Compare commits
144 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 7c2cc383c1 | |||
|
|
26c05888f6 | ||
|
|
510cf875f4 | ||
| d37c229249 | |||
|
|
2c252e52b2 | ||
|
|
4b9f6869e5 | ||
|
|
dbd9e25017 | ||
| da34ec0bdf | |||
|
|
b441d1c913 | ||
|
|
6efd29da18 | ||
|
|
37063d38e1 | ||
|
|
0cfb386c90 | ||
|
|
0c7f1f63e9 | ||
|
|
9591d770be | ||
|
|
1ffe61ea88 | ||
|
|
ce5280bef1 | ||
|
|
55156efab2 | ||
|
|
d3a973adea | ||
|
|
710f20a98e | ||
|
|
42ff0855ed | ||
|
|
96e42f9899 | ||
|
|
ba72d321ba | ||
|
|
eeb0330ed2 | ||
|
|
23cf83d92b | ||
|
|
bfa97c8286 | ||
|
|
6125cc9f4b | ||
|
|
c7c8f2683a | ||
|
|
9f7af7e39e | ||
|
|
dfcf9423f2 | ||
|
|
b8755c7399 | ||
|
|
bee1882830 | ||
|
|
75922e886e | ||
|
|
8dae7c76c7 | ||
|
|
43e8fd5408 | ||
|
|
2233069ce1 | ||
|
|
068badbe0b | ||
|
|
b757fa5452 | ||
|
|
ee9819a42f | ||
|
|
9cab91c074 | ||
|
|
3a6ee99866 | ||
|
|
60218f2306 | ||
|
|
98f5d6c0ae | ||
|
|
2077174ef6 | ||
|
|
742a811313 | ||
|
|
1cab84dc7b | ||
|
|
ded06de176 | ||
|
|
5009d7826a | ||
|
|
e5c01279b7 | ||
|
|
935f8fa372 | ||
|
|
e18124c73a | ||
| bd62e7c153 | |||
| 75cecf0321 | |||
| de24873d04 | |||
| f39659f7bf | |||
| d9703b0c19 | |||
|
|
bebb4e9900 | ||
|
|
dff652819a | ||
| b911b7ea50 | |||
| 2bbf786aa6 | |||
| 7b5f249581 | |||
| 09b0d4e8d1 | |||
| 30e58fdc30 | |||
| 9e66a1e31d | |||
| 8bbc158e49 | |||
| d2df6afaa4 | |||
| f051fd67b8 | |||
| 4420efb5a1 | |||
| c38032e64e | |||
| 9db6db713a | |||
| b5acdf28b5 | |||
| e2c3079ab1 | |||
| 83262697c0 | |||
| 5b3fb7d3f6 | |||
| abb6c45590 | |||
| 98f8ad1635 | |||
|
|
765f68f3b7 | ||
| 88b58158de | |||
| e44528627c | |||
| b5efcc378c | |||
| 29cc95ef33 | |||
|
|
dd0dcfecd4 | ||
|
|
4c5f812003 | ||
|
|
2647f2554b | ||
|
|
c6dff71420 | ||
|
|
8357ccee8a | ||
|
|
c5f95ee66f | ||
|
|
2ca8360388 | ||
|
|
3830144269 | ||
|
|
2ee621bf3e | ||
|
|
4a0d099ba7 | ||
|
|
d077847c00 | ||
| fb1a36c2fd | |||
| c45150bc98 | |||
|
|
047e2e6a91 | ||
|
|
e7ce7d09a0 | ||
| 1cb049ba9b | |||
| 327212ea6f | |||
| 3b5a6ddcc0 | |||
|
|
4baf5ae1b6 | ||
|
|
38bb4de76c | ||
| 34c05548f6 | |||
|
|
4b15a60589 | ||
|
|
dab050c6ed | ||
|
|
390cf969d6 | ||
|
|
adff1623dd | ||
| 4198f1dfbc | |||
| 9ee7e1f76a | |||
| 1ccb177d3c | |||
| 79cb9d3d42 | |||
| e9c582800e | |||
| 1827903c41 | |||
| 1017f93c6e | |||
| 89d5bc0f09 | |||
|
|
8aec298543 | ||
|
|
b5a1b0c151 | ||
|
|
7e7be96785 | ||
|
|
98543a457f | ||
|
|
6a239da9a7 | ||
|
|
491e3b652f | ||
|
|
a093046832 | ||
|
|
65f5418803 | ||
|
|
604c048812 | ||
|
|
c6b7b3f173 | ||
|
|
62e190f535 | ||
|
|
c6baeedd0c | ||
|
|
599eba2031 | ||
|
|
ca2b2c5523 | ||
|
|
ba0e3be067 | ||
|
|
661e90da61 | ||
|
|
67610ef269 | ||
|
|
744db30c5d | ||
|
|
e854d6064a | ||
| 0e9172fb88 | |||
| 5bd29a46f1 | |||
| eb2192b8f0 | |||
|
|
fbdad7f412 | ||
| 60d2901a0e | |||
| 1ae2a13198 | |||
| 802f0b44fc | |||
| 9391ea9c82 | |||
| dabd39f34d | |||
|
|
e1287ee464 | ||
|
|
e3867c012c | ||
| c10d84861f |
3
.gitignore
vendored
3
.gitignore
vendored
@ -1,8 +1,9 @@
|
|||||||
.idea
|
.idea
|
||||||
.claude
|
.claude
|
||||||
CLAUDE.md
|
|
||||||
.env
|
.env
|
||||||
|
|
||||||
tmp
|
tmp
|
||||||
.tmp/
|
.tmp/
|
||||||
snapshots/*
|
snapshots/*
|
||||||
|
scripts/.venv
|
||||||
|
scripts
|
||||||
81
CLAUDE.md
Normal file
81
CLAUDE.md
Normal file
@ -0,0 +1,81 @@
|
|||||||
|
# Карта репозитория
|
||||||
|
|
||||||
|
Навигационный индекс `infra/iac`: где что лежит, какие здесь конвенции путей и на чём легко ошибиться. Для быстрого входа новым людям и для агентов (файл автоматически подхватывается Claude Code).
|
||||||
|
|
||||||
|
Не дублирует [README.md](README.md) (как пользоваться Flux, как добавить компонент) и [IAC-CATALOG.md](IAC-CATALOG.md) (подробный каталог всего estate `infra/*`) — отсылает к ним.
|
||||||
|
|
||||||
|
## Что это за репозиторий
|
||||||
|
|
||||||
|
Только **FluxCD v2 (GitOps) + Kustomize-оверлеи + HelmRelease**.
|
||||||
|
|
||||||
|
Здесь принципиально **нет** и искать бесполезно:
|
||||||
|
|
||||||
|
| Что | Где искать |
|
||||||
|
|---|---|
|
||||||
|
| Terraform / Terragrunt | `infra/terraform`, `infra/terraform-contour`, `infra/terraform-contour-mirror` |
|
||||||
|
| Ansible | `infra/ansible-playbooks`, `ansible-patroni-cluster`, `ansible-minio-cluster` |
|
||||||
|
| Провижининг кластеров | `infra/kubespray`, `infra/k8s-provision` |
|
||||||
|
| ArgoCD (контур ГПН) | `infra/iac-gpn` |
|
||||||
|
| CI сборки образов | `generic/common-ci`, `generic/base-image` |
|
||||||
|
| Push-деплой через `.helm/` (ветка = контур) | ~60 компонентных репозиториев, см. `IAC-CATALOG.md` §4 |
|
||||||
|
|
||||||
|
Чарты тянутся из `oci://cr.yandex/crp3ccidau046kdj8g9q/charts`, образы — `cr.yandex/crp3ccidau046kdj8g9q/<name>:<tag>`. Все приложения ставятся на общий чарт `universal-chart`; значения обёрнуты в ключ `_default` и выбираются по `global.env`.
|
||||||
|
|
||||||
|
## Дерево
|
||||||
|
|
||||||
|
| Путь | Что |
|
||||||
|
|---|---|
|
||||||
|
| `clusters/` | 10 точек входа Flux — **источник истины «что где раскатано»** |
|
||||||
|
| `infrastructure/` | 36 платформенных компонентов |
|
||||||
|
| `apps/` | 37 прикладных сервисов |
|
||||||
|
| `docs/apps/` | 35 mermaid-диаграмм по сервисам + `README.md` с доменной группировкой |
|
||||||
|
| `docs/closed-contour-deployment.md` | ранбук поднятия закрытого контура |
|
||||||
|
| `README.md` | mermaid-мегакарта платформы, структура репозитория, инструкции по добавлению app / infra / кластера |
|
||||||
|
| `IAC-CATALOG.md` | каталог всего `infra/*`; §5 — про этот репозиторий |
|
||||||
|
| `inventory.yaml` | сгенерированный снимок прода: 59 namespace → kind → имена |
|
||||||
|
|
||||||
|
## Конвенции путей
|
||||||
|
|
||||||
|
**Кластер.** `clusters/<cluster>/kustomization.yaml` — плоский список `../../apps/<app>/<cluster>`. Инфраструктура подключается двумя разными способами:
|
||||||
|
|
||||||
|
- `d8-ugmk-prod` — прямо в корневом kustomization как `../../infrastructure/<comp>/d8-ugmk-prod`;
|
||||||
|
- `brusnika-prod`, `brusnika-stage`, `wb` — через `clusters/<c>/infrastructure/kustomization.yaml`, который ссылается на `../../../infrastructure/<comp>` (резолвится в `base`), а различия лежат в `clusters/<c>/infrastructure/patches/*.yaml`.
|
||||||
|
|
||||||
|
Кластеры: `brusnika-prod`, `brusnika-stage`, `d8-ugmk-prod`, `wb`, `yc-cps-prod`, `yc-ecp`, `yc-infra-prod`, `yc-k8s-test`, `yc-k8s-test-02`, `contour`.
|
||||||
|
|
||||||
|
**Приложение.** `apps/<app>/base/` — по одному `.yaml` на процесс (`backend.yaml`, `celery.yaml`, `frontend.yaml`) плюс `namespace.yaml`; оверлеи в `apps/<app>/<cluster>/`. Namespace = имя приложения. Рядом с манифестами лежит документация: `CONFIGURATION.md` (все env-переменные и откуда берутся), `ENDPOINTS.md` (исходящие HTTP-вызовы), `openapi.yaml` (входящий контракт), `.env.example`. Если процессов несколько — файлы с префиксом процесса: `api.ENDPOINTS.md`, `pdm.CONFIGURATION.md`, `frontend.CONFIGURATION.md`.
|
||||||
|
|
||||||
|
**Инфра-компонент.** `infrastructure/<comp>/base/` + оверлеи `<comp>/<cluster>/`. Корневой `infrastructure/<comp>/kustomization.yaml` всегда указывает просто на `base`. Чарты идут с суффиксом контура: `vault-contour`, `keycloak-contour`, `postgresql-contour` и — внимание — `idp-contour` это Zitadel.
|
||||||
|
|
||||||
|
## Где искать конкретное
|
||||||
|
|
||||||
|
| Вопрос | Файл |
|
||||||
|
|---|---|
|
||||||
|
| Что развёрнуто в контуре X | `clusters/X/kustomization.yaml` (+ `clusters/X/infrastructure/kustomization.yaml`) |
|
||||||
|
| Откуда Flux тянет контур | `clusters/X/flux-system/gotk-sync.yaml` |
|
||||||
|
| Внешние хосты, TLS, path-роутинг | `infrastructure/istio-config/<cluster>/istio-config.yaml` либо `clusters/<c>/infrastructure/patches/istio-config.yaml` |
|
||||||
|
| Кто кого зовёт (граф сервисов) | `apps/*/ENDPOINTS.md` + env-переменные с `*.svc.cluster.local` в `apps/**/*.yaml` |
|
||||||
|
| Что делает сервис, его БД / брокер / S3 | `docs/apps/<app>.md` |
|
||||||
|
| Значение env-переменной | `apps/<app>/CONFIGURATION.md` |
|
||||||
|
| Секреты | Vault Agent Injector; путь `secrets/data/apps/<app>/postgres`, role = имя приложения, SA = `<app>-vault` |
|
||||||
|
| Тег образа в контуре | `apps/<app>/<cluster>/*.yaml`, поле `image.tag` |
|
||||||
|
| Что реально в проде по namespace | `inventory.yaml` |
|
||||||
|
| Где лежит исходный код приложения | `IAC-CATALOG.md` §5.3.8 |
|
||||||
|
|
||||||
|
## Ловушки
|
||||||
|
|
||||||
|
- **`dsinv/`** — оверлей есть у 25 приложений, но `clusters/dsinv/` не существует. Это материализованный снимок живого контура WB, а не источник деплоя. Развёрнутым не считать.
|
||||||
|
- **Две несовместимые конвенции оверлеев** (`IAC-CATALOG.md` §5.3.4). `d8-ugmk-prod`, `yc-k8s-test`, `dsinv` наследуют `base` и патчат его. `brusnika-prod`, `brusnika-stage`, `yc-ecp` — полные копии HelmRelease, которые молча дрейфуют от base. Правка `base` на них не влияет.
|
||||||
|
- **`IAC-CATALOG.md` — снимок на 05.08.2026** и по составу приложений на контур уже расходится с реальностью (там у `wb` ноль приложений, фактически 26 оверлеев). Всегда сверяться с `clusters/*/kustomization.yaml`.
|
||||||
|
- **Мегадиаграмма в `README.md` идеализирована** — рисована руками, показывает все приложения на одной Postgres и все фронтенды за `control-interface`. Проверяемые источники — env-переменные и istio-config.
|
||||||
|
- **`clusters/contour/` — не кластер, а шаблон**: в нём нет `flux-system`, только `apps.yaml`, `infrastructure.yaml`, `helm-repositories.yaml`.
|
||||||
|
- **Path-роутинг виден в репозитории только у `d8-ugmk-prod` и `yc-ecp`.** В Brusnika и WB весь прикладной трафик уходит одним правилом в `nginx-service.global-ingress` / `yet-another-nginx-service.global-ingress`, а разводка по путям происходит вне репозитория. Через Istio там публикуются только платформенные UI (Gitea, Grafana, OpenObserve, Superset, Vault, Zitadel, Camunda, MinIO).
|
||||||
|
- **Имена namespace расходятся между источниками**: `inventory.yaml` использует суффикс (`flows-prod`), `apps/` — голое имя (`flows`).
|
||||||
|
- **17 оверлеев приложений не подключены ни к одному кластеру** — мёртвый код.
|
||||||
|
- **Нет диаграмм** в `docs/apps/` для `iam`, `auth-flow`, `ams-sync`.
|
||||||
|
- **Чистые фронтенды без бэкенда в этом репозитории**: `auth-flow`, `control-interface`, `cross-section`, `document-link`, `prescriptions`, `projects`, `remarks`, `reviews`, `stamp-verification`. Бэкенд `projects` живёт в `planning/projects-backend`.
|
||||||
|
- Самые центральные сервисы по числу входящих ссылок: `documentations` (~85), `processing` / `workflow` (~76), `django` (~53), `eav` (~47), `resources` (~44), `bim` (~39), `flows` (~38). Менять их конфигурацию — дороже всего.
|
||||||
|
|
||||||
|
## Поддержка файла
|
||||||
|
|
||||||
|
Карта описывает структуру и конвенции, а не текущий состав. Обновлять при появлении нового кластера, смене конвенции оверлеев или когда очередная ловушка перестаёт быть правдой. Списки приложений и версии сюда не дублировать — для этого есть `clusters/*/kustomization.yaml` и `IAC-CATALOG.md`.
|
||||||
@ -85,6 +85,20 @@ spec:
|
|||||||
_default: regcred
|
_default: regcred
|
||||||
labels:
|
labels:
|
||||||
monitoring: prometheus
|
monitoring: prometheus
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: cm-ya-ca-cert
|
||||||
|
mountPath:
|
||||||
|
_default: /etc/ca-certificates/Yandex/
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: kafka-cert
|
||||||
|
items:
|
||||||
|
- key: YandexInternalRootCA.crt
|
||||||
|
path:
|
||||||
|
_default: YandexInternalRootCA.crt
|
||||||
|
|
||||||
envs:
|
envs:
|
||||||
- name: AMS_SYNC_TOPIC
|
- name: AMS_SYNC_TOPIC
|
||||||
|
|||||||
6
apps/ams-sync/ugok/kustomization.yaml
Normal file
6
apps/ams-sync/ugok/kustomization.yaml
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: ams-sync
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
11
apps/ams-sync/wb/kustomization.yaml
Normal file
11
apps/ams-sync/wb/kustomization.yaml
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: ams-sync
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: patch.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: ams-sync
|
||||||
55
apps/ams-sync/wb/patch.yaml
Normal file
55
apps/ams-sync/wb/patch.yaml
Normal file
@ -0,0 +1,55 @@
|
|||||||
|
---
|
||||||
|
# Патч для контура wb.
|
||||||
|
#
|
||||||
|
# ВНИМАНИЕ: envs — список, kustomize заменяет его ЦЕЛИКОМ (JSON merge patch),
|
||||||
|
# поэтому здесь продублирован весь набор из apps/ams-sync/base/helmrelease.yaml.
|
||||||
|
#
|
||||||
|
# В base image-тег и USER_SERVER_HOST/AUTH_HOST зашиты под другого клиента
|
||||||
|
# (sarex.ugok.lan, образ ams-sync:ugok) — для wb это srx.wb.ru.
|
||||||
|
# secretEnvs (telegram/zitadel/kafka/db) не трогаем — они читаются из обычных
|
||||||
|
# k8s Secret'ов (не vault-agent), которые в wb уже должны быть заведены отдельно.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: ams-sync
|
||||||
|
namespace: ams-sync
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
envs:
|
||||||
|
- name: AMS_SYNC_TOPIC
|
||||||
|
value:
|
||||||
|
_default: "ams-sync"
|
||||||
|
|
||||||
|
- name: ENVIRONMENT
|
||||||
|
value:
|
||||||
|
_default: "PRODUCTION"
|
||||||
|
|
||||||
|
- name: HOST_ORGANIZATION_ID
|
||||||
|
value:
|
||||||
|
_default: "368536846176636704"
|
||||||
|
|
||||||
|
- name: ALERT_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
- name: USER_SERVER_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: VERIFY_USERS
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: KAFKA_SECURITY_PROTOCOL
|
||||||
|
value:
|
||||||
|
_default: "SSL"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_MECHANISM
|
||||||
|
value:
|
||||||
|
_default: "SCRAM-SHA-512"
|
||||||
144
apps/attachments/ugok/backend.yaml
Normal file
144
apps/attachments/ugok/backend.yaml
Normal file
@ -0,0 +1,144 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/attachments/wb/backend.yaml — base
