++ pilot external rabbitmq module on brusnika-stage only

This commit is contained in:
Kochetkov S 2026-08-07 11:45:06 +03:00
parent d46f540a79
commit cd14614538
5 changed files with 1220 additions and 1081 deletions

View File

@ -7,7 +7,9 @@ name: Terraform Terragrunt (contour)
# KAFKA_BOOTSTRAP, SKIP_POSTGRES_ADMIN, SKIP_KAFKA_ADMIN, SKIP_MINIO_ADMIN # KAFKA_BOOTSTRAP, SKIP_POSTGRES_ADMIN, SKIP_KAFKA_ADMIN, SKIP_MINIO_ADMIN
# secrets: TF_STATE_S3_ENDPOINT, TF_STATE_S3_BUCKET, S3_ACCESS_KEY, S3_SECRET_KEY, # secrets: TF_STATE_S3_ENDPOINT, TF_STATE_S3_BUCKET, S3_ACCESS_KEY, S3_SECRET_KEY,
# VAULT_ADDR, VAULT_TOKEN, SOPS_AGE_KEY_CONTOUR, KUBECONFIG_B64 (external # VAULT_ADDR, VAULT_TOKEN, SOPS_AGE_KEY_CONTOUR, KUBECONFIG_B64 (external
# runner only), KUBE_CONTEXT (external runner only) # runner only), KUBE_CONTEXT (external runner only), GITLAB_MODULE_TOKEN
# (read_repository access to infra/terraform-modules/* - needed once a
# stack's terraform { source } points at an external module repo)
# Infra-service admin creds are NOT passed as secrets — they are read from Vault # Infra-service admin creds are NOT passed as secrets — they are read from Vault
# at run time (see the "Run ... stacks" step) so the single source of truth stays # at run time (see the "Run ... stacks" step) so the single source of truth stays
# in the contour Vault. # in the contour Vault.
@ -64,6 +66,7 @@ jobs:
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }} KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
KUBECONFIG: /workspace/.kube/config KUBECONFIG: /workspace/.kube/config
GIT_AUTH_TOKEN: ${{ github.token }} GIT_AUTH_TOKEN: ${{ github.token }}
GITLAB_MODULE_TOKEN: ${{ secrets.GITLAB_MODULE_TOKEN }}
steps: steps:
- name: Checkout (without Node.js action) - name: Checkout (without Node.js action)
run: | run: |
@ -92,6 +95,9 @@ jobs:
else else
echo "No KUBECONFIG_B64 — in-cluster runner: kubernetes/vault providers use the pod ServiceAccount kubeconfig or in-cluster config." echo "No KUBECONFIG_B64 — in-cluster runner: kubernetes/vault providers use the pod ServiceAccount kubeconfig or in-cluster config."
fi fi
- name: Configure module registry auth
run: |
git config --global url."https://${GITLAB_MODULE_TOKEN}@gitlab.sarex.io/".insteadOf "ssh://git@gitlab.sarex.io/"
- name: Decrypt secret values - name: Decrypt secret values
# SOPS_AGE_KEY only reaches this step, not the whole job - the rest # SOPS_AGE_KEY only reaches this step, not the whole job - the rest
# (checkout, kubeconfig, terragrunt run) never sees it. # (checkout, kubeconfig, terragrunt run) never sees it.
@ -123,6 +129,7 @@ jobs:
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }} KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
KUBECONFIG: /workspace/.kube/config KUBECONFIG: /workspace/.kube/config
GIT_AUTH_TOKEN: ${{ github.token }} GIT_AUTH_TOKEN: ${{ github.token }}
GITLAB_MODULE_TOKEN: ${{ secrets.GITLAB_MODULE_TOKEN }}
steps: steps:
- name: Checkout (without Node.js action) - name: Checkout (without Node.js action)
run: | run: |
@ -149,6 +156,9 @@ jobs:
echo "$KUBECONFIG_B64" | base64 -d > /workspace/.kube/config echo "$KUBECONFIG_B64" | base64 -d > /workspace/.kube/config
chmod 600 /workspace/.kube/config chmod 600 /workspace/.kube/config
fi fi
- name: Configure module registry auth
run: |
git config --global url."https://${GITLAB_MODULE_TOKEN}@gitlab.sarex.io/".insteadOf "ssh://git@gitlab.sarex.io/"
- name: Decrypt secret values - name: Decrypt secret values
# SOPS_AGE_KEY only reaches this step, not the whole job - the rest # SOPS_AGE_KEY only reaches this step, not the whole job - the rest
# (checkout, kubeconfig, terragrunt run) never sees it. # (checkout, kubeconfig, terragrunt run) never sees it.
@ -181,6 +191,7 @@ jobs:
KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }} KUBECONFIG_B64: ${{ secrets.KUBECONFIG_B64 }}
KUBECONFIG: /workspace/.kube/config KUBECONFIG: /workspace/.kube/config
GIT_AUTH_TOKEN: ${{ github.token }} GIT_AUTH_TOKEN: ${{ github.token }}
GITLAB_MODULE_TOKEN: ${{ secrets.GITLAB_MODULE_TOKEN }}
steps: steps:
- name: Checkout (without Node.js action) - name: Checkout (without Node.js action)
run: | run: |
@ -207,6 +218,9 @@ jobs:
echo "$KUBECONFIG_B64" | base64 -d > /workspace/.kube/config echo "$KUBECONFIG_B64" | base64 -d > /workspace/.kube/config
chmod 600 /workspace/.kube/config chmod 600 /workspace/.kube/config
fi fi
- name: Configure module registry auth
run: |
git config --global url."https://${GITLAB_MODULE_TOKEN}@gitlab.sarex.io/".insteadOf "ssh://git@gitlab.sarex.io/"
- name: Decrypt secret values - name: Decrypt secret values
# SOPS_AGE_KEY only reaches this step, not the whole job - the rest # SOPS_AGE_KEY only reaches this step, not the whole job - the rest
# (checkout, kubeconfig, terragrunt run) never sees it. # (checkout, kubeconfig, terragrunt run) never sees it.

