Commit Graph

1267 Commits

Author SHA1 Message Date
d37c229249 ++ default local-path storage class to retain 2026-09-01 18:21:48 +03:00
ivan
2c252e52b2 ++ 2026-09-01 18:23:40 +05:00
ivan
4b9f6869e5 ++ 2026-09-01 17:45:25 +05:00
ivan
dbd9e25017 ++ 2026-09-01 14:42:10 +05:00
da34ec0bdf ++ exclude jwt-secret from flux-managed superset render 2026-09-01 11:28:33 +03:00
ivan
b441d1c913 ++ 2026-08-31 23:46:11 +05:00
ivan
6efd29da18 fix(brusnika-stage): битые внутрикластерные ссылки + чистка мусорных оверлеев
- django/s3-proxy: образ export-project -> s3-proxy:stable
- message-hub: backend-service.pm -> backend-svc.pm
- processing: documentations-filestream-service -> documentations-filestream
- resources: minio-service -> minio-svc
- documentations: bim-api-service -> backend-service.bim:8000;
  inspections-service -> backend-service.inspections:8000;
  remarks-static-service.remarks -> remarks-static.issues:80
- notes: sarex-* namespace -> реальные, documentations-service -> documentations-api,
  sarex-processing -> ns workflow / workflows-api-service,
  BASE_HOST уралхим -> test.sarex.brusnika.tech/notes
- подключён inspections в clusters/brusnika-stage/kustomization.yaml
- удалены мёртвые копипаст-оверлеи cross-section/faas/prescriptions/comparisons
  (нигде не подключены, побайтовые копии documentations/drawings)