|
||||||
|
# vault-native, а в ugok Vault не используется. Command/args/serviceAccount
|
||||||
|
# из base не нужны и не нужны были даже вживую: реальный дамп кластера
|
||||||
|
# показывает, что контейнер стартует штатным entrypoint'ом образа без
|
||||||
|
# обёртки и без выделенного serviceAccount, а креды S3 монтируются
|
||||||
|
# напрямую секретом attachments-s3-secret (не генерируются скриптом).
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: attachments
|
||||||
|
namespace: attachments
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
attachments:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/att9:dev
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: attachments
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: attachments-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: attachments-s3-secret
|
||||||
|
mountPath:
|
||||||
|
_default: /etc/sarex/yc-s3-storage
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
secret:
|
||||||
|
secretName:
|
||||||
|
_default: attachments-s3-secret
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8000
|
||||||
|
- name: YANDEX_S3_ACCOUNT_PATH
|
||||||
|
value:
|
||||||
|
_default: /etc/sarex/yc-s3-storage/yc-s3-service-account.json
|
||||||
|
- name: BUCKET_NAME
|
||||||
|
value:
|
||||||
|
_default: attachments-storage
|
||||||
|
- name: DATABASE_SSL_MODE
|
||||||
|
value:
|
||||||
|
_default: disable
|
||||||
|
- name: YANDEX_S3_VERIFY
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
- name: YANDEX_S3_USE_SSL
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
secretName:
|
||||||
|
_default: attachments-postgresql-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
secretName:
|
||||||
|
_default: attachments-postgresql-secret
|
||||||
|
secretKey: port
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
secretName:
|
||||||
|
_default: attachments-postgresql-secret
|
||||||
|
secretKey: database
|
||||||
|
- name: DATABASE_USER
|
||||||
|
secretName:
|
||||||
|
_default: attachments-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: attachments-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
7
apps/attachments/ugok/kustomization.yaml
Normal file
7
apps/attachments/ugok/kustomization.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — см. комментарий в backend.yaml.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: attachments
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
166
apps/attachments/wb/backend.yaml
Normal file
166
apps/attachments/wb/backend.yaml
Normal file
@ -0,0 +1,166 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: attachments
|
||||||
|
namespace: attachments
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
attachments:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/att9:dev
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: attachments
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 63m
|
||||||
|
memory:
|
||||||
|
_default: 205Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 164Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: attachments-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: yc-s3
|
||||||
|
mountPath:
|
||||||
|
_default: /etc/sarex/yc-s3-storage
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
secret:
|
||||||
|
secretName:
|
||||||
|
_default: yc-s3
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0:8000"
|
||||||
|
|
||||||
|
- name: YANDEX_S3_ACCOUNT_PATH
|
||||||
|
value:
|
||||||
|
_default: "/etc/sarex/yc-s3-storage/yc-s3-service-account.json"
|
||||||
|
|
||||||
|
- name: BUCKET_NAME
|
||||||
|
value:
|
||||||
|
_default: "attachments-storage"
|
||||||
|
|
||||||
|
- name: DATABASE_SSL_MODE
|
||||||
|
value:
|
||||||
|
_default: "disable"
|
||||||
|
|
||||||
|
- name: YANDEX_S3_VERIFY
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
- name: YANDEX_S3_USE_SSL
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "port"
|
||||||
|
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "database"
|
||||||
|
|
||||||
|
- name: DATABASE_USER
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
namespace: measurements
|
namespace: attachments
|
||||||
resources:
|
resources:
|
||||||
- backend.yaml
|
- backend.yaml
|
||||||
192
apps/bi/base/backend.yaml
Normal file
192
apps/bi/base/backend.yaml
Normal file
@ -0,0 +1,192 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-backend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
main:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
serviceAccount:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: bi-vault
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-backend:production_37902c73
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["/bin/sh", "-ec"]
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- |
|
||||||
|
set -a
|
||||||
|
[ -f /vault/secrets/bi-db ] && . /vault/secrets/bi-db
|
||||||
|
[ -f /vault/secrets/bi-jwt ] && . /vault/secrets/bi-jwt
|
||||||
|
set +a
|
||||||
|
exec /opt/entrypoint.sh
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 500m
|
||||||
|
memory:
|
||||||
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: SETTINGS_DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SETTINGS_VERIFY_SSL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SETTINGS_API_V1_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/api/v1"
|
||||||
|
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://lk.sarex.io"
|
||||||
|
|
||||||
|
- name: WORKER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
|
||||||
|
- name: PYTHONPATH
|
||||||
|
value:
|
||||||
|
_default: "src"
|
||||||
|
|
||||||
|
- name: ISSUES_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://sarex-issues-service.issues-prod"
|
||||||
|
|
||||||
|
- name: EAV_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://eav-service.eav-prod"
|
||||||
|
|
||||||
|
- name: PM_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://pm-backend-service.pm-prod:8000"
|
||||||
|
|
||||||
|
- name: SUPERSET_SYSTEM_WIDGETS
|
||||||
|
value:
|
||||||
|
_default: '{"MDR": {"id": "e7343f21-1ee0-4a87-b712-e8cfd413cc49","name": "MDR"},"SC": {"id": "d63d25e4-eab6-452f-8b31-065094bc2cb6","name": "Стройконтроль"}}'
|
||||||
|
|
||||||
|
- name: SUPERSET_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://lk.sarex.io/documentations/"
|
||||||
|
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["localhost:9091"]'
|
||||||
|
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-prod"}'
|
||||||
|
|
||||||
|
- name: KAFKA_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
podAnnotations:
|
||||||
|
_default:
|
||||||
|
traffic.sidecar.istio.io/excludeOutboundPorts: "8200"
|
||||||
|
vault.hashicorp.com/agent-init-first: "true"
|
||||||
|
vault.hashicorp.com/agent-inject: "true"
|
||||||
|
vault.hashicorp.com/agent-pre-populate-only: "true"
|
||||||
|
vault.hashicorp.com/auth-path: auth/kubernetes
|
||||||
|
vault.hashicorp.com/role: bi
|
||||||
|
vault.hashicorp.com/agent-inject-secret-bi-db: secrets/data/apps/bi/postgres
|
||||||
|
vault.hashicorp.com/agent-inject-template-bi-db: |-
|
||||||
|
{{- with secret "secrets/data/apps/bi/postgres" -}}
|
||||||
|
DB_HOST={{ index .Data.data "host" }}
|
||||||
|
DB_PORT={{ index .Data.data "port" }}
|
||||||
|
DB_DATABASE={{ index .Data.data "database" }}
|
||||||
|
DB_USERNAME={{ index .Data.data "username" }}
|
||||||
|
DB_PASSWORD={{ index .Data.data "password" }}
|
||||||
|
{{- end -}}
|
||||||
|
vault.hashicorp.com/agent-inject-secret-bi-jwt: secrets/data/vault/apps/bi
|
||||||
|
vault.hashicorp.com/agent-inject-template-bi-jwt: |-
|
||||||
|
{{- with secret "secrets/data/vault/apps/bi" -}}
|
||||||
|
SUPERSET_JWT_SECRET={{ index .Data.data "SUPERSET_JWT_SECRET" }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
127
apps/bi/base/frontend.yaml
Normal file
127
apps/bi/base/frontend.yaml
Normal file
@ -0,0 +1,127 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-frontend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-frontend:contour_9cfd1a0b
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 100m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 60
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 1
|
||||||
|
failureThreshold:
|
||||||
|
_default: 3
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 30
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 1
|
||||||
|
failureThreshold:
|
||||||
|
_default: 3
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend-frontend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
8
apps/bi/base/kustomization.yaml
Normal file
8
apps/bi/base/kustomization.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: bi
|
||||||
|
resources:
|
||||||
|
- namespace.yaml
|
||||||
|
- backend.yaml
|
||||||
|
- frontend.yaml
|
||||||
7
apps/bi/base/namespace.yaml
Normal file
7
apps/bi/base/namespace.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: bi
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
191
apps/bi/brusnika-prod/backend.yaml
Normal file
191
apps/bi/brusnika-prod/backend.yaml
Normal file
@ -0,0 +1,191 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/bi/ugok — контур brusnika-prod, без Vault.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-backend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
main:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-backend:production_37902c73
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 100m
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: tcpSocket
|
||||||
|
tcpSocket:
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 20
|
||||||
|
periodSeconds:
|
||||||
|
_default: 30
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 3
|
||||||
|
failureThreshold:
|
||||||
|
_default: 5
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: tcpSocket
|
||||||
|
tcpSocket:
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 10
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 3
|
||||||
|
failureThreshold:
|
||||||
|
_default: 6
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: SETTINGS_DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SETTINGS_VERIFY_SSL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SETTINGS_API_V1_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/api/v1"
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://cde.brusnika.ru"
|
||||||
|
- name: WORKER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
- name: PYTHONPATH
|
||||||
|
value:
|
||||||
|
_default: "src"
|
||||||
|
- name: ISSUES_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://issues-service.issues.svc.cluster.local"
|
||||||
|
- name: EAV_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
|
- name: PM_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.pm.svc.cluster.local:8000"
|
||||||
|
- name: SUPERSET_SYSTEM_WIDGETS
|
||||||
|
value:
|
||||||
|
_default: '{"MDR": {"id": "e7343f21-1ee0-4a87-b712-e8cfd413cc49","name": "MDR"},"SC": {"id": "d63d25e4-eab6-452f-8b31-065094bc2cb6","name": "Стройконтроль"}}'
|
||||||
|
- name: SUPERSET_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://cde.brusnika.ru/documentations/"
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["brusnika-stage-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-prod"}'
|
||||||
|
- name: KAFKA_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: DB_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service"
|
||||||
|
- name: DB_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: DB_DATABASE
|
||||||
|
value:
|
||||||
|
_default: "bi_db"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DB_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: bi-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DB_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: bi-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: SUPERSET_JWT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: bi-superset-secret
|
||||||
|
secretKey: jwt_secret
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
96
apps/bi/brusnika-prod/frontend.yaml
Normal file
96
apps/bi/brusnika-prod/frontend.yaml
Normal file
@ -0,0 +1,96 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/bi/ugok.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-frontend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-frontend:production_afb137d4
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 50m
|
||||||
|
memory:
|
||||||
|
_default: 64Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend-frontend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
8
apps/bi/brusnika-prod/kustomization.yaml
Normal file
8
apps/bi/brusnika-prod/kustomization.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — standalone HelmRelease, как apps/bi/ugok.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: bi
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
|
- frontend.yaml
|
||||||
191
apps/bi/brusnika-stage/backend.yaml
Normal file
191
apps/bi/brusnika-stage/backend.yaml
Normal file
@ -0,0 +1,191 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/bi/ugok — контур brusnika-stage, без Vault.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-backend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
main:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-backend:production_37902c73
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 100m
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: tcpSocket
|
||||||
|
tcpSocket:
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 20
|
||||||
|
periodSeconds:
|
||||||
|
_default: 30
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 3
|
||||||
|
failureThreshold:
|
||||||
|
_default: 5
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: tcpSocket
|
||||||
|
tcpSocket:
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 10
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 3
|
||||||
|
failureThreshold:
|
||||||
|
_default: 6
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: SETTINGS_DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SETTINGS_VERIFY_SSL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SETTINGS_API_V1_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/api/v1"
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://test.sarex.brusnika.tech"
|
||||||
|
- name: WORKER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
- name: PYTHONPATH
|
||||||
|
value:
|
||||||
|
_default: "src"
|
||||||
|
- name: ISSUES_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://issues-service.issues.svc.cluster.local"
|
||||||
|
- name: EAV_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
|
- name: PM_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.pm.svc.cluster.local:8000"
|
||||||
|
- name: SUPERSET_SYSTEM_WIDGETS
|
||||||
|
value:
|
||||||
|
_default: '{"MDR": {"id": "e7343f21-1ee0-4a87-b712-e8cfd413cc49","name": "MDR"},"SC": {"id": "d63d25e4-eab6-452f-8b31-065094bc2cb6","name": "Стройконтроль"}}'
|
||||||
|
- name: SUPERSET_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://test.sarex.brusnika.tech/documentations/"
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["brusnika-stage-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-prod"}'
|
||||||
|
- name: KAFKA_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: DB_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service"
|
||||||
|
- name: DB_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: DB_DATABASE
|
||||||
|
value:
|
||||||
|
_default: "bi_db"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DB_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: bi-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DB_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: bi-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: SUPERSET_JWT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: bi-superset-secret
|
||||||
|
secretKey: jwt_secret
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
96
apps/bi/brusnika-stage/frontend.yaml
Normal file
96
apps/bi/brusnika-stage/frontend.yaml
Normal file
@ -0,0 +1,96 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/bi/ugok.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-frontend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-frontend:production_afb137d4
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 50m
|
||||||
|
memory:
|
||||||
|
_default: 64Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend-frontend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
8
apps/bi/brusnika-stage/kustomization.yaml
Normal file
8
apps/bi/brusnika-stage/kustomization.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — standalone HelmRelease, как apps/bi/ugok.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: bi
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
|
- frontend.yaml
|
||||||
66
apps/bi/d8-ugmk-prod/backend.yaml
Normal file
66
apps/bi/d8-ugmk-prod/backend.yaml
Normal file
@ -0,0 +1,66 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-backend
|
||||||
|
namespace: bi
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
main:
|
||||||
|
envs:
|
||||||
|
- name: SETTINGS_DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SETTINGS_VERIFY_SSL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SETTINGS_API_V1_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/api/v1"
|
||||||
|
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.uralmine.com"
|
||||||
|
|
||||||
|
- name: WORKER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
|
||||||
|
- name: PYTHONPATH
|
||||||
|
value:
|
||||||
|
_default: "src"
|
||||||
|
|
||||||
|
- name: ISSUES_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.issues.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: EAV_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.eav.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: PM_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-svc.pm.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: SUPERSET_SYSTEM_WIDGETS
|
||||||
|
value:
|
||||||
|
_default: '{"MDR": {"id": "e7343f21-1ee0-4a87-b712-e8cfd413cc49","name": "MDR"},"SC": {"id": "d63d25e4-eab6-452f-8b31-065094bc2cb6","name": "Стройконтроль"}}'
|
||||||
|
|
||||||
|
- name: SUPERSET_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.uralmine.com/documentations/"
|
||||||
|
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["kafka-kafka-contour.kafka.svc.cluster.local:9092"]'
|
||||||
|
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-prod"}'
|
||||||
|
|
||||||
|
- name: KAFKA_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
14
apps/bi/d8-ugmk-prod/kustomization.yaml
Normal file
14
apps/bi/d8-ugmk-prod/kustomization.yaml
Normal file
@ -0,0 +1,14 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: namespace.yaml
|
||||||
|
target:
|
||||||
|
kind: Namespace
|
||||||
|
name: bi
|
||||||
|
- path: backend.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: bi-backend
|
||||||
8
apps/bi/d8-ugmk-prod/namespace.yaml
Normal file
8
apps/bi/d8-ugmk-prod/namespace.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Namespace
|
||||||
|
metadata:
|
||||||
|
name: bi
|
||||||
|
labels:
|
||||||
|
istio-injection: enabled
|
||||||
|
security.deckhouse.io/pod-policy: privileged
|
||||||
194
apps/bi/ugok/backend.yaml
Normal file
194
apps/bi/ugok/backend.yaml
Normal file
@ -0,0 +1,194 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/bi/base + apps/eav/ugok — в ugok
|
||||||
|
# Vault не используется, поэтому не наследуем base (vault-native), а собираем
|
||||||
|
# отдельный HelmRelease с обычными secretEnvs, без serviceAccount /
|
||||||
|
# podAnnotations / vault-обёртки в command/args.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-backend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
main:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/bi-backend:production_37902c73
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 100m
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: tcpSocket
|
||||||
|
tcpSocket:
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 20
|
||||||
|
periodSeconds:
|
||||||
|
_default: 30
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 3
|
||||||
|
failureThreshold:
|
||||||
|
_default: 5
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: tcpSocket
|
||||||
|
tcpSocket:
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 10
|
||||||
|
timeoutSeconds:
|
||||||
|
_default: 3
|
||||||
|
failureThreshold:
|
||||||
|
_default: 6
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: SETTINGS_DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SETTINGS_VERIFY_SSL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SETTINGS_API_V1_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/api/v1"
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.ugok.lan"
|
||||||
|
- name: WORKER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
- name: PYTHONPATH
|
||||||
|
value:
|
||||||
|
_default: "src"
|
||||||
|
- name: ISSUES_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://issues-service.issues.svc.cluster.local"
|
||||||
|
- name: EAV_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
|
- name: PM_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend-service.pm.svc.cluster.local:8000"
|
||||||
|
- name: SUPERSET_SYSTEM_WIDGETS
|
||||||
|
value:
|
||||||
|
_default: '{"MDR": {"id": "e7343f21-1ee0-4a87-b712-e8cfd413cc49","name": "MDR"},"SC": {"id": "d63d25e4-eab6-452f-8b31-065094bc2cb6","name": "Стройконтроль"}}'
|
||||||
|
- name: SUPERSET_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://sarex.ugok.lan/documentations/"
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["ugok-prod-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-prod"}'
|
||||||
|
- name: KAFKA_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: DB_HOST
|
||||||
|
value:
|
||||||
|
_default: "postgres-service"
|
||||||
|
- name: DB_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: DB_DATABASE
|
||||||
|
value:
|
||||||
|
_default: "bi_db"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DB_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: bi-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DB_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: bi-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: SUPERSET_JWT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: bi-superset-secret
|
||||||
|
secretKey: jwt_secret
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
95
apps/bi/ugok/frontend.yaml
Normal file
95
apps/bi/ugok/frontend.yaml
Normal file
@ -0,0 +1,95 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-frontend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/bi-frontend:production_afb137d4
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 50m
|
||||||
|
memory:
|
||||||
|
_default: 64Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-frontend-frontend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
9
apps/bi/ugok/kustomization.yaml
Normal file
9
apps/bi/ugok/kustomization.yaml
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — в ugok Vault не используется.
|
||||||
|
# Отдельные standalone HelmRelease с обычными secretEnvs.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: bi
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
|
- frontend.yaml
|
||||||
162
apps/bi/wb/backend.yaml
Normal file
162
apps/bi/wb/backend.yaml
Normal file
@ -0,0 +1,162 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-backend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
main:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-backend:production_e607dcc6
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 500m
|
||||||
|
memory:
|
||||||
|
_default: 1Gi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: bi-backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: SETTINGS_DEBUG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SETTINGS_VERIFY_SSL
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SETTINGS_API_V1_PREFIX
|
||||||
|
value:
|
||||||
|
_default: "/api/v1"
|
||||||
|
- name: AUTH_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
- name: WORKER_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "120"
|
||||||
|
- name: PYTHONPATH
|
||||||
|
value:
|
||||||
|
_default: "src"
|
||||||
|
- name: ISSUES_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://issues-service.issues.svc.cluster.local:80"
|
||||||
|
- name: EAV_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://eav-service.eav.svc.cluster.local:8000"
|
||||||
|
- name: PM_SERVICE_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://pm-backend-service.pm.svc.cluster.local:8000"
|
||||||
|
- name: SUPERSET_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://bi-srx.wb.ru"
|
||||||
|
- name: SUPERSET_SYSTEM_WIDGETS
|
||||||
|
value:
|
||||||
|
_default: '{"MDR":{"id":"29dea0fc-67c0-472f-a580-da5aca52076a","name":"MDR"}}'
|
||||||
|
- name: SUPERSET_SYSTEM_DASHBOARDS_JSON
|
||||||
|
value:
|
||||||
|
_default: '{"MDR": {"id": "29dea0fc-67c0-472f-a580-da5aca52076a", "name": "MDR"}}'
|
||||||
|
- name: SUPERSET_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru/documentations/"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DB_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: pg-secret
|
||||||
|
secretKey: user
|
||||||
|
- name: DB_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: pg-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: DB_DATABASE
|
||||||
|
secretName:
|
||||||
|
_default: pg-secret
|
||||||
|
secretKey: database
|
||||||
|
- name: DB_HOST
|
||||||
|
secretName:
|
||||||
|
_default: pg-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: DB_PORT
|
||||||
|
secretName:
|
||||||
|
_default: pg-secret
|
||||||
|
secretKey: port
|
||||||
|
- name: SUPERSET_JWT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: superset-jwt-secret
|
||||||
|
secretKey: jwt_secret
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
95
apps/bi/wb/frontend.yaml
Normal file
95
apps/bi/wb/frontend.yaml
Normal file
@ -0,0 +1,95 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: bi-frontend
|
||||||
|
namespace: bi
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
static:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bi-frontend:contour_9cfd1a0b
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: static
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 50m
|
||||||
|
memory:
|
||||||
|
_default: 64Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: static-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
7
apps/bi/wb/kustomization.yaml
Normal file
7
apps/bi/wb/kustomization.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: bi
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
|
- frontend.yaml
|
||||||
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:prod_b0bd750b
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:donstroi1
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
228
apps/bim/ugok/backend.yaml
Normal file
228
apps/bim/ugok/backend.yaml
Normal file
@ -0,0 +1,228 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease — base vault-native, в ugok Vault не используется.
