apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap — vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's login.sarex.local.uralkali.com). Two things are left as explicit placeholders pending real infra: the Zitadel client_id/org_id (TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application registered yet) and the Kafka CA cert in pm/issues/message-hub/flows (copied from vad, will need swapping once uralkal's Kafka actually generates its own CA, same as vad's history). infrastructure/s3-proxy/uralkal: new component, nginx upstream points at the single uralkal minio endpoint (10.133.0.245:9000) from terraform, unlike vad's 4-node list. clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps. infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28 path-routed virtualServices under sarex.local.uralkali.com (mirroring vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy) plus stamp-verification/document-link/s3 on their already-declared hosts. Pre-existing zitadel/superset/camunda-operate blocks are untouched. apps/django/vad/backend.yaml: drop a stale explanatory comment (also removed from the uralkal copy before this commit). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
32 lines
1.5 KiB
YAML
32 lines
1.5 KiB
YAML
---
|
||
# Патч s3-proxy для vad.
|
||
#
|
||
# В base зашит AWS_API_ENDPOINT=https://minio.contour.infra.sarex.tech —
|
||
# в закрытом контуре этот хост недоступен, прокси не достучится до MinIO
|
||
# и маршрут /media/ (s3-proxy-virt-service в istio-config) вернёт ошибку.
|
||
#
|
||
# podAnnotations — map, мержится по ключам, поэтому переопределён только
|
||
# agent-inject-template-s3; остальные vault-аннотации берутся из base.
|
||
# Эндпоинт задан литералом, а не через .Data.data.client.endpoint: так же
|
||
# сделано в apps/django/vad/backend.yaml для того же секрета
|
||
# secrets/data/minio/apps/django — держим один способ на весь ns.
|
||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||
kind: HelmRelease
|
||
metadata:
|
||
name: s3-proxy
|
||
namespace: django
|
||
spec:
|
||
values:
|
||
services:
|
||
s3-proxy:
|
||
podAnnotations:
|
||
_default:
|
||
vault.hashicorp.com/agent-inject-template-s3: |
|
||
{{- with secret "secrets/data/minio/apps/django" }}
|
||
AWS_API_ENDPOINT=http://s3-proxy.s3-proxy.svc.cluster.local
|
||
{{- $buckets := index .Data.data "buckets" }}
|
||
AWS_S3_BUCKET={{ if gt (len $buckets) 0 }}{{ index (index $buckets 0) "name" }}{{ else }}django{{ end }}
|
||
AWS_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
|
||
AWS_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
|
||
{{- end }}
|