apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap — vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's login.sarex.local.uralkali.com). Two things are left as explicit placeholders pending real infra: the Zitadel client_id/org_id (TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application registered yet) and the Kafka CA cert in pm/issues/message-hub/flows (copied from vad, will need swapping once uralkal's Kafka actually generates its own CA, same as vad's history). infrastructure/s3-proxy/uralkal: new component, nginx upstream points at the single uralkal minio endpoint (10.133.0.245:9000) from terraform, unlike vad's 4-node list. clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps. infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28 path-routed virtualServices under sarex.local.uralkali.com (mirroring vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy) plus stamp-verification/document-link/s3 on their already-declared hosts. Pre-existing zitadel/superset/camunda-operate blocks are untouched. apps/django/vad/backend.yaml: drop a stale explanatory comment (also removed from the uralkal copy before this commit). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
147 lines
4.6 KiB
YAML
147 lines
4.6 KiB
YAML
---
|
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
|
kind: HelmRelease
|
|
metadata:
|
|
name: documentations-filestream
|
|
namespace: documentations
|
|
spec:
|
|
values:
|
|
services:
|
|
backend:
|
|
envs:
|
|
- name: POSTGRES_POOL_SIZE
|
|
value:
|
|
_default: "20"
|
|
- name: ZITADEL_ACCOUNT
|
|
value:
|
|
_default: /vault/secrets/documentations-zitadel-account-json
|
|
- name: ZITADEL_DOMAIN
|
|
value:
|
|
_default: login.sarex.local.uralkali.com
|
|
- name: USE_ZITADEL
|
|
value:
|
|
_default: "1"
|
|
- name: FLOWS_URL
|
|
value:
|
|
_default: http://backend-svc.flows.svc.cluster.local:80
|
|
- name: LAST_MASTER_BIM
|
|
value:
|
|
_default: "36311"
|
|
- name: API_ADDRESS
|
|
value:
|
|
_default: 0.0.0.0:8080
|
|
- name: API_ADDRESS_FILE
|
|
value:
|
|
_default: 0.0.0.0:8080
|
|
- name: DOCUMENT_PUBLIC_LINK_JWT_EXPIRATION_MINUTES
|
|
value:
|
|
_default: "5"
|
|
- name: ENABLE_SQL_QUERY
|
|
value:
|
|
_default: "0"
|
|
- name: ENABLE_SSL
|
|
value:
|
|
_default: "0"
|
|
- name: WORKSPACE_V2_EXTERNAL_URL
|
|
value:
|
|
_default: https://sarex.local.uralkali.com/workspaces-v2/
|
|
- name: ENABLE_S3
|
|
value:
|
|
_default: "1"
|
|
- name: CONTAINER_REGISTRY
|
|
value:
|
|
_default: cr.yandex/crp3ccidau046kdj8g9q
|
|
- name: ENVIRONMENT
|
|
value:
|
|
_default: production
|
|
- name: LAST_SLAVE_1_BIM
|
|
value:
|
|
_default: "1000000"
|
|
- name: HOST
|
|
value:
|
|
_default: http://backend-api-svc.documentations.svc.cluster.local:80
|
|
- name: FILE_STREAM_HOST
|
|
value:
|
|
_default: sarex.local.uralkali.com
|
|
- name: DOCUMENTATION_URL
|
|
value:
|
|
_default: http://backend-api-svc.documentations.svc.cluster.local:80/
|
|
- name: WORKFLOW_URL
|
|
value:
|
|
_default: http://workflows-api-service.workflow.svc.cluster.local:8000/
|
|
- name: WORKSPACE_URL
|
|
value:
|
|
_default: http://backend-svc.workspaces.svc.cluster.local:80/
|
|
- name: BIM_API_URL
|
|
value:
|
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
|
- name: BIM_API_V2_URL
|
|
value:
|
|
_default: http://backend-svc.bim.svc.cluster.local:80/
|
|
- name: WORKSPACE_BUNDLE_VERSION
|
|
value:
|
|
_default: v1
|
|
- name: SYSTEM_LOG_URL
|
|
value:
|
|
_default: http://api-service.system-log.svc.cluster.local:80
|
|
- name: DJANGO_HOST
|
|
value:
|
|
_default: http://backend-svc.django.svc.cluster.local:80
|
|
- name: MARKS_PROCESSING_URL
|
|
value:
|
|
_default: http://marks-service:8000
|
|
- name: PUBLIC_LINK_HOST
|
|
value:
|
|
_default: https://document-link.sarex.local.uralkali.com
|
|
- name: NAMESPACE
|
|
value:
|
|
_default: documentations
|
|
- name: DJANGO_ORIGINATOR
|
|
value:
|
|
_default: docs_prod
|
|
- name: WORKFLOW_IMAGES_VERSION
|
|
value:
|
|
_default: master
|
|
- name: WORKFLOWS_IMAGES_VERSION
|
|
value:
|
|
_default: master
|
|
- name: S3_SERVICE_ACCOUNT
|
|
value:
|
|
_default: /vault/secrets/documentations-s3-account-json
|
|
- name: READ_WRITE_TIMEOUT_FILE_STREAM
|
|
value:
|
|
_default: 6h
|
|
- name: CACHE_DEFAULT_EXPIRATION
|
|
value:
|
|
_default: 60s
|
|
- name: ENABLE_SMTP
|
|
value:
|
|
_default: "True"
|
|
- name: ENABLE_MAILGUN
|
|
value:
|
|
_default: "False"
|
|
- name: CACHE_CLEANUP_INTERVAL
|
|
value:
|
|
_default: 60s
|
|
- name: ENABLE_AUTH_JWT_IN_URL
|
|
value:
|
|
_default: "false"
|
|
- name: ENABLE_SIGNATURE_IN_URL
|
|
value:
|
|
_default: "true"
|
|
- name: DOCUMENT_PUBLIC_LINK_JWT_SECRET
|
|
value:
|
|
_default: "mock"
|
|
- name: USE_CACHE_IN_FILE_STREAMER
|
|
value:
|
|
_default: "0"
|
|
- name: VALKEY_ADDR
|
|
value:
|
|
_default: redis:6379
|
|
- name: VALKEY_HOST
|
|
value:
|
|
_default: redis
|
|
- name: VALKEY_PORT
|
|
value:
|
|
_default: "6379"
|