Root cause: apps/*/ugok extended ../base via kustomize patches, but base is vault-native (Vault Agent Injector annotations + serviceAccount + command/args wrapper sourcing /vault/secrets/*). The Vault Agent Injector webhook IS deployed cluster-wide in ugok (infrastructure/vault/ugok), so it actually intercepted these pods — but no per-app Vault roles/secrets were ever provisioned there, so every pod hung in Init. Fix, mirrored from apps/*/wb (which never extends base for these apps): rebuild every affected app as a standalone HelmRelease per service, with no serviceAccount/podAnnotations override and no vault-sourcing wrapper in command/args (dropped entirely, or replaced with the real functional command where base's wrapper did double duty — e.g. celery invocations, pm's `python manage.py migrate`, pdf-markings-amqp's `start-amqp-worker`). Also recreates ConfigMaps that were referenced by name in volumes but never actually captured into the repo (eav, subscriptions, pm, issues, django) — copied verbatim from the cluster dump and verified byte-for-byte against it. Incidental bugs found and fixed along the way: - message-hub was still extending base (missed in an earlier pass). - system-log's patches targeted services.api/services.worker while base uses services.backend for both — would have produced duplicate Deployments per release, one of them permanently vault-broken. - contracts' real container port is 8080, not base's default 8000. - drawings' Service.targetPort (8000) didn't match the real containerPort (8080), breaking routing. - inspections/ugok was missing entirely from this pass. apps/documentations: intentionally left without a redis Deployment even though VALKEY_ADDR now points at one — the cluster dump has no redis in that namespace, so provisioning one is a scope decision, not a bug fix. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
11 lines
4.5 KiB
YAML
11 lines
4.5 KiB
YAML
---
|
|
# Скопировано из живого ConfigMap кластера ugok (namespace django) —
|
|
# монтируется frontend в /etc/nginx/nginx.conf.
|
|
apiVersion: v1
|
|
kind: ConfigMap
|
|
metadata:
|
|
name: nginx-configmap
|
|
namespace: django
|
|
data:
|
|
nginx.conf: "worker_processes auto;\n\npid /var/run/nginx.pid;\n\nevents {\n use epoll;\n worker_connections 1024;\n}\n\nhttp {\n\n # Basic Settings\n large_client_header_buffers 8 128k;\n sendfile on;\n tcp_nopush on;\n tcp_nodelay on;\n keepalive_timeout 300;\n types_hash_max_size 2048;\n client_max_body_size 5000M;\n client_header_buffer_size 5M;\n # server_tokens off;\n # server_names_hash_bucket_size 64;\n # server_name_in_redirect off;\n include /etc/nginx/mime.types;\n default_type application/octet-stream;\n\n # Logging Settings\n access_log /var/log/nginx/access.log;\n error_log /var/log/nginx/error.log;\n\n # GZIP Settings\n gzip on;\n gzip_vary on;\n gzip_proxied any;\n gzip_comp_level 6;\n gzip_buffers 16 8k;\n gzip_http_version 1.1;\n gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript;\n\n log_format main '$remote_addr - $remote_user [$time_local] \"$request\" '\n '$status $body_bytes_sent \"$http_referer\" '\n '\"$http_user_agent\" \"$http_x_forwarded_for\"';\n\n server {\n listen 80;\n listen [::]:80;\n root /opt/react_client/;\n\n add_header 'Access-Control-Allow-Origin' '*' always;\n add_header 'Access-Control-Allow-Methods' '*' always;\n add_header 'Access-Control-Allow-Headers' '*' always;\n\n location = /static/index.bundle.js {\n add_header Cache-Control 'no-store no-cache, must-revalidate, proxy-revalidate, max-age=0';\n if_modified_since off;\n expires off;\n }\n location ~^/api/pm/ {\n proxy_set_header Host $host;\n proxy_pass http://backend-service.pm.svc.cluster.local:8000;\n }\n\n location ~^/media/ {\n rewrite ^/media/(.*)$ /$1 break;\n proxy_set_header Host $host;\n proxy_pass http://s3-proxy-service:80;\n }\n\n location ~^/api/v1/documents/ {\n rewrite /api/(.+) /$1 break;\n proxy_set_header Host $host;\n proxy_pass http://documentations-filestream.documentations.svc.cluster.local:8080;\n }\n\n location ~^/(api|admin)/ {\n proxy_set_header Host $host;\n proxy_pass http://backend:8000;\n }\n \n # location ~^/flows/static/ {\n # rewrite /flows/static/(.+) /$1 break;\n # proxy_pass http://frontend-service.flows:80;\n # }\n \n # location = ~^/orchestrator/ {\n # rewrite ^/orchestrator$ /api/ break;\n # proxy_pass http://cde.orchestrator.svc.cluster.local:8080;\n # }\n\n # location = ~^/orchestrator/api/process {\n # rewrite ^/orchestrator/api/process$ /api/process break;\n # proxy_pass http://cde.orchestrator.svc.cluster.local:8080;\n # }\n \n # location ~ ^/orchestrator/api/process/(.*)$ {\n # rewrite ^/orchestrator/api/process/(.*)$ /api/process/$1 break;\n # proxy_pass http://cde.orchestrator.svc.cluster.local:8080;\n # }\n \n # location = ~^/orchestrator/api/sign {\n # rewrite ^/orchestrator/api/sign$ /api/sign break;\n # proxy_pass http://cde.orchestrator.svc.cluster.local:8080;\n # }\n \n \n location ~^/workspaces-v2/(.+).js {\n proxy_http_version 1.1;\n proxy_set_header Host $host;\n proxy_set_header Connection \"\";\n rewrite /workspaces-v2/(.+) /$1 break;\n proxy_pass http://frontend-svc.workspaces.svc.cluster.local:8080;\n }\n\n location @index {\n add_header Cache-Control 'no-cache, must-revalidate, proxy-revalidate, max-age=0';\n if_modified_since off;\n expires off;\n try_files /static/index.html =404;\n }\n \n location ~^/workflows/(.+).js {\n rewrite /workflows/(.+) /$1 break;\n proxy_pass http://frontend-service.workflow.svc.cluster.local:8080;\n }\n location /service-worker.js {\n try_files /static/$uri @index;\n }\n\n location / {\n try_files $uri @index;\n }\n }\n}\n"
|