Commit Graph

150 Commits

Author SHA1 Message Date
0752ccc54e change camunda identity secrets for vad connectors optimize tasklist zeebe
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m10s
Terraform Terragrunt (contour) / plan (push) Successful in 1m10s
Terraform Terragrunt (contour) / apply (push) Successful in 1m18s
2026-09-23 12:46:55 +03:00
d639dcd20b change camunda identity secret for vad 2026-09-23 12:17:51 +03:00
ivan
04de6df28a vad: minio credentials for notes (bucket notes, admin creds via s3-proxy)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 13:37:17 +05:00
ivan
4db9ed087c vad: minio credentials for rfi (bucket rfi, admin creds via s3-proxy)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 13:36:44 +05:00
ivan
f3e59c9ca2 vad: minio credentials for contracts (bucket contracts, admin creds via s3-proxy)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m5s
Terraform Terragrunt (contour) / plan (push) Successful in 1m6s
Terraform Terragrunt (contour) / apply (push) Successful in 1m7s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 17:30:43 +05:00
ivan
859075837e vad: processing task credentials in vault/common/django_auth (django-auth, pdm-api-db, bim-api-v2-db, yc-s3) and read access
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m11s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 16:59:47 +05:00
ivan
bd0e968a36 vad: fixed kafka credentials - user proc (flows, issues) and pm (pm, message-hub)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 16:15:39 +05:00
ivan
b643a4be6d vad: real zitadel service account key for documentations
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:51:33 +05:00
ivan
d23ce35d7b vad: real zitadel access token for django and iam
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:32:35 +05:00
ivan
df5c8cf0b7 vad: pm uses the django bucket instead of its own
S3 bucket names must be at least 3 characters, so a bucket called "pm" cannot
be created (live/s3 apply failed on it). Drop the pm bucket and point the
minio/apps/pm secret at the existing django bucket.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:01:40 +05:00
ivan
f868b8285a vad: fix cde-env secrets entry (v2 needs id/schema, data must be base64)
The entry used v2-only keys (ownership/targets/extra_fields) but was named
via `name`, so live/secrets failed on `secret.id`. Also v2 `data` values are
base64 in k8s-secret (base64decode), so the plaintext values are now encoded.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 12:38:00 +05:00
ivan
6fd13c1290 vad: pm, message-hub, cde
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m8s
pm: postgres, rabbitmq, own kafka producer (self-contained
generate:true, message-hub reads the same credentials), S3.
message-hub: reads pm's postgres (same db/user, separate vault path)
and pm's kafka creds, own S3 bucket.
cde: single opaque vault/apps/cde blob per its CONFIGURATION.md.
Reused the real PUBLIC_KEY/CAMUNDA_CLIENT_SECRET/Telegram
token+group already shared identically between ugmk and yc-k8s-test.
AMQP creds pulled via secret_ref from the already-provisioned
rabbitmq/apps/cde secret. DATABASE_URL composed with the real
documentations postgres password.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:37:33 +05:00
ivan
234039f2e3 vad: kafka for flows, issues
Needed by the env-override patches in the iac repo (flows/backend.yaml,
flows/celery.yaml, issues/backend-s3.yaml, issues/celery-s3.yaml) which
source a vault-agent kafka secret that didn't exist for these apps yet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:16:19 +05:00
ivan
766e5e6daf vad: iam, faas
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m11s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s
iam reads django's own postgres credentials (per explicit
instruction - same underlying database), written to its own
apps/iam/postgres vault path via a second dependency-based secrets
entry pointing at the same cluster/db/user as django-postgres. Kafka
and S3 follow the established self-contained/admin-creds patterns.
Also added django_zitadel_access_token to the shared django_auth
extra fields (placeholder, non-functional, only needs to be present).

faas has no vault dependencies at all - namespace only, for regcred.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:06:50 +05:00
ivan
e7ebdcd174 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal
Same shapes already proven for sarex-contour: kafka for
inspections/mapper/system-log via the self-contained generate:true
path (field shape mismatch with the v2 type), S3 via the eav/django
admin credentials. subscriptions gets postgis declared per explicit
instruction - not installed on vad's postgres yet, needs to be done
out of band since I have no SSH access there.

transmittal additionally needs a one-off opaque secret at
vault/apps/transmittal (mailgun API key) - a random placeholder via
the v2 secrets type=opaque/random_keys, since there's no real mailgun
account and the app only needs the field to be present.

