Adds apps/<app>/ugok overlays for 31 applications, derived strictly from a live cluster dump (kubectl get deployment/service/configmap/secret), following the wb overlay pattern (standalone HelmRelease patches on universal-chart, plain k8s Secret + secretKeyRef instead of Vault Agent since the ugok cluster has zero Vault usage cluster-wide). - processing (workflow namespace) does not extend base: base is vault-native, ugok is not, so it's four standalone HelmReleases modeled on apps/processing/wb/*. - issues/redis and django/redis are raw Deployments patched via JSON6902. - documentations/pdf-markings and django/auth-flow-frontend, export-project are copied in as standalone files (base has no HelmRelease for them, and kustomize forbids cross-overlay references outside a directory's own tree). - Images and images-with-registry updated to match wb where the same build lineage applies; left as-is where the wb tag carries a distinct client/cluster name (donstroi1, brusnika_*, dev4, UGOK_*, ugok1_*) or points at a different image repository entirely. - Missing backend envs backfilled from wb where safe (internal svc.cluster.local refs, feature flags, already-established ugok domains); skipped where wb-specific (external DB/Kafka hosts, TLS CA content, features not deployed in ugok like gatekeeper/Superset). - message-hub patch was missing its entire env block from the original bootstrap; rebuilt from the raw dump (not wb, whose Kafka/DB config is incompatible) plus a handful of small env gaps found while cross-checking every ugok app's rendered envs against the raw dump. clusters/ugok/kustomization.yaml keeps the apps section commented out — not wired into the Flux Kustomization yet, pending review. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
185 lines
4.6 KiB
YAML
185 lines
4.6 KiB
YAML
---
|
||
# subscriptions/base — сырой Deployment (не universal-chart), а wb использует
|
||
# отдельный standalone HelmRelease (apps/subscriptions/wb/backend.yaml), не
|
||
# наследуя base. Для ugok — та же схема, значения из дампа кластера.
|
||
apiVersion: helm.toolkit.fluxcd.io/v2
|
||
kind: HelmRelease
|
||
metadata:
|
||
name: sarex-subscriptions
|
||
namespace: subscriptions
|
||
|
||
spec:
|
||
interval: 10m
|
||
|
||
chart:
|
||
spec:
|
||
chart: universal-chart
|
||
version: "0.1.7"
|
||
sourceRef:
|
||
kind: HelmRepository
|
||
name: yc-oci-charts
|
||
namespace: flux-system
|
||
interval: 10m
|
||
|
||
install:
|
||
remediation:
|
||
retries: 3
|
||
|
||
upgrade:
|
||
remediation:
|
||
retries: 3
|
||
|
||
values:
|
||
global:
|
||
env: _default
|
||
|
||
services:
|
||
sarex-subscriptions:
|
||
enabled: true
|
||
|
||
image:
|
||
name:
|
||
_default: cr.yandex/crp3ccidau046kdj8g9q/subscriptions:prod_a50928e1
|
||
pullPolicy:
|
||
_default: IfNotPresent
|
||
|
||
deployment:
|
||
enabled: true
|
||
|
||
name:
|
||
_default: sarex-subscriptions
|
||
|
||
replicaCount:
|
||
_default: 1
|
||
|
||
port:
|
||
_default: 8000
|
||
|
||
probes:
|
||
liveness:
|
||
enabled: false
|
||
readiness:
|
||
enabled: false
|
||
|
||
service:
|
||
enabled: true
|
||
|
||
name:
|
||
_default: backend-svc
|
||
|
||
type:
|
||
_default: ClusterIP
|
||
|
||
port:
|
||
_default: 8000
|
||
|
||
targetPort:
|
||
_default: 8000
|
||
|
||
portName:
|
||
_default: http
|
||
|
||
imagePullSecrets:
|
||
enabled:
|
||
_default: true
|
||
name:
|
||
_default: regcred
|
||
|
||
volumes:
|
||
_default:
|
||
- name: uwsgi-configmap
|
||
mountPath:
|
||
_default: /opt/server/uwsgi.ini
|
||
subPath:
|
||
_default: uwsgi.ini
|
||
readOnly:
|
||
_default: true
|
||
configMap:
|
||
name:
|
||
_default: uwsgi-configmap
|
||
items:
|
||
- key: uwsgi.ini
|
||
path:
|
||
_default: uwsgi.ini
|
||
|
||
- name: django-configmap
|
||
mountPath:
|
||
_default: /server/config/settings/production.py
|
||
subPath:
|
||
_default: production.py
|
||
readOnly:
|
||
_default: true
|
||
configMap:
|
||
name:
|
||
_default: django-configmap
|
||
items:
|
||
- key: production.py
|
||
path:
|
||
_default: production.py
|
||
|
||
envs:
|
||
- name: DATABASE_HOST
|
||
value:
|
||
_default: postgres-service
|
||
- name: DATABASE_PORT
|
||
value:
|
||
_default: "5432"
|
||
- name: DATABASE_NAME
|
||
value:
|
||
_default: subscriptions_db
|
||
- name: API_ADDRESS
|
||
value:
|
||
_default: "8000"
|
||
- name: SYSTEM_LOG_HOST
|
||
value:
|
||
_default: http://api-service.system-log
|
||
- name: USER_SERVICE_HOST
|
||
value:
|
||
_default: http://backend.django.svc.cluster.local:8000
|
||
- name: IS_USE_TELEGRAM
|
||
value:
|
||
_default: "false"
|
||
- name: IS_MAILGUN_USE
|
||
value:
|
||
_default: "0"
|
||
- name: SMTP_EMAIL_FROM
|
||
value:
|
||
_default: sarex@rb.ru
|
||
- name: SMTP_EMAIL_HOST
|
||
value:
|
||
_default: mail.rb.ru
|
||
- name: SMTP_EMAIL_PORT
|
||
value:
|
||
_default: "465"
|
||
|
||
secretEnvs:
|
||
- name: DATABASE_USER
|
||
secretName:
|
||
_default: subscriptions-postgresql-secret
|
||
secretKey: username
|
||
- name: DATABASE_PASSWORD
|
||
secretName:
|
||
_default: subscriptions-postgresql-secret
|
||
secretKey: password
|
||
- name: YC_S3_ACCESS_KEY_ID
|
||
secretName:
|
||
_default: subscriptions-s3-secret
|
||
secretKey: access_key
|
||
- name: YC_S3_SECRET_ACCESS_KEY
|
||
secretName:
|
||
_default: subscriptions-s3-secret
|
||
secretKey: secret_key
|
||
- name: YC_S3_BUCKET_NAME
|
||
secretName:
|
||
_default: subscriptions-s3-secret
|
||
secretKey: bucket
|
||
- name: YC_S3_ENDPOINT_URL
|
||
secretName:
|
||
_default: subscriptions-s3-secret
|
||
secretKey: endpoint
|
||
|
||
commitSha: ""
|
||
gitlabUri: ""
|
||
gitlabJobUrl: ""
|
||
owner: ""
|