brusnika-prod не трогаем.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 20:51:07 +05:00
ivan
37063d38e1 feat(bi): standalone-оверлеи bi для ugok, brusnika-stage, brusnika-prod
Не наследуют base (vault-native) — отдельные HelmRelease на universal-chart
с обычными secretEnvs, как остальные сервисы этих контуров. Свои хосты,
имена сервисов и kafka-bootstrap на контур; KAFKA_ENABLE=0, поэтому kafka
без секретов. Подключены к соответствующим clusters/*/kustomization.yaml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 19:51:23 +05:00
ivan
0cfb386c90 fix(bi): bi-backend слушает :8000, не :80
Приложение (gunicorn/uvicorn) биндится на 0.0.0.0:8000. Service targetPort
и containerPort были 80 -> istio -> svc:80 -> pod:80 (никто не слушает) -> 503.
targetPort и deployment.port -> 8000, service.port остаётся 80 (в него бьёт VS).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 17:04:23 +05:00
ivan
0c7f1f63e9 ++ 2026-08-31 16:56:22 +05:00
ivan
9591d770be ++ 2026-08-31 16:55:22 +05:00
ivan
1ffe61ea88 feat(bi/d8-ugmk-prod): istio-маршруты для bi на sarex-bi.uralmine.com
/analytics-v2/api/ -> /api/  -> bi-backend-service.bi:80
/analytics-v2/static/, /analytics-v2/ -> / -> bi-frontend-frontend-svc.bi:80
Префиксы уже, чем catch-all `/` -> superset на том же хосте.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:54:09 +05:00
ivan
ce5280bef1 ++ 2026-08-31 16:33:57 +05:00
ivan
55156efab2 ++ 2026-08-31 16:23:28 +05:00
ivan
d3a973adea feat(bi): новое приложение bi (ns bi) на universal-chart + подключение к d8-ugmk-prod
apps/bi/base — bi-backend (vault-native, SA bi-vault) и bi-frontend.
apps/bi/d8-ugmk-prod — патч env под контур УГМК (хосты issues/eav/pm,
AUTH_HOST, kafka), namespace с deckhouse pod-policy.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:08:29 +05:00
ivan
710f20a98e fix(flows/brusnika-stage): не создавать backend-service из celery HR
celery.yaml и backend.yaml оба рендерили Service backend-service; релиз
celery выигрывал владение и ставил селектор app=celery -> трафик уходил
в celery-под -> 503. service.enabled: false, как в brusnika-prod.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 16:08:29 +05:00
ivan
42ff0855ed ++ 2026-08-31 14:54:08 +05:00
ivan
96e42f9899 ++ 2026-08-31 14:49:47 +05:00
ivan
ba72d321ba change images brusnika stage 2026-08-31 13:52:56 +05:00
ivan
eeb0330ed2 ++ 2026-08-31 01:23:17 +05:00
ivan
23cf83d92b ++ 2026-08-29 15:42:18 +05:00
ivan
bfa97c8286 ++ 2026-08-29 14:17:45 +05:00
ivan
6125cc9f4b ++ 2026-08-29 13:43:21 +05:00
ivan
c7c8f2683a ++ 2026-08-29 13:42:08 +05:00
ivan
9f7af7e39e ++ 2026-08-29 12:57:51 +05:00
ivan
dfcf9423f2 ++ 2026-08-29 12:55:04 +05:00
ivan
b8755c7399 ++ 2026-08-29 12:53:22 +05:00
ivan
bee1882830 ++ 2026-08-29 12:50:53 +05:00
ivan
75922e886e ++ 2026-08-29 04:54:22 +05:00
ivan
8dae7c76c7 ++ 2026-08-29 04:33:09 +05:00
ivan
43e8fd5408 ++ 2026-08-29 04:07:08 +05:00
ivan
2233069ce1 ++ 2026-08-29 04:00:37 +05:00
ivan
068badbe0b ++ 2026-08-29 03:57:01 +05:00
ivan
b757fa5452 ++ 2026-08-29 03:52:37 +05:00
ivan
ee9819a42f ++ 2026-08-29 03:38:35 +05:00
ivan
9cab91c074 ++ 2026-08-29 03:12:46 +05:00
ivan
3a6ee99866 ++ 2026-08-29 02:41:33 +05:00
ivan
60218f2306 ++ 2026-08-29 01:53:29 +05:00
ivan
98f5d6c0ae ugok: fix 11 images that regressed to cr.yandex during vault rebuild
The standalone rebuild in the previous commit reconstructed several
services from base/wb reference values and missed re-applying the
cr.yandex -> 10.4.10.187 registry swap for: checklists, issues/frontend,
contracts, drawings, flows (backend/celery/frontend),
documentations/pdf-markings, django/s3-proxy, django/srx-admin,
inspections. All 32 previously wb-synced images now verified back on
10.4.10.187:80/library.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-29 01:41:52 +05:00
ivan
2077174ef6 ++ 2026-08-29 01:37:04 +05:00
ivan
742a811313 ugok: rebuild all apps as standalone HelmReleases, drop vault-native base
Root cause: apps/*/ugok extended ../base via kustomize patches, but base
is vault-native (Vault Agent Injector annotations + serviceAccount +
command/args wrapper sourcing /vault/secrets/*). The Vault Agent Injector
webhook IS deployed cluster-wide in ugok (infrastructure/vault/ugok), so
it actually intercepted these pods — but no per-app Vault roles/secrets
were ever provisioned there, so every pod hung in Init.

Fix, mirrored from apps/*/wb (which never extends base for these apps):
rebuild every affected app as a standalone HelmRelease per service, with
no serviceAccount/podAnnotations override and no vault-sourcing wrapper
in command/args (dropped entirely, or replaced with the real functional
command where base's wrapper did double duty — e.g. celery invocations,
pm's `python manage.py migrate`, pdf-markings-amqp's `start-amqp-worker`).

Also recreates ConfigMaps that were referenced by name in volumes but
never actually captured into the repo (eav, subscriptions, pm, issues,
django) — copied verbatim from the cluster dump and verified byte-for-byte
against it.

