|
||||||
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
|
||||||
{{ index .Data.data "public_key" }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
|
||||||
serviceAccountName: flows-vault
|
|
||||||
containers:
|
|
||||||
- name: celery
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command: ["/bin/sh", "-ec"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
set -a
|
|
||||||
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
|
|
||||||
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
|
|
||||||
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
|
|
||||||
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
|
|
||||||
set +a
|
|
||||||
exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: LOG_LEVEL
|
|
||||||
value: DEBUG
|
|
||||||
- name: BASE_HOST
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: CELERY_QUEUE
|
|
||||||
value: flow
|
|
||||||
- name: EAV_HOST
|
|
||||||
value: http://backend-svc.eav.svc.cluster.local:80
|
|
||||||
- name: DJANGO_HOST
|
|
||||||
value: http://backend-svc.django.svc.cluster.local:80/api
|
|
||||||
- name: PLANNING_HOST
|
|
||||||
value: http://backend-service.pm.svc.cluster.local:80/api/pm/msp
|
|
||||||
- name: PLANNING_USE
|
|
||||||
value: "True"
|
|
||||||
- name: DOCUMENTATION_HOST
|
|
||||||
value: http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1
|
|
||||||
- name: DOCUMENTATION_EXTERNAL_HOST
|
|
||||||
value: http://backend-api-svc.documentations.svc.cluster.local:80/api/v1
|
|
||||||
- name: ENABLE_ANALYTICS
|
|
||||||
value: "1"
|
|
||||||
- name: ENABLE_CELERY
|
|
||||||
value: "1"
|
|
||||||
- name: ENABLE_MAILGUN
|
|
||||||
value: "0"
|
|
||||||
- name: ENABLE_METRICS
|
|
||||||
value: "0"
|
|
||||||
- name: FROM_EMAIL
|
|
||||||
value: sarex@rwb.ru
|
|
||||||
- name: GATEWAY_URL
|
|
||||||
value: http://pdm-api.documentations.svc.cluster.local:8080
|
|
||||||
- name: RESOURCE_URL
|
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000
|
|
||||||
- name: SERVICE_HOST
|
|
||||||
value: https://srx.wb.ru/flows/api/v1
|
|
||||||
- name: SMTP_HOST
|
|
||||||
value: mail.rwb.ru
|
|
||||||
- name: CHECKLIST_HOST
|
|
||||||
value: http://checklists-backend-service.checklists.svc.cluster.local:80
|
|
||||||
- name: SMTP_PORT
|
|
||||||
value: "465"
|
|
||||||
- name: SYNC_RESOURCE_ID
|
|
||||||
value: "1"
|
|
||||||
- name: TIMEOUT
|
|
||||||
value: "120"
|
|
||||||
- name: WORKFLOWS_HOST
|
|
||||||
value: http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1
|
|
||||||
- name: WORKFLOWS_TIMEOUT
|
|
||||||
value: "60"
|
|
||||||
- name: DOCUMENTATION_TIMEOUT
|
|
||||||
value: "60"
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: "25m"
|
|
||||||
memory: 128Mi
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
248
apps/flows/base/celery.yaml
Normal file
248
apps/flows/base/celery.yaml
Normal file
@ -0,0 +1,248 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: celery
|
||||||
|
namespace: flows
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
celery:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: flows-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_2a439111
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: celery
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/flows-postgresql ] && . /vault/secrets/flows-postgresql
|
||||||
|
[ -f /vault/secrets/flows-documentations-db ] && . /vault/secrets/flows-documentations-db
|
||||||
|
[ -f /vault/secrets/flows-rabbitmq ] && . /vault/secrets/flows-rabbitmq
|
||||||
|
[ -f /vault/secrets/flows-django-auth ] && . /vault/secrets/flows-django-auth
|
||||||
|
[ -f /vault/secrets/flows-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/flows-jwt-public)"
|
||||||
|
set +a
|
||||||
|
exec celery -A src.worker worker -l INFO -E --concurrency=1 -Q flow
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: "DEBUG"
|
||||||
|
|
||||||
|
- name: BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: CELERY_QUEUE
|
||||||
|
value:
|
||||||
|
_default: "flow"
|
||||||
|
|
||||||
|
- name: EAV_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.eav.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.django.svc.cluster.local:80/api"
|
||||||
|
|
||||||
|
- name: PLANNING_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-service.pm.svc.cluster.local:80/api/pm/msp"
|
||||||
|
|
||||||
|
- name: PLANNING_USE
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/internal/v1"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_EXTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
|
||||||
|
|
||||||
|
- name: ENABLE_ANALYTICS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: ENABLE_CELERY
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: ENABLE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: ENABLE_METRICS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: FROM_EMAIL
|
||||||
|
value:
|
||||||
|
_default: "sarex@rwb.ru"
|
||||||
|
|
||||||
|
- name: GATEWAY_URL
|
||||||
|
value:
|
||||||
|
_default: "http://pdm-api.documentations.svc.cluster.local:8080"
|
||||||
|
|
||||||
|
- name: RESOURCE_URL
|
||||||
|
value:
|
||||||
|
_default: "http://resources-service.resources.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru/flows/api/v1"
|
||||||
|
|
||||||
|
- name: SMTP_HOST
|
||||||
|
value:
|
||||||
|
_default: "mail.rwb.ru"
|
||||||
|
|
||||||
|
- name: CHECKLIST_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "465"
|
||||||
|
|
||||||
|
- name: SYNC_RESOURCE_ID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000/api/v1"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: flows
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-postgresql: secrets/data/apps/flows/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-postgresql: |-
|
||||||
|
{{- with secret "secrets/data/apps/flows/postgres" -}}
|
||||||
|
PG_DB={{ index .Data.data "database" }}
|
||||||
|
PG_LOGIN={{ index .Data.data "username" }}
|
||||||
|
PG_HOST={{ index .Data.data "host" }}
|
||||||
|
PG_PORT={{ index .Data.data "port" }}
|
||||||
|
PG_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-documentations-db: secrets/data/apps/documentations/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-documentations-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/documentations/postgres" -}}
|
||||||
|
DOCUMENTATION_PG_HOST={{ index .Data.data "host" }}
|
||||||
|
DOCUMENTATION_PG_PORT={{ index .Data.data "port" }}
|
||||||
|
DOCUMENTATION_PG_DATABASE={{ index .Data.data "database" }}
|
||||||
|
DOCUMENTATION_PG_USERNAME={{ index .Data.data "username" }}
|
||||||
|
DOCUMENTATION_PG_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-rabbitmq: secrets/data/rabbitmq/apps/flows
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-rabbitmq: |-
|
||||||
|
{{- with secret "secrets/data/rabbitmq/apps/flows" -}}
|
||||||
|
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
||||||
|
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
||||||
|
RABBITMQ_HOST=rabbitmq.rabbitmq.svc.cluster.local
|
||||||
|
RABBITMQ_PORT=5672
|
||||||
|
ADMIN_PANEL_SECRET_KEY=rabbitmq.rabbitmq:5672
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-django-auth: secrets/data/vault/common/django_auth
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-django-auth: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
||||||
|
DJANGO_TOKEN={{ index .Data.data "key" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-flows-jwt-public: secrets/data/vault/common/rsa_keys
|
||||||
|
vault.hashicorp.com/agent-inject-template-flows-jwt-public: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
||||||
|
{{ index .Data.data "public_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,32 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: frontend
|
|
||||||
namespace: flows
|
|
||||||
labels:
|
|
||||||
app: frontend
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: frontend
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: frontend
