apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap — vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's login.sarex.local.uralkali.com). Two things are left as explicit placeholders pending real infra: the Zitadel client_id/org_id (TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application registered yet) and the Kafka CA cert in pm/issues/message-hub/flows (copied from vad, will need swapping once uralkal's Kafka actually generates its own CA, same as vad's history). infrastructure/s3-proxy/uralkal: new component, nginx upstream points at the single uralkal minio endpoint (10.133.0.245:9000) from terraform, unlike vad's 4-node list. clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps. infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28 path-routed virtualServices under sarex.local.uralkali.com (mirroring vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy) plus stamp-verification/document-link/s3 on their already-declared hosts. Pre-existing zitadel/superset/camunda-operate blocks are untouched. apps/django/vad/backend.yaml: drop a stale explanatory comment (also removed from the uralkal copy before this commit). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
161 lines
6.5 KiB
YAML
161 lines
6.5 KiB
YAML
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: nginx-configmap
|
|
namespace: django
|
|
data:
|
|
nginx.conf: |
|
|
worker_processes auto;
|
|
|
|
pid /var/run/nginx.pid;
|
|
|
|
events {
|
|
use epoll;
|
|
worker_connections 1024;
|
|
}
|
|
|
|
http {
|
|
|
|
# Basic Settings
|
|
large_client_header_buffers 8 128k;
|
|
sendfile on;
|
|
tcp_nopush on;
|
|
tcp_nodelay on;
|
|
keepalive_timeout 300;
|
|
types_hash_max_size 2048;
|
|
client_max_body_size 5000M;
|
|
client_header_buffer_size 5M;
|
|
include /etc/nginx/mime.types;
|
|
default_type application/octet-stream;
|
|
|
|
# Logging Settings
|
|
access_log /var/log/nginx/access.log;
|
|
error_log /var/log/nginx/error.log;
|
|
|
|
# GZIP Settings
|
|
gzip on;
|
|
gzip_vary on;
|
|
gzip_proxied any;
|
|
gzip_comp_level 6;
|
|
gzip_buffers 16 8k;
|
|
gzip_http_version 1.1;
|
|
gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;
|
|
|
|
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
|
|
'$status $body_bytes_sent "$http_referer" '
|
|
'"$http_user_agent" "$http_x_forwarded_for"';
|
|
|
|
server {
|
|
listen 80;
|
|
listen [::]:80;
|
|
root /opt/react_client/;
|
|
|
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
|
add_header 'Access-Control-Allow-Methods' '*' always;
|
|
add_header 'Access-Control-Allow-Headers' '*' always;
|
|
|
|
location = /static/index.bundle.js {
|
|
add_header Cache-Control 'no-store no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
|
if_modified_since off;
|
|
expires off;
|
|
}
|
|
|
|
# location ~^/api/pm/ {
|
|
# proxy_http_version 1.1;
|
|
# proxy_set_header Connection "";
|
|
# proxy_set_header Host $host;
|
|
# proxy_pass http://backend-svc.pm.svc.cluster.local:8000;
|
|
# }
|
|
|
|
location ~^/api/v1/documents/ {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_pass http://backend-filestream-svc.documentations.svc.cluster.local:80;
|
|
}
|
|
|
|
location ~^/(api|admin)/ {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
proxy_set_header Host $host;
|
|
proxy_pass http://backend-svc.django.svc.cluster.local:80;
|
|
}
|
|
|
|
location = /static/pdf-runtime/assets/mupdf-wasm.wasm {
|
|
alias /opt/react_client/static/pdf-runtime/assets/mupdf-wasm.wasm;
|
|
add_header Content-Type application/wasm always;
|
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
|
add_header Access-Control-Allow-Origin "*" always;
|
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
|
}
|
|
|
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.js {
|
|
alias /opt/react_client/static/viewer-pdf/mupdf-wasm.js;
|
|
add_header Content-Type application/javascript always;
|
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
|
add_header Access-Control-Allow-Origin "*" always;
|
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
|
}
|
|
|
|
location = /workspaces-v2/worker/mupdf.worker-3.3.9.js {
|
|
alias /opt/react_client/static/pdf-runtime/mupdf.worker-3.3.9.js;
|
|
add_header Content-Type application/javascript always;
|
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
|
add_header Access-Control-Allow-Origin "*" always;
|
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
|
}
|
|
|
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf.js {
|
|
alias /opt/react_client/static/viewer-pdf/mupdf.js;
|
|
add_header Content-Type application/javascript always;
|
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
|
add_header Access-Control-Allow-Origin "*" always;
|
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
|
}
|
|
|
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.wasm {
|
|
add_header Content-Type application/wasm always;
|
|
alias /opt/react_client/static/viewer-pdf/mupdf-wasm.wasm;
|
|
}
|
|
|
|
location ~^/workspaces-v2/(.+).js {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
rewrite /workspaces-v2/(.+) /$1 break;
|
|
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
|
|
}
|
|
|
|
location ~^/workspaces-v2/(.+)\.wasm$ {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
rewrite ^/workspaces-v2/(.+) /$1 break;
|
|
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:80;
|
|
}
|
|
|
|
location @index {
|
|
add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
|
if_modified_since off;
|
|
expires off;
|
|
try_files /static/index.html =404;
|
|
}
|
|
|
|
location ~^/workflows/(.+).js {
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
rewrite /workflows/(.+) /$1 break;
|
|
proxy_pass http://frontend-svc.processing.svc.cluster.local:80;
|
|
}
|
|
|
|
location /service-worker.js {
|
|
try_files /static/$uri @index;
|
|
}
|
|
|
|
location / {
|
|
try_files $uri @index;
|
|
}
|
|
}
|
|
}
|