New service on universal-chart with Vault Agent: role premises, SA
premises-vault, creds for its own postgres, kafka and S3 plus the five
neighbour databases the sync script reads. The vad overlay mounts the Kafka CA
and drops the prod-sized resource requests; istio-config routes
sarex.vadroad.ru/premises/api/ to backend-svc.premises.
Same cde-api virtual service as d8-ugmk-prod: /orchestrator/api/process/,
/orchestrator/api/sign and /orchestrator/ are rewritten to /api/... and sent
to cde-svc.cde.svc.cluster.local:80.
KAFKA_SASL_MECHANISM is read from auth.sasl_mechanism when the nested auth
map exists and from the top-level sasl_mechanism otherwise, so the pods start
both before and after kafka/apps/pm switches to creds delivered from the
kafka-topics terraform stack.
flows, issues, pm and message-hub read ca.crt from a copy of the Kafka TLS
secret in their own namespace instead of an inline PEM (flows) or a
per-namespace kafka-ca-cert ConfigMap (issues, pm, message-hub). Mount paths
and env names are unchanged. The secret must exist in each namespace before
the pods restart.
universal-chart already injects proxy.istio.io/config and
traffic.sidecar.istio.io/excludeOutboundPorts by default for every
service — explicitly setting them too produced a duplicate-key YAML
error in Flux's post-render step:
error while running post render on files: ... yaml: unmarshal errors:
line 42: mapping key "traffic.sidecar.istio.io/excludeOutboundPorts" already defined at line 25
line 41: mapping key "proxy.istio.io/config" already defined at line 26
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
New HelmRelease services.admin-frontend in apps/control-interface/base,
matching the live Deployment's image/port/resources (cpu 100m, memory
100Mi) and istio tracing podAnnotations. Downward-API envs (K8S_POD_UID/
K8S_POD_NAME/K8S_NAMESPACE/OTEL_RESOURCE_ATTRIBUTES) were left out — no
existing app in this repo uses valueFrom/fieldRef in the universal-chart
envs schema and the chart source isn't reachable to confirm support.
imagePullSecrets uses regcred (vad's actual convention) instead of the
source's dockerhub.
Since control-interface/vad and /uralkal both just inherit ../base
unmodified, this also shows up in uralkal as a side effect.
infrastructure/istio-config/vad: adds a plain admin-frontend route
(/admin-frontend/static/ -> admin-frontend-svc.control-interface, rewrite
/), matching the minimal style of the other sarex.vadroad.ru routes —
no cors block, per request.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>