Incidental bugs found and fixed along the way:
- message-hub was still extending base (missed in an earlier pass).
- system-log's patches targeted services.api/services.worker while base
  uses services.backend for both — would have produced duplicate
  Deployments per release, one of them permanently vault-broken.
- contracts' real container port is 8080, not base's default 8000.
- drawings' Service.targetPort (8000) didn't match the real containerPort
  (8080), breaking routing.
- inspections/ugok was missing entirely from this pass.

apps/documentations: intentionally left without a redis Deployment even
though VALKEY_ADDR now points at one — the cluster dump has no redis in
that namespace, so provisioning one is a scope decision, not a bug fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-29 01:22:21 +05:00
ivan
1cab84dc7b ++ 2026-08-29 00:35:12 +05:00
ivan
ded06de176 change images ugok 2026-08-29 00:32:55 +05:00
ivan
5009d7826a ++ 2026-08-29 00:05:54 +05:00
ivan
e5c01279b7 ugok: bootstrap application layer on universal-chart from cluster dump
Adds apps/<app>/ugok overlays for 31 applications, derived strictly from
a live cluster dump (kubectl get deployment/service/configmap/secret),
following the wb overlay pattern (standalone HelmRelease patches on
universal-chart, plain k8s Secret + secretKeyRef instead of Vault Agent
since the ugok cluster has zero Vault usage cluster-wide).

- processing (workflow namespace) does not extend base: base is
  vault-native, ugok is not, so it's four standalone HelmReleases
  modeled on apps/processing/wb/*.
- issues/redis and django/redis are raw Deployments patched via JSON6902.
- documentations/pdf-markings and django/auth-flow-frontend,
  export-project are copied in as standalone files (base has no
  HelmRelease for them, and kustomize forbids cross-overlay references
  outside a directory's own tree).
- Images and images-with-registry updated to match wb where the same
  build lineage applies; left as-is where the wb tag carries a distinct
  client/cluster name (donstroi1, brusnika_*, dev4, UGOK_*, ugok1_*) or
  points at a different image repository entirely.
- Missing backend envs backfilled from wb where safe (internal
  svc.cluster.local refs, feature flags, already-established ugok
  domains); skipped where wb-specific (external DB/Kafka hosts, TLS CA
  content, features not deployed in ugok like gatekeeper/Superset).
- message-hub patch was missing its entire env block from the original
  bootstrap; rebuilt from the raw dump (not wb, whose Kafka/DB config is
  incompatible) plus a handful of small env gaps found while
  cross-checking every ugok app's rendered envs against the raw dump.

clusters/ugok/kustomization.yaml keeps the apps section commented out —
not wired into the Flux Kustomization yet, pending review.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-28 23:41:50 +05:00
ivan
935f8fa372 Revert "brusnika-stage: align images with wb, add missing backend envs"
This reverts commit e18124c73a.
2026-08-28 19:03:00 +05:00
ivan
e18124c73a brusnika-stage: align images with wb, add missing backend envs
Образы подтянуты под теги wb там, где это один и тот же сервис.
В backend-файлах добавлены недостающие env-переменные — с адаптацией
доменов под конвенцию brusnika-stage (test.sarex.brusnika.tech), без
слепого копирования wb-специфичных значений (доменов/секретов).

Не тронуты apps/comparisons/brusnika-stage/backend.yaml,
apps/faas/brusnika-stage/backend.yaml, apps/notes/brusnika-stage/backend.yaml —
по содержимому принадлежат другим приложениям/клиенту, требуют отдельного
разбора.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-28 16:00:24 +05:00
bd62e7c153 ++ force empty nodeselector and tolerations for ugok vault 2026-08-28 13:21:49 +03:00
75cecf0321 ++ add vault install for ugok 2026-08-28 13:14:11 +03:00
de24873d04 ++ revert bad certSecretRef field on gitrepository 2026-08-28 12:58:36 +03:00