apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap — vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's login.sarex.local.uralkali.com). Two things are left as explicit placeholders pending real infra: the Zitadel client_id/org_id (TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application registered yet) and the Kafka CA cert in pm/issues/message-hub/flows (copied from vad, will need swapping once uralkal's Kafka actually generates its own CA, same as vad's history). infrastructure/s3-proxy/uralkal: new component, nginx upstream points at the single uralkal minio endpoint (10.133.0.245:9000) from terraform, unlike vad's 4-node list. clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps. infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28 path-routed virtualServices under sarex.local.uralkali.com (mirroring vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy) plus stamp-verification/document-link/s3 on their already-declared hosts. Pre-existing zitadel/superset/camunda-operate blocks are untouched. apps/django/vad/backend.yaml: drop a stale explanatory comment (also removed from the uralkal copy before this commit). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
35 lines
1.6 KiB
YAML
35 lines
1.6 KiB
YAML
apiVersion: helm.toolkit.fluxcd.io/v2
|
|
kind: HelmRelease
|
|
metadata:
|
|
name: attachments
|
|
namespace: attachments
|
|
spec:
|
|
values:
|
|
services:
|
|
attachments:
|
|
podAnnotations:
|
|
_default:
|
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
|
vault.hashicorp.com/role: attachments
|
|
vault.hashicorp.com/agent-inject-secret-attachments-db: secrets/data/apps/attachments/postgres
|
|
vault.hashicorp.com/agent-inject-template-attachments-db: |-
|
|
{{- with secret "secrets/data/apps/attachments/postgres" -}}
|
|
DATABASE_HOST={{ index .Data.data "host" }}
|
|
DATABASE_PORT={{ index .Data.data "port" }}
|
|
DATABASE_NAME={{ index .Data.data "database" }}
|
|
DATABASE_USER={{ index .Data.data "username" }}
|
|
DATABASE_PASSWORD={{ index .Data.data "password" }}
|
|
DATABASE_SSL_MODE=disable
|
|
{{- end -}}
|
|
vault.hashicorp.com/agent-inject-secret-attachments-s3: secrets/data/minio/apps/attachments
|
|
vault.hashicorp.com/agent-inject-template-attachments-s3: |-
|
|
{{- with secret "secrets/data/minio/apps/attachments" -}}
|
|
YANDEX_S3_ENDPOINT_URL=s3-proxy.s3-proxy.svc.cluster.local
|
|
YANDEX_S3_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
|
|
YANDEX_S3_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
|
|
YANDEX_S3_USE_SSL=false
|
|
YANDEX_S3_REGION=ru-central
|
|
YANDEX_S3_VERIFY=false
|
|
BUCKET_NAME=attachments
|
|
{{- end -}}
|