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: frontend
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 80
|
|
||||||
protocol: TCP
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 25m
|
|
||||||
memory: 100Mi
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: frontend-svc
|
|
||||||
namespace: flows
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: frontend
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 80
|
|
||||||
protocol: TCP
|
|
||||||
90
apps/flows/base/frontend.yaml
Normal file
90
apps/flows/base/frontend.yaml
Normal file
@ -0,0 +1,90 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: flows
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_5b2bd144
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
@ -4,9 +4,6 @@ kind: Kustomization
|
|||||||
namespace: flows
|
namespace: flows
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- serviceaccount.yaml
|
- backend.yaml
|
||||||
- backend-deployment.yaml
|
- celery.yaml
|
||||||
- celery-deployment.yaml
|
- frontend.yaml
|
||||||
- frontend-deployment.yaml
|
|
||||||
- backend-service.yaml
|
|
||||||
- frontend-service.yaml
|
|
||||||
|
|||||||
@ -1,5 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: flows-vault
|
|
||||||
namespace: flows
|
|
||||||
10
apps/flows/d8-ugmk-prod/kustomization.yaml
Normal file
10
apps/flows/d8-ugmk-prod/kustomization.yaml
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: namespace.yaml
|
||||||
|
target:
|
||||||
|
kind: Namespace
|
||||||
|
name: flows
|
||||||
8
apps/flows/d8-ugmk-prod/namespace.yaml
Normal file
8
apps/flows/d8-ugmk-prod/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: flows
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -1,92 +1,182 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: backend
|
name: backend
|
||||||
namespace: flows
|
namespace: flows
|
||||||
spec:
|
spec:
|
||||||
replicas: 2
|
values:
|
||||||
template:
|
services:
|
||||||
spec:
|
backend:
|
||||||
containers:
|
image:
|
||||||
- name: backend
|
name:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend:production_a5d748f0
|
||||||
env:
|
|
||||||
- name: DEBUG
|
deployment:
|
||||||
value: 'false'
|
replicaCount:
|
||||||
- name: PLANNING_HOST
|
_default: 2
|
||||||
value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp
|
|
||||||
- name: PLANNING_USE
|
envs:
|
||||||
value: 'True'
|
- name: LOG_LEVEL
|
||||||
- name: PG_PORT
|
value:
|
||||||
value: '5432'
|
_default: "DEBUG"
|
||||||
- name: EAV_HOST
|
|
||||||
value: http://eav-service.eav.svc.cluster.local:8000
|
- name: BASE_HOST
|
||||||
- name: PROXY_PATH_PREFIX
|
value:
|
||||||
value: /flows
|
_default: "https://sarex.dsinv.ru"
|
||||||
- name: DJANGO_HOST
|
|
||||||
value: http://backend.django.svc.cluster.local:8000/api
|
- name: CELERY_QUEUE
|
||||||
- name: DOCUMENTATION_TIMEOUT
|
value:
|
||||||
value: '240'
|
_default: "flow"
|
||||||
- name: DOCUMENTATION_HOST
|
|
||||||
value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1
|
- name: EAV_HOST
|
||||||
- name: DOCUMENTATION_EXTERNAL_HOST
|
value:
|
||||||
value: http://documentations-service.documentations.svc.cluster.local:8080/api/v1
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
- name: BASE_HOST
|
|
||||||
value: https://sarex.dsinv.ru
|
- name: DJANGO_HOST
|
||||||
- name: DOCUMENTATION_PG_PORT
|
value:
|
||||||
value: '5432'
|
_default: "http://backend.django.svc.cluster.local:8000/api"
|
||||||
- name: DOCUMENTATION_PG_DATABASE
|
|
||||||
value: documentations
|
- name: PLANNING_HOST
|
||||||
- name: DOCUMENTATION_PG_HOST
|
value:
|
||||||
value: postgres-service.documentations.svc.cluster.local
|
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
|
||||||
- name: WORKFLOWS_HOST
|
|
||||||
value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1
|
- name: PLANNING_USE
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
|
value:
|
||||||
value: cr.yandex/crp3ccidau046kdj8g9q
|
_default: "True"
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
|
|
||||||
value: relay.dsinv.ru
|
- name: DOCUMENTATION_HOST
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
|
value:
|
||||||
value: '25'
|
_default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1"
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
|
|
||||||
value: sarex@dsinv.ru
|
- name: DOCUMENTATION_EXTERNAL_HOST
|
||||||
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
|
value:
|
||||||
value: '0'
|
_default: "http://documentations-service.documentations.svc.cluster.local:8080/api/v1"
|
||||||
- name: RESOURCES_HOST
|
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000
|
- name: ENABLE_ANALYTICS
|
||||||
- name: ENABLE_METRICS
|
value:
|
||||||
value: '0'
|
_default: "1"
|
||||||
- name: ENABLE_MAILGUN
|
|
||||||
value: '0'
|
- name: ENABLE_CELERY
|
||||||
- name: SMTP_HOST
|
value:
|
||||||
value: relay.dsinv.ru
|
_default: "1"
|
||||||
- name: SMTP_PORT
|
|
||||||
value: '25'
|
- name: ENABLE_MAILGUN
|
||||||
- name: FROM_EMAIL
|
value:
|
||||||
value: sarex@dsinv.ru
|
_default: "0"
|
||||||
- name: TIMEOUT
|
|
||||||
value: '240'
|
- name: ENABLE_METRICS
|
||||||
- name: WORKFLOWS_TIMEOUT
|
value:
|
||||||
value: '20'
|
_default: "0"
|
||||||
- name: RESOURCE_URL
|
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000/
|
- name: FROM_EMAIL
|
||||||
- name: GATEWAY_URL
|
value:
|
||||||
value: http://pdm-api.documentations.svc.cluster.local:8080/
|
_default: "sarex@dsinv.ru"
|
||||||
- name: SYNC_RESOURCE_ID
|
|
||||||
value: '1'
|
- name: GATEWAY_URL
|
||||||
- name: SERVICE_HOST
|
value:
|
||||||
value: https://sarex.dsinv.ru/flows/api/v1
|
_default: "http://pdm-api.documentations.svc.cluster.local:8080/"
|
||||||
- name: ENABLE_ANALYTICS
|
|
||||||
value: '1'
|
- name: RESOURCE_URL
|
||||||
- name: ENABLE_CELERY
|
value:
|
||||||
value: '1'
|
_default: "http://resources-service.resources.svc.cluster.local:8000/"
|
||||||
- name: CELERY_QUEUE
|
|
||||||
value: flow
|
- name: SERVICE_HOST
|
||||||
- name: RABBITMQ_HOST
|
value:
|
||||||
value: rabbitmq-service.flows.svc
|
_default: "https://sarex.dsinv.ru/flows/api/v1"
|
||||||
- name: RABBITMQ_PORT
|
|
||||||
value: '5672'
|
- name: SMTP_HOST
|
||||||
- name: RABBITMQ_VHOST
|
value:
|
||||||
value: flow
|
_default: "relay.dsinv.ru"
|
||||||
- name: PG_HOST
|
|
||||||
value: postgres-service.flows.svc.cluster.local
|
- name: CHECKLIST_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "25"
|
||||||
|
|
||||||
|
- name: SYNC_RESOURCE_ID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "240"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "20"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "240"
|
||||||
|
|
||||||
|
- name: DEBUG
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
- name: PG_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: PROXY_PATH_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/flows"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_PG_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_PG_DATABASE
|
||||||
|
value:
|
||||||
|
_default: "documentations"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_PG_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.documentations.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
|
||||||
|
value:
|
||||||
|
_default: "cr.yandex/crp3ccidau046kdj8g9q"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
|
||||||
|
value:
|
||||||
|
_default: "relay.dsinv.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "25"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
|
||||||
|
value:
|
||||||
|
_default: "sarex@dsinv.ru"
|
||||||
|
|
||||||
|
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: RESOURCES_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://resources-service.resources.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: RABBITMQ_HOST
|
||||||
|
value:
|
||||||
|
_default: "rabbitmq-service.flows.svc"
|
||||||
|
|
||||||
|
- name: RABBITMQ_PORT
|
||||||
|
value:
|
||||||
|
_default: "5672"
|