|
||||||
|
# Образ оставлен как был в ugok (donstroi1 в wb — похоже на билд другого
|
||||||
|
# клиента, не переносим — см. предыдущее решение).
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: bim
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/bim-backend-v2:prod_2bde8e0a
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /ping
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 60
|
||||||
|
failureThreshold:
|
||||||
|
_default: 10
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /ping
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 5
|
||||||
|
periodSeconds:
|
||||||
|
_default: 5
|
||||||
|
failureThreshold:
|
||||||
|
_default: 20
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "100000"
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "94015"
|
||||||
|
- name: LAST_MASTER_BIM_V3
|
||||||
|
value:
|
||||||
|
_default: "100000"
|
||||||
|
- name: LAST_SLAVE_1_BIM_V3
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: DB_CERT_PATH_2
|
||||||
|
value:
|
||||||
|
_default: /root/yandex_pg.pem
|
||||||
|
- name: DB_CERT_PATH_3
|
||||||
|
value:
|
||||||
|
_default: /root/yandex_pg.pem
|
||||||
|
- name: DB_CERT_PATH_4
|
||||||
|
value:
|
||||||
|
_default: /root/yandex_pg.pem
|
||||||
|
- name: POSTGRES_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: postgresql-service
|
||||||
|
- name: POSTGRES_ADDRESS_2
|
||||||
|
value:
|
||||||
|
_default: postgresql-service
|
||||||
|
- name: POSTGRES_ADDRESS_3
|
||||||
|
value:
|
||||||
|
_default: postgresql-service
|
||||||
|
- name: POSTGRES_ADDRESS_4
|
||||||
|
value:
|
||||||
|
_default: postgresql-service
|
||||||
|
- name: POSTGRES_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: POSTGRES_PORT_2
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: POSTGRES_PORT_3
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: POSTGRES_PORT_4
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value:
|
||||||
|
_default: bim_db
|
||||||
|
- name: POSTGRES_DB_2
|
||||||
|
value:
|
||||||
|
_default: bim_db
|
||||||
|
- name: POSTGRES_DB_3
|
||||||
|
value:
|
||||||
|
_default: bim_db
|
||||||
|
- name: POSTGRES_DB_4
|
||||||
|
value:
|
||||||
|
_default: bim_db
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8000
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend.django.svc.cluster.local:8000
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: POSTGRES_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: POSTGRES_USER_2
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: POSTGRES_PASSWORD_2
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: POSTGRES_USER_3
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: POSTGRES_PASSWORD_3
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: POSTGRES_USER_4
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: POSTGRES_PASSWORD_4
|
||||||
|
secretName:
|
||||||
|
_default: bim-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
7
apps/bim/ugok/kustomization.yaml
Normal file
7
apps/bim/ugok/kustomization.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — см. комментарий в backend.yaml.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: bim
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
234
apps/bim/wb/backend.yaml
Normal file
234
apps/bim/wb/backend.yaml
Normal file
@ -0,0 +1,234 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: bim
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/bim-backend-v2:donstroi1
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 51Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 34Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "100000"
|
||||||
|
|
||||||
|
- name: LAST_MASTER_BIM_V3
|
||||||
|
value:
|
||||||
|
_default: "100000"
|
||||||
|
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "1000000"
|
||||||
|
|
||||||
|
- name: POSTGRES_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "sarex-vpsql-01.xc.wb.ru"
|
||||||
|
|
||||||
|
- name: POSTGRES_PORT
|
||||||
|
value:
|
||||||
|
_default: "6432"
|
||||||
|
|
||||||
|
- name: POSTGRES_DB
|
||||||
|
value:
|
||||||
|
_default: "bim_db"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_2
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|
||||||
|
- name: POSTGRES_ADDRESS_2
|
||||||
|
value:
|
||||||
|
_default: "sarex-vpsql-01.xc.wb.ru"
|
||||||
|
|
||||||
|
- name: POSTGRES_PORT_2
|
||||||
|
value:
|
||||||
|
_default: "6432"
|
||||||
|
|
||||||
|
- name: POSTGRES_DB_2
|
||||||
|
value:
|
||||||
|
_default: "bim_db"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_3
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|
||||||
|
- name: POSTGRES_ADDRESS_3
|
||||||
|
value:
|
||||||
|
_default: "sarex-vpsql-01.xc.wb.ru"
|
||||||
|
|
||||||
|
- name: POSTGRES_PORT_3
|
||||||
|
value:
|
||||||
|
_default: "6432"
|
||||||
|
|
||||||
|
- name: POSTGRES_DB_3
|
||||||
|
value:
|
||||||
|
_default: "bim_db"
|
||||||
|
|
||||||
|
- name: DB_CERT_PATH_4
|
||||||
|
value:
|
||||||
|
_default: "/root/yandex_pg.pem"
|
||||||
|
|
||||||
|
- name: POSTGRES_ADDRESS_4
|
||||||
|
value:
|
||||||
|
_default: "sarex-vpsql-01.xc.wb.ru"
|
||||||
|
|
||||||
|
- name: POSTGRES_PORT_4
|
||||||
|
value:
|
||||||
|
_default: "6432"
|
||||||
|
|
||||||
|
- name: POSTGRES_DB_4
|
||||||
|
value:
|
||||||
|
_default: "bim_db"
|
||||||
|
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0:8000"
|
||||||
|
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://backend.django.svc.cluster.local:8000"
|
||||||
|
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: POSTGRES_USER
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: POSTGRES_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: POSTGRES_USER_2
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: POSTGRES_PASSWORD_2
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: POSTGRES_USER_3
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: POSTGRES_PASSWORD_3
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: POSTGRES_USER_4
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: POSTGRES_PASSWORD_4
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
namespace: measurements
|
namespace: bim
|
||||||
resources:
|
resources:
|
||||||
- backend.yaml
|
- backend.yaml
|
||||||
File diff suppressed because it is too large
Load Diff
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/checklists-backend:preprod_b1980fc6
|
_default: cr.yandex/crp3ccidau046kdj8g9q/checklists-backend:production_3d148228
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
134
apps/checklists/ugok/backend.yaml
Normal file
134
apps/checklists/ugok/backend.yaml
Normal file
@ -0,0 +1,134 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/checklists/wb/backend.yaml — base
|
||||||
|
# vault-native, в ugok Vault не используется.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: checklists
|
||||||
|
namespace: checklists
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
checklists:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/checklists-backend:production_3d148228
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: checklists-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: checklists-backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: HTTP_APP_HOST
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0"
|
||||||
|
- name: HTTP_APP_PORT
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
- name: HTTP_APP_ROOT_PATH
|
||||||
|
value:
|
||||||
|
_default: /checklists
|
||||||
|
- name: HTTP_APP_WORKERS
|
||||||
|
value:
|
||||||
|
_default: "8"
|
||||||
|
- name: HTTP_APP_ADMIN_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: JWT_AUTH_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: DEBUG
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
secretName:
|
||||||
|
_default: checklists-postgresql-secret
|
||||||
|
secretKey: hostname
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
secretName:
|
||||||
|
_default: checklists-postgresql-secret
|
||||||
|
secretKey: port
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
secretName:
|
||||||
|
_default: checklists-postgresql-secret
|
||||||
|
secretKey: database
|
||||||
|
- name: DATABASE_USER
|
||||||
|
secretName:
|
||||||
|
_default: checklists-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: checklists-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: JWT_AUTH_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: checklists-public-key
|
||||||
|
secretKey: key
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
7
apps/checklists/ugok/kustomization.yaml
Normal file
7
apps/checklists/ugok/kustomization.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — см. комментарий в backend.yaml.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: checklists
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
157
apps/checklists/wb/backend.yaml
Normal file
157
apps/checklists/wb/backend.yaml
Normal file
@ -0,0 +1,157 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: checklists-backend
|
||||||
|
namespace: checklists
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
checklists-backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/checklists-backend:production_3d148228
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: checklists-backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 1023Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 818Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: checklists-backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: HTTP_APP_HOST
|
||||||
|
value:
|
||||||
|
_default: "0.0.0.0"
|
||||||
|
|
||||||
|
- name: HTTP_APP_PORT
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
- name: HTTP_APP_ROOT_PATH
|
||||||
|
value:
|
||||||
|
_default: "/checklists"
|
||||||
|
|
||||||
|
- name: HTTP_APP_WORKERS
|
||||||
|
value:
|
||||||
|
_default: "8"
|
||||||
|
|
||||||
|
- name: HTTP_APP_ADMIN_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "sarex-vpsql-01.xc.wb.ru"
|
||||||
|
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
value:
|
||||||
|
_default: "checklists_db"
|
||||||
|
|
||||||
|
- name: JWT_AUTH_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: DEBUG
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DATABASE_USER
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "user"
|
||||||
|
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: JWT_AUTH_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "jwt-secret"
|
||||||
|
secretKey: "public-key"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -1,6 +1,6 @@
|
|||||||
---
|
---
|
||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
kind: Kustomization
|
kind: Kustomization
|
||||||
namespace: measurements
|
namespace: checklists
|
||||||
resources:
|
resources:
|
||||||
- backend.yaml
|
- backend.yaml
|
||||||
228
apps/comparisons/ugok/backend.yaml
Normal file
228
apps/comparisons/ugok/backend.yaml
Normal file
@ -0,0 +1,228 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease — base vault-native, в ugok Vault не используется.
|
||||||
|
# volumes (tasks-execution-config) убраны: в живом дампе кластера у backend
|
||||||
|
# нет volumeMounts вообще, ни такого ConfigMap'а в namespace.
|
||||||
|
# Образ оставлен как в ugok (в wb — другое имя репозитория образа целиком,
|
||||||
|
# не просто тег, см. предыдущее решение по этому приложению).
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: comparisons
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/comparisons-backend:c864f102a3a476b9a80658148da2b3f7acb772ac
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /ping
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 10
|
||||||
|
periodSeconds:
|
||||||
|
_default: 60
|
||||||
|
failureThreshold:
|
||||||
|
_default: 10
|
||||||
|
readiness:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
type:
|
||||||
|
_default: httpGet
|
||||||
|
httpGet:
|
||||||
|
path:
|
||||||
|
_default: /ping
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
initialDelaySeconds:
|
||||||
|
_default: 5
|
||||||
|
periodSeconds:
|
||||||
|
_default: 5
|
||||||
|
failureThreshold:
|
||||||
|
_default: 20
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: HTTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "8080"
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "100_000"
|
||||||
|
- name: APP_NAME
|
||||||
|
value:
|
||||||
|
_default: comparisons-api-v2
|
||||||
|
- name: APP_VERSION
|
||||||
|
value:
|
||||||
|
_default: 0.0.1
|
||||||
|
- name: LOGGER_LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: info
|
||||||
|
- name: DATABASE_HOST
|
||||||
|
value:
|
||||||
|
_default: postgres-service
|
||||||
|
- name: DATABASE_PORT
|
||||||
|
value:
|
||||||
|
_default: "5432"
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
value:
|
||||||
|
_default: postgres
|
||||||
|
- name: DATABASE_DB
|
||||||
|
value:
|
||||||
|
_default: comparisons_db
|
||||||
|
- name: API_ADDRESS
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8080
|
||||||
|
- name: API_ADDRESS_FILE
|
||||||
|
value:
|
||||||
|
_default: 0.0.0.0:8080
|
||||||
|
- name: ENABLE_SQL_QUERY
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: DOCUMENTATIONS_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://documentations-api.documentations.svc.cluster.local:8080
|
||||||
|
- name: DOCUMENTATIONS_EXTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://documentations-api.documentations.svc.cluster.local:8080/
|
||||||
|
- name: DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: http://documentations-api.documentations.svc.cluster.local:8080/
|
||||||
|
- name: DOCUMENTATION_FILESTREAM_URL
|
||||||
|
value:
|
||||||
|
_default: http://documentations-filestream.documentations.svc.cluster.local:8080/
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://workflows-api-service.workflow.svc.cluster.local:8000/
|
||||||
|
- name: EAV_HOST
|
||||||
|
value:
|
||||||
|
_default: http://eav-service.eav.svc.cluster.local:8000
|
||||||
|
- name: WORKSPACES_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.workspaces.svc.cluster.local:8000/
|
||||||
|
- name: COMPARISON_URL
|
||||||
|
value:
|
||||||
|
_default: http://backend-service.comparisons.svc.cluster.local:8000/
|
||||||
|
- name: WORKFLOWS_IMAGE_VERSION
|
||||||
|
value:
|
||||||
|
_default: master
|
||||||
|
- name: EXTERNAL_DOCUMENTATION_URL
|
||||||
|
value:
|
||||||
|
_default: http://documentations-api.documentations.svc.cluster.local:8080/
|
||||||
|
- name: WORKFLOWS_BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend-svc.bim.svc.cluster.local:8000/
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: WORKFLOWS_DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend.django.svc.cluster.local:8000
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "94015"
|
||||||
|
- name: LAST_SLAVE_2_BIM
|
||||||
|
value:
|
||||||
|
_default: "135771"
|
||||||
|
- name: ABAP_FIXED_CONC
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: WORKFLOWS_CONFIG_FILEPATH
|
||||||
|
value:
|
||||||
|
_default: /etc/app/tasks-execution-config.json
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DATABASE_USER
|
||||||
|
secretName:
|
||||||
|
_default: comparisons-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DATABASE_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: comparisons-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: AUTH_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: public-key
|
||||||
|
secretKey: key
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
88
apps/comparisons/ugok/frontend.yaml
Normal file
88
apps/comparisons/ugok/frontend.yaml
Normal file
@ -0,0 +1,88 @@
|
|||||||
|
---
|
||||||
|
# volumes (nginx-configmap) убраны: в живом дампе кластера у frontend нет
|
||||||
|
# volumeMounts и такого ConfigMap'а в namespace.
|
||||||
|
# Образ оставлен как в ugok (в wb — другое имя репозитория образа целиком).
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: comparisons
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/comparisons-frontend-static:69d50235fdc8fd654ae63308e23fc27f28e9cd99_relative
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
8
apps/comparisons/ugok/kustomization.yaml
Normal file
8
apps/comparisons/ugok/kustomization.yaml
Normal file
@ -0,0 +1,8 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (backend vault-native) — см. комментарии в файлах.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: comparisons
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
|
- frontend.yaml
|
||||||
94
apps/comparisons/wb/backend.yaml
Normal file
94
apps/comparisons/wb/backend.yaml
Normal file
@ -0,0 +1,94 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: comparisons
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
envs:
|
||||||
|
- name: APP_NAME
|
||||||
|
value:
|
||||||
|
_default: "comparisons"
|
||||||
|
|
||||||
|
- name: APP_VERSION
|
||||||
|
value:
|
||||||
|
_default: "0.0.1"
|
||||||
|
|
||||||
|
- name: LOGGER_LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: "info"
|
||||||
|
|
||||||
|
- name: DATABASE_NAME
|
||||||
|
value:
|
||||||
|
_default: "postgres"
|
||||||
|
|
||||||
|
- name: ENABLE_SSL
|
||||||
|
value:
|
||||||
|
_default: "false"
|
||||||
|
|
||||||
|
- name: POSTGRES_POOL_SIZE
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
|
||||||
|
- name: HTTP_PORT
|
||||||
|
value:
|
||||||
|
_default: "8000"
|
||||||
|
|
||||||
|
- name: DOCUMENTATIONS_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://documentations-service.documentations"
|
||||||
|
|
||||||
|
- name: DOCUMENTATIONS_EXTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://lk.srx.wb.ru:30443/documentations"
|
||||||
|
|
||||||
|
- name: DOCUMENTATION_FILESTREAM_URL
|
||||||
|
value:
|
||||||
|
_default: "http://backend-filestream-svc.documentations.svc.cluster.local/"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workflows-service.workflow"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_IMAGE_VERSION
|
||||||
|
value:
|
||||||
|
_default: "master"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://lk.srx.wb.ru:30443"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://bim-backend-v2-service.bim-api"
|
||||||
|
|
||||||
|
- name: WORKSPACES_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://workspaces-service.workspaces"
|
||||||
|
|
||||||
|
- name: EAV_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://lk.srx.wb.ru:30443/eav"
|
||||||
|
|
||||||
|
- name: LAST_MASTER_BIM
|
||||||
|
value:
|
||||||
|
_default: "36311"
|
||||||
|
|
||||||
|
- name: LAST_SLAVE_1_BIM
|
||||||
|
value:
|
||||||
|
_default: "94015"
|
||||||
|
|
||||||
|
- name: LAST_SLAVE_2_BIM
|
||||||
|
value:
|
||||||
|
_default: "135771"
|
||||||
|
|
||||||
|
- name: ABAP_FIXED_CONC
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_CONFIG_FILEPATH
|
||||||
|
value:
|
||||||
|
_default: "/etc/app/tasks-execution-config.json"
|
||||||
11
apps/comparisons/wb/kustomization.yaml
Normal file
11
apps/comparisons/wb/kustomization.yaml
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: comparisons
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: backend.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: backend
|
||||||
94
apps/contracts/ugok/backend.yaml
Normal file
94
apps/contracts/ugok/backend.yaml
Normal file
@ -0,0 +1,94 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease по образцу apps/contracts/wb/backend.yaml — base
|
||||||
|
# vault-native, в ugok Vault не используется.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: contracts
|
||||||
|
namespace: contracts
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
contracts:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/contracts:prod_d3bbd9fc
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DB_URL
|
||||||
|
secretName:
|
||||||
|
_default: contracts-postgresql-secret
|
||||||
|
secretKey: url
|
||||||
|
- name: PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: contracts-public-key
|
||||||
|
secretKey: key
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
7
apps/contracts/ugok/kustomization.yaml
Normal file
7
apps/contracts/ugok/kustomization.yaml
Normal file
@ -0,0 +1,7 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (vault-native) — см. комментарий в backend.yaml.
