vad: pm, message-hub, cde
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m8s

pm: postgres, rabbitmq, own kafka producer (self-contained
generate:true, message-hub reads the same credentials), S3.
message-hub: reads pm's postgres (same db/user, separate vault path)
and pm's kafka creds, own S3 bucket.
cde: single opaque vault/apps/cde blob per its CONFIGURATION.md.
Reused the real PUBLIC_KEY/CAMUNDA_CLIENT_SECRET/Telegram
token+group already shared identically between ugmk and yc-k8s-test.
AMQP creds pulled via secret_ref from the already-provisioned
rabbitmq/apps/cde secret. DATABASE_URL composed with the real
documentations postgres password.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
ivan 2026-09-18 02:37:33 +05:00
parent 234039f2e3
commit 6fd13c1290
2 changed files with 1816 additions and 1653 deletions

File diff suppressed because one or more lines are too long

View File

@ -748,6 +748,15 @@ environments:
- name: iam
manage: false
image_pull_secret: true
- name: pm
manage: false
image_pull_secret: true
- name: message-hub
manage: false
image_pull_secret: true
- name: cde
manage: false
image_pull_secret: true
postgresql:
default_host: 192.168.8.131
@ -1033,6 +1042,19 @@ environments:
password_special: false
conn_limit: 20
- cluster_id: main
database:
name: pm
extensions:
- uuid-ossp
- pg_stat_statements
- ltree
user:
name: pm
password_length: 32
password_special: false
conn_limit: 20
minio:
endpoint: http://192.168.8.121:9000
@ -1058,6 +1080,12 @@ environments:
- name: issues
acl: private
- name: pm
acl: private
- name: message-hub
acl: private
- name: attachments
acl: private
@ -1115,6 +1143,7 @@ environments:
- name: issues
- name: mapper
- name: transmittal
- name: pm
users:
- name: notes
password_length: 32
@ -1136,6 +1165,8 @@ environments:
password_length: 32
- name: issues
password_length: 32
- name: pm
password_length: 32
permissions:
- vhost: notes
user: notes
@ -1187,6 +1218,11 @@ environments:
configure: ".*"
write: ".*"
read: ".*"
- vhost: pm
user: pm
configure: ".*"
write: ".*"
read: ".*"
sarex-contour:
postgresql: