apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap — vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's login.sarex.local.uralkali.com). Two things are left as explicit placeholders pending real infra: the Zitadel client_id/org_id (TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application registered yet) and the Kafka CA cert in pm/issues/message-hub/flows (copied from vad, will need swapping once uralkal's Kafka actually generates its own CA, same as vad's history). infrastructure/s3-proxy/uralkal: new component, nginx upstream points at the single uralkal minio endpoint (10.133.0.245:9000) from terraform, unlike vad's 4-node list. clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps. infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28 path-routed virtualServices under sarex.local.uralkali.com (mirroring vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy) plus stamp-verification/document-link/s3 on their already-declared hosts. Pre-existing zitadel/superset/camunda-operate blocks are untouched. apps/django/vad/backend.yaml: drop a stale explanatory comment (also removed from the uralkal copy before this commit). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
79 lines
1.7 KiB
YAML
79 lines
1.7 KiB
YAML
---
|
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
|
kind: HelmRelease
|
|
metadata:
|
|
name: iam-backend
|
|
namespace: iam
|
|
spec:
|
|
values:
|
|
services:
|
|
backend:
|
|
envs:
|
|
- name: ENVIRONMENT
|
|
value:
|
|
_default: "prod"
|
|
|
|
- name: LOG_LEVEL
|
|
value:
|
|
_default: "debug"
|
|
|
|
- name: AUTH_ENABLED
|
|
value:
|
|
_default: "true"
|
|
|
|
- name: HTTP_PORT
|
|
value:
|
|
_default: "8080"
|
|
|
|
- name: HTTP_READ_BUFFER_SIZE
|
|
value:
|
|
_default: "131072"
|
|
|
|
- name: DB_MIGRATIONS_PATH
|
|
value:
|
|
_default: "migrations"
|
|
|
|
- name: ZITADEL_ENABLED
|
|
value:
|
|
_default: "true"
|
|
|
|
- name: ZITADEL_HOST
|
|
value:
|
|
_default: "https://login.sarex.local.uralkali.com"
|
|
|
|
- name: ZITADEL_ORG_RULES_FILE
|
|
value:
|
|
_default: "config/zitadel/org-rules-prod.json"
|
|
|
|
- name: S3_ENABLED
|
|
value:
|
|
_default: "true"
|
|
|
|
- name: S3_ENDPOINT_URL
|
|
value:
|
|
_default: "http://s3-proxy.s3-proxy.svc.cluster.local"
|
|
|
|
- name: S3_BUCKET_NAME
|
|
value:
|
|
_default: "iam"
|
|
|
|
- name: S3_REGION
|
|
value:
|
|
_default: "ru-central1"
|
|
|
|
- name: S3_PRESIGN_EXPIRES
|
|
value:
|
|
_default: "1h"
|
|
|
|
- name: KAFKA_ENABLED
|
|
value:
|
|
_default: "false"
|
|
|
|
- name: KAFKA_SSL_CAFILE
|
|
value:
|
|
_default: "/etc/ca-certificates/Yandex/ca-cert"
|
|
|
|
- name: KAFKA_TOPIC_LEGACY_AMS_SYNC
|
|
value:
|
|
_default: "ams-sync"
|