||||||
|
|
||||||
|
- name: RABBITMQ_VHOST
|
||||||
|
value:
|
||||||
|
_default: "flow"
|
||||||
|
|
||||||
|
- name: PG_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.flows.svc.cluster.local"
|
||||||
|
|||||||
@ -1,93 +1,198 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: celery
|
name: celery
|
||||||
namespace: flows
|
namespace: flows
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
celery:
|
||||||
- name: celery
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0
|
name:
|
||||||
env:
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-backend_worker:production_a5d748f0
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL
|
|
||||||
value: sarex@dsinv.ru
|
envs:
|
||||||
- name: ENABLE_METRICS
|
- name: LOG_LEVEL
|
||||||
value: '0'
|
value:
|
||||||
- name: ENABLE_MAILGUN
|
_default: "DEBUG"
|
||||||
value: '0'
|
|
||||||
- name: SMTP_HOST
|
- name: BASE_HOST
|
||||||
value: relay.dsinv.ru
|
value:
|
||||||
- name: SMTP_PORT
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: '25'
|
|
||||||
- name: FROM_EMAIL
|
- name: CELERY_QUEUE
|
||||||
value: sarex@dsinv.ru
|
value:
|
||||||
- name: MAILGUN_HOST
|
_default: "flow"
|
||||||
value: http:localhost:8000
|
|
||||||
- name: MAILGUN_API_KEY
|
- name: EAV_HOST
|
||||||
value: empty
|
value:
|
||||||
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
|
_default: "http://backend-svc.eav.svc.cluster.local:80"
|
||||||
value: '0'
|
|
||||||
- name: WORKFLOWS_HOST
|
- name: DJANGO_HOST
|
||||||
value: http://workflows-service.workflow.svc.cluster.local:8000/api/v1
|
value:
|
||||||
- name: FLOWS_HOST
|
_default: "http://backend.django.svc.cluster.local:8000/api"
|
||||||
value: http://backend-service.flows.svc.cluster.local:8000
|
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
|
- name: PLANNING_HOST
|
||||||
value: cr.yandex/crp3ccidau046kdj8g9q
|
value:
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
|
_default: "http://backend-service.pm.svc.cluster.local:8000/api/pm/msp"
|
||||||
value: relay.dsinv.ru
|
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
|
- name: PLANNING_USE
|
||||||
value: '25'
|
value:
|
||||||
- name: PLANNING_HOST
|
_default: "True"
|
||||||
value: http://backend-service.pm.svc.cluster.local:8000/api/pm/msp
|
|
||||||
- name: PLANNING_USE
|
- name: DOCUMENTATION_HOST
|
||||||
value: 'True'
|
value:
|
||||||
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
|
_default: "http://documentations-service.documentations.svc.cluster.local:8080/internal/v1"
|
||||||
value: sarex@dsinv.ru
|
|
||||||
- name: FLOWS_DB_HOST
|
- name: DOCUMENTATION_EXTERNAL_HOST
|
||||||
value: postgres-service.flows.svc.cluster.local
|
value:
|
||||||
- name: ISSUES_DB_HOST
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80/api/v1"
|
||||||
value: postgres-service.issues.svc.cluster.local
|
|
||||||
- name: DEBUG
|
- name: ENABLE_ANALYTICS
|
||||||
value: '0'
|
value:
|
||||||
- name: PG_PORT
|
_default: "1"
|
||||||
value: '5432'
|
|
||||||
- name: FLOWS_DB_PORT
|
- name: ENABLE_CELERY
|
||||||
value: '5432'
|
value:
|
||||||
- name: ISSUES_DB_PORT
|
_default: "1"
|
||||||
value: '5432'
|
|
||||||
- name: DJANGO_HOST
|
- name: ENABLE_MAILGUN
|
||||||
value: http://backend.django.svc.cluster.local:8000/api
|
value:
|
||||||
- name: DJANGO_BASE_HOST
|
_default: "0"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: DOCUMENTATION_HOST
|
- name: ENABLE_METRICS
|
||||||
value: http://documentations-service.documentations.svc.cluster.local:8080/internal/v1
|
value:
|
||||||
- name: BASE_HOST
|
_default: "0"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: RESOURCES_HOST
|
- name: FROM_EMAIL
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000/
|
value:
|
||||||
- name: TIMEOUT
|
_default: "sarex@dsinv.ru"
|
||||||
value: '120'
|
|
||||||
- name: RESOURCE_URL
|
- name: GATEWAY_URL
|
||||||
value: http://resources-service.resources/api/v1
|
value:
|
||||||
- name: GATEWAY_URL
|
_default: "http://pdm-api.documentations.svc.cluster.local:8080/api/v1"
|
||||||
value: http://pdm-api.documentations.svc.cluster.local:8080/api/v1
|
|
||||||
- name: SYNC_RESOURCE_ID
|
- name: RESOURCE_URL
|
||||||
value: '1'
|
value:
|
||||||
- name: SERVICE_HOST
|
_default: "http://resources-service.resources/api/v1"
|
||||||
value: https://sarex.dsinv.ru/flows/api/v1
|
|
||||||
- name: ENABLE_ANALYTICS
|
- name: SERVICE_HOST
|
||||||
value: '1'
|
value:
|
||||||
- name: ENABLE_CELERY
|
_default: "https://sarex.dsinv.ru/flows/api/v1"
|
||||||
value: '1'
|
|
||||||
- name: CELERY_QUEUE
|
- name: SMTP_HOST
|
||||||
value: flow
|
value:
|
||||||
- name: RABBITMQ_HOST
|
_default: "relay.dsinv.ru"
|
||||||
value: rabbitmq-service.flows.svc
|
|
||||||
- name: RABBITMQ_PORT
|
- name: CHECKLIST_HOST
|
||||||
value: '5672'
|
value:
|
||||||
- name: RABBITMQ_VHOST
|
_default: "http://checklists-backend-service.checklists.svc.cluster.local:80"
|
||||||
value: flow
|
|
||||||
- name: PG_HOST
|
- name: SMTP_PORT
|
||||||
value: postgres-service.flows.svc.cluster.local
|
value:
|
||||||
|
_default: "25"
|
||||||
|
|
||||||
|
- name: SYNC_RESOURCE_ID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-service.workflow.svc.cluster.local:8000/api/v1"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAIL
|
||||||
|
value:
|
||||||
|
_default: "sarex@dsinv.ru"
|
||||||
|
|
||||||
|
- name: MAILGUN_HOST
|
||||||
|
value:
|
||||||
|
_default: "http:localhost:8000"
|
||||||
|
|
||||||
|
- name: MAILGUN_API_KEY
|
||||||
|
value:
|
||||||
|
_default: "empty"
|
||||||
|
|
||||||
|
- name: NOTIFICATION_SETTINGS_USE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: FLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-service.flows.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_REGISTRY
|
||||||
|
value:
|
||||||
|
_default: "cr.yandex/crp3ccidau046kdj8g9q"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_SMTP_HOST
|
||||||
|
value:
|
||||||
|
_default: "relay.dsinv.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "25"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_NOTIFICATIONS_FROM_EMAI
|
||||||
|
value:
|
||||||
|
_default: "sarex@dsinv.ru"
|
||||||
|
|
||||||
|
- name: FLOWS_DB_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.flows.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: ISSUES_DB_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.issues.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: PG_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: FLOWS_DB_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: ISSUES_DB_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: DJANGO_BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.dsinv.ru"
|
||||||
|
|
||||||
|
- name: RESOURCES_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://resources-service.resources.svc.cluster.local:8000/"
|
||||||
|
|
||||||
|
- name: RABBITMQ_HOST
|
||||||
|
value:
|
||||||
|
_default: "rabbitmq-service.flows.svc"
|
||||||
|
|
||||||
|
- name: RABBITMQ_PORT
|
||||||
|
value:
|
||||||
|
_default: "5672"
|
||||||
|
|
||||||
|
- name: RABBITMQ_VHOST
|
||||||
|
value:
|
||||||
|
_default: "flow"
|
||||||
|
|
||||||
|
- name: PG_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.flows.svc.cluster.local"
|
||||||
|
|||||||
@ -1,12 +1,13 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: frontend
|
name: frontend
|
||||||
namespace: flows
|
namespace: flows
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
frontend:
|
||||||
- name: frontend
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/flows-frontend:contour_bad7aeb2
|
||||||
|
|||||||
@ -10,13 +10,13 @@ resources:
|
|||||||
patches:
|
patches:
|
||||||
- path: backend.yaml
|
- path: backend.yaml
|
||||||
target:
|
target:
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
name: backend
|
name: backend
|
||||||
- path: celery.yaml
|
- path: celery.yaml
|
||||||
target:
|
target:
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
name: celery
|
name: celery