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: contracts
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
111
apps/contracts/wb/backend.yaml
Normal file
111
apps/contracts/wb/backend.yaml
Normal file
@ -0,0 +1,111 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: contracts
|
||||||
|
namespace: contracts
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
contracts:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/contracts:prod_d3bbd9fc
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: contracts
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 48Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 32Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: contracts-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: DB_URL
|
||||||
|
secretName:
|
||||||
|
_default: "ya-pg-secret"
|
||||||
|
secretKey: "db_url"
|
||||||
|
|
||||||
|
- name: PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "public-key"
|
||||||
|
secretKey: "key"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
6
apps/contracts/wb/kustomization.yaml
Normal file
6
apps/contracts/wb/kustomization.yaml
Normal file
@ -0,0 +1,6 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: contracts
|
||||||
|
resources:
|
||||||
|
- backend.yaml
|
||||||
11
apps/control-interface/ugok/kustomization.yaml
Normal file
11
apps/control-interface/ugok/kustomization.yaml
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: control-interface
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: patch.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: frontend
|
||||||
13
apps/control-interface/ugok/patch.yaml
Normal file
13
apps/control-interface/ugok/patch.yaml
Normal file
@ -0,0 +1,13 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: control-interface
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/srx-admin:prod_638c3442
|
||||||
11
apps/cross-section/ugok/kustomization.yaml
Normal file
11
apps/cross-section/ugok/kustomization.yaml
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: cross-section
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: patch.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: cross-section-static
|
||||||
15
apps/cross-section/ugok/patch.yaml
Normal file
15
apps/cross-section/ugok/patch.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
# В ugok образ реально называется cross-section-static (не cross-section-app,
|
||||||
|
# как в base) — берём как есть из дампа кластера.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: cross-section-static
|
||||||
|
namespace: cross-section
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/cross-section-static:988a872bfe72ca29ffa6a43e074b94118e9e655a
|
||||||
@ -101,6 +101,7 @@ Module Federation) конфигурируется отдельно на этап
|
|||||||
| `JWT_PUBLIC_KEY` | string | — | Публичный RSA-ключ проверки |
|
| `JWT_PUBLIC_KEY` | string | — | Публичный RSA-ключ проверки |
|
||||||
| `JWT_KID` | string | `None` | `kid` в заголовке токена (используется для межсервисных вызовов) |
|
| `JWT_KID` | string | `None` | `kid` в заголовке токена (используется для межсервисных вызовов) |
|
||||||
| `DJANGO_JWT_SECRET` | string | `Froom too much love of living` | Легаси-секрет |
|
| `DJANGO_JWT_SECRET` | string | `Froom too much love of living` | Легаси-секрет |
|
||||||
|
| `SERVER_SUPERSET_JWT_SECRET` | string | `""` | hmac-секрет для embedded superset guest token. В контуре wb берётся из k8s-секрета `superset-jwt-secret`, ключ `jwt_secret` |
|
||||||
|
|
||||||
### Celery (`CELERY_*`)
|
### Celery (`CELERY_*`)
|
||||||
|
|
||||||
@ -299,11 +300,19 @@ Module Federation) конфигурируется отдельно на этап
|
|||||||
| `django-kafka` | `secrets/data/kafka/apps/django` | `KAFKA_BOOTSTRAP_SERVERS/SECURITY_PROTOCOL/SASL_*` |
|
| `django-kafka` | `secrets/data/kafka/apps/django` | `KAFKA_BOOTSTRAP_SERVERS/SECURITY_PROTOCOL/SASL_*` |
|
||||||
| `django-jwt-private` / `django-jwt-public` | `secrets/data/vault/common/rsa_keys` | `JWT_PRIVATE_KEY` / `JWT_PUBLIC_KEY` |
|
| `django-jwt-private` / `django-jwt-public` | `secrets/data/vault/common/rsa_keys` | `JWT_PRIVATE_KEY` / `JWT_PUBLIC_KEY` |
|
||||||
| `django-common` | `secrets/data/vault/common/django_auth` | `ZITADEL_ACCESS_TOKEN` |
|
| `django-common` | `secrets/data/vault/common/django_auth` | `ZITADEL_ACCESS_TOKEN` |
|
||||||
|
| `superset-jwt-secret` | k8s-секрет в неймспейсе `django` | `SERVER_SUPERSET_JWT_SECRET` для `/api/analytics/widgets/<id>/superset_guest_token/` |
|
||||||
|
|
||||||
Контейнер экспортирует эти файлы в окружение до запуска (`set -a; . /vault/secrets/...`).
|
Контейнер экспортирует эти файлы в окружение до запуска (`set -a; . /vault/secrets/...`).
|
||||||
Кроме того, `production.py` из ConfigMap содержит функцию `_load_env_file`, которая
|
Кроме того, `production.py` из ConfigMap содержит функцию `_load_env_file`, которая
|
||||||
подхватывает те же файлы при запуске `manage.py` через `kubectl exec` вне entrypoint.
|
подхватывает те же файлы при запуске `manage.py` через `kubectl exec` вне entrypoint.
|
||||||
|
|
||||||
|
Для wb superset guest token не использует сервисную учётку Guest Token API: backend
|
||||||
|
формирует jwt локально и подписывает его `SERVER_SUPERSET_JWT_SECRET`, а superset
|
||||||
|
проверяет тем же значением через `GUEST_TOKEN_JWT_SECRET = os.getenv("JWT_SECRET")`.
|
||||||
|
Оба значения должны совпадать: `superset/jwt-secret` используется superset как
|
||||||
|
`JWT_SECRET`, а `django/superset-jwt-secret` используется backend как
|
||||||
|
`SERVER_SUPERSET_JWT_SECRET`.
|
||||||
|
|
||||||
Остальные (несекретные) переменные задаются в блоке `env` контейнеров
|
Остальные (несекретные) переменные задаются в блоке `env` контейнеров
|
||||||
`backend`/`celery` (`SERVER_*`, `WORKFLOWS_*`, `BIMV2_*`, `MEASUREMENTS_*`,
|
`backend`/`celery` (`SERVER_*`, `WORKFLOWS_*`, `BIMV2_*`, `MEASUREMENTS_*`,
|
||||||
`ZITADEL_HOST`, `KAFKA_TOPICS`, `EAV_ENABLE`, `PDM_SYNC`, `JWT_KID` и др.).
|
`ZITADEL_HOST`, `KAFKA_TOPICS`, `EAV_ENABLE`, `PDM_SYNC`, `JWT_KID` и др.).
|
||||||
|
|||||||
@ -296,6 +296,10 @@ data:
|
|||||||
"name": "Запросы",
|
"name": "Запросы",
|
||||||
"uri": "/rfi"
|
"uri": "/rfi"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"name": "Аналитика",
|
||||||
|
"uri": "/analytics"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"name": "Управление проектами",
|
"name": "Управление проектами",
|
||||||
"uri": "/management/projects"
|
"uri": "/management/projects"
|
||||||
|
|||||||
@ -29,7 +29,7 @@ spec:
|
|||||||
enabled: true
|
enabled: true
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-frontend-dev:contour_5.22.0
|
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-frontend-dev:contour_5.22.3
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
deployment:
|
deployment:
|
||||||
|
|||||||
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_8f05291e
|
_default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_7d0ec48b
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/export-project:prod_37a48176
|
_default: cr.yandex/crp3ccidau046kdj8g9q/export-project:prod_ef8aa756
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/export-project:prod_37a48176
|
_default: cr.yandex/crp3ccidau046kdj8g9q/s3-proxy:stable
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
@ -93,6 +93,12 @@ spec:
|
|||||||
- name: APP_PORT
|
- name: APP_PORT
|
||||||
value:
|
value:
|
||||||
_default: "8000"
|
_default: "8000"
|
||||||
|
- name: ACCESS_LOG
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: CORS_ALLOW_HEADERS
|
||||||
|
value:
|
||||||
|
_default: "Content-Type, Accept-Ranges, Content-Range, Content-Encoding"
|
||||||
secretEnvs:
|
secretEnvs:
|
||||||
- name: AWS_ACCESS_KEY_ID
|
- name: AWS_ACCESS_KEY_ID
|
||||||
secretName:
|
secretName:
|
||||||
|
|||||||
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_8f05291e
|
_default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_7d0ec48b
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
@ -35,7 +35,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-frontend-dev:contour_5.16.3
|
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-frontend-dev:contour_5.22.3
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
91
apps/django/ugok/auth-flow-frontend.yaml
Normal file
91
apps/django/ugok/auth-flow-frontend.yaml
Normal file
@ -0,0 +1,91 @@
|
|||||||
|
---
|
||||||
|
# Скопировано из apps/django/wb/auth-flow-frontend.yaml (см. pdf-markings.yaml
|
||||||
|
# для причины) — компонент auth-flow, развёрнутый в ns django.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: auth-flow-frontend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
auth-flow-frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/auth-flow-frontend:contour_fe9ea2a3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: auth-flow-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 100m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: auth-flow-frontend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
369
apps/django/ugok/backend.yaml
Normal file
369
apps/django/ugok/backend.yaml
Normal file
@ -0,0 +1,369 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease — base vault-native, в ugok Vault не используется.
|
||||||
|
# command/args из base — только vault-обёртка (в живом дампе кластера у
|
||||||
|
# backend command/args нет вообще), не переносим.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/backend:production_7d0ec48b
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: django-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/config/settings/production.py
|
||||||
|
subPath:
|
||||||
|
_default: production.py
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: django-configmap
|
||||||
|
items:
|
||||||
|
- key: production.py
|
||||||
|
path:
|
||||||
|
_default: production.py
|
||||||
|
|
||||||
|
- name: uwsgi-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/uwsgi.ini
|
||||||
|
subPath:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: uwsgi-configmap
|
||||||
|
items:
|
||||||
|
- key: uwsgi.ini
|
||||||
|
path:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
|
||||||
|
- name: kafka-cert-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /usr/local/share/ca-certificates
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: kafka-cert
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: ALLOWED_HOSTS
|
||||||
|
value:
|
||||||
|
_default: "*"
|
||||||
|
- name: SERVER_USE_CHANGELOG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_ZITADEL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: config.settings.production
|
||||||
|
- name: CELERY_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: redis-service
|
||||||
|
- name: CELERY_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_USERNAME_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_EMAIL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: DJANGO_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: redis-service
|
||||||
|
- name: DJANGO_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
- name: BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://bim-backend-v2-service.bim-api
|
||||||
|
- name: BIMV2_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
- name: JWT_KID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: PDM_SYNC
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: KC_SYNC_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: MEASUREMENTS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://measurement-svc.measurements.svc.cluster.local:8000/api
|
||||||
|
- name: MEASUREMENTS_USE_MEASUREMENTS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_API_HOST
|
||||||
|
value:
|
||||||
|
_default: https://ugok-sarex.uralmine.com
|
||||||
|
- name: SERVER_HOST
|
||||||
|
value:
|
||||||
|
_default: https://ugok-sarex.uralmine.com
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://workflows-api-service.workflow.svc.cluster.local:8000
|
||||||
|
- name: WORKFLOWS_BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend.django.svc.cluster.local:8000
|
||||||
|
- name: WORKFLOWS_PREFIX
|
||||||
|
value:
|
||||||
|
_default: /internal/v1
|
||||||
|
- name: WORKFLOWS_USE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_S3_STREAM_IMPORT
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_SAVE_DIFF_DEM
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_USE_CLICKHOUSE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_DJANGO_STORAGE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_USE_METASHAPE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_CHANGELOG_MODE_SYSTEM_LOG
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHANGELOG_MODE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_DJANGO_URLS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: ZITADEL_HOST
|
||||||
|
value:
|
||||||
|
_default: https://ugok-zitadel-sarex.uralmine.com
|
||||||
|
- name: EAV_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHUNKED_PATH
|
||||||
|
value:
|
||||||
|
_default: /tmp/chunked_uploads/%Y/%m/%d
|
||||||
|
- name: SERVER_HIDE_USER_SCROLL_PERMISSIONS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_WRORKFLOW_STATUS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_KAFKA_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: RESOURCES_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://iams.iam.svc.cluster.local:8080
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}'
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["ugok-prod-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
- name: KAFKA_SECURITY_PROTOCOL
|
||||||
|
value:
|
||||||
|
_default: SSL
|
||||||
|
- name: KAFKA_SASL_MECHANISM
|
||||||
|
value:
|
||||||
|
_default: SCRAM-SHA-512
|
||||||
|
- name: KAFKA_SSL_CAFILE
|
||||||
|
value:
|
||||||
|
_default: /usr/local/share/ca-certificates/kafka.crt
|
||||||
|
- name: S3_HOST
|
||||||
|
value:
|
||||||
|
_default: http://minio.minio.svc.cluster.local:9000
|
||||||
|
- name: KC_USE_REDIRECT_LOGOUT
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: ZITADEL_ACCESS_TOKEN
|
||||||
|
secretName:
|
||||||
|
_default: zitadel-secret
|
||||||
|
secretKey: access_token
|
||||||
|
- name: KAFKA_SASL_PLAIN_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: kafka-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: KAFKA_SASL_PLAIN_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: kafka-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: AWS_S3_ENDPOINT_URL
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: endpoint
|
||||||
|
- name: CELERY_RABBITMQ_HOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: CELERY_RABBITMQ_USER
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: CELERY_RABBITMQ_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: CELERY_RABBITMQ_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: vhost
|
||||||
|
- name: DJANGO_POSTGRES_HOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: DJANGO_POSTGRES_PORTS
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: port
|
||||||
|
- name: DJANGO_POSTGRES_USER
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DJANGO_POSTGRES_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: DJANGO_POSTGRES_DATABASE
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: database
|
||||||
|
- name: DJANGO_RABBIT_HOSTNAME
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: DJANGO_RABBIT_USER
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DJANGO_RABBIT_PASS
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: DJANGO_RABBIT_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: vhost
|
||||||
|
- name: JWT_PRIVATE_KEY
|
||||||
|
secretName:
|
||||||
|
_default: backend-secret
|
||||||
|
secretKey: ssh_private.key
|
||||||
|
- name: JWT_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: backend-secret
|
||||||
|
secretKey: ssh_public.key
|
||||||
|
- name: S3_BUCKET
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: bucket
|
||||||
|
- name: S3_LOGIN
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: access_key
|
||||||
|
- name: S3_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: secret_key
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
360
apps/django/ugok/celery.yaml
Normal file
360
apps/django/ugok/celery.yaml
Normal file
@ -0,0 +1,360 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease — base vault-native, в ugok Vault не используется.
|
||||||
|
# command — реальная команда запуска celery из дампа кластера (не
|
||||||
|
# vault-обёртка).
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: celery
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
celery:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/backend:production_7d0ec48b
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: celery
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["celery", "-A", "config", "worker", "-B", "-l", "info", "-E", "-Q", "default", "-n", "default_worker.%h", "--concurrency=2"]
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 128Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: django-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/config/settings/production.py
|
||||||
|
subPath:
|
||||||
|
_default: production.py
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: django-configmap
|
||||||
|
items:
|
||||||
|
- key: production.py
|
||||||
|
path:
|
||||||
|
_default: production.py
|
||||||
|
|
||||||
|
- name: uwsgi-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/uwsgi.ini
|
||||||
|
subPath:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: uwsgi-configmap
|
||||||
|
items:
|
||||||
|
- key: uwsgi.ini
|
||||||
|
path:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
|
||||||
|
- name: kafka-cert-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /usr/local/share/ca-certificates
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: kafka-cert
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: ALLOWED_HOSTS
|
||||||
|
value:
|
||||||
|
_default: "*"
|
||||||
|
- name: SERVER_USE_CHANGELOG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_ZITADEL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: config.settings.production
|
||||||
|
- name: CELERY_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: redis-service
|
||||||
|
- name: CELERY_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_USERNAME_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_EMAIL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: DJANGO_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: redis-service
|
||||||
|
- name: DJANGO_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
- name: BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://bim-backend-v2-service.bim-api
|
||||||
|
- name: BIMV2_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
- name: JWT_KID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: PDM_SYNC
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: KC_SYNC_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: MEASUREMENTS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://measurement-svc.measurements.svc.cluster.local:8000/api
|
||||||
|
- name: MEASUREMENTS_USE_MEASUREMENTS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_API_HOST
|
||||||
|
value:
|
||||||
|
_default: https://ugok-sarex.uralmine.com
|
||||||
|
- name: SERVER_HOST
|
||||||
|
value:
|
||||||
|
_default: https://ugok-sarex.uralmine.com
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: http://workflows-api-service.workflow.svc.cluster.local:8000
|
||||||
|
- name: WORKFLOWS_BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: http://backend.django.svc.cluster.local:8000
|
||||||
|
- name: WORKFLOWS_PREFIX
|
||||||
|
value:
|
||||||
|
_default: /internal/v1
|
||||||
|
- name: WORKFLOWS_USE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_S3_STREAM_IMPORT
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_SAVE_DIFF_DEM
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_USE_CLICKHOUSE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_DJANGO_STORAGE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_USE_METASHAPE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_CHANGELOG_MODE_SYSTEM_LOG
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHANGELOG_MODE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_DJANGO_URLS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: EAV_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_CHUNKED_PATH
|
||||||
|
value:
|
||||||
|
_default: /tmp/chunked_uploads/%Y/%m/%d
|
||||||
|
- name: SERVER_HIDE_USER_SCROLL_PERMISSIONS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
- name: SERVER_USE_WRORKFLOW_STATUS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
- name: SERVER_KAFKA_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
- name: RESOURCES_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: http://iams.iam.svc.cluster.local:8080
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}'
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["ugok-prod-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
- name: KAFKA_SECURITY_PROTOCOL
|
||||||
|
value:
|
||||||
|
_default: SSL
|
||||||
|
- name: KAFKA_SASL_MECHANISM
|
||||||
|
value:
|
||||||
|
_default: SCRAM-SHA-512
|
||||||
|
- name: KAFKA_SSL_CAFILE
|
||||||
|
value:
|
||||||
|
_default: /usr/local/share/ca-certificates/kafka.crt
|
||||||
|
- name: S3_HOST
|
||||||
|
value:
|
||||||
|
_default: http://minio.minio.svc.cluster.local:9000
|
||||||
|
- name: CACHE_HOST
|
||||||
|
value:
|
||||||
|
_default: redis.pm.svc.cluster.local
|
||||||
|
- name: ZITADEL_HOST
|
||||||
|
value:
|
||||||
|
_default: https://ugok-zitadel-sarex.uralmine.com
|
||||||
|
- name: KC_USE_REDIRECT_LOGOUT
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: ZITADEL_ACCESS_TOKEN
|
||||||
|
secretName:
|
||||||
|
_default: zitadel-secret
|
||||||
|
secretKey: access_token
|
||||||
|
- name: KAFKA_SASL_PLAIN_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: kafka-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: KAFKA_SASL_PLAIN_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: kafka-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: AWS_S3_ENDPOINT_URL
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: endpoint
|
||||||
|
- name: CELERY_RABBITMQ_HOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: CELERY_RABBITMQ_USER
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: CELERY_RABBITMQ_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: CELERY_RABBITMQ_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: vhost
|
||||||
|
- name: DJANGO_POSTGRES_HOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: DJANGO_POSTGRES_PORTS
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: port
|
||||||
|
- name: DJANGO_POSTGRES_USER
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DJANGO_POSTGRES_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: DJANGO_POSTGRES_DATABASE
|
||||||
|
secretName:
|
||||||
|
_default: sarex-postgresql-secret
|
||||||
|
secretKey: database
|
||||||
|
- name: DJANGO_RABBIT_HOSTNAME
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: host
|
||||||
|
- name: DJANGO_RABBIT_USER
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: username
|
||||||
|
- name: DJANGO_RABBIT_PASS
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: password
|
||||||
|
- name: DJANGO_RABBIT_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: sarex-rabbitmq-secret
|
||||||
|
secretKey: vhost
|
||||||
|
- name: JWT_PRIVATE_KEY
|
||||||
|
secretName:
|
||||||
|
_default: backend-secret
|
||||||
|
secretKey: ssh_private.key
|
||||||
|
- name: JWT_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: backend-secret