5 pure-frontend apps also wired in this push (cross-section,
document-link, prescriptions, projects, stamp-verification) - no
vault dependencies, namespaces added for regcred only.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:00:48 +05:00
ivan
98d0e2ceb9 vad: processing, flows, issues, bim
processing needs smtp_auth (newly enabled, generate:true placeholder
- non-functional SMTP but structurally valid so the pod starts).
flows reads the already-existing apps/documentations/postgres secret
(read-only grant, no new database). issues' S3 uses the eav admin
creds like django/documentations; note the app itself hardcodes the
bucket name to "rfi" instead of "issues" - pre-existing bug, not
fixed here. bim only needs its own postgres, same as sarex-contour.

Pinned the shared vault/common/django_auth to the real sarex-backend
superuser (hagen013) so issues' API calls actually authenticate -
the other consumers (workspaces, django, documentations, notes,
contracts) only use the raw token for inter-service basic auth trust
and don't care about the specific value.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:49:11 +05:00
ivan
51fd8b275a vad: django + documentations
django and documentations get postgres, rabbitmq (django + a shared
cde vhost that documentations' hasher/marks depend on), and rsa_keys
(already enabled). Kafka for django uses the self-contained
generate:true path, same reasoning as notes/contracts.

S3 for both uses the eav admin credentials directly (per explicit
instruction) rather than the two-push bucket dance - buckets are
still ordered via live/s3 so they physically exist, but the vault
secret is wired with the admin key/secret right away.

documentations also needs two extra django_auth fields it reads as
raw JSON (documentations_s3_service_account_json and
_zitadel_account_json - a structurally-valid but non-functional
placeholder RSA key, same approach used for sarex-contour, since the
app only needs a decodable PEM at startup, not a working Zitadel
integration).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:26:02 +05:00
ivan
92216914d8 vad: fix rabbitmq secret depends_on field names
k8s-secret's contract check and its rabbitmq_outputs_map lookup both
only honor depends_on.rabbitmq_vhost/rabbitmq_user - the vhost/user
fallback never fires because the primary keys default to "" rather
than being absent, so try() never falls through to them.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:10:46 +05:00
ivan
6d1817ee02 vad: notes, rfi, checklists, contracts postgres/rabbitmq/kafka (stage 1)
checklists needs only postgres + the already-enabled rsa_keys, fully
wired in one push. notes/rfi/contracts also get real rabbitmq
vhosts/users (v2 secrets type, field shapes match app templates) and
self-contained kafka creds via the legacy generate:true path (same
precedent as sarex-contour - the v2 kafka type writes flat fields but
these apps read a nested auth.* object, so it doesn't fit).