|
||||||
- path: frontend.yaml
|
- path: frontend.yaml
|
||||||
target:
|
target:
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
name: frontend
|
name: frontend
|
||||||
|
|||||||
@ -1,120 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: inspections-backend
|
|
||||||
namespace: inspections
|
|
||||||
labels:
|
|
||||||
app: inspections-backend
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: inspections-backend
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: inspections-backend
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: inspections
|
|
||||||
vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/postgresql/apps/inspections
|
|
||||||
vault.hashicorp.com/agent-inject-template-inspections-db: |-
|
|
||||||
{{- with secret "secrets/data/postgresql/apps/inspections" -}}
|
|
||||||
DATABASE_HOST=postgresql.inspections.svc.cluster.local
|
|
||||||
DATABASE_PORT=5432
|
|
||||||
DATABASE_NAME=inspections_db
|
|
||||||
DATABASE_USER={{ index .Data.data "username" }}
|
|
||||||
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections
|
|
||||||
vault.hashicorp.com/agent-inject-template-inspections-kafka: |-
|
|
||||||
{{- with secret "secrets/data/kafka/apps/inspections" -}}
|
|
||||||
KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }}
|
|
||||||
KAFKA_USERNAME={{ index .Data.data "username" }}
|
|
||||||
KAFKA_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth
|
|
||||||
vault.hashicorp.com/agent-inject-template-inspections-django-auth: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
|
||||||
SAREX_BACKEND_AUTH={{ index .Data.data "key" }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
|
||||||
serviceAccountName: inspections-vault
|
|
||||||
containers:
|
|
||||||
- name: inspections-backend
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command: ["/bin/bash", "-ec"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
set -a
|
|
||||||
[ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db
|
|
||||||
[ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka
|
|
||||||
[ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth
|
|
||||||
set +a
|
|
||||||
exec ./entrypoint.sh
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: DEBUG
|
|
||||||
value: "false"
|
|
||||||
- name: SERVICE_URL
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: HTTP_APP_HOST
|
|
||||||
value: 0.0.0.0
|
|
||||||
- name: HTTP_APP_PORT
|
|
||||||
value: "8000"
|
|
||||||
- name: HTTP_APP_ROOT_PATH
|
|
||||||
value: /inspections
|
|
||||||
- name: HTTP_APP_WORKERS
|
|
||||||
value: "3"
|
|
||||||
- name: HTTP_APP_ADMIN_ENABLE
|
|
||||||
value: "true"
|
|
||||||
- name: KAFKA_SSL_CAFILE
|
|
||||||
value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt
|
|
||||||
- name: KAFKA_EAV_ASSETS_TOPIC
|
|
||||||
value: assets_broadcast
|
|
||||||
- name: JWT_AUTH_ENABLE
|
|
||||||
value: "true"
|
|
||||||
- name: NOTIFICATIONS_ENABLE
|
|
||||||
value: "true"
|
|
||||||
- name: NOTIFICATIONS_EMAIL_FROM
|
|
||||||
value: hello@sarex.io
|
|
||||||
- name: SAREX_BACKEND_URL
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: SAREX_BACKEND_TIMEOUT
|
|
||||||
value: "30"
|
|
||||||
- name: EAV_URL
|
|
||||||
value: http://eav-service.eav
|
|
||||||
- name: EAV_TIMEOUT
|
|
||||||
value: "30"
|
|
||||||
- name: WORKFLOWS_URL
|
|
||||||
value: http://workflows-service.processing-prod
|
|
||||||
- name: WORKFLOWS_TIMEOUT
|
|
||||||
value: "30"
|
|
||||||
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
|
|
||||||
value: cr.yandex/crp3ccidau046kdj8g9q/notification:email
|
|
||||||
- name: MOBILE_APP_CURRENT_VERSION
|
|
||||||
value: 1.0.0
|
|
||||||
- name: MOBILE_APP_RECOMMENDED_VERSION
|
|
||||||
value: 1.0.0
|
|
||||||
- name: MOBILE_APP_REQUIRED_VERSION
|
|
||||||
value: 1.0.0
|
|
||||||
- name: MAILER_URL
|
|
||||||
value: http://mailer-service.mailer:8000
|
|
||||||
- name: MAILER_TIMEOUT
|
|
||||||
value: "30"
|
|
||||||
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: "25m"
|
|
||||||
memory: 128Mi
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: rfi-backend-api-svc
|
|
||||||
namespace: rfi
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: rfi-backend-api
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
240
apps/inspections/base/backend.yaml
Normal file
240
apps/inspections/base/backend.yaml
Normal file
@ -0,0 +1,240 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: inspections
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: inspections-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_1a33f6f4
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: inspections-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/bash", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/inspections-db ] && . /vault/secrets/inspections-db
|
||||||
|
[ -f /vault/secrets/inspections-kafka ] && . /vault/secrets/inspections-kafka
|
||||||
|
[ -f /vault/secrets/inspections-django-auth ] && . /vault/secrets/inspections-django-auth
|
||||||
|
set +a
|
||||||
|
exec ./entrypoint.sh
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: DEBUG
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
- name: SERVICE_URL
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: HTTP_APP_HOST
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0"
|
||||||
|
|
||||||
|
- name: HTTP_APP_PORT
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
- name: HTTP_APP_ROOT_PATH
|
||||||
|
value:
|
||||||
|
_default: "/inspections"
|
||||||
|
|
||||||
|
- name: HTTP_APP_WORKERS
|
||||||
|
value:
|
||||||
|
_default: "3"
|
||||||
|
|
||||||
|
- name: HTTP_APP_ADMIN_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: KAFKA_SSL_CAFILE
|
||||||
|
value:
|
||||||
|
_default: "/usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt"
|
||||||
|
|
||||||
|
- name: KAFKA_EAV_ASSETS_TOPIC
|
||||||
|
value:
|
||||||
|
_default: "assets_broadcast"
|
||||||
|
|
||||||
|
- name: JWT_AUTH_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: NOTIFICATIONS_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: NOTIFICATIONS_EMAIL_FROM
|
||||||
|
value:
|
||||||
|
_default: "hello@sarex.io"
|
||||||
|
|
||||||
|
- name: SAREX_BACKEND_URL
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: SAREX_BACKEND_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: EAV_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.eav.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: EAV_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.processing.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
|
||||||
|
value:
|
||||||
|
_default: "cr.yandex/crp3ccidau046kdj8g9q/notification:email"
|
||||||
|
|
||||||
|
- name: MOBILE_APP_CURRENT_VERSION
|
||||||
|
value:
|
||||||
|
_default: "1.0.0"
|
||||||
|
|
||||||
|
- name: MOBILE_APP_RECOMMENDED_VERSION
|
||||||
|
value:
|
||||||
|
_default: "1.0.0"
|
||||||
|
|
||||||
|
- name: MOBILE_APP_REQUIRED_VERSION
|
||||||
|
value:
|
||||||
|
_default: "1.0.0"
|
||||||
|
|
||||||
|
- name: MAILER_URL
|
||||||
|
value:
|
||||||
|
_default: "http://mailer-service.mailer:8000"
|
||||||
|
|
||||||
|
- name: MAILER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: inspections
|
||||||
|
vault.hashicorp.com/agent-inject-secret-inspections-db: secrets/data/apps/inspections/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-inspections-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/inspections/postgres" -}}
|
||||||
|
DATABASE_HOST={{ index .Data.data "host" }}
|
||||||
|
DATABASE_PORT={{ index .Data.data "port" }}
|
||||||
|
DATABASE_NAME={{ index .Data.data "database" }}
|
||||||
|
DATABASE_USER={{ index .Data.data "username" }}
|
||||||
|
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-inspections-kafka: secrets/data/kafka/apps/inspections
|
||||||
|
vault.hashicorp.com/agent-inject-template-inspections-kafka: |-
|
||||||
|
{{- with secret "secrets/data/kafka/apps/inspections" -}}
|
||||||
|
KAFKA_HOST={{ index .Data.data.auth "bootstrap_servers" }}
