Adds apps/<app>/ugok overlays for 31 applications, derived strictly from a live cluster dump (kubectl get deployment/service/configmap/secret), following the wb overlay pattern (standalone HelmRelease patches on universal-chart, plain k8s Secret + secretKeyRef instead of Vault Agent since the ugok cluster has zero Vault usage cluster-wide). - processing (workflow namespace) does not extend base: base is vault-native, ugok is not, so it's four standalone HelmReleases modeled on apps/processing/wb/*. - issues/redis and django/redis are raw Deployments patched via JSON6902. - documentations/pdf-markings and django/auth-flow-frontend, export-project are copied in as standalone files (base has no HelmRelease for them, and kustomize forbids cross-overlay references outside a directory's own tree). - Images and images-with-registry updated to match wb where the same build lineage applies; left as-is where the wb tag carries a distinct client/cluster name (donstroi1, brusnika_*, dev4, UGOK_*, ugok1_*) or points at a different image repository entirely. - Missing backend envs backfilled from wb where safe (internal svc.cluster.local refs, feature flags, already-established ugok domains); skipped where wb-specific (external DB/Kafka hosts, TLS CA content, features not deployed in ugok like gatekeeper/Superset). - message-hub patch was missing its entire env block from the original bootstrap; rebuilt from the raw dump (not wb, whose Kafka/DB config is incompatible) plus a handful of small env gaps found while cross-checking every ugok app's rendered envs against the raw dump. clusters/ugok/kustomization.yaml keeps the apps section commented out — not wired into the Flux Kustomization yet, pending review. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
15 lines
696 B
YAML
15 lines
696 B
YAML
---
|
||
# processing разворачивается в ugok в неймспейс workflow (как и в wb).
|
||
# base — vault-native (secretEnvs через Vault Agent), а в ugok Vault вообще
|
||
# не используется (весь дамп кластера — ни одной vault.hashicorp.com
|
||
# аннотации), поэтому не наследуем base, а собираем отдельные standalone
|
||
# HelmRelease с обычными secretEnvs — по образцу apps/processing/wb/engine.yaml.
|
||
apiVersion: kustomize.config.k8s.io/v1beta1
|
||
kind: Kustomization
|
||
namespace: workflow
|
||
resources:
|
||
- engine.yaml
|
||
- engine-low.yaml
|
||
- frontend.yaml
|
||
- workflows-api.yaml
|