iac/apps/message-hub/uralkal/message-hub.yaml
ivan 9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00

106 lines
3.3 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
# Патч message-hub для vad.
#
# ВНИМАНИЕ: envs — список, kustomize заменяет его ЦЕЛИКОМ (JSON merge patch),
# поэтому здесь продублирован весь набор из apps/message-hub/base/message-hub.yaml.
# podAnnotations — map, мержится по ключам, поэтому переопределён только
# agent-inject-template-message-hub-kafka; остальные берутся из base.
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: message-hub
namespace: message-hub
spec:
values:
services:
backend:
envs:
- name: WORKER_TIMEOUT
value:
_default: "60"
- name: PYTHONPATH
value:
_default: "src"
- name: SETTINGS_MAX_RETRIES
value:
_default: "1"
- name: SETTINGS_TOPICS
value:
_default: '{"planning": "message-hub-prod", "assets":"assets_broadcast","issues": "issues_broadcast_prod", "resources_updated": "iam.resource.updated.v2", "resources_deleted": "iam.resource.deleted.v2"}'
- name: SETTINGS_VERIFY_SSL
value:
_default: "0"
- name: SAREX_BASE_HOST
value:
_default: "http://backend-svc.pm.svc.cluster.local:8000"
- name: PM_HOST
value:
_default: "http://backend-svc.pm.svc.cluster.local:8000"
- name: EAV_HOST
value:
_default: "http://backend-svc.eav.svc.cluster.local:80"
- name: ISSUES_HOST
value:
_default: "http://backend-svc.issues.svc.cluster.local:80"
- name: CACHE_HOST
value:
_default: "redis.pm.svc.cluster.local"
- name: CACHE_PORT
value:
_default: "6379"
- name: CACHE_SSL
value:
_default: "0"
- name: KAFKA_HOST
value:
_default: "kafka-kafka-contour.kafka.svc.cluster.local"
- name: KAFKA_PORT
value:
_default: "9092"
- name: KAFKA_SSL_CAFILE
value:
_default: "/usr/local/share/ca-certificates/kafka.crt"
- name: KAFKA_SECURITY_PROTOCOL
value:
_default: "SASL_SSL"
volumes:
_default:
- name: kafka-ca-cert
mountPath:
_default: /usr/local/share/ca-certificates/kafka.crt
subPath:
_default: kafka.crt
readOnly:
_default: true
configMap:
name:
_default: kafka-ca-cert
items:
- key: kafka.crt
path:
_default: kafka.crt
podAnnotations:
_default:
vault.hashicorp.com/agent-inject-secret-message-hub-kafka: secrets/data/kafka/apps/pm
vault.hashicorp.com/agent-inject-template-message-hub-kafka: |-
{{- with secret "secrets/data/kafka/apps/pm" -}}
KAFKA_USERNAME={{ index .Data.data "username" }}
KAFKA_PASSWORD={{ index .Data.data "password" }}
KAFKA_SASL_MECHANISM={{ index .Data.data.auth "sasl_mechanism" }}
{{- end -}}