iac/apps/django/uralkal/s3-proxy.yaml
ivan 9ec172c0f4 uralkal: replicate the vad business-app footprint (36 apps) with uralkal domains
apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from
clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap —
vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's
login.sarex.local.uralkali.com). Two things are left as explicit
placeholders pending real infra: the Zitadel client_id/org_id
(TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application
registered yet) and the Kafka CA cert in pm/issues/message-hub/flows
(copied from vad, will need swapping once uralkal's Kafka actually
generates its own CA, same as vad's history).

infrastructure/s3-proxy/uralkal: new component, nginx upstream points at
the single uralkal minio endpoint (10.133.0.245:9000) from terraform,
unlike vad's 4-node list.

clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps.

infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28
path-routed virtualServices under sarex.local.uralkali.com (mirroring
vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy)
plus stamp-verification/document-link/s3 on their already-declared hosts.
Pre-existing zitadel/superset/camunda-operate blocks are untouched.

apps/django/vad/backend.yaml: drop a stale explanatory comment (also
removed from the uralkal copy before this commit).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:56:17 +03:00

32 lines
1.5 KiB
YAML
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
# Патч s3-proxy для vad.
#
# В base зашит AWS_API_ENDPOINT=https://minio.contour.infra.sarex.tech —
# в закрытом контуре этот хост недоступен, прокси не достучится до MinIO
# и маршрут /media/ (s3-proxy-virt-service в istio-config) вернёт ошибку.
#
# podAnnotations — map, мержится по ключам, поэтому переопределён только
# agent-inject-template-s3; остальные vault-аннотации берутся из base.
# Эндпоинт задан литералом, а не через .Data.data.client.endpoint: так же
# сделано в apps/django/vad/backend.yaml для того же секрета
# secrets/data/minio/apps/django — держим один способ на весь ns.
apiVersion: helm.toolkit.fluxcd.io/v2
kind: HelmRelease
metadata:
name: s3-proxy
namespace: django
spec:
values:
services:
s3-proxy:
podAnnotations:
_default:
vault.hashicorp.com/agent-inject-template-s3: |
{{- with secret "secrets/data/minio/apps/django" }}
AWS_API_ENDPOINT=http://s3-proxy.s3-proxy.svc.cluster.local
{{- $buckets := index .Data.data "buckets" }}
AWS_S3_BUCKET={{ if gt (len $buckets) 0 }}{{ index (index $buckets 0) "name" }}{{ else }}django{{ end }}
AWS_ACCESS_KEY_ID={{ index .Data.data "access_key" }}
AWS_SECRET_ACCESS_KEY={{ index .Data.data "secret_key" }}
{{- end }}