|
||||||
|
secretKey: ssh_public.key
|
||||||
|
- name: S3_BUCKET
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: bucket
|
||||||
|
- name: S3_LOGIN
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: access_key
|
||||||
|
- name: S3_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: secret_key
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
10
apps/django/ugok/django-configmap.yaml
Normal file
10
apps/django/ugok/django-configmap.yaml
Normal file
File diff suppressed because one or more lines are too long
103
apps/django/ugok/export-project.yaml
Normal file
103
apps/django/ugok/export-project.yaml
Normal file
@ -0,0 +1,103 @@
|
|||||||
|
---
|
||||||
|
# Скопировано из apps/django/wb/export-project.yaml — в base нет HelmRelease
|
||||||
|
# для этого сервиса (только в wb overlay), а ссылаться на файл в другом
|
||||||
|
# оверлее kustomize не даёт (вне дерева каталога). Образ/envs совпадают с
|
||||||
|
# дампом ugok уже "из коробки" (только регистр другой — правится патчем).
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: export-project
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
export-project:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/export-project:prod_ef8aa756
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: export-project
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: "2"
|
||||||
|
memory:
|
||||||
|
_default: 8Gi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: "1"
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: export-project-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "180"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
116
apps/django/ugok/frontend.yaml
Normal file
116
apps/django/ugok/frontend.yaml
Normal file
@ -0,0 +1,116 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/sarex-frontend-dev:contour_5.22.3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: nginx-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /etc/nginx/nginx.conf
|
||||||
|
subPath:
|
||||||
|
_default: nginx.conf
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: nginx-configmap
|
||||||
|
items:
|
||||||
|
- key: nginx.conf
|
||||||
|
path:
|
||||||
|
_default: nginx.conf
|
||||||
|
|
||||||
|
- name: zitadel-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/react_client/static/config.json
|
||||||
|
subPath:
|
||||||
|
_default: config.json
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: zitadel-configmap
|
||||||
|
items:
|
||||||
|
- key: config.json
|
||||||
|
path:
|
||||||
|
_default: config.json
|
||||||
39
apps/django/ugok/kafka-cert.yaml
Normal file
39
apps/django/ugok/kafka-cert.yaml
Normal file
@ -0,0 +1,39 @@
|
|||||||
|
---
|
||||||
|
# Скопировано из живого ConfigMap кластера ugok (namespace django).
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: kafka-cert
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
kafka.crt: |
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIFLTCCAxWgAwIBAgIUD6mKIbYkBT6T/cgK3Ibgm75vRrAwDQYJKoZIhvcNAQEN
|
||||||
|
BQAwLTETMBEGA1UECgwKaW8uc3RyaW16aTEWMBQGA1UEAwwNY2x1c3Rlci1jYSB2
|
||||||
|
MDAeFw0yNjA0MTQwODQ1MTRaFw0yNzA0MTQwODQ1MTRaMC0xEzARBgNVBAoMCmlv
|
||||||
|
LnN0cmltemkxFjAUBgNVBAMMDWNsdXN0ZXItY2EgdjAwggIiMA0GCSqGSIb3DQEB
|
||||||
|
AQUAA4ICDwAwggIKAoICAQCc9ecE59Ju5JRuGr1ConD8wPINXO9jgKdctuiwZloE
|
||||||
|
eHYZGfLpEZY1v6CulK3xlVdK4rJRH7MA0r5G3+o7ZkGW4htaAz1zk71npiibLxC/
|
||||||
|
2g7MQoMsfheglB8NpVpjGlbMScCJUIbWZr6UK1JUX9kAPgZBMR3E/R24nlYiygKP
|
||||||
|
4T9EEMw0YgKFkXZl20+cH2pmaUK7219+WR/MdiQ+d+445L7DLJNYI/xn9Yoc8OQb
|
||||||
|
A63SVK5APWwGFvXAjNqrcJpvrud3Age9CRqJ+M4Y6PTu05Pf1C6GUhLfTfsdleU6
|
||||||
|
PsORiG/9DVc9rjDOvEk7pwrBYaK4u39BA5XBnppxHuAsxPjbnVAwGBia/3N2vLa4
|
||||||
|
Fht4PBIDMH0KUKDRktT+rGFdg+gl1HJ/vT2Z+HqAOdW3DUCt4aY8B10/jPWHWByq
|
||||||
|
gvRNUSJSBGeLI2Yk3pbQKerS+UOMjcmGXw8gZHSvqwEs6EAX/msSmcTS2wDbu83E
|
||||||
|
tAXrHyriNpHilIaxlizbb7h3jXVhZX7G2o0BtPqFOsV9eo0bzUcRaf8XWqXHFoGw
|
||||||
|
6rks0Q06HOTrARDhAG0qot8pQ6WIM8zYjPT5Jb+Wx2UbPbdLtqY+W/t9udL8Q+tW
|
||||||
|
eL3+4oTllSeuHtCJy/UX1/GyN+O/PAXxDeEP1AmamweftXALlMhHzV/FHJjvd2L4
|
||||||
|
rQIDAQABo0UwQzAdBgNVHQ4EFgQUlPHFj51uMcGYeqJ9bf7BRqOiWdowEgYDVR0T
|
||||||
|
AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQADggIB
|
||||||
|
ABsb407P4GzhY1in3wwA9wB2evF4WhtuBQw4Cm1/jDFv6Yhe+qTFOM8+g8RiFJl4
|
||||||
|
KfGLzzQWiBbZfyKdqYTSDjio2WJhdXjP+V9YVmnNBXAwdTJOUbKjKgZlo1CniC3O
|
||||||
|
O/xzEmohC6Vkl9Ph4aGzqMivpYfiVjRzs1TeJNzPO131HOwzLUtrXEUJ5I9AWEzE
|
||||||
|
C0QCdr38ZoXSOq+eNm7q4ANi10ElHoiUdIkgjobCu2y6m+oiaeWLhs+i/LjE93vb
|
||||||
|
hlIzsIcJRIc5hC7QIORiR4pDuoxn/WP+41wdfUfVF7FugAaPhyF5TOJgTx0baCj9
|
||||||
|
3gtCfcfsy6Md2U4GLXj0UIs5M//7s0pdjCrvyDOCbrZUQs8JUZ4viqIUqVGRSFjg
|
||||||
|
5ofP1KgOIbG225T+XaXVapJETu29ggOv/ZhGm9JHZjAKi6yCUvXS2H7VWVk1Ob+e
|
||||||
|
GAXCtCWPF8C4uM4rkNwXCYzlX4kEeGyq0PifxOlz/KDSY+5C00fK9Ke+4C3aV53v
|
||||||
|
1NDoOaOYbObWHls3jrZ4EN08vYh9RIHmLpXCTdwwPqhHj/oJSFwN9ZHh0gW5NcYW
|
||||||
|
etX8+dQHoVkJP7KDMgAJ3l3Bgh2qOh6bM4gmvAc4Kp7YdlslBxzGscnKbkfoQYl+
|
||||||
|
NK4a+hSjXnk7ttSxachKb38LSZRNBA/LGUUB3t07anjZ
|
||||||
|
-----END CERTIFICATE-----
|
||||||
21
apps/django/ugok/kustomization.yaml
Normal file
21
apps/django/ugok/kustomization.yaml
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
---
|
||||||
|
# Не наследуем base (backend/celery/s3-proxy vault-native) — см. комментарии
|
||||||
|
# в файлах. auth-flow-frontend.yaml/export-project.yaml/pdf-markings.yaml
|
||||||
|
# скопированы из wb (в base для них нет HelmRelease).
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: django
|
||||||
|
resources:
|
||||||
|
- django-configmap.yaml
|
||||||
|
- uwsgi-configmap.yaml
|
||||||
|
- kafka-cert.yaml
|
||||||
|
- nginx-configmap.yaml
|
||||||
|
- zitadel-configmap.yaml
|
||||||
|
- backend.yaml
|
||||||
|
- celery.yaml
|
||||||
|
- frontend.yaml
|
||||||
|
- s3-proxy.yaml
|
||||||
|
- srx-admin.yaml
|
||||||
|
- auth-flow-frontend.yaml
|
||||||
|
- export-project.yaml
|
||||||
|
- redis.yaml
|
||||||
188
apps/django/ugok/nginx-configmap.yaml
Normal file
188
apps/django/ugok/nginx-configmap.yaml
Normal file
@ -0,0 +1,188 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: nginx-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
nginx.conf: |
|
||||||
|
worker_processes auto;
|
||||||
|
|
||||||
|
pid /var/run/nginx.pid;
|
||||||
|
|
||||||
|
events {
|
||||||
|
use epoll;
|
||||||
|
worker_connections 1024;
|
||||||
|
}
|
||||||
|
|
||||||
|
http {
|
||||||
|
|
||||||
|
# Basic Settings
|
||||||
|
large_client_header_buffers 8 128k;
|
||||||
|
sendfile on;
|
||||||
|
tcp_nopush on;
|
||||||
|
tcp_nodelay on;
|
||||||
|
keepalive_timeout 300;
|
||||||
|
types_hash_max_size 2048;
|
||||||
|
client_max_body_size 5000M;
|
||||||
|
client_header_buffer_size 5M;
|
||||||
|
# server_tokens off;
|
||||||
|
# server_names_hash_bucket_size 64;
|
||||||
|
# server_name_in_redirect off;
|
||||||
|
include /etc/nginx/mime.types;
|
||||||
|
default_type application/octet-stream;
|
||||||
|
|
||||||
|
# Logging Settings
|
||||||
|
access_log /var/log/nginx/access.log;
|
||||||
|
error_log /var/log/nginx/error.log;
|
||||||
|
|
||||||
|
# GZIP Settings
|
||||||
|
gzip on;
|
||||||
|
gzip_vary on;
|
||||||
|
gzip_proxied any;
|
||||||
|
gzip_comp_level 6;
|
||||||
|
gzip_buffers 16 8k;
|
||||||
|
gzip_http_version 1.1;
|
||||||
|
gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;
|
||||||
|
|
||||||
|
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
|
||||||
|
'$status $body_bytes_sent "$http_referer" '
|
||||||
|
'"$http_user_agent" "$http_x_forwarded_for"';
|
||||||
|
|
||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
listen [::]:80;
|
||||||
|
root /opt/react_client/;
|
||||||
|
|
||||||
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
||||||
|
add_header 'Access-Control-Allow-Methods' '*' always;
|
||||||
|
add_header 'Access-Control-Allow-Headers' '*' always;
|
||||||
|
|
||||||
|
location = /static/index.bundle.js {
|
||||||
|
add_header Cache-Control 'no-store no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
||||||
|
if_modified_since off;
|
||||||
|
expires off;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/api/pm/ {
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://backend-service.pm.svc.cluster.local:8000;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/media/ {
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
rewrite ^/media/(.*)$ /$1 break;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://s3-proxy-service:80;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/api/v1/documents/ {
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
rewrite /api/(.+) /$1 break;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://documentations-filestream.documentations.svc.cluster.local:8080;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/(api|admin)/ {
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://backend:8000;
|
||||||
|
}
|
||||||
|
|
||||||
|
# location ~^/flows/static/ {
|
||||||
|
# rewrite /flows/static/(.+) /$1 break;
|
||||||
|
# proxy_pass http://frontend-service.flows:80;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location = ~^/orchestrator/ {
|
||||||
|
# rewrite ^/orchestrator$ /api/ break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location = ~^/orchestrator/api/process {
|
||||||
|
# rewrite ^/orchestrator/api/process$ /api/process break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location ~ ^/orchestrator/api/process/(.*)$ {
|
||||||
|
# rewrite ^/orchestrator/api/process/(.*)$ /api/process/$1 break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location = ~^/orchestrator/api/sign {
|
||||||
|
# rewrite ^/orchestrator/api/sign$ /api/sign break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
location = /static/pdf-runtime/assets/mupdf-wasm.wasm {
|
||||||
|
alias /opt/react_client/static/pdf-runtime/assets/mupdf-wasm.wasm;
|
||||||
|
add_header Content-Type application/wasm always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.js {
|
||||||
|
alias /opt/react_client/static/viewer-pdf/mupdf-wasm.js;
|
||||||
|
add_header Content-Type application/javascript always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/mupdf.worker-3.3.9.js {
|
||||||
|
alias /opt/react_client/static/pdf-runtime/mupdf.worker-3.3.9.js;
|
||||||
|
add_header Content-Type application/javascript always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf.js {
|
||||||
|
alias /opt/react_client/static/viewer-pdf/mupdf.js;
|
||||||
|
add_header Content-Type application/javascript always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.wasm {
|
||||||
|
add_header Content-Type application/wasm always;
|
||||||
|
alias /opt/react_client/static/viewer-pdf/mupdf-wasm.wasm;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/workspaces-v2/(.+).js {
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_set_header Connection "";
|
||||||
|
rewrite /workspaces-v2/(.+) /$1 break;
|
||||||
|
proxy_pass http://frontend-svc.workspaces.svc.cluster.local:8080;
|
||||||
|
}
|
||||||
|
|
||||||
|
location @index {
|
||||||
|
add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
||||||
|
if_modified_since off;
|
||||||
|
expires off;
|
||||||
|
try_files /static/index.html =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/workflows/(.+).js {
|
||||||
|
proxy_http_version 1.1;
|
||||||
|
rewrite /workflows/(.+) /$1 break;
|
||||||
|
proxy_pass http://frontend-service.workflow.svc.cluster.local:8080;
|
||||||
|
}
|
||||||
|
|
||||||
|
location /service-worker.js {
|
||||||
|
try_files /static/$uri @index;
|
||||||
|
}
|
||||||
|
|
||||||
|
location / {
|
||||||
|
try_files $uri @index;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
41
apps/django/ugok/redis.yaml
Normal file
41
apps/django/ugok/redis.yaml
Normal file
@ -0,0 +1,41 @@
|
|||||||
|
---
|
||||||
|
# Скопировано из apps/django/base/redis-deployment.yaml + redis-service.yaml —
|
||||||
|
# сырой Deployment (не universal-chart, не vault-native), перенесён в
|
||||||
|
# standalone-оверлей, чтобы не зависеть от ../base.
|
||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: redis
|
||||||
|
namespace: django
|
||||||
|
labels:
|
||||||
|
app: redis
|
||||||
|
spec:
|
||||||
|
replicas: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
app: redis
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
app: redis
|
||||||
|
spec:
|
||||||
|
containers:
|
||||||
|
- name: redis
|
||||||
|
image: 10.4.10.187:80/library/redis:latest
|
||||||
|
imagePullPolicy: Always
|
||||||
|
ports:
|
||||||
|
- containerPort: 6379
|
||||||
|
protocol: TCP
|
||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: redis
|
||||||
|
namespace: django
|
||||||
|
spec:
|
||||||
|
selector:
|
||||||
|
app: redis
|
||||||
|
ports:
|
||||||
|
- port: 6379
|
||||||
|
targetPort: 6379
|
||||||
|
protocol: TCP
|
||||||
103
apps/django/ugok/s3-proxy.yaml
Normal file
103
apps/django/ugok/s3-proxy.yaml
Normal file
@ -0,0 +1,103 @@
|
|||||||
|
---
|
||||||
|
# standalone HelmRelease — base vault-native, в ugok Vault не используется.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: s3-proxy
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
s3-proxy:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/s3-proxy:stable
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: s3-proxy
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: s3-proxy-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: AWS_API_ENDPOINT
|
||||||
|
value:
|
||||||
|
_default: http://minio.minio.svc.cluster.local:9000
|
||||||
|
- name: ACCESS_LOG
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
- name: CORS_ALLOW_HEADERS
|
||||||
|
value:
|
||||||
|
_default: "Content-Type, Accept-Ranges, Content-Range, Content-Encoding"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: AWS_ACCESS_KEY_ID
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: access_key
|
||||||
|
- name: AWS_SECRET_ACCESS_KEY
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: secret_key
|
||||||
|
- name: AWS_S3_BUCKET
|
||||||
|
secretName:
|
||||||
|
_default: sarex-s3-secret
|
||||||
|
secretKey: bucket
|
||||||
85
apps/django/ugok/srx-admin.yaml
Normal file
85
apps/django/ugok/srx-admin.yaml
Normal file
@ -0,0 +1,85 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: srx-admin-frontend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.9"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
srx-admin:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: 10.4.10.187:80/library/srx-admin:prod_638c3442
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: srx-admin-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 25m
|
||||||
|
memory:
|
||||||
|
_default: 100Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: srx-admin-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
9
apps/django/ugok/uwsgi-configmap.yaml
Normal file
9
apps/django/ugok/uwsgi-configmap.yaml
Normal file
@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
# Скопировано из живого ConfigMap кластера ugok (namespace django).
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: uwsgi-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
uwsgi.ini: "[uwsgi]\r\nmodule = config.wsgi:application\r\nDJANGO_SETTINGS_MODULE = config.settings.production\r\nhttp = 0.0.0.0:8000\r\nprocesses = 16\r\nmaster = true\r\nvacuum = true\r\nenable-threads = true\r\nbuffer-size = 65535\r\nstats = :3031\r\nstats-http = true\r\nmemory-report = true\r\nlazy-apps = true\r\nlisten = 128\r\ndisable-write-exception= 0\r\nharakiri = 300\r\nsocket-timeout = 300\r\nchunked-input-timeout = 300\r\nhttp-timeout = 300\r\nworker-reload-mercy = 240\r\nmule-reload-mercy = 240\r\nstatic-map = /static=/opt/sarex/sarex/static/\r\nstatic-map = /media=/media/\r\n"