|
||||||
|
KAFKA_USERNAME={{ index .Data.data "username" }}
|
||||||
|
KAFKA_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-inspections-django-auth: secrets/data/vault/common/django_auth
|
||||||
|
vault.hashicorp.com/agent-inject-template-inspections-django-auth: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
||||||
|
SAREX_BACKEND_AUTH={{ index .Data.data "key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -4,6 +4,4 @@ kind: Kustomization
|
|||||||
namespace: inspections
|
namespace: inspections
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- serviceaccount.yaml
|
- backend.yaml
|
||||||
- backend-deployment.yaml
|
|
||||||
- backend-service.yaml
|
|
||||||
|
|||||||
@ -1,5 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: inspections-vault
|
|
||||||
namespace: inspections
|
|
||||||
10
apps/inspections/d8-ugmk-prod/kustomization.yaml
Normal file
10
apps/inspections/d8-ugmk-prod/kustomization.yaml
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: namespace.yaml
|
||||||
|
target:
|
||||||
|
kind: Namespace
|
||||||
|
name: inspections
|
||||||
8
apps/inspections/d8-ugmk-prod/namespace.yaml
Normal file
8
apps/inspections/d8-ugmk-prod/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: inspections
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -1,61 +1,13 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: inspections-backend
|
name: backend
|
||||||
namespace: inspections
|
namespace: inspections
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
backend:
|
||||||
- name: inspections-backend
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d
|
name:
|
||||||
env:
|
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-inspections:production_5fcce90d
|
||||||
- name: DEBUG
|
|
||||||
value: 'false'
|
|
||||||
- name: SERVICE_URL
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: HTTP_APP_HOST
|
|
||||||
value: 0.0.0.0
|
|
||||||
- name: HTTP_APP_PORT
|
|
||||||
value: '8000'
|
|
||||||
- name: HTTP_APP_ROOT_PATH
|
|
||||||
value: /inspections
|
|
||||||
- name: HTTP_APP_WORKERS
|
|
||||||
value: '3'
|
|
||||||
- name: HTTP_APP_ADMIN_ENABLE
|
|
||||||
value: 'true'
|
|
||||||
- name: KAFKA_SSL_CAFILE
|
|
||||||
value: /usr/local/share/ca-certificates/Yandex/YandexInternalRootCA.crt
|
|
||||||
- name: KAFKA_EAV_ASSETS_TOPIC
|
|
||||||
value: assets_broadcast
|
|
||||||
- name: JWT_AUTH_ENABLE
|
|
||||||
value: 'true'
|
|
||||||
- name: NOTIFICATIONS_ENABLE
|
|
||||||
value: 'true'
|
|
||||||
- name: NOTIFICATIONS_EMAIL_FROM
|
|
||||||
value: hello@sarex.io
|
|
||||||
- name: SAREX_BACKEND_URL
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: SAREX_BACKEND_TIMEOUT
|
|
||||||
value: '30'
|
|
||||||
- name: EAV_URL
|
|
||||||
value: http://eav-service.eav
|
|
||||||
- name: EAV_TIMEOUT
|
|
||||||
value: '30'
|
|
||||||
- name: WORKFLOWS_URL
|
|
||||||
value: http://workflows-service.processing-prod
|
|
||||||
- name: WORKFLOWS_TIMEOUT
|
|
||||||
value: '30'
|
|
||||||
- name: WORKFLOWS_EMAIL_DOCKER_IMAGE
|
|
||||||
value: cr.yandex/crp3ccidau046kdj8g9q/notification:email
|
|
||||||
- name: MOBILE_APP_CURRENT_VERSION
|
|
||||||
value: 1.0.0
|
|
||||||
- name: MOBILE_APP_RECOMMENDED_VERSION
|
|
||||||
value: 1.0.0
|
|
||||||
- name: MOBILE_APP_REQUIRED_VERSION
|
|
||||||
value: 1.0.0
|
|
||||||
- name: MAILER_URL
|
|
||||||
value: http://mailer-service.mailer:8000
|
|
||||||
- name: MAILER_TIMEOUT
|
|
||||||
value: '30'
|
|
||||||
|
|||||||
@ -9,5 +9,5 @@ resources:
|
|||||||
patches:
|
patches:
|
||||||
- path: inspections-backend.yaml
|
- path: inspections-backend.yaml
|
||||||
target:
|
target:
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
name: inspections-backend
|
name: backend
|
||||||
|
|||||||
@ -1,135 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: backend
|
|
||||||
namespace: issues
|
|
||||||
labels:
|
|
||||||
app: backend
|
|
||||||
service: backend
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: backend
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: backend
|
|
||||||
service: backend
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: issues
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-db: |-
|
|
||||||
{{- with secret "secrets/data/postgresql/apps/issues" -}}
|
|
||||||
DATABASE_PORT=5432
|
|
||||||
DATABASE_HOST=postgresql.issues.svc.cluster.local
|
|
||||||
DATABASE_USER={{ index .Data.data "username" }}
|
|
||||||
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
DATABASE_NAME=issues_db
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
|
|
||||||
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
|
|
||||||
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
|
||||||
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
|
||||||
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
|
|
||||||
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-s3: |-
|
|
||||||
{{- with secret "secrets/data/minio/apps/issues" -}}
|
|
||||||
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
|
|
||||||
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
|
|
||||||
YC_S3_BUCKET_NAME=rfi
|
|
||||||
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
|
||||||
DJANGO_TOKEN={{ index .Data.data "key" }}
|
|
||||||
SAREX_USERNAME={{ index .Data.data "username" }}
|
|
||||||
SAREX_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
|
||||||
{{ index .Data.data "private_key" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
|
||||||
{{ index .Data.data "public_key" }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
|
||||||
serviceAccountName: issues-vault
|
|
||||||
volumes:
|
|
||||||
- name: production-configmap
|
|
||||||
configMap:
|
|
||||||
name: production-configmap
|
|
||||||
items:
|
|
||||||
- key: production.py
|
|
||||||
path: production.py
|
|
||||||
defaultMode: 420
|
|
||||||
containers:
|
|
||||||
- name: backend
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command: ["/bin/sh", "-ec"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
set -a
|
|
||||||
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
|
|
||||||
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
|
|
||||||
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
|
|
||||||
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
|
|
||||||
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
|
|
||||||
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
|
|
||||||
set +a
|
|
||||||
exec /src/entrypoint.sh
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: ENVIRONMENT
|
|
||||||
value: production
|
|
||||||
- name: AERO_PUBLIC_HOST
|
|
||||||
value: https://sarex.contour.infra.sarex.tech
|
|
||||||
- name: AERO_HOST
|
|
||||||
value: https://sarex.contour.infra.sarex.tech
|
|
||||||
- name: BASE_AERO_URL
|
|
||||||
value: https://sarex.contour.infra.sarex.tech
|
|
||||||
- name: BASE_AUTH_URL
|
|
||||||
value: http://backend-svc.django.svc.cluster.local:80
|
|
||||||
- name: WORKFLOWS_HOST
|
|
||||||
value: http://backend-svc.workflow.svc.cluster.local:80
|
|
||||||
- name: WORKFLOWS_URL
|
|
||||||
value: http://backend-svc.workflow.svc.cluster.local:80
|
|
||||||
- name: RESOURCES_API_HOST
|
|
||||||
value: http://backend-svc.resources.svc.cluster.local:80
|
|
||||||
- name: EAV_HOST
|
|
||||||
value: http://backend-svc.eav.svc.cluster.local:80
|
|
||||||
- name: SAREX_API
|
|
||||||
value: https://sarex.contour.infra.sarex.tech
|
|
||||||
- name: DOCUMENTATIONS_URL
|
|
||||||
value: http://documentations-api-svc.documentations.svc.cluster.local:80
|
|
||||||
- name: DJANGO_SETTINGS_MODULE
|
|
||||||
value: config.settings.production
|
|
||||||
- name: API_ADDRESS
|
|
||||||
value: "8000"
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: "25m"
|
|
||||||
memory: 128Mi
|
|
||||||
volumeMounts:
|
|
||||||
- name: production-configmap
|
|
||||||
mountPath: /src/config/settings/production.py
|
|
||||||
subPath: production.py
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: backend-svc