File diff suppressed because it is too large Load Diff

View File

@ -541,6 +541,9 @@ environments:
- name: test-terraform - name: test-terraform
manage: true manage: true
image_pull_secret: false # regcred сюда приходит через v2 ownership=referenced, не через legacy fan-out image_pull_secret: false # regcred сюда приходит через v2 ownership=referenced, не через legacy fan-out
- name: rabbitmq-module-test
manage: true
image_pull_secret: false
# In-cluster RabbitMQ (bitnami, ns django). Admin creds - secrets/rabbitmq/auth # In-cluster RabbitMQ (bitnami, ns django). Admin creds - secrets/rabbitmq/auth
# в Vault, засеяно вручную из существующего django/rabbitmq-secret (см. план, # в Vault, засеяно вручную из существующего django/rabbitmq-secret (см. план,
@ -550,17 +553,59 @@ environments:
amqp_port: 5672 amqp_port: 5672
vhosts: vhosts:
- name: test-terraform - name: test-terraform
- name: rabbitmq-module-test
users: users:
- name: test-terraform - name: test-terraform
password_length: 32 password_length: 32
password_special: false password_special: false
- name: rabbitmq-module-test
password_length: 32
password_special: false
permissions: permissions:
- user: test-terraform - user: test-terraform
vhost: test-terraform vhost: test-terraform
configure: ".*" configure: ".*"
write: ".*" write: ".*"
read: ".*" read: ".*"
- user: rabbitmq-module-test
vhost: rabbitmq-module-test
configure: ".*"
write: ".*"
read: ".*"
# Пилот внешнего модуля terraform-modules/rabbitmq (RABBITMQ-MODULE-PILOT.md) -
# отдельные vhost/user/queue от test-terraform, чтобы не трогать уже рабочий
# secrets-contract-probe. Задействует все сущности, которые умеет модуль.
topic_permissions:
- vhost: rabbitmq-module-test
user: rabbitmq-module-test
permissions:
- exchange: rabbitmq-module-test.topic
write: "^allowed\\..*"
read: "^allowed\\..*"
exchanges:
- name: rabbitmq-module-test.direct
vhost: rabbitmq-module-test
type: direct
- name: rabbitmq-module-test.topic
vhost: rabbitmq-module-test
type: topic
queues: queues:
- name: test-terraform-probe - name: test-terraform-probe
vhost: test-terraform vhost: test-terraform
durable: true durable: true
- name: rabbitmq-module-test-probe
vhost: rabbitmq-module-test
durable: true
bindings:
- vhost: rabbitmq-module-test
source: rabbitmq-module-test.direct
destination: rabbitmq-module-test-probe
destination_type: queue
routing_key: rabbitmq-module-test.routing
policies:
- name: rabbitmq-module-test-ttl
vhost: rabbitmq-module-test
pattern: "^rabbitmq-module-test"
apply_to: queues
definition:
message-ttl: "60000"

View File

@ -40,7 +40,10 @@ remote_state {
} }
terraform { terraform {
source = "${get_terragrunt_dir()}/../../modules//rabbitmq" # Пилот внешнего модуля обкатывается только на brusnika-stage - остальные
# контуры остаются на локальном modules/rabbitmq до полной миграции
# (RABBITMQ-MODULE-PILOT.md, раздел 9).
source = local.env_name == "brusnika-stage" ? "git::ssh://git@gitlab.sarex.io/infra/terraform-modules/rabbitmq.git?ref=v1.0.2" : "${get_terragrunt_dir()}/../../modules//rabbitmq"
} }
inputs = { inputs = {

View File

@ -0,0 +1,48 @@
# Acceptance-test deployment for the standalone rabbitmq module pilot
# (RABBITMQ-MODULE-PILOT.md) on brusnika-stage. Applied manually with kubectl
# after `live/namespace`, `live/rabbitmq` and `live/secrets` are applied for
# INFRA_ENV=brusnika-stage - not part of any terragrunt stack, throwaway probe.
apiVersion: apps/v1
kind: Deployment
metadata:
name: rabbitmq-module-test-probe
namespace: rabbitmq-module-test
labels:
app: rabbitmq-module-test-probe
spec:
replicas: 1
selector:
matchLabels:
app: rabbitmq-module-test-probe
template:
metadata:
labels:
app: rabbitmq-module-test-probe
spec:
imagePullSecrets:
- name: regcred
containers:
- name: probe
image: cr.yandex/crp3ccidau046kdj8g9q/secrets-contract-probe:v1
env:
- name: RABBITMQ_HOST
valueFrom: { secretKeyRef: { name: rabbitmq, key: host } }
- name: RABBITMQ_PORT
valueFrom: { secretKeyRef: { name: rabbitmq, key: port } }
- name: RABBITMQ_VHOST
valueFrom: { secretKeyRef: { name: rabbitmq, key: vhost } }
- name: RABBITMQ_USERNAME
valueFrom: { secretKeyRef: { name: rabbitmq, key: username } }
- name: RABBITMQ_PASSWORD
valueFrom: { secretKeyRef: { name: rabbitmq, key: password } }
- name: PROBE_QUEUE
value: rabbitmq-module-test-probe
- name: PROBE_INTERVAL_SECONDS
value: "15"
resources:
requests:
cpu: 10m
memory: 32Mi
limits:
cpu: 100m
memory: 64Mi