iac/apps/django
ivan 742a811313 ugok: rebuild all apps as standalone HelmReleases, drop vault-native base
Root cause: apps/*/ugok extended ../base via kustomize patches, but base
is vault-native (Vault Agent Injector annotations + serviceAccount +
command/args wrapper sourcing /vault/secrets/*). The Vault Agent Injector
webhook IS deployed cluster-wide in ugok (infrastructure/vault/ugok), so
it actually intercepted these pods — but no per-app Vault roles/secrets
were ever provisioned there, so every pod hung in Init.

Fix, mirrored from apps/*/wb (which never extends base for these apps):
rebuild every affected app as a standalone HelmRelease per service, with
no serviceAccount/podAnnotations override and no vault-sourcing wrapper
in command/args (dropped entirely, or replaced with the real functional
command where base's wrapper did double duty — e.g. celery invocations,
pm's `python manage.py migrate`, pdf-markings-amqp's `start-amqp-worker`).

Also recreates ConfigMaps that were referenced by name in volumes but
never actually captured into the repo (eav, subscriptions, pm, issues,
django) — copied verbatim from the cluster dump and verified byte-for-byte
against it.

Incidental bugs found and fixed along the way:
- message-hub was still extending base (missed in an earlier pass).
- system-log's patches targeted services.api/services.worker while base
  uses services.backend for both — would have produced duplicate
  Deployments per release, one of them permanently vault-broken.
- contracts' real container port is 8080, not base's default 8000.
- drawings' Service.targetPort (8000) didn't match the real containerPort
  (8080), breaking routing.
- inspections/ugok was missing entirely from this pass.

apps/documentations: intentionally left without a redis Deployment even
though VALKEY_ADDR now points at one — the cluster dump has no redis in
that namespace, so provisioning one is a scope decision, not a bug fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-29 01:22:21 +05:00
..
base ++ 2026-08-07 13:27:56 +05:00
brusnika-prod ++ 2026-06-07 13:35:36 +05:00
brusnika-stage Revert "brusnika-stage: align images with wb, add missing backend envs" 2026-08-28 19:03:00 +05:00
d8-ugmk-prod Add message-hub HelmRelease to d8-ugmk-prod: configure Kafka topics, environment variables, and enable Kafka integration in django. 2026-08-05 17:09:39 +03:00
dsinv ++ 2026-07-28 18:11:41 +05:00
ugok ugok: rebuild all apps as standalone HelmReleases, drop vault-native base 2026-08-29 01:22:21 +05:00
wb wb: set requests/limits from 14d VictoriaMetrics utilization 2026-08-27 15:36:59 +05:00
yc-ecp Add S3 Proxy apps to yc-ecp: define s3-proxy and s3-proxy-bim HelmReleases with chart, deployment, and service configurations, and include in cluster Kustomization 2026-08-05 02:19:42 +03:00
yc-k8s-test ++ 2026-07-29 16:05:18 +05:00
.env.example Add example .env files and configuration documentation for ams-sync, auth-flow, bim, cde, comparisons, django, document-link, flows, iam, inspections services. 2026-07-14 19:23:02 +03:00
CONFIGURATION.md ++ use wb superset jwt k8s secret 2026-08-17 17:19:21 +03:00
ENDPOINTS.md Add example .env files and configuration documentation for ams-sync, auth-flow, bim, cde, comparisons, django, document-link, flows, iam, inspections services. 2026-07-14 19:23:02 +03:00
FRONTEND_REQUESTS.md Add example .env files and configuration documentation for ams-sync, auth-flow, bim, cde, comparisons, django, document-link, flows, iam, inspections services. 2026-07-14 19:23:02 +03:00
openapi.yaml Add example .env files and configuration documentation for ams-sync, auth-flow, bim, cde, comparisons, django, document-link, flows, iam, inspections services. 2026-07-14 19:23:02 +03:00