|
|
||||||
namespace: issues
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: backend
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
237
apps/issues/base/backend.yaml
Normal file
237
apps/issues/base/backend.yaml
Normal file
@ -0,0 +1,237 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: issues
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: issues-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
|
||||||
|
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
|
||||||
|
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
|
||||||
|
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
|
||||||
|
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
|
||||||
|
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
|
||||||
|
set +a
|
||||||
|
exec /src/entrypoint.sh
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: production-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /src/config/settings/production.py
|
||||||
|
subPath:
|
||||||
|
_default: production.py
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: production-configmap
|
||||||
|
items:
|
||||||
|
- key: production.py
|
||||||
|
path:
|
||||||
|
_default: production.py
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: ENVIRONMENT
|
||||||
|
value:
|
||||||
|
_default: "production"
|
||||||
|
|
||||||
|
- name: AERO_PUBLIC_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.contour.infra.sarex.tech"
|
||||||
|
|
||||||
|
- name: AERO_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.contour.infra.sarex.tech"
|
||||||
|
|
||||||
|
- name: BASE_AERO_URL
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.contour.infra.sarex.tech"
|
||||||
|
|
||||||
|
- name: BASE_AUTH_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.django.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.workflow.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.workflow.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: RESOURCES_API_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://iam-backend.iam.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: EAV_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.eav.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: SAREX_API
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.contour.infra.sarex.tech"
|
||||||
|
|
||||||
|
- name: DOCUMENTATIONS_URL
|
||||||
|
value:
|
||||||
|
_default: "http://documentations-api-svc.documentations.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: "config.settings.production"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: issues
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/issues/postgres" -}}
|
||||||
|
DATABASE_PORT={{ index .Data.data "port" }}
|
||||||
|
DATABASE_HOST={{ index .Data.data "host" }}
|
||||||
|
DATABASE_USER={{ index .Data.data "username" }}
|
||||||
|
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
DATABASE_NAME={{ index .Data.data "database" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
|
||||||
|
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
|
||||||
|
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
||||||
|
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
||||||
|
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
|
||||||
|
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-s3: |-
|
||||||
|
{{- with secret "secrets/data/minio/apps/issues" -}}
|
||||||
|
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
|
||||||
|
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
|
||||||
|
YC_S3_BUCKET_NAME=rfi
|
||||||
|
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
||||||
|
DJANGO_TOKEN={{ index .Data.data "key" }}
|
||||||
|
SAREX_USERNAME={{ index .Data.data "username" }}
|
||||||
|
SAREX_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
||||||
|
{{ index .Data.data "private_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
||||||
|
{{ index .Data.data "public_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,135 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: celery
|
|
||||||
namespace: issues
|
|
||||||
labels:
|
|
||||||
app: celery
|
|
||||||
service: celery
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: celery
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: celery
|
|
||||||
service: celery
|
|
||||||
annotations:
|
|
||||||
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
|
||||||
vault.hashicorp.com/agent-init-first: "true"
|
|
||||||
vault.hashicorp.com/agent-inject: "true"
|
|
||||||
vault.hashicorp.com/agent-pre-populate-only: "true"
|
|
||||||
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
||||||
vault.hashicorp.com/role: issues
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/postgresql/apps/issues
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-db: |-
|
|
||||||
{{- with secret "secrets/data/postgresql/apps/issues" -}}
|
|
||||||
DATABASE_PORT=5432
|
|
||||||
DATABASE_HOST=postgresql.issues.svc.cluster.local
|
|
||||||
DATABASE_USER={{ index .Data.data "username" }}
|
|
||||||
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
DATABASE_NAME=issues_db
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
|
|
||||||
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
|
|
||||||
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
|
||||||
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
|
||||||
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
|
|
||||||
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-s3: |-
|
|
||||||
{{- with secret "secrets/data/minio/apps/issues" -}}
|
|
||||||
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
|
|
||||||
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
|
|
||||||
YC_S3_BUCKET_NAME=rfi
|
|
||||||
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
|
||||||
DJANGO_TOKEN={{ index .Data.data "key" }}
|
|
||||||
SAREX_USERNAME={{ index .Data.data "username" }}
|
|
||||||
SAREX_PASSWORD={{ index .Data.data "password" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
|
||||||
{{ index .Data.data "private_key" }}
|
|
||||||
{{- end -}}
|
|
||||||
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
|
|
||||||
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
|
|
||||||
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
|
||||||
{{ index .Data.data "public_key" }}
|
|
||||||
{{- end -}}
|
|
||||||
spec:
|
|
||||||
serviceAccountName: issues-vault
|
|
||||||
volumes:
|
|
||||||
- name: production-configmap
|
|
||||||
configMap:
|
|
||||||
name: production-configmap
|
|
||||||
items:
|
|
||||||
- key: production.py
|
|
||||||
path: production.py
|
|
||||||
defaultMode: 420
|
|
||||||
containers:
|
|
||||||
- name: celery
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
command: ["/bin/sh", "-ec"]
|
|
||||||
args:
|
|
||||||
- |
|
|
||||||
set -a
|
|
||||||
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
|
|
||||||
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
|
|
||||||
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
|
|
||||||
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
|
|
||||||
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
|
|
||||||
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
|
|
||||||
set +a
|
|
||||||
exec celery -A config worker -l info -E
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
env:
|
|
||||||
- name: ENVIRONMENT
|
|
||||||
value: production
|
|
||||||
- name: AERO_PUBLIC_HOST
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: AERO_HOST
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: BASE_AERO_URL
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: BASE_AUTH_URL
|
|
||||||
value: http://backend-svc.django.svc.cluster.local:80
|
|
||||||
- name: WORKFLOWS_HOST
|
|
||||||
value: http://workflows-api-service.workflow.svc.cluster.local:8000
|
|
||||||
- name: WORKFLOWS_URL
|
|
||||||
value: http://workflows-api-service.workflow.svc.cluster.local:8000
|
|
||||||
- name: RESOURCES_API_HOST
|
|
||||||