|
||||||
17
apps/django/ugok/zitadel-configmap.yaml
Normal file
17
apps/django/ugok/zitadel-configmap.yaml
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
# Скопировано из живого ConfigMap кластера ugok (namespace django) —
|
||||||
|
# монтируется frontend в /opt/react_client/static/config.json.
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: zitadel-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
config.json: |-
|
||||||
|
{
|
||||||
|
"auth_type": "zitadel",
|
||||||
|
"zitadel": {
|
||||||
|
"client_id": "368538787334147872",
|
||||||
|
"host": "https://ugok-zitadel-sarex.uralmine.com"
|
||||||
|
}
|
||||||
|
}
|
||||||
102
apps/django/wb/auth-flow-frontend.yaml
Normal file
102
apps/django/wb/auth-flow-frontend.yaml
Normal file
@ -0,0 +1,102 @@
|
|||||||
|
---
|
||||||
|
# auth-flow-frontend — компонент приложения auth-flow (apps/auth-flow),
|
||||||
|
# в wb развёрнут в ns django, а не в своём собственном неймспейсе.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: auth-flow-frontend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
auth-flow-frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/auth-flow-frontend:contour_fe9ea2a3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: auth-flow-frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 48Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 32Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: auth-flow-frontend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
465
apps/django/wb/backend.yaml
Normal file
465
apps/django/wb/backend.yaml
Normal file
@ -0,0 +1,465 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: backend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_7d0ec48b
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 2223m
|
||||||
|
memory:
|
||||||
|
_default: 7626Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 495m
|
||||||
|
memory:
|
||||||
|
_default: 6012Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: backend-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: tmp-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /tmp
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
|
- name: uwsgi-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/uwsgi.ini
|
||||||
|
subPath:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: uwsgi-configmap
|
||||||
|
items:
|
||||||
|
- key: uwsgi.ini
|
||||||
|
path:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
|
||||||
|
- name: django-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/config/settings/production.py
|
||||||
|
subPath:
|
||||||
|
_default: production.py
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: django-configmap
|
||||||
|
items:
|
||||||
|
- key: production.py
|
||||||
|
path:
|
||||||
|
_default: production.py
|
||||||
|
|
||||||
|
- name: kafka-cert-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /usr/local/share/ca-certificates
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: kafka-cert
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: GK_ENCRYPTION_KEY
|
||||||
|
value:
|
||||||
|
_default: "zfDjuszywHSbAhY8KJQbESbpUYN74XTs"
|
||||||
|
|
||||||
|
- name: ALLOWED_HOSTS
|
||||||
|
value:
|
||||||
|
_default: "*"
|
||||||
|
|
||||||
|
- name: SERVER_USE_CHANGELOG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_ZITADEL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: "config.settings.production"
|
||||||
|
|
||||||
|
- name: CELERY_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis-service"
|
||||||
|
|
||||||
|
- name: CELERY_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
|
||||||
|
- name: DJANGO_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis-service"
|
||||||
|
|
||||||
|
- name: DJANGO_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
|
||||||
|
- name: BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://bim-backend-v2-service.bim-api"
|
||||||
|
|
||||||
|
- name: BIMV2_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
- name: JWT_KID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: PDM_SYNC
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: KC_SYNC_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: MEASUREMENTS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://measurements-service.measurements.svc.cluster.local:8000/api"
|
||||||
|
|
||||||
|
- name: MEASUREMENTS_USE_MEASUREMENTS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_USERNAME_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: SERVER_EXTERNAL_FIND_BY_EMAIL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: SERVER_API_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: SERVER_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: SERVER_SUPERSET_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://bi-srx.wb.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_USE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_S3_STREAM_IMPORT
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_SAVE_DIFF_DEM
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_USE_CLICKHOUSE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_USE_DJANGO_STORAGE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_USE_METASHAPE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_CHANGELOG_MODE_SYSTEM_LOG
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_CHANGELOG_MODE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_DJANGO_URLS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: EAV_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_CHUNKED_PATH
|
||||||
|
value:
|
||||||
|
_default: "/tmp/chunked_uploads/%Y/%m/%d"
|
||||||
|
|
||||||
|
- name: SERVER_HIDE_USER_SCROLL_PERMISSIONS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_USE_WRORKFLOW_STATUS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: ZITADEL_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://zitadel-srx.wb.ru"
|
||||||
|
|
||||||
|
- name: SERVER_KAFKA_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}'
|
||||||
|
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["wb-prod-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
|
||||||
|
- name: KAFKA_SECURITY_PROTOCOL
|
||||||
|
value:
|
||||||
|
_default: "SSL"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_MECHANISM
|
||||||
|
value:
|
||||||
|
_default: "SCRAM-SHA-512"
|
||||||
|
|
||||||
|
- name: KAFKA_SSL_CAFILE
|
||||||
|
value:
|
||||||
|
_default: "/usr/local/share/ca-certificates/kafka.crt"
|
||||||
|
|
||||||
|
- name: S3_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://10.49.10.90:9000"
|
||||||
|
|
||||||
|
- name: KC_USE_REDIRECT_LOGOUT
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: SERVER_SUPERSET_JWT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: "superset-jwt-secret"
|
||||||
|
secretKey: "jwt_secret"
|
||||||
|
|
||||||
|
- name: ZITADEL_ACCESS_TOKEN
|
||||||
|
secretName:
|
||||||
|
_default: "zitadel-secret"
|
||||||
|
secretKey: "access_token"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_PLAIN_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: "kafka-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_PLAIN_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "kafka-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: KC_CLIENT_ID
|
||||||
|
secretName:
|
||||||
|
_default: "gatekeeper-secret"
|
||||||
|
secretKey: "client_id"
|
||||||
|
|
||||||
|
- name: KC_CLIENT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: "gatekeeper-secret"
|
||||||
|
secretKey: "client_secret"
|
||||||
|
|
||||||
|
- name: AWS_S3_ENDPOINT_URL
|
||||||
|
secretName:
|
||||||
|
_default: "s3-secret"
|
||||||
|
secretKey: "endpoint"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_HOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_USER
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "vhost"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_HOST
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_PORTS
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "port"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_USER
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_DATABASE
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "database"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_HOSTNAME
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_USER
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_PASS
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "vhost"
|
||||||
|
|
||||||
|
- name: JWT_PRIVATE_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "backend-secret"
|
||||||
|
secretKey: "ssh_private.key"
|
||||||
|
|
||||||
|
- name: JWT_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "backend-secret"
|
||||||
|
secretKey: "ssh_public.key"
|
||||||
|
|
||||||
|
- name: S3_BUCKET
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "bucket"
|
||||||
|
|
||||||
|
- name: S3_LOGIN
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "login"
|
||||||
|
|
||||||
|
- name: S3_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
440
apps/django/wb/celery.yaml
Normal file
440
apps/django/wb/celery.yaml
Normal file
@ -0,0 +1,440 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: celery
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
celery:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/backend:production_7d0ec48b
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: celery
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["celery", "-A", "config", "worker", "-B", "-l", "info", "-E", "-Q", "default", "-n", "default_worker.%h", "--concurrency=2"]
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 1385Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 1107Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: tmp-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /tmp
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
|
- name: uwsgi-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/uwsgi.ini
|
||||||
|
subPath:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: uwsgi-configmap
|
||||||
|
items:
|
||||||
|
- key: uwsgi.ini
|
||||||
|
path:
|
||||||
|
_default: uwsgi.ini
|
||||||
|
|
||||||
|
- name: django-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/sarex/config/settings/production.py
|
||||||
|
subPath:
|
||||||
|
_default: production.py
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: django-configmap
|
||||||
|
items:
|
||||||
|
- key: production.py
|
||||||
|
path:
|
||||||
|
_default: production.py
|
||||||
|
|
||||||
|
- name: kafka-cert-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /usr/local/share/ca-certificates
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: kafka-cert
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: GK_ENCRYPTION_KEY
|
||||||
|
value:
|
||||||
|
_default: "zfDjuszywHSbAhY8KJQbESbpUYN74XTs"
|
||||||
|
|
||||||
|
- name: ALLOWED_HOSTS
|
||||||
|
value:
|
||||||
|
_default: "*"
|
||||||
|
|
||||||
|
- name: SERVER_USE_CHANGELOG
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_ZITADEL_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
- name: DJANGO_SETTINGS_MODULE
|
||||||
|
value:
|
||||||
|
_default: "config.settings.production"
|
||||||
|
|
||||||
|
- name: CELERY_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis-service"
|
||||||
|
|
||||||
|
- name: CELERY_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
|
||||||
|
- name: DJANGO_REDIS_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis-service"
|
||||||
|
|
||||||
|
- name: CACHE_HOST
|
||||||
|
value:
|
||||||
|
_default: "redis.pm.svc.cluster.local"
|
||||||
|
|
||||||
|
- name: DJANGO_REDIS_PORT
|
||||||
|
value:
|
||||||
|
_default: "6379"
|
||||||
|
|
||||||
|
- name: BIMV2_INTERNAL_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://bim-backend-v2-service.bim-api"
|
||||||
|
|
||||||
|
- name: BIMV2_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "60"
|
||||||
|
|
||||||
|
- name: JWT_KID
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: PDM_SYNC
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: KC_SYNC_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: MEASUREMENTS_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://measurements-service.measurements.svc.cluster.local:8000/api"
|
||||||
|
|
||||||
|
- name: MEASUREMENTS_USE_MEASUREMENTS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_API_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: SERVER_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_BASE_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://srx.wb.ru"
|
||||||
|
|
||||||
|
- name: WORKFLOWS_USE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_S3_STREAM_IMPORT
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_SAVE_DIFF_DEM
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_USE_CLICKHOUSE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_USE_CREATE_COMPARED_GEOTIFF_TASK
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_USE_DJANGO_STORAGE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_USE_METASHAPE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_CHANGELOG_MODE_SYSTEM_LOG
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: ZITADEL_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://zitadel-srx.wb.ru"
|
||||||
|
|
||||||
|
- name: SERVER_KAFKA_ENABLED
|
||||||
|
value:
|
||||||
|
_default: "True"
|
||||||
|
|
||||||
|
- name: KAFKA_TOPICS
|
||||||
|
value:
|
||||||
|
_default: '{"planning": "message-hub-stage", "ams-sync": "ams-sync"}'
|
||||||
|
|
||||||
|
- name: KAFKA_BOOTSTRAP_SERVERS
|
||||||
|
value:
|
||||||
|
_default: '["wb-prod-kafka-bootstrap.kafka.svc.cluster.local:9093"]'
|
||||||
|
|
||||||
|
- name: KAFKA_SECURITY_PROTOCOL
|
||||||
|
value:
|
||||||
|
_default: "SSL"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_MECHANISM
|
||||||
|
value:
|
||||||
|
_default: "SCRAM-SHA-512"
|
||||||
|
|
||||||
|
- name: KAFKA_SSL_CAFILE
|
||||||
|
value:
|
||||||
|
_default: "/usr/local/share/ca-certificates/kafka.crt"
|
||||||
|
|
||||||
|
- name: SERVER_CHANGELOG_MODE
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_DJANGO_URLS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: EAV_ENABLE
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_CHECK_IMPORT_HASH
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: SERVER_CHUNKED_PATH
|
||||||
|
value:
|
||||||
|
_default: "/tmp/chunked_uploads/%Y/%m/%d"
|
||||||
|
|
||||||
|
- name: SERVER_HIDE_USER_SCROLL_PERMISSIONS
|
||||||
|
value:
|
||||||
|
_default: "0"
|
||||||
|
|
||||||
|
- name: SERVER_USE_WRORKFLOW_STATUS
|
||||||
|
value:
|
||||||
|
_default: "1"
|
||||||
|
|
||||||
|
- name: S3_HOST
|
||||||
|
value:
|
||||||
|
_default: "http://10.49.10.90:9000"
|
||||||
|
|
||||||
|
- name: KC_USE_REDIRECT_LOGOUT
|
||||||
|
value:
|
||||||
|
_default: "False"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: ZITADEL_ACCESS_TOKEN
|
||||||
|
secretName:
|
||||||
|
_default: "zitadel-secret"
|
||||||
|
secretKey: "access_token"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_PLAIN_USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: "kafka-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: KAFKA_SASL_PLAIN_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "kafka-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: KC_CLIENT_ID
|
||||||
|
secretName:
|
||||||
|
_default: "gatekeeper-secret"
|
||||||
|
secretKey: "client_id"
|
||||||
|
|
||||||
|
- name: KC_CLIENT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: "gatekeeper-secret"
|
||||||
|
secretKey: "client_secret"
|
||||||
|
|
||||||
|
- name: AWS_S3_ENDPOINT_URL
|
||||||
|
secretName:
|
||||||
|
_default: "s3-secret"
|
||||||
|
secretKey: "endpoint"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_HOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_USER
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: CELERY_RABBITMQ_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "vhost"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_HOST
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_PORTS
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "port"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_USER
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: DJANGO_POSTGRES_DATABASE
|
||||||
|
secretName:
|
||||||
|
_default: "postgres-secret"
|
||||||
|
secretKey: "database"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_HOSTNAME
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_USER
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_PASS
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: DJANGO_RABBIT_VHOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq-secret"
|
||||||
|
secretKey: "vhost"
|
||||||
|
|
||||||
|
- name: JWT_PRIVATE_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "backend-secret"
|
||||||
|
secretKey: "ssh_private.key"
|
||||||
|
|
||||||
|
- name: JWT_PUBLIC_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "backend-secret"
|
||||||
|
secretKey: "ssh_public.key"
|
||||||
|
|
||||||
|
- name: S3_BUCKET
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "bucket"
|
||||||
|
|
||||||
|
- name: S3_LOGIN
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "login"
|
||||||
|
|
||||||
|
- name: S3_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
288
apps/django/wb/django-configmap.yaml
Normal file
288
apps/django/wb/django-configmap.yaml
Normal file
@ -0,0 +1,288 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: django-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
production.py: |
|
||||||
|
|
||||||
|
import os
|
||||||
|
from .base import *
|
||||||
|
from logging.handlers import SysLogHandler
|
||||||
|
from datetime import timedelta
|
||||||
|
|
||||||
|
ALLOWED_HOSTS = ["*"]
|
||||||
|
FILE_UPLOAD_PERMISSIONS = 0o644
|
||||||
|
DEBUG = False
|
||||||
|
CSRF_COOKIE_SECURE = True
|
||||||
|
CSRF_TRUSTED_ORIGINS = ["https://lk.srx.wb.ru:30443", "https://lk.srx.wb.ru"]
|
||||||
|
SESSION_COOKIE_SECURE = True
|
||||||
|
SECURE_SSL_REDIRECT = False
|
||||||
|
|
||||||
|
SECRET_KEY = 't2=9+($2f%7ptsdy4!rby$)mcfl1l%o2e@vs^d(g&(wwi&%k1v'
|
||||||
|
|
||||||
|
CORS_ORIGIN_ALLOW_ALL = True
