iac/apps/iam/uralkal/backend-s3.yaml
ivan 9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00

79 lines
1.7 KiB
YAML

---
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: iam-backend
namespace: iam
spec:
values:
services:
backend:
envs:
- name: ENVIRONMENT
value:
_default: "prod"
- name: LOG_LEVEL
value:
_default: "debug"
- name: AUTH_ENABLED
value:
_default: "true"
- name: HTTP_PORT
value:
_default: "8080"
- name: HTTP_READ_BUFFER_SIZE
value:
_default: "131072"
- name: DB_MIGRATIONS_PATH
value:
_default: "migrations"
- name: ZITADEL_ENABLED
value:
_default: "true"
- name: ZITADEL_HOST
value:
_default: "https://login.sarex.local.uralkali.com"
- name: ZITADEL_ORG_RULES_FILE
value:
_default: "config/zitadel/org-rules-prod.json"
- name: S3_ENABLED
value:
_default: "true"
- name: S3_ENDPOINT_URL
value:
_default: "http://s3-proxy.s3-proxy.svc.cluster.local"
- name: S3_BUCKET_NAME
value:
_default: "iam"
- name: S3_REGION
value:
_default: "ru-central1"
- name: S3_PRESIGN_EXPIRES
value:
_default: "1h"
- name: KAFKA_ENABLED
value:
_default: "false"
- name: KAFKA_SSL_CAFILE
value:
_default: "/etc/ca-certificates/Yandex/ca-cert"
- name: KAFKA_TOPIC_LEGACY_AMS_SYNC
value:
_default: "ams-sync"