value: http://backend-svc.resources.svc.cluster.local:80
|
|
||||||
- name: EAV_HOST
|
|
||||||
value: http://backend-svc.eav.svc.cluster.local:80
|
|
||||||
- name: SAREX_API
|
|
||||||
value: https://srx.wb.ru
|
|
||||||
- name: DOCUMENTATIONS_URL
|
|
||||||
value: http://backend-api-svc.documentations.svc.cluster.local:80
|
|
||||||
- name: DJANGO_SETTINGS_MODULE
|
|
||||||
value: config.settings.production
|
|
||||||
- name: API_ADDRESS
|
|
||||||
value: "8000"
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: "25m"
|
|
||||||
memory: 128Mi
|
|
||||||
volumeMounts:
|
|
||||||
- name: production-configmap
|
|
||||||
mountPath: /src/config/settings/production.py
|
|
||||||
subPath: production.py
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
222
apps/issues/base/celery.yaml
Normal file
222
apps/issues/base/celery.yaml
Normal file
@ -0,0 +1,222 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: celery
|
||||||
|
namespace: issues
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
celery:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: issues-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_17c438aa
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: celery
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/issues-db ] && . /vault/secrets/issues-db
|
||||||
|
[ -f /vault/secrets/issues-rabbitmq ] && . /vault/secrets/issues-rabbitmq
|
||||||
|
[ -f /vault/secrets/issues-s3 ] && . /vault/secrets/issues-s3
|
||||||
|
[ -f /vault/secrets/issues-django-auth ] && . /vault/secrets/issues-django-auth
|
||||||
|
[ -f /vault/secrets/issues-jwt-private ] && export JWT_PRIVATE_KEY="$(cat /vault/secrets/issues-jwt-private)"
|
||||||
|
[ -f /vault/secrets/issues-jwt-public ] && export JWT_PUBLIC_KEY="$(cat /vault/secrets/issues-jwt-public)"
|
||||||
|
set +a
|
||||||
|
exec celery -A config worker -l info -E
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: production-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /src/config/settings/production.py
|
||||||
|
subPath:
|
||||||
|
_default: production.py
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: production-configmap
|
||||||
|
items:
|
||||||
|
- key: production.py
|
||||||
|
path:
|
||||||
|
_default: production.py
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: ENVIRONMENT
|
||||||
|
value:
|
||||||
|
_default: "production"
|
||||||
|
|
||||||
|
- name: AERO_PUBLIC_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: AERO_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: BASE_AERO_URL
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: BASE_AUTH_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.django.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_URL
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-api-service.workflow.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: RESOURCES_API_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://iam-backend.iam.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: EAV_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.eav.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: SAREX_API
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: DOCUMENTATIONS_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: "config.settings.production"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: issues
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-db: secrets/data/apps/issues/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/issues/postgres" -}}
|
||||||
|
DATABASE_PORT={{ index .Data.data "port" }}
|
||||||
|
DATABASE_HOST={{ index .Data.data "host" }}
|
||||||
|
DATABASE_USER={{ index .Data.data "username" }}
|
||||||
|
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
DATABASE_NAME={{ index .Data.data "database" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-rabbitmq: secrets/data/rabbitmq/apps/issues
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-rabbitmq: |-
|
||||||
|
{{- with secret "secrets/data/rabbitmq/apps/issues" -}}
|
||||||
|
RABBITMQ_VHOST={{ index .Data.data "vhost" }}
|
||||||
|
RABBITMQ_USERNAME={{ index .Data.data "username" }}
|
||||||
|
RABBITMQ_HOSTNAME=rabbitmq.rabbitmq.svc.cluster.local
|
||||||
|
RABBITMQ_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-s3: secrets/data/minio/apps/issues
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-s3: |-
|
||||||
|
{{- with secret "secrets/data/minio/apps/issues" -}}
|
||||||
|
YC_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
|
||||||
|
YC_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
|
||||||
|
YC_S3_BUCKET_NAME=rfi
|
||||||
|
YC_S3_ENDPOINT_URL=https://minio.contour.infra.sarex.tech
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-django-auth: secrets/data/vault/common/django_auth
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-django-auth: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/django_auth" -}}
|
||||||
|
DJANGO_TOKEN={{ index .Data.data "key" }}
|
||||||
|
SAREX_USERNAME={{ index .Data.data "username" }}
|
||||||
|
SAREX_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-jwt-private: secrets/data/vault/common/rsa_keys
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-jwt-private: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
||||||
|
{{ index .Data.data "private_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-issues-jwt-public: secrets/data/vault/common/rsa_keys
|
||||||
|
vault.hashicorp.com/agent-inject-template-issues-jwt-public: |-
|
||||||
|
{{- with secret "secrets/data/vault/common/rsa_keys" -}}
|
||||||
|
{{ index .Data.data "public_key" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,32 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: frontend
|
|
||||||
namespace: issues
|
|
||||||
labels:
|
|
||||||
app: frontend
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app: frontend
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app: frontend
|
|
||||||
spec:
|
|
||||||
containers:
|
|
||||||
- name: frontend
|
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73
|
|
||||||
imagePullPolicy: IfNotPresent
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
containerPort: 80
|
|
||||||
protocol: TCP
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
cpu: 25m
|
|
||||||
memory: 100Mi
|
|
||||||
imagePullSecrets:
|
|
||||||
- name: regcred
|
|
||||||
@ -1,15 +0,0 @@
|
|||||||
---
|
|
||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: frontend-svc
|
|
||||||
namespace: issues
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app: frontend
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
port: 80
|
|
||||||
targetPort: 80
|
|
||||||
protocol: TCP
|
|
||||||
90
apps/issues/base/frontend.yaml
Normal file
90
apps/issues/base/frontend.yaml
Normal file
@ -0,0 +1,90 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: issues
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:716a2b73
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
@ -4,10 +4,7 @@ kind: Kustomization
|
|||||||
namespace: issues
|
namespace: issues
|
||||||
resources:
|
resources:
|
||||||
- namespace.yaml
|
- namespace.yaml
|
||||||
- serviceaccount.yaml
|
- backend.yaml
|
||||||
- backend-deployment.yaml
|
- celery.yaml
|
||||||
- celery-deployment.yaml
|
- frontend.yaml
|
||||||
- frontend-deployment.yaml
|
|
||||||
- backend-service.yaml
|
|
||||||
- frontend-service.yaml
|
|
||||||
- production-configmap.yaml
|
- production-configmap.yaml
|
||||||
|
|||||||
@ -1,5 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: ServiceAccount
|
|
||||||
metadata:
|
|
||||||
name: issues-vault
|
|
||||||
namespace: issues
|
|
||||||
10
apps/issues/d8-ugmk-prod/kustomization.yaml
Normal file
10
apps/issues/d8-ugmk-prod/kustomization.yaml
Normal file
@ -0,0 +1,10 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: namespace.yaml
|
||||||
|
target:
|
||||||
|
kind: Namespace
|
||||||
|
name: issues
|
||||||
8
apps/issues/d8-ugmk-prod/namespace.yaml
Normal file
8