|
||||||
|
SERVERSETTINGS.cache_enabled = True
|
||||||
|
INSTALLED_APPS = list(INSTALLED_APPS) + ['corsheaders']
|
||||||
|
|
||||||
|
CORS_ALLOW_METHODS = (
|
||||||
|
'DELETE',
|
||||||
|
'GET',
|
||||||
|
'OPTIONS',
|
||||||
|
'PATCH',
|
||||||
|
'POST',
|
||||||
|
'PUT',
|
||||||
|
)
|
||||||
|
BASIC_USER_ID = 2
|
||||||
|
|
||||||
|
CORS_ALLOW_HEADERS = (
|
||||||
|
'accept',
|
||||||
|
'accept-encoding',
|
||||||
|
'authorization',
|
||||||
|
'content-type',
|
||||||
|
'user-agent',
|
||||||
|
'x-csrftoken',
|
||||||
|
'x-requested-with',
|
||||||
|
'x-token',
|
||||||
|
'Bearer',
|
||||||
|
)
|
||||||
|
|
||||||
|
HOST = "https://wb.sarex.io"
|
||||||
|
|
||||||
|
POSTGRES_DATABASE = os.environ.get('DJANGO_POSTGRES_DATABASE')
|
||||||
|
POSTGRES_USER = os.environ.get('DJANGO_POSTGRES_USER')
|
||||||
|
POSTGRES_PASSWORD = os.environ.get('DJANGO_POSTGRES_PASSWORD')
|
||||||
|
POSTGRES_HOST = os.environ.get('DJANGO_POSTGRES_HOST')
|
||||||
|
POSTGRES_PORTS = os.environ.get('DJANGO_POSTGRES_PORTS', "5432")
|
||||||
|
|
||||||
|
DATABASES = {
|
||||||
|
'default': {
|
||||||
|
'ENGINE': 'django_prometheus.db.backends.postgresql',
|
||||||
|
'NAME': POSTGRES_DATABASE,
|
||||||
|
'USER': POSTGRES_USER,
|
||||||
|
'PASSWORD': POSTGRES_PASSWORD,
|
||||||
|
'HOST': POSTGRES_HOST,
|
||||||
|
'PORT': POSTGRES_PORTS,
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
LOGGING = {
|
||||||
|
'version': 1,
|
||||||
|
'disable_existing_loggers': False,
|
||||||
|
'filters': {
|
||||||
|
'require_debug_false': {
|
||||||
|
'()': 'django.utils.log.RequireDebugFalse',
|
||||||
|
}
|
||||||
|
},
|
||||||
|
'formatters': {
|
||||||
|
'verbose': {
|
||||||
|
'format': '[contactor] %(levelname)s %(asctime)s %(message)s',
|
||||||
|
},
|
||||||
|
},
|
||||||
|
'handlers': {
|
||||||
|
'console': {
|
||||||
|
'level': 'DEBUG',
|
||||||
|
'class': 'logging.StreamHandler',
|
||||||
|
},
|
||||||
|
'sentry': {
|
||||||
|
'level': 'ERROR',
|
||||||
|
'filters': ['require_debug_false'],
|
||||||
|
'class': 'logging.StreamHandler',
|
||||||
|
},
|
||||||
|
},
|
||||||
|
'loggers': {
|
||||||
|
'': {
|
||||||
|
'handlers': ['console', 'sentry'],
|
||||||
|
'level': 'INFO',
|
||||||
|
'propagate': False,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
COMPARATOR_JWT = os.environ.get("COMPARATOR_JWT", "default_jwt")
|
||||||
|
COMPARATOR_URL = os.environ.get("COMPARATOR_URL", "https://wb.sarex.io/comparator")
|
||||||
|
COMPARATOR_SECTION = os.environ.get("COMPARATOR_SECTION", "sarex-production-storage")
|
||||||
|
|
||||||
|
SIMPLE_JWT = {
|
||||||
|
'ACCESS_TOKEN_LIFETIME': timedelta(hours=1),
|
||||||
|
'REFRESH_TOKEN_LIFETIME': timedelta(days=1),
|
||||||
|
'ROTATE_REFRESH_TOKENS': False,
|
||||||
|
'BLACKLIST_AFTER_ROTATION': True,
|
||||||
|
'UPDATE_LAST_LOGIN': False,
|
||||||
|
'ALGORITHM': 'RS512',
|
||||||
|
'SIGNING_KEY': os.environ.get("JWT_PRIVATE_KEY").replace("\\n", "\n"),
|
||||||
|
'VERIFYING_KEY': os.environ.get("JWT_PUBLIC_KEY").replace("\\n", "\n"),
|
||||||
|
'AUDIENCE': None,
|
||||||
|
'ISSUER': os.environ.get('SIMPLE_JWT_ISSUER', 'default_issuer'),
|
||||||
|
'AUTH_HEADER_TYPES': ('Bearer',),
|
||||||
|
'AUTH_HEADER_NAME': 'HTTP_AUTHORIZATION',
|
||||||
|
'USER_ID_FIELD': 'id',
|
||||||
|
'USER_ID_CLAIM': 'user_id',
|
||||||
|
'AUTH_TOKEN_CLASSES': ('rest_framework_simplejwt.tokens.AccessToken',),
|
||||||
|
'TOKEN_TYPE_CLAIM': 'token_type',
|
||||||
|
'JTI_CLAIM': 'jti',
|
||||||
|
'SLIDING_TOKEN_REFRESH_EXP_CLAIM': 'refresh_exp',
|
||||||
|
'SLIDING_TOKEN_LIFETIME': timedelta(minutes=5),
|
||||||
|
'SLIDING_TOKEN_REFRESH_LIFETIME': timedelta(days=1),
|
||||||
|
}
|
||||||
|
|
||||||
|
os.environ["DJANGO_ALLOW_ASYNC_UNSAFE"] = "true"
|
||||||
|
DEFAULT_FILE_STORAGE = 'sarex.core.storages.CustomS3Boto3Storage'
|
||||||
|
DATA_UPLOAD_MAX_MEMORY_SIZE = 268435456
|
||||||
|
|
||||||
|
if not os.environ.get('ISOLATED', False):
|
||||||
|
import sentry_sdk
|
||||||
|
from sentry_sdk.integrations.django import DjangoIntegration
|
||||||
|
|
||||||
|
sentry_sdk.init(
|
||||||
|
dsn="https://3df2f4b8d3d14595a06c92e9d7c562cb@sentry.io/1501541",
|
||||||
|
integrations=[DjangoIntegration()],
|
||||||
|
environment=os.environ.get('SENTRY_ENVIRONMENT', 'production'),
|
||||||
|
send_default_pii=True,
|
||||||
|
)
|
||||||
|
|
||||||
|
COMPARISON_API_URL = f"{os.environ.get('WORKFLOWSSETTINGS_HOST')}/comparisons"
|
||||||
|
DOCUMENTATION_API_URL = f"{os.environ.get('WORKFLOWSSETTINGS_HOST')}/documentations"
|
||||||
|
PDM_FILES_API_URL = f"{os.environ.get('WORKFLOWSSETTINGS_HOST')}/files"
|
||||||
|
|
||||||
|
WORKFLOWS_TASKS = {
|
||||||
|
"update_orthomosaic_data": {
|
||||||
|
"image": f"{os.environ.get('WORKFLOWSSETTINGS_REGISTRY')}/update-orthomosaic-data:dev",
|
||||||
|
"service_requests": ["django-auth"],
|
||||||
|
"backoff_limit": 3,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
REST_FRAMEWORK = { 'DEFAULT_PAGINATION_CLASS': (
|
||||||
|
'rest_framework.pagination.LimitOffsetPagination' ),
|
||||||
|
'DEFAULT_SCHEMA_CLASS': 'rest_framework.schemas.coreapi.AutoSchema',
|
||||||
|
'PAGE_SIZE': 1000, 'DEFAULT_FILTER_BACKENDS': [
|
||||||
|
'django_filters.rest_framework.DjangoFilterBackend' ],
|
||||||
|
'DEFAULT_AUTHENTICATION_CLASSES': [
|
||||||
|
'sarex.authentication.backends.ZitadelJWTAuthentication',
|
||||||
|
'rest_framework.authentication.RemoteUserAuthentication',
|
||||||
|
'rest_framework_simplejwt.authentication.JWTAuthentication',
|
||||||
|
'rest_framework.authentication.BasicAuthentication',
|
||||||
|
'rest_framework.authentication.SessionAuthentication',
|
||||||
|
'sarex.authentication.backends.JWTAuthentication' ],
|
||||||
|
'DEFAULT_PERMISSION_CLASSES': [
|
||||||
|
'rest_framework.permissions.IsAuthenticated', ] }
|
||||||
|
|
||||||
|
AUTHENTICATION_BACKENDS = [
|
||||||
|
'sarex.authentication.backends.CustomRemoteUserBackend',
|
||||||
|
'django.contrib.auth.backends.ModelBackend',
|
||||||
|
'guardian.backends.ObjectPermissionBackend',
|
||||||
|
]
|
||||||
|
|
||||||
|
MIDDLEWARE = [
|
||||||
|
'django_prometheus.middleware.PrometheusBeforeMiddleware',
|
||||||
|
'django.middleware.security.SecurityMiddleware',
|
||||||
|
'django.contrib.sessions.middleware.SessionMiddleware',
|
||||||
|
'django.middleware.common.CommonMiddleware',
|
||||||
|
'django.middleware.csrf.CsrfViewMiddleware',
|
||||||
|
#'django_keycloak.middlewares.AuthorizationHeaderMiddleware',
|
||||||
|
#'django_keycloak.middlewares.KeycloakSessionMiddleware',
|
||||||
|
'django.contrib.auth.middleware.AuthenticationMiddleware',
|
||||||
|
#'django.contrib.auth.middleware.RemoteUserMiddleware',
|
||||||
|
'django.contrib.messages.middleware.MessageMiddleware',
|
||||||
|
'django.middleware.clickjacking.XFrameOptionsMiddleware',
|
||||||
|
'django_user_agents.middleware.UserAgentMiddleware',
|
||||||
|
'simple_history.middleware.HistoryRequestMiddleware',
|
||||||
|
'django_prometheus.middleware.PrometheusAfterMiddleware', ]
|
||||||
|
|
||||||
|
|
||||||
|
class KeyCloakSettings(BaseSettings):
|
||||||
|
client_id: str = "client_id"
|
||||||
|
client_secret: str = "client_secret"
|
||||||
|
discovery_url: str = "https://login.wb.sarex.io/realms/sarex/.well-known/openid-configuration"
|
||||||
|
staff: Optional[str] = "Sarex staff"
|
||||||
|
superuser: Optional[str] = "Sarex superusers"
|
||||||
|
sync_with_django: bool = True
|
||||||
|
sync_admin: bool = False
|
||||||
|
group_prefix: str = 'Sarex-Role'
|
||||||
|
company_prefix: str = 'Sarex-Company'
|
||||||
|
department_prefix: str = 'Sarex-Department'
|
||||||
|
position_prefix: str = 'Sarex-Position'
|
||||||
|
separator: str = '__'
|
||||||
|
sync_user_groups: bool = False
|
||||||
|
sync_user_positions: bool = False
|
||||||
|
sync_user_departments: bool = False
|
||||||
|
sync_user_companies: bool = False
|
||||||
|
use_redirect_logout: bool = False
|
||||||
|
logout_redirect_uri: str = "/"
|
||||||
|
default_group_name: Optional[str] = 'Тест'
|
||||||
|
default_company_name: Optional[str] = 'Брусника'
|
||||||
|
trusted_uri: List[str] = ['/api/core/orthophotos/', '/api/token', '/api/token/me']
|
||||||
|
trusted_uri: List[str] = []
|
||||||
|
|
||||||
|
class Config:
|
||||||
|
env_prefix = "KC_"
|
||||||
|
|
||||||
|
|
||||||
|
KEYCLOAKSETTINGS = KeyCloakSettings()
|
||||||
|
|
||||||
|
REMOTE_USER_DEFAULT_COMPANY_ID = 1
|
||||||
|
SAREX_MODULES = [
|
||||||
|
{
|
||||||
|
"name": "Замечания",
|
||||||
|
"uri": "/remarks"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Управление проектами",
|
||||||
|
"uri": "/management/projects",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Замечания V2",
|
||||||
|
"uri": "/issues"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Документация",
|
||||||
|
"uri": "/documentations"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Согласование документов",
|
||||||
|
"uri": "/reviews"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Рабочие процессы",
|
||||||
|
"uri": "/processes"
|
||||||
|
},
|
||||||
|
|
||||||
|
{
|
||||||
|
"name": "Аналитика",
|
||||||
|
"uri": "/analytics"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "Запросы",
|
||||||
|
"uri": "/rfi"
|
||||||
|
},
|
||||||
|
|
||||||
|
# {
|
||||||
|
# "name": "Обзор",
|
||||||
|
# "uri": "/projects"
|
||||||
|
# },
|
||||||
|
{
|
||||||
|
"name": "Передача документации",
|
||||||
|
"uri": "/transmittal"
|
||||||
|
},
|
||||||
|
]
|
||||||
|
AUTH_SETTINGS = {
|
||||||
|
"refresh_token": False,
|
||||||
|
"refresh_token_uri": "/api/token/me",
|
||||||
|
"refresh_oauth_token": True,
|
||||||
|
"refresh_oauth_token_uri": "/oauth/token",
|
||||||
|
"refresh_time": 240,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
DEBUG=False
|
||||||
|
#WEB_APP_AUTH_MODE='jwt-session-based'
|
||||||
|
|
||||||
|
|
||||||
|
SAREX_MODULES_SETTINGS = {
|
||||||
|
"aero": {
|
||||||
|
"enable_new_media": True
|
||||||
|
},
|
||||||
|
"sso_logout_redirect": True
|
||||||
|
}
|
||||||
@ -1,8 +1,9 @@
|
|||||||
|
---
|
||||||
apiVersion: helm.toolkit.fluxcd.io/v2
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
kind: HelmRelease
|
kind: HelmRelease
|
||||||
metadata:
|
metadata:
|
||||||
name: measurements
|
name: export-project
|
||||||
namespace: measurements
|
namespace: django
|
||||||
|
|
||||||
spec:
|
spec:
|
||||||
interval: 10m
|
interval: 10m
|
||||||
@ -24,20 +25,18 @@ spec:
|
|||||||
upgrade:
|
upgrade:
|
||||||
remediation:
|
remediation:
|
||||||
retries: 3
|
retries: 3
|
||||||
driftDetection:
|
|
||||||
mode: enabled
|
|
||||||
|
|
||||||
values:
|
values:
|
||||||
global:
|
global:
|
||||||
env: _default
|
env: _default
|
||||||
|
|
||||||
services:
|
services:
|
||||||
backend:
|
export-project:
|
||||||
enabled: true
|
enabled: true
|
||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations:prod_5904312b
|
_default: cr.yandex/crp3ccidau046kdj8g9q/export-project:prod_ef8aa756
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
@ -45,16 +44,25 @@ spec:
|
|||||||
enabled: true
|
enabled: true
|
||||||
|
|
||||||
name:
|
name:
|
||||||
_default: measurements
|
_default: export-project
|
||||||
|
|
||||||
replicaCount:
|
replicaCount:
|
||||||
_default: 1
|
_default: 1
|
||||||
stage: 1
|
|
||||||
preprod: 3
|
|
||||||
production: 3
|
|
||||||
|
|
||||||
port:
|
port:
|
||||||
_default: 8080
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: "2"
|
||||||
|
memory:
|
||||||
|
_default: 8Gi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: "1"
|
||||||
|
memory:
|
||||||
|
_default: 512Mi
|
||||||
|
|
||||||
probes:
|
probes:
|
||||||
liveness:
|
liveness:
|
||||||
@ -66,7 +74,7 @@ spec:
|
|||||||
enabled: true
|
enabled: true
|
||||||
|
|
||||||
name:
|
name:
|
||||||
_default: measurements-service
|
_default: export-project-service
|
||||||
|
|
||||||
type:
|
type:
|
||||||
_default: ClusterIP
|
_default: ClusterIP
|
||||||
@ -84,16 +92,12 @@ spec:
|
|||||||
enabled:
|
enabled:
|
||||||
_default: true
|
_default: true
|
||||||
name:
|
name:
|
||||||
_default: regcred
|
_default: dockerhub
|
||||||
|
|
||||||
|
envs:
|
||||||
labels:
|
- name: TIMEOUT
|
||||||
monitoring: prometheus
|
value:
|
||||||
secretEnvs:
|
_default: "180"
|
||||||
- name: S3_JSON_SETTINGS
|
|
||||||
secretName:
|
|
||||||
_default: "s3-json-settings"
|
|
||||||
secretKey: "S3_JSON_SETTINGS"
|
|
||||||
|
|
||||||
commitSha: ""
|
commitSha: ""
|
||||||
gitlabUri: ""
|
gitlabUri: ""
|
||||||
130
apps/django/wb/frontend.yaml
Normal file
130
apps/django/wb/frontend.yaml
Normal file
@ -0,0 +1,130 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/sarex-frontend-dev:contour_5.22.3
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 66m
|
||||||
|
memory:
|
||||||
|
_default: 61Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 39Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: frontend-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: nginx-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /etc/nginx/nginx.conf
|
||||||
|
subPath:
|
||||||
|
_default: nginx.conf
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: nginx-configmap
|
||||||
|
items:
|
||||||
|
- key: nginx.conf
|
||||||
|
path:
|
||||||
|
_default: nginx.conf
|
||||||
|
|
||||||
|
- name: zitadel-configmap
|
||||||
|
mountPath:
|
||||||
|
_default: /opt/react_client/static/config.json
|
||||||
|
subPath:
|
||||||
|
_default: config.json
|
||||||
|
readOnly:
|
||||||
|
_default: true
|
||||||
|
configMap:
|
||||||
|
name:
|
||||||
|
_default: zitadel-configmap
|
||||||
|
items:
|
||||||
|
- key: config.json
|
||||||
|
path:
|
||||||
|
_default: config.json
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
132
apps/django/wb/gatekeeper.yaml
Normal file
132
apps/django/wb/gatekeeper.yaml
Normal file
@ -0,0 +1,132 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: gatekeeper
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
gatekeeper:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/gatekeeper:2.12.1
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: gatekeeper
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
args:
|
||||||
|
_default:
|
||||||
|
- "--discovery-url=https://keycloak.wildberries.ru/realms/infrastructure/.well-known/openid-configuration"
|
||||||
|
- "--listen=0.0.0.0:8080"
|
||||||
|
- "--enable-logging=true"
|
||||||
|
- "--upstream-url=http://frontend-service.django.svc.cluster.local:80/"
|
||||||
|
- "--enable-refresh-tokens=true"
|
||||||
|
- "--enable-session-cookies=true"
|
||||||
|
- "--verbose"
|
||||||
|
- "--resources=uri=/*"
|
||||||
|
- "--encryption-key=zfDjuszywHSbAhY8KJQbESbpUYN74XTs"
|
||||||
|
- "--secure-cookie=false"
|
||||||
|
- "--cors-origins=*"
|
||||||
|
- "--skip-openid-provider-tls-verify=true"
|
||||||
|
- "--enable-default-deny=false"
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 48Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 32Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: gatekeeper-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: PROXY_REDIRECTION_URL
|
||||||
|
value:
|
||||||
|
_default: "https://lk.srx.wb.ru"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: PROXY_CLIENT_ID
|
||||||
|
secretName:
|
||||||
|
_default: "gatekeeper-secret"
|
||||||
|
secretKey: "client_id"
|
||||||
|
|
||||||
|
- name: PROXY_CLIENT_SECRET
|
||||||
|
secretName:
|
||||||
|
_default: "gatekeeper-secret"
|
||||||
|
secretKey: "client_secret"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
38
apps/django/wb/kafka-cert-configmap.yaml
Normal file
38
apps/django/wb/kafka-cert-configmap.yaml
Normal file
@ -0,0 +1,38 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: kafka-cert
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
kafka.crt: |
|
||||||
|
-----BEGIN CERTIFICATE-----
|
||||||
|
MIIFLTCCAxWgAwIBAgIUYDZPxGRsr7IiqHEmfd07QTQlOKYwDQYJKoZIhvcNAQEN
|
||||||
|
BQAwLTETMBEGA1UECgwKaW8uc3RyaW16aTEWMBQGA1UEAwwNY2x1c3Rlci1jYSB2
|
||||||
|
MDAeFw0yNTEyMTYxNDM0NTVaFw0yNjEyMTYxNDM0NTVaMC0xEzARBgNVBAoMCmlv
|
||||||
|
LnN0cmltemkxFjAUBgNVBAMMDWNsdXN0ZXItY2EgdjAwggIiMA0GCSqGSIb3DQEB
|
||||||
|
AQUAA4ICDwAwggIKAoICAQCfzDZhEzw2pbU5Xpu8OzD+3iQG+DVjU8PQWWQEF27h
|
||||||
|
yjohDkUr3zCZtW7xMKWKUNxBgrKsfe4TDOQN8cij3cS9sy0So+UhMeF7Bq9PU1Yd
|
||||||
|
bmTRq8q1PiuNUkiCGJ5wrb3+NZvVxZLJUIFgiealsRw80MgMWWSzy0I35T2Edn/a
|
||||||
|
DU4jhlgQxyzQ621+oGP0n28gCjmm6pCq2tkj/Z8WTdu1gOWyRdK02a2uE2Ts2nLa
|
||||||
|
Di32GaZrIbIuD/WUd6Ek66uCeJvh2CT7s+SqgtMbtT7gibUuPQ3hk1VGQsjy22l3
|
||||||
|
hUNpLu86nrwbuf21mY55KnLOcaVq1ag1TpIIKfZAL/KWFCGZ6H6kwEIbCAL0Hei7
|
||||||
|
cJ2Wm2/qlzKUeU869M7YybZAfXl/t6XT4QgFgje+42N980vy5A4GhWi1Z7lPqqOe
|
||||||
|
jPGBstkRZybKz1sTk87+oJx82iQU/ozVmzjSEK1SoYRNbvug8PNpxmPoPnJ2flgG
|
||||||
|
t2q2+2ZQP3f1aAHVcZ3U5+hWlRmKPXzjrJv7gnhuvqJl7OwB50y+yWiVfZ9xrYl2
|
||||||
|
EpX+yHuFFK+9NnB5taUK8Fz+hQaLU8J4q7P0bRqkoI+LdcEErjuDT/eI2d5+Ql8K
|
||||||
|
/JkV823hX2WNB9bdaQ24BelVUbsxGpR7ms6KWrM11kHnbzUlEM+AxZES6F7Qbr55
|
||||||
|
TwIDAQABo0UwQzAdBgNVHQ4EFgQUM7hshx7e9TFEN82Pf446aBrJUA4wEgYDVR0T
|
||||||
|
AQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAQYwDQYJKoZIhvcNAQENBQADggIB
|
||||||
|
AFNHFGPDxY966fz0dxDFFSfeo47y7XQZMK9xAwH73cQoSeqx+IMxzgM8nfJQ9XMN
|
||||||
|
PeLwVRZ7pvRee2ZhUPglBSTHnW2rvfmLBOO9xyKZxRsCkoFxuHH9xfM7bFWb96R6
|
||||||
|
fGrOdEZDB3yj00T+tkubwqt+/dUhQUj8juwyPs55WMb/0BIbapaoQ6QOP13CaXDV
|
||||||
|
ZmAfsEEIBkNxfq7GTr/z0Rq0B4+9FxAf3Jrsmi/dYoFD/prHsvBDkYw1daoFyp5C
|
||||||
|
tbctvB9wtphnCCynekt8UBvpVKHUU/xaUa09TQTToXjBbV1SZeIOHNG0MNbWa4sz
|
||||||
|
AL/cpXdq1EAxiTeAVT9XhCwhe/xJvFZIWuFLmW3J+ZxrOUCKieCYpTqBY2tBkkDY
|
||||||
|
//egic787yTR6zxqQNSzvNU5LhzrN7lu+KHGM06T35+HvpzgPPiRCzsxO62p63op
|
||||||
|
mq04K31yYZgLiqeAj5W+rioRGJNn4TXJpH9KIrzmGM7lVWLYWMAKeZU4r1lDUdcu
|
||||||
|
7jsBH8BRJWJeVK3xVw2HB3lk7Xn0WrR92adeYQ3f0vKbMIAVUnSJ3yCKJ4NMFSki
|
||||||
|
j78nx2mi/G0RhUPGZ9hhLXQKj9BtbpEnwpbGWtf0ShtVOxD/HKLCr7koBtW9TMPS
|
||||||
|
9K0sJhE5VjsQLkDDu9p3GdRcuLNA/oa7xFvRFtqGFsLj
|
||||||
|
-----END CERTIFICATE-----
|
||||||
20
apps/django/wb/kustomization.yaml
Normal file
20
apps/django/wb/kustomization.yaml
Normal file
@ -0,0 +1,20 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: django
|
||||||
|
resources:
