mirror of
https://gitlab.sarex.io/infra/terraform-contour-mirror.git
synced 2026-10-07 13:51:36 +03:00
add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
370ce528d1
commit
f57f154d83
@ -2698,6 +2698,19 @@ environments:
|
||||
- kind: kubernetes
|
||||
namespace: test-namespace
|
||||
name: s3
|
||||
- id: test-namespace-kafka
|
||||
schema: kafka.v1
|
||||
namespace: test-namespace
|
||||
ownership: managed
|
||||
source:
|
||||
kind: kafka_user
|
||||
ref:
|
||||
cluster: wb
|
||||
user: wb-test
|
||||
targets:
|
||||
- kind: kubernetes
|
||||
namespace: test-namespace
|
||||
name: kafka
|
||||
sops:
|
||||
kms: []
|
||||
gcp_kms: []
|
||||
@ -2722,8 +2735,8 @@ sops:
|
||||
M0JZb1k0R0ErQ0M3SDNDWGRBclpnZjgKlEUpn/tBw6bs2PQqAfKwnpAEEThfiVAH
|
||||
uKIOpOFRImGY/7DTwtqfttnmIXKOm5kUJCOxzgEjh3MYc3ChQar3kQ==
|
||||
-----END AGE ENCRYPTED FILE-----
|
||||
lastmodified: "2026-08-11T10:15:46Z"
|
||||
mac: ENC[AES256_GCM,data:YyutnTb5sSZWpYItoi6oAesq97eBMaozvmWsNOyusOnHfKPhdbhOh0KseGlE8lPIjL1k8d5kOmwGxjjqRKzMP8xwxQO08gTWHvagovBnkx8mu7szi0wbBhvhkDlU0YvS5LzcFYVtpZHldyzWzZlVCz+Xxehrumk1uXWUYlyr22M=,iv:iCLGFMbb1nKx8MR6CtcKq4jCJtKDEc07XD/Fcd5CQvw=,tag:a9N2xAA/K7o9soZi9zrLkw==,type:str]
|
||||
lastmodified: "2026-08-11T11:10:49Z"
|
||||
mac: ENC[AES256_GCM,data:nZB+hvEqJDaaRoWD09mnRXscbKFfvh66OyUvhQ1+nbZ3I13q7zuQ9McmSRYunw9BRoO7omFQ9i68iWQQ1AdWe+0zr76f1cLfKlOt0+grFC40LOiZeEJd/VpCLp1N45Jre4A7WNjWuvN/YxgK2sl3u+1IP/zacDi3XZWqdhk25Sg=,iv:lFg0iOAJCfJWYiZLstqJFRQyGo7EwOUzBaNoYdHk49c=,tag:7LSpxCl7x/2ZAlY0pVDMvw==,type:str]
|
||||
pgp: []
|
||||
encrypted_regex: ^(data)$
|
||||
version: 3.12.2
|
||||
|
||||
@ -571,6 +571,29 @@ environments:
|
||||
- name: test-queue
|
||||
vhost: test-vhost
|
||||
durable: true
|
||||
kafka:
|
||||
kafka_cluster_refs:
|
||||
wb:
|
||||
bootstrap_servers: wb-prod-kafka-bootstrap.kafka.svc.cluster.local:9093
|
||||
sasl_mechanism: SCRAM-SHA-512
|
||||
security_protocol: SSL
|
||||
tls_enabled: true
|
||||
default_partitions: 3
|
||||
default_replication_factor: 3
|
||||
max_replication_factor: 3
|
||||
topics:
|
||||
- name: wb.test.event.v1
|
||||
owner: wb-test
|
||||
clusterRef: wb
|
||||
partitions: 3
|
||||
replicationFactor: 3
|
||||
users:
|
||||
- name: wb-test
|
||||
clusterRef: wb
|
||||
permissions:
|
||||
- topic: wb.test.event.v1
|
||||
roles:
|
||||
- PRODUCER
|
||||
|
||||
brusnika-stage:
|
||||
namespaces:
|
||||
|
||||
@ -98,9 +98,16 @@ provider "postgresql" {
|
||||
provider "kafka" {
|
||||
bootstrap_servers = ["${get_env("KAFKA_BOOTSTRAP", "kafka-kafka-contour-controller-0.kafka-kafka-contour-controller-headless.kafka.svc.cluster.local:9094")}"]
|
||||
tls_enabled = ${get_env("KAFKA_TLS_ENABLED", "false")}
|
||||
%{if get_env("KAFKA_CA_CERT", "") != ""~}
|
||||
ca_cert = <<-EOT
|
||||
${get_env("KAFKA_CA_CERT", "")}
|
||||
EOT
|
||||
%{endif~}
|
||||
%{if get_env("KAFKA_SASL_MECHANISM", "plain") != ""~}
|
||||
sasl_mechanism = "${get_env("KAFKA_SASL_MECHANISM", "plain")}"
|
||||
sasl_username = "${get_env("KAFKA_ADMIN_USER", "inter_broker_user")}"
|
||||
sasl_password = "${get_env("KAFKA_ADMIN_PASSWORD", "")}"
|
||||
%{endif~}
|
||||
}
|
||||
|
||||
# RabbitMQ provider is configured INSIDE modules/rabbitmq (from its management_*
|
||||
|
||||
Loading…
Reference in New Issue
Block a user