++ uralkal apps vault
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m7s
Terraform Terragrunt (contour) / plan (push) Successful in 1m13s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s

This commit is contained in:
Kochetkov S 2026-09-25 16:46:07 +03:00
parent 3696e4d675
commit df13f562c0
2 changed files with 91 additions and 7 deletions

View File

@ -5006,9 +5006,33 @@ environments:
create_infra_secrets: true
create_infra_policies: true
create_infra_roles: true
create_app_policies: false
create_app_roles: false
applications: {}
create_app_policies: true
create_app_roles: true
applications:
superset:
enabled: true
policy_name: superset
role_name: superset
service_account_names:
- superset
service_account_namespaces:
- superset
token_ttl: 24h
read_paths:
- vault/apps/superset
- apps/superset/postgres
trino:
enabled: true
policy_name: trino
role_name: trino
service_account_names:
- trino
service_account_namespaces:
- trino
token_ttl: 24h
read_paths:
- vault/apps/trino
- apps/trino/postgres
data:
infrastructure:
postgresql:
@ -5039,9 +5063,9 @@ environments:
identity_firstuser:
generate: ENC[AES256_GCM,data:dLlQrQ==,iv:fhWQqYQ4RdiqGZ87ujRKSoj7qqzhISJDt7eW9egGSMI=,tag:nnLaKPUC2uhcg353FrJX6Q==,type:bool]
keycloak_admin:
generate: ENC[AES256_GCM,data:RiGk8Q==,iv:bJkHALu/TIzSGBzBbyDA6AtENnqhkMwFaZBkY5cjchc=,tag:3CmLaSTFhGEa/+/z4UZRRA==,type:bool]
enabled: ENC[AES256_GCM,data:drLzRiI=,iv:g5Wr2wD3vFjTCcspmfMTHgdx7I1c7xXCdKrYZ3ZsY7Q=,tag:rfH/dkk1Ob1pKHJMlQqtmQ==,type:bool]
postgresql:
generate: ENC[AES256_GCM,data:gQ2bEA==,iv:HkREXF/4S+hMNej3wI4YCwe9OkfKqphkPjNIUuUiiHc=,tag:DUVyElfGWffQHM3Fdapgag==,type:bool]
enabled: ENC[AES256_GCM,data:5dqTc9E=,iv:8cBSQMF3A6CVpwPunLRI+GUKs+zMUiQH1Xud0WcerIY=,tag:qNXicY8posHFTCdg+OmfnQ==,type:bool]
secrets:
- name: uralkal-test-postgres
namespace: uralkal-test
@ -5127,6 +5151,46 @@ environments:
TRINO_INTERNAL_SHARED_SECRET:
length: 32
special: false
- name: camunda-keycloak-db
namespace: camunda
type: database
sink: vault
vault_path: camunda/_keycloak_db
depends_on:
cluster: main
db: bitnami_keycloak
user: bn_keycloak
- id: camunda-postgresql
schema: ""
namespace: camunda
ownership: managed
targets:
- kind: vault
path: camunda/postgresql
extra_fields:
postgres-password:
source:
kind: secret_ref
ref: vault://postgresql/admin#postgres-password
keycloak-password:
source:
kind: secret_ref
ref: vault://camunda/_keycloak_db#password
source:
kind: postgresql_user
ref:
cluster: main
database: identity
user: identity
- name: camunda-keycloak-admin
namespace: camunda
type: opaque
sink: vault
vault_path: camunda/keycloak-admin
random_keys:
admin-password:
length: 32
special: false
sops:
kms: []
gcp_kms: []
@ -5151,8 +5215,8 @@ sops:
dXRWUzlUOWVYMVdUR2tlREJveWF6SVEK/99wDif8yD2VGEqnCeTT6sunURWU+IEu
xwlt+WPoox0GUNw4efVFL4E7gd7FDJGtur+8si6i26XufQf2Tsk3xQ==
-----END AGE ENCRYPTED FILE-----
lastmodified: "2026-09-25T13:25:39Z"
mac: ENC[AES256_GCM,data:p9gHSOe3qwn/Od2AUjBnSex7yFmjMvv5lzlFr2tIe6DQiDUisYkGxQIVjpp86cUR3PIa51zTAS3zJuCmjJeIv3Yrf+nsDow+ev1Wkcjo8pu3eXH7KbhUuKbBUzCJhNQGt2t0tJrwIut2ZnGht6/QmVhD5HqDtE7PgQzuayaDZJ4=,iv:6fOxCJBdYqan7RvPs5q3JD2Tj9+HyXXMS9XlK35kjVU=,tag:JGjqQbF1WYEzf659hAQ9NQ==,type:str]
lastmodified: "2026-09-25T13:44:07Z"
mac: ENC[AES256_GCM,data:osu74g3eiUgSTBB+e2SWWSdKol3eW9U7hIYGwqsgTRDQ5BqqMMHji8hqOQeL6Ed2YMEamiIkKUq/YA8fWXHmXGKyDfhJmbx2/sWNjRww/u7q38r7JF1R/NCQDCr3UZImIsZY6/0sEfockIkEnOU0zu1WGWhCFz4ioMyl1uuErW8=,iv:VRtJ3LKtEnTxdXSYEGNg3rVXA+/NCQkvXDGkOfBNw2w=,tag:Y5NDxtfPs+qSo883VUR3tg==,type:str]
pgp: []
encrypted_regex: ^(data)$
version: 3.12.2

View File

@ -1285,6 +1285,26 @@ environments:
password_special: false
conn_limit: 20
- cluster_id: main
database:
name: identity
extensions: []
user:
name: identity
password_length: 32
password_special: false
conn_limit: 20
- cluster_id: main
database:
name: bitnami_keycloak
extensions: []
user:
name: bn_keycloak
password_length: 32
password_special: false
conn_limit: 20
minio:
endpoint: http://10.133.0.245:9000