|
||||||
|
- django-configmap.yaml
|
||||||
|
- uwsgi-configmap.yaml
|
||||||
|
- zitadel-configmap.yaml
|
||||||
|
- nginx-configmap.yaml
|
||||||
|
- kafka-cert-configmap.yaml
|
||||||
|
- backend.yaml
|
||||||
|
- celery.yaml
|
||||||
|
- export-project.yaml
|
||||||
|
- frontend.yaml
|
||||||
|
- gatekeeper.yaml
|
||||||
|
- measurement.yaml
|
||||||
|
- redis.yaml
|
||||||
|
- s3-proxy.yaml
|
||||||
|
- srx-admin.yaml
|
||||||
|
- auth-flow-frontend.yaml
|
||||||
124
apps/django/wb/measurement.yaml
Normal file
124
apps/django/wb/measurement.yaml
Normal file
@ -0,0 +1,124 @@
|
|||||||
|
---
|
||||||
|
# measurement — компонент приложения measurements (apps/measurements),
|
||||||
|
# в wb развёрнут в ns django, а не в своём собственном неймспейсе.
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: measurement
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
measurement:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/measurements:prod_ece72657
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: measurement
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 761Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 596Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: measurement-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8000
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: tmp-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /tmp
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: DJANGO_HOST
|
||||||
|
value:
|
||||||
|
_default: "https://lk.srx.wb.ru:30443"
|
||||||
|
|
||||||
|
- name: S3_JSON_FILE
|
||||||
|
value:
|
||||||
|
_default: "/opt/cred_s3.json"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: S3_JSON_SETTINGS
|
||||||
|
secretName:
|
||||||
|
_default: "s3-json-settings"
|
||||||
|
secretKey: "S3_JSON_SETTINGS"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
180
apps/django/wb/nginx-configmap.yaml
Normal file
180
apps/django/wb/nginx-configmap.yaml
Normal file
@ -0,0 +1,180 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: nginx-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
nginx.conf: |
|
||||||
|
worker_processes auto;
|
||||||
|
|
||||||
|
pid /var/run/nginx.pid;
|
||||||
|
|
||||||
|
events {
|
||||||
|
use epoll;
|
||||||
|
worker_connections 1024;
|
||||||
|
}
|
||||||
|
|
||||||
|
http {
|
||||||
|
|
||||||
|
# Basic Settings
|
||||||
|
large_client_header_buffers 8 128k;
|
||||||
|
sendfile on;
|
||||||
|
tcp_nopush on;
|
||||||
|
tcp_nodelay on;
|
||||||
|
keepalive_timeout 300;
|
||||||
|
types_hash_max_size 2048;
|
||||||
|
client_max_body_size 5000M;
|
||||||
|
client_header_buffer_size 5M;
|
||||||
|
# server_tokens off;
|
||||||
|
# server_names_hash_bucket_size 64;
|
||||||
|
# server_name_in_redirect off;
|
||||||
|
include /etc/nginx/mime.types;
|
||||||
|
default_type application/octet-stream;
|
||||||
|
|
||||||
|
# Logging Settings
|
||||||
|
access_log /var/log/nginx/access.log;
|
||||||
|
error_log /var/log/nginx/error.log;
|
||||||
|
|
||||||
|
# GZIP Settings
|
||||||
|
gzip on;
|
||||||
|
gzip_vary on;
|
||||||
|
gzip_proxied any;
|
||||||
|
gzip_comp_level 6;
|
||||||
|
gzip_buffers 16 8k;
|
||||||
|
gzip_http_version 1.1;
|
||||||
|
gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;
|
||||||
|
|
||||||
|
log_format main '$remote_addr - $remote_user [$time_local] "$request" '
|
||||||
|
'$status $body_bytes_sent "$http_referer" '
|
||||||
|
'"$http_user_agent" "$http_x_forwarded_for"';
|
||||||
|
|
||||||
|
server {
|
||||||
|
listen 80;
|
||||||
|
listen [::]:80;
|
||||||
|
root /opt/react_client/;
|
||||||
|
|
||||||
|
add_header 'Access-Control-Allow-Origin' '*' always;
|
||||||
|
add_header 'Access-Control-Allow-Methods' '*' always;
|
||||||
|
add_header 'Access-Control-Allow-Headers' '*' always;
|
||||||
|
|
||||||
|
location = /static/index.bundle.js {
|
||||||
|
add_header Cache-Control 'no-store no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
||||||
|
if_modified_since off;
|
||||||
|
expires off;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /static/pdf-runtime/assets/mupdf-wasm.wasm {
|
||||||
|
alias /opt/react_client/static/pdf-runtime/assets/mupdf-wasm.wasm;
|
||||||
|
add_header Content-Type application/wasm always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.js {
|
||||||
|
alias /opt/react_client/static/viewer-pdf/mupdf-wasm.js;
|
||||||
|
add_header Content-Type application/javascript always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/mupdf.worker-3.3.9.js {
|
||||||
|
alias /opt/react_client/static/pdf-runtime/mupdf.worker-3.3.9.js;
|
||||||
|
add_header Content-Type application/javascript always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf.js {
|
||||||
|
alias /opt/react_client/static/viewer-pdf/mupdf.js;
|
||||||
|
add_header Content-Type application/javascript always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
add_header Access-Control-Allow-Origin "*" always;
|
||||||
|
add_header Access-Control-Allow-Methods "GET, OPTIONS" always;
|
||||||
|
add_header Access-Control-Allow-Headers "DNT,Keep-Alive,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range,Authorization" always;
|
||||||
|
}
|
||||||
|
|
||||||
|
location = /workspaces-v2/worker/static/viewer-pdf/mupdf-wasm.wasm {
|
||||||
|
add_header Content-Type application/wasm always;
|
||||||
|
alias /opt/react_client/static/viewer-pdf/mupdf-wasm.wasm;
|
||||||
|
}
|
||||||
|
# location ~^/api/pm/ {
|
||||||
|
# #rewrite /api/(.+) /$1 break;
|
||||||
|
# proxy_set_header Host $host;
|
||||||
|
# proxy_pass http://backend-service.pm.svc.cluster.local:8000;
|
||||||
|
# }
|
||||||
|
|
||||||
|
location ~^/media/ {
|
||||||
|
rewrite ^/media/(.*)$ /$1 break;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://s3-proxy-service:80;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/api/v1/documents/ {
|
||||||
|
#rewrite /api/(.+) /$1 break;
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://documentations-filestream.documentations.svc.cluster.local:8080;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/(api|admin)/ {
|
||||||
|
proxy_set_header Host $host;
|
||||||
|
proxy_pass http://backend:8000;
|
||||||
|
}
|
||||||
|
|
||||||
|
# location ~^/flows/static/ {
|
||||||
|
# rewrite /flows/static/(.+) /$1 break;
|
||||||
|
# proxy_pass http://frontend-service.flows:80;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location = ~^/orchestrator/ {
|
||||||
|
# rewrite ^/orchestrator$ /api/ break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location = ~^/orchestrator/api/process {
|
||||||
|
# rewrite ^/orchestrator/api/process$ /api/process break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location ~ ^/orchestrator/api/process/(.*)$ {
|
||||||
|
# rewrite ^/orchestrator/api/process/(.*)$ /api/process/$1 break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
# location = ~^/orchestrator/api/sign {
|
||||||
|
# rewrite ^/orchestrator/api/sign$ /api/sign break;
|
||||||
|
# proxy_pass http://cde.orchestrator.svc.cluster.local:8080;
|
||||||
|
# }
|
||||||
|
|
||||||
|
|
||||||
|
location ~^/workspaces-v2/(.+).js {
|
||||||
|
rewrite /workspaces-v2/(.+) /$1 break;
|
||||||
|
proxy_pass http://workspaces-v2-frontend-static-service.workspaces.svc.cluster.local:8080;
|
||||||
|
}
|
||||||
|
|
||||||
|
location @index {
|
||||||
|
add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';
|
||||||
|
if_modified_since off;
|
||||||
|
expires off;
|
||||||
|
try_files /static/index.html =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~^/workflows/(.+).js {
|
||||||
|
rewrite /workflows/(.+) /$1 break;
|
||||||
|
proxy_pass http://frontend-service.workflow.svc.cluster.local:8080;
|
||||||
|
}
|
||||||
|
location /service-worker.js {
|
||||||
|
try_files /static/$uri @index;
|
||||||
|
}
|
||||||
|
|
||||||
|
location / {
|
||||||
|
try_files $uri @index;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
100
apps/django/wb/redis.yaml
Normal file
100
apps/django/wb/redis.yaml
Normal file
@ -0,0 +1,100 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: redis
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
redis:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/redis:latest
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: redis
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 6379
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 48Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 32Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: redis-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 6379
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 6379
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: tcp
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
129
apps/django/wb/s3-proxy.yaml
Normal file
129
apps/django/wb/s3-proxy.yaml
Normal file
@ -0,0 +1,129 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: s3-proxy
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
s3-proxy:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/s3-proxy:stable
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: s3-proxy
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 48Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 32Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: s3-proxy-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: AWS_API_ENDPOINT
|
||||||
|
value:
|
||||||
|
_default: "http://10.49.10.90:9000"
|
||||||
|
|
||||||
|
- name: ACCESS_LOG
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: CORS_ALLOW_HEADERS
|
||||||
|
value:
|
||||||
|
_default: "Content-Type, Accept-Ranges, Content-Range, Content-Encoding"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: AWS_ACCESS_KEY_ID
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "login"
|
||||||
|
|
||||||
|
- name: AWS_SECRET_ACCESS_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: AWS_S3_BUCKET
|
||||||
|
secretName:
|
||||||
|
_default: "sarex-media-storage-secret"
|
||||||
|
secretKey: "bucket"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
107
apps/django/wb/srx-admin.yaml
Normal file
107
apps/django/wb/srx-admin.yaml
Normal file
@ -0,0 +1,107 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: srx-admin
|
||||||
|
namespace: django
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
srx-admin:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/srx-admin:prod_ee0a6717
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: srx-admin
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
resources:
|
||||||
|
limits:
|
||||||
|
cpu:
|
||||||
|
_default: 20m
|
||||||
|
memory:
|
||||||
|
_default: 48Mi
|
||||||
|
requests:
|
||||||
|
cpu:
|
||||||
|
_default: 10m
|
||||||
|
memory:
|
||||||
|
_default: 32Mi
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: srx-admin-svc
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 80
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: dockerhub
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
_default:
|
||||||
|
- name: tmp-volume
|
||||||
|
mountPath:
|
||||||
|
_default: /tmp
|
||||||
|
emptyDir: {}
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
31
apps/django/wb/uwsgi-configmap.yaml
Normal file
31
apps/django/wb/uwsgi-configmap.yaml
Normal file
@ -0,0 +1,31 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: uwsgi-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
uwsgi.ini: |
|
||||||
|
[uwsgi]
|
||||||
|
module = config.wsgi:application
|
||||||
|
DJANGO_SETTINGS_MODULE = config.settings.production
|
||||||
|
http = 0.0.0.0:8000
|
||||||
|
processes = 16
|
||||||
|
master = true
|
||||||
|
vacuum = true
|
||||||
|
enable-threads = true
|
||||||
|
buffer-size = 65535
|
||||||
|
stats = :3031
|
||||||
|
stats-http = true
|
||||||
|
memory-report = true
|
||||||
|
lazy-apps = true
|
||||||
|
listen = 128
|
||||||
|
disable-write-exception= 0
|
||||||
|
harakiri = 300
|
||||||
|
socket-timeout = 300
|
||||||
|
chunked-input-timeout = 300
|
||||||
|
http-timeout = 300
|
||||||
|
worker-reload-mercy = 240
|
||||||
|
mule-reload-mercy = 240
|
||||||
|
static-map = /static=/opt/sarex/sarex/static/
|
||||||
|
static-map = /media=/media/
|
||||||
15
apps/django/wb/zitadel-configmap.yaml
Normal file
15
apps/django/wb/zitadel-configmap.yaml
Normal file
@ -0,0 +1,15 @@
|
|||||||
|
---
|
||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: zitadel-configmap
|
||||||
|
namespace: django
|
||||||
|
data:
|
||||||
|
config.json: |-
|
||||||
|
{
|
||||||
|
"auth_type": "zitadel",
|
||||||
|
"zitadel": {
|
||||||
|
"client_id": "363741990556356237",
|
||||||
|
"host": "https://zitadel-srx.wb.ru"
|
||||||
|
}
|
||||||
|
}
|
||||||
11
apps/document-link/ugok/kustomization.yaml
Normal file
11
apps/document-link/ugok/kustomization.yaml
Normal file
@ -0,0 +1,11 @@
|
|||||||
|
---
|
||||||
|
apiVersion: kustomize.config.k8s.io/v1beta1
|
||||||
|
kind: Kustomization
|
||||||
|
namespace: document-link
|
||||||
|
resources:
|
||||||
|
- ../base
|
||||||
|
patches:
|
||||||
|
- path: patch.yaml
|
||||||
|
target:
|
||||||
|
kind: HelmRelease
|
||||||
|
name: frontend
|
||||||
17
apps/document-link/ugok/patch.yaml
Normal file
17
apps/document-link/ugok/patch.yaml
Normal file
@ -0,0 +1,17 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: frontend
|
||||||
|
namespace: document-link
|
||||||
|
spec:
|
||||||
|
values:
|
||||||
|
services:
|
||||||
|
frontend:
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/document-link-frontend:wb_cb2027ce
|
||||||
|
envs:
|
||||||
|
- name: NODE_ENV
|
||||||
|
value:
|
||||||
|
_default: production
|
||||||
@ -64,7 +64,7 @@ spec:
|
|||||||
enabled: false
|
enabled: false
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/pdmv2:prod_38958427
|
_default: cr.yandex/crp3ccidau046kdj8g9q/pdmv2:prod_9507c2d5
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
service:
|
service:
|
||||||
@ -183,7 +183,7 @@ spec:
|
|||||||
_default: INFO
|
_default: INFO
|
||||||
- name: NOTES_URL
|
- name: NOTES_URL
|
||||||
value:
|
value:
|
||||||
_default: ""
|
_default: "mock"
|
||||||
- name: OBSERVABILITY_COLLECTOR_ENDPOINT
|
- name: OBSERVABILITY_COLLECTOR_ENDPOINT
|
||||||
value:
|
value:
|
||||||
_default: temp
|
_default: temp
|
||||||
|
|||||||
@ -212,6 +212,10 @@ spec:
|
|||||||
value:
|
value:
|
||||||
_default: "v1"
|
_default: "v1"
|
||||||
|
|
||||||
|
- name: USE_MARKS_RABBITMQ
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
- name: SYSTEM_LOG_URL
|
- name: SYSTEM_LOG_URL
|
||||||
value:
|
value:
|
||||||
_default: "http://api-service.system-log.svc.cluster.local:80"
|
_default: "http://api-service.system-log.svc.cluster.local:80"
|
||||||
@ -293,6 +297,32 @@ spec:
|
|||||||
secretName:
|
secretName:
|
||||||
_default: "django-auth"
|
_default: "django-auth"
|
||||||
secretKey: "key"
|
secretKey: "key"
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ_HOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ_PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ_USER
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ_API
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "vhost"
|
||||||
|
|
||||||
|
- name: MARKS_RABBITMQ_PORT
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "port"
|
||||||
|
|
||||||
|
|
||||||
- name: DJANGO_BASIC_AUTH_FOR_GET_USER
|
- name: DJANGO_BASIC_AUTH_FOR_GET_USER
|
||||||
secretName:
|
secretName:
|
||||||
|
|||||||
186
apps/documentations/brusnika-prod/hasher.yaml
Normal file
186
apps/documentations/brusnika-prod/hasher.yaml
Normal file
@ -0,0 +1,186 @@
|
|||||||
|
---
|
||||||
|
apiVersion: helm.toolkit.fluxcd.io/v2
|
||||||
|
kind: HelmRelease
|
||||||
|
metadata:
|
||||||
|
name: documentations-hasher
|
||||||
|
namespace: documentations
|
||||||
|
|
||||||
|
spec:
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
chart:
|
||||||
|
spec:
|
||||||
|
chart: universal-chart
|
||||||
|
version: "0.1.7"
|
||||||
|
sourceRef:
|
||||||
|
kind: HelmRepository
|
||||||
|
name: yc-oci-charts
|
||||||
|
namespace: flux-system
|
||||||
|
interval: 10m
|
||||||
|
|
||||||
|
install:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
|
||||||
|
upgrade:
|
||||||
|
remediation:
|
||||||
|
retries: 3
|
||||||
|
driftDetection:
|
||||||
|
mode: enabled
|
||||||
|
|
||||||
|
values:
|
||||||
|
global:
|
||||||
|
env: _default
|
||||||
|
|
||||||
|
services:
|
||||||
|
backend:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
image:
|
||||||
|
name:
|
||||||
|
_default: cr.yandex/crp3ccidau046kdj8g9q/hasher:production_3f853d3a
|
||||||
|
pullPolicy:
|
||||||
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
deployment:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: hasher
|
||||||
|
|
||||||
|
replicaCount:
|
||||||
|
_default: 1
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
command:
|
||||||
|
_default: ["run-amqp-server"]
|
||||||
|
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
enabled: false
|
||||||
|
readiness:
|
||||||
|
enabled: false
|
||||||
|
|
||||||
|
service:
|
||||||
|
enabled: true
|
||||||
|
|
||||||
|
name:
|
||||||
|
_default: hasher-service
|
||||||
|
|
||||||
|
type:
|
||||||
|
_default: ClusterIP
|
||||||
|
|
||||||
|
port:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
targetPort:
|
||||||
|
_default: 8080
|
||||||
|
|
||||||
|
portName:
|
||||||
|
_default: http
|
||||||
|
|
||||||
|
imagePullSecrets:
|
||||||
|
enabled:
|
||||||
|
_default: true
|
||||||
|
name:
|
||||||
|
_default: regcred
|
||||||
|
|
||||||
|
labels:
|
||||||
|
monitoring: prometheus
|
||||||
|
|
||||||
|
envs:
|
||||||
|
- name: HASHER_APP__LOG_LEVEL
|
||||||
|
value:
|
||||||
|
_default: "INFO"
|
||||||
|
|
||||||
|
- name: HASHER_APP__NUM_WORKERS
|
||||||
|
value:
|
||||||
|
_default: "4"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_QUEUE
|
||||||
|
value:
|
||||||
|
_default: "hash.compute.normal.tasks"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE
|
||||||
|
value:
|
||||||
|
_default: "hash.compute"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_EXCHANGE_TYPE
|
||||||
|
value:
|
||||||
|
_default: "direct"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__ROUTING__TASK_INPUT_ROUTING_KEY
|
||||||
|
value:
|
||||||
|
_default: "hash.compute.normal"
|
||||||
|
|
||||||
|
- name: HASHER_S3__MAX_POOL_CONNECTIONS
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
|
||||||
|
- name: HASHER_S3__CONNECT_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "10"
|
||||||
|
|
||||||
|
- name: HASHER_S3__READ_TIMEOUT
|
||||||
|
value:
|
||||||
|
_default: "30"
|
||||||
|
|
||||||
|
- name: HASHER_S3__REGION_NAME
|
||||||
|
value:
|
||||||
|
_default: "ru-central1"
|
||||||
|
|
||||||
|
- name: HASHER_S3__USE_SSL
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
- name: HASHER_S3__VERIFY
|
||||||
|
value:
|
||||||
|
_default: "true"
|
||||||
|
|
||||||
|
secretEnvs:
|
||||||
|
- name: HASHER_AMQP__HOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "host"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__PORT
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "port"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__USERNAME
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "username"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__PASSWORD
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "password"
|
||||||
|
|
||||||
|
- name: HASHER_AMQP__VHOST
|
||||||
|
secretName:
|
||||||
|
_default: "rabbitmq"
|
||||||
|
secretKey: "vhost"
|
||||||
|
|
||||||
|
- name: HASHER_S3__ENDPOINT
|
||||||
|
secretName:
|
||||||
|
_default: "hasher-s3-secret"
|
||||||
|
secretKey: "endpoint"
|
||||||
|
|
||||||
|
- name: HASHER_S3__ACCESS_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "hasher-s3-secret"
|
||||||
|
secretKey: "access_key"
|
||||||
|
|
||||||
|
- name: HASHER_S3__SECRET_KEY
|
||||||
|
secretName:
|
||||||
|
_default: "hasher-s3-secret"
|
||||||
|
secretKey: "secret_key"
|
||||||
|
|
||||||
|
commitSha: ""
|
||||||
|
gitlabUri: ""
|
||||||
|
gitlabJobUrl: ""
|
||||||
|
owner: ""
|
||||||
@ -7,3 +7,4 @@ resources:
|
|||||||
- pdm.yaml
|
- pdm.yaml
|
||||||
- api.yaml
|
- api.yaml
|
||||||
- filestream.yaml
|
- filestream.yaml
|
||||||
|
- hasher.yaml
|
||||||
|
|||||||
@ -37,7 +37,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations:prod_5904312b
|
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations:prod_179e518c
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
@ -194,7 +194,7 @@ spec:
|
|||||||
|
|
||||||
- name: BIM_API_URL
|
- name: BIM_API_URL
|
||||||
value:
|
value:
|
||||||
_default: "http://bim-api-service.bim.svc.cluster.local:8080/"
|
_default: "http://backend-service.bim.svc.cluster.local:8000/"
|
||||||
|
|
||||||
- name: BIM_API_V2_URL
|
- name: BIM_API_V2_URL
|
||||||
value:
|
value:
|
||||||
|
|||||||
@ -37,7 +37,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations-api-files:prod_5904312b
|
_default: cr.yandex/crp3ccidau046kdj8g9q/documentations-api-files:prod_3f19a21d
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
@ -194,7 +194,7 @@ spec:
|
|||||||
|
|
||||||
- name: BIM_API_URL
|
- name: BIM_API_URL
|
||||||
value:
|
value:
|
||||||
_default: "http://bim-api-service.bim.svc.cluster.local:8080/"
|
_default: "http://backend-service.bim.svc.cluster.local:8000/"
|
||||||
|
|
||||||
- name: BIM_API_V2_URL
|
- name: BIM_API_V2_URL
|
||||||
value:
|
value:
|
||||||
|
|||||||
@ -37,7 +37,7 @@ spec:
|
|||||||
|
|
||||||
image:
|
image:
|
||||||
name:
|
name:
|
||||||
_default: cr.yandex/crp3ccidau046kdj8g9q/documentation-frontend-app:brusnika_5a4e4adc
|
_default: cr.yandex/crp3ccidau046kdj8g9q/documentation-frontend-app:brusnika_e5f99d7c
|
||||||
pullPolicy:
|
pullPolicy:
|
||||||
_default: IfNotPresent
|
_default: IfNotPresent
|
||||||
|
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Loading…
Reference in New Issue
Block a user