apps/issues/d8-ugmk-prod/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: issues
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
@ -1,53 +1,102 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: backend
|
name: backend
|
||||||
namespace: issues
|
namespace: issues
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
backend:
|
||||||
- name: backend
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
|
name:
|
||||||
env:
|
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
|
||||||
- name: ENABLE_MAILGUN
|
|
||||||
value: 'False'
|
envs:
|
||||||
- name: SMTP_HOST
|
- name: ENVIRONMENT
|
||||||
value: relay.dsinv.ru
|
value:
|
||||||
- name: SMTP_PORT
|
_default: "production"
|
||||||
value: '25'
|
|
||||||
- name: EMAIL_FROM
|
- name: AERO_PUBLIC_HOST
|
||||||
value: sarex@dsinv.ru
|
value:
|
||||||
- name: USE_NOTIFICATIONS
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: 'True'
|
|
||||||
- name: DJANGO_SETTINGS_MODULE
|
- name: AERO_HOST
|
||||||
value: config.settings.production
|
value:
|
||||||
- name: REDIS_HOST
|
_default: "https://sarex.contour.infra.sarex.tech"
|
||||||
value: redis-service.issues.svc.cluster.local
|
|
||||||
- name: DATABASE_HOST
|
- name: BASE_AERO_URL
|
||||||
value: postgres-service.issues.svc.cluster.local
|
value:
|
||||||
- name: DATABASE_PORT
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
value: '5432'
|
|
||||||
- name: DATABASE_NAME
|
- name: BASE_AUTH_URL
|
||||||
value: issues
|
value:
|
||||||
- name: API_ADDRESS
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
value: '8000'
|
|
||||||
- name: ENVIRONMENT
|
- name: WORKFLOWS_HOST
|
||||||
value: production
|
value:
|
||||||
- name: AERO_PUBLIC_HOST
|
_default: "http://workflows-service.workflow.svc.cluster.local:8000"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: BASE_AERO_URL
|
- name: WORKFLOWS_URL
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
value:
|
||||||
- name: BASE_AUTH_URL
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
|
||||||
- name: WORKFLOWS_HOST
|
- name: RESOURCES_API_HOST
|
||||||
value: http://workflows-service.workflow.svc.cluster.local:8000
|
value:
|
||||||
- name: WORKFLOWS_URL
|
_default: "http://resources-service.resources.svc.cluster.local:8000"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: RESOURCES_API_HOST
|
- name: EAV_HOST
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000
|
value:
|
||||||
- name: EAV_HOST
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
value: http://eav-service.eav.svc.cluster.local:8000
|
|
||||||
- name: SAREX_API
|
- name: SAREX_API
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
value:
|
||||||
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: DOCUMENTATIONS_URL
|
||||||
|
value:
|
||||||
|
_default: "http://documentations-api-svc.documentations.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: "config.settings.production"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
- name: ENABLE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
- name: SMTP_HOST
|
||||||
|
value:
|
||||||
|
_default: "relay.dsinv.ru"
|
||||||
|
|
||||||
|
- name: SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "25"
|
||||||
|
|
||||||
|
- name: EMAIL_FROM
|
||||||
|
value:
|
||||||
|
_default: "sarex@dsinv.ru"
|
||||||
|
|
||||||
|
- name: USE_NOTIFICATIONS
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis-service.issues.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.issues.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
value:
|
||||||
|
_default: "issues"
|
||||||
|
|||||||
@ -1,57 +1,110 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: celery
|
name: celery
|
||||||
namespace: issues
|
namespace: issues
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
celery:
|
||||||
- name: celery
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
|
name:
|
||||||
env:
|
_default: cr.yandex/crp3ccidau046kdj8g9q/issues:production_31aef17b
|
||||||
- name: KAFKA_EAV_ASSETS_TOPIC
|
|
||||||
value: sarex
|
envs:
|
||||||
- name: AERO_PUBLIC_HOST
|
- name: ENVIRONMENT
|
||||||
value: https://sarex.dsinv.ru
|
value:
|
||||||
- name: ENABLE_MAILGUN
|
_default: "production"
|
||||||
value: 'False'
|
|
||||||
- name: SMTP_HOST
|
- name: AERO_PUBLIC_HOST
|
||||||
value: relay.dsinv.ru
|
value:
|
||||||
- name: SMTP_PORT
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: '25'
|
|
||||||
- name: EMAIL_FROM
|
- name: AERO_HOST
|
||||||
value: sarex@dsinv.ru
|
value:
|
||||||
- name: REDIS_HOST
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: redis-service.issues.svc.cluster.local
|
|
||||||
- name: DATABASE_HOST
|
- name: BASE_AERO_URL
|
||||||
value: postgres-service.issues.svc.cluster.local
|
value:
|
||||||
- name: DATABASE_PORT
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
value: '5432'
|
|
||||||
- name: DATABASE_NAME
|
- name: BASE_AUTH_URL
|
||||||
value: issues
|
value:
|
||||||
- name: USE_NOTIFICATIONS
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: 'True'
|
|
||||||
- name: API_ADDRESS
|
- name: WORKFLOWS_HOST
|
||||||
value: '8000'
|
value:
|
||||||
- name: YC_S3_VERIFY
|
_default: "http://workflows-service.workflow.svc.cluster.local:8000"
|
||||||
value: 'False'
|
|
||||||
- name: ENVIRONMENT
|
- name: WORKFLOWS_URL
|
||||||
value: production
|
value:
|
||||||
- name: AERO_HOST
|
_default: "https://sarex.dsinv.ru"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: BASE_AERO_URL
|
- name: RESOURCES_API_HOST
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
value:
|
||||||
- name: BASE_AUTH_URL
|
_default: "http://resources-service.resources.svc.cluster.local:8000"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: WORKFLOWS_HOST
|
- name: EAV_HOST
|
||||||
value: http://workflows-service.workflow.svc.cluster.local:8000
|
value:
|
||||||
- name: WORKFLOWS_URL
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
value: https://sarex.dsinv.ru
|
|
||||||
- name: RESOURCES_API_HOST
|
- name: SAREX_API
|
||||||
value: http://resources-service.resources.svc.cluster.local:8000
|
value:
|
||||||
- name: EAV_HOST
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
value: http://eav-service.eav.svc.cluster.local:8000
|
|
||||||
- name: SAREX_API
|
- name: DOCUMENTATIONS_URL
|
||||||
value: http://backend.django.svc.cluster.local:8000
|
value:
|
||||||
|
_default: "http://backend-api-svc.documentations.svc.cluster.local:80"
|
||||||
|
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: "config.settings.production"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
- name: KAFKA_EAV_ASSETS_TOPIC
|
||||||
|
value:
|
||||||
|
_default: "sarex"
|
||||||
|
|
||||||
|
- name: ENABLE_MAILGUN
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
- name: SMTP_HOST
|
||||||
|
value:
|
||||||
|
_default: "relay.dsinv.ru"
|
||||||
|
|
||||||
|
- name: SMTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "25"
|
||||||
|
|
||||||
|
- name: EMAIL_FROM
|
||||||
|
value:
|
||||||
|
_default: "sarex@dsinv.ru"
|
||||||
|
|
||||||
|
- name: REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis-service.issues.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service.issues.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
value:
|
||||||
|
_default: "issues"
|
||||||
|
|
||||||
|
- name: USE_NOTIFICATIONS
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: YC_S3_VERIFY
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|||||||
@ -1,12 +1,13 @@
|
|||||||
---
|
---
|
||||||
apiVersion: apps/v1
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: Deployment
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: frontend
|
name: frontend
|
||||||
namespace: issues
|
namespace: issues
|
||||||
spec:
|
spec:
|
||||||
template:
|
values:
|
||||||
spec:
|
services:
|
||||||
containers:
|
frontend:
|
||||||
- name: frontend
|
image:
|
||||||
image: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/contour_issues-frontend:24ab8d2b
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user