S3 for notes/rfi/contracts is deliberately left out: same nested
client.endpoint shape mismatch as eav. Buckets ordered via live/s3;
vault.data.infrastructure.minio.apps entries follow in stage 2 once
the real generated credentials are known.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:52:07 +05:00
ivan
5c257ad1b7 vad: eav S3 credentials (stage 2 of 2)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:38:21 +05:00
ivan
e657596ec6 vad: eav postgres db + role/policy (stage 1 of 2)
Adds the eav database and app policy/role/rsa_keys wiring. The minio
S3 secret for eav is deliberately left unset here: the new v2 secrets
contract writes flat s3 fields that don't match eav's expected nested
client.endpoint shape, so that secret has to be hand-populated with
the real live/s3-generated credentials in a follow-up commit. Until
then eav's pod will not start (agent-pre-populate-only needs every
declared secret path to resolve).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:17:24 +05:00
ivan
79144bed98 vad: workspaces postgres db + vault wiring
Enables app-level policy/role creation for vad (was fully disabled),
adds the workspaces database and a v2 secrets entry that pulls the
generated password from live/database via dependency block.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:22:33 +05:00
ivan
57ec941046 sarex-contour: fix zitadel k8s-auth role losing bound_service_account_namespaces
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m9s
Terraform Terragrunt (contour) / apply (push) Successful in 1m10s
The module's top-level infra merge replaces the role block wholesale
rather than deep-merging, so overriding only service_account_names
silently dropped the default service_account_namespaces on apply.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:15:09 +05:00
ivan
60d5fe3fce sarex-contour: bim, comparisons, drawings, inspections, mapper, measurements, notes, rfi, subscriptions, system-log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:10:28 +05:00
ivan
97fef103a3 sarex-contour: django_auth -> hagen013/zealot096 (реальный суперюзер django)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m16s
Terraform Terragrunt (contour) / plan (push) Successful in 1m13s
Terraform Terragrunt (contour) / apply (push) Successful in 1m12s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 15:14:17 +05:00
ivan
9f35b79310 sarex-contour: django_auth.token = base64(username:password)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m12s
Terraform Terragrunt (contour) / apply (push) Successful in 1m13s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 15:01:31 +05:00
ivan
51cff0eb7c sarex-contour: documentations_zitadel_account_json — валидный RSA PEM вместо заглушки
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:55:55 +05:00
ivan
ce4ef30621 sarex-contour: attachments + documentations vault (minio, rabbitmq/cde, django_auth extras)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:32:40 +05:00
ivan
f0af3ed8a0 sarex-contour: django_auth explicit username/password
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:57:19 +05:00
ivan
442fc92816 ++ sarex-contour: flows, issues, checklists, contracts vault (+ documentations stub for flows cross-db read)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:51:08 +05:00
ivan
d9409fd6bd ++ sarex-contour: eav + bi vault (postgres, eav также minio)
applications.eav — apps/eav/postgres + read_paths на minio/apps/eav и
vault/common/rsa_keys; minio.apps.eav с client.endpoint (шаблон eav
читает YC_S3_ENDPOINT_URL из .Data.data.client.endpoint, в отличие от
django, где эндпоинт захардкожен в манифесте).
applications.bi — apps/bi/postgres, единственная зависимость.
Все пароли — литералом из live/database и live/s3.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:26:52 +05:00
ivan
ac534338e8 ++ sarex-contour: rabbitmq.apps.django
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m10s
Terraform Terragrunt (contour) / plan (push) Successful in 1m9s
Terraform Terragrunt (contour) / apply (push) Successful in 1m11s
vhost/юзер django реально созданы в живом RabbitMQ (rabbitmqctl
add_vhost/add_user/set_permissions через kubectl exec) — тут только
кладём те же значения в Vault (generate: false, литерал), чтобы
vault-agent django их подхватил.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 13:05:13 +05:00
ivan
eb3afef85a ++ sarex-contour: RSA keys + kafka.apps.django
create_rsa_keys: true + common.rsa_keys.generate — закрывает
vault/common/rsa_keys для django (JWT_PRIVATE_KEY/JWT_PUBLIC_KEY).
kafka.apps.django.generate — закрывает kafka/apps/django; функционально
kafka django не использует (SERVER_KAFKA_ENABLED=False), но путь должен
резолвиться для vault-agent-init.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 13:01:47 +05:00
ivan
dda946f59e ++ sarex-contour: django postgres + zitadel access token
applications.django — secret_path apps/django/postgres (путь из
apps/django/base/backend.yaml), данные литералом из live/database.
read_paths включает rabbitmq/apps/django, minio/apps/django,
kafka/apps/django (ещё не заведены — следующим шагом) и
vault/common/{rsa_keys,django_auth}.

django_zitadel_access_token — то же значение, что у yc-k8s-test
(общее поле vault/common/django_auth.extra, по просьбе).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:59:21 +05:00
ivan
94f98b36ff ++ sarex-contour: minio.apps.django (данные из live/s3)
minio.enabled: true только ради apps.django — admin/role явно
выключены (нет in-cluster minio-инстанса, писать туда нечего и незачем
роль заводить). access_key/secret_key — реальные, с внешнего MinIO
(live/s3, bucket "django" + IAM-юзер django-sa с policy только на этот
бакет).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:52:06 +05:00
ivan
4e0ea3532d ++ sarex-contour: workspaces (postgres + django_auth stub)
applications.workspaces — secret_path apps/workspaces/postgres (путь,
захардкоженный в iac base/backend.yaml), данные литералом из
live/database (реальная роль/база workspaces_db на 111.88.255.180).
read_paths включает vault/common/django_auth — приложение объявляет
эту vault-secret в манифесте (DJANGO_BASIC_AUTH), хотя код её не
использует (см. apps/workspaces/CONFIGURATION.md) — без неё
vault-agent-init не стартует.

create_django_auth/create_app_policies/create_app_roles: true —
только для sarex-contour, остальные окружения не тронуты (diff
подтверждён).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:32:25 +05:00
ivan
37d89a1b44 ++ sarex-contour: zitadel role.service_account_names: zitadel
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m18s
Terraform Terragrunt (contour) / plan (push) Successful in 1m7s
Terraform Terragrunt (contour) / apply (push) Successful in 1m11s
chart с serviceAccount.name: zitadel (не дефолтный zitadel-idp-contour)
- vault role должен биндиться на реальное имя SA, иначе 403 "service
account name not authorized" (как у vad — тот же паттерн).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:19:50 +05:00
ivan
679e79e4e1 ++ sarex-contour: zitadel.postgresql (пароль от live/database)
zitadel.enabled: true, postgresql.password — литерал, взят из вывода
live/database (реальная роль/база zitadel на внешнем postgres
111.88.255.180, создана этим же прогоном). generate: