apps/<app>/uralkal mirrors apps/<app>/vad for all 36 apps from clusters/vad/kustomization.yaml, with domains remapped (not a suffix swap — vad's sarex-login.vadroad.ru etc. use a different host scheme than uralkal's login.sarex.local.uralkali.com). Two things are left as explicit placeholders pending real infra: the Zitadel client_id/org_id (TBD_URALKAL_ZITADEL_CLIENT_ID, since uralkal's Zitadel has no application registered yet) and the Kafka CA cert in pm/issues/message-hub/flows (copied from vad, will need swapping once uralkal's Kafka actually generates its own CA, same as vad's history). infrastructure/s3-proxy/uralkal: new component, nginx upstream points at the single uralkal minio endpoint (10.133.0.245:9000) from terraform, unlike vad's 4-node list. clusters/uralkal/kustomization.yaml: wires in s3-proxy + all 36 apps. infrastructure/istio-config/uralkal/istio-config.yaml: adds the 28 path-routed virtualServices under sarex.local.uralkali.com (mirroring vad's sarex.vadroad.ru routing, incl. the documentations-api CORS policy) plus stamp-verification/document-link/s3 on their already-declared hosts. Pre-existing zitadel/superset/camunda-operate blocks are untouched. apps/django/vad/backend.yaml: drop a stale explanatory comment (also removed from the uralkal copy before this commit). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
99 lines
2.2 KiB
YAML
99 lines
2.2 KiB
YAML
---
|
||
# Redis для celery в ns pm. В base его нет — там CELERY_REDIS_HOST указывает
|
||
# на redis.pm.svc.cluster.local, но сам сервис не разворачивается.
|
||
#
|
||
# Имя Service обязано быть ровно "redis" (не redis-svc, как принято в остальных
|
||
# релизах), иначе не сойдётся с CELERY_REDIS_HOST в backend.yaml и celery.yaml.
|
||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||
kind: HelmRelease
|
||
metadata:
|
||
name: redis
|
||
namespace: pm
|
||
|
||
spec:
|
||
interval: 10m
|
||
|
||
chart:
|
||
spec:
|
||
chart: universal-chart
|
||
version: "0.1.9"
|
||
sourceRef:
|
||
kind: HelmRepository
|
||
name: yc-oci-charts
|
||
namespace: flux-system
|
||
interval: 10m
|
||
|
||
install:
|
||
remediation:
|
||
retries: 3
|
||
|
||
upgrade:
|
||
remediation:
|
||
retries: 3
|
||
|
||
values:
|
||
global:
|
||
env: _default
|
||
|
||
services:
|
||
redis:
|
||
enabled: true
|
||
|
||
image:
|
||
name:
|
||
_default: cr.yandex/crp3ccidau046kdj8g9q/redis:latest
|
||
pullPolicy:
|
||
_default: Always
|
||
|
||
deployment:
|
||
enabled: true
|
||
|
||
name:
|
||
_default: redis
|
||
|
||
replicaCount:
|
||
_default: 1
|
||
|
||
port:
|
||
_default: 6379
|
||
|
||
resources:
|
||
requests:
|
||
cpu:
|
||
_default: 25m
|
||
memory:
|
||
_default: 64Mi
|
||
|
||
probes:
|
||
liveness:
|
||
enabled: false
|
||
readiness:
|
||
enabled: false
|
||
|
||
service:
|
||
enabled: true
|
||
|
||
name:
|
||
_default: redis
|
||
|
||
type:
|
||
_default: ClusterIP
|
||
|
||
port:
|
||
_default: 6379
|
||
|
||
targetPort:
|
||
_default: 6379
|
||
|
||
# НЕ http: чарт по умолчанию подставляет "http", и тогда Istio навесит
|
||
# на 6379 HTTP-фильтры и сломает RESP. Префикс tcp- переводит порт
|
||
# в режим обычного TCP-проксирования.
|
||
portName:
|
||
_default: tcp-redis
|
||
|
||
imagePullSecrets:
|
||
enabled:
|
||
_default: true
|
||
name:
|
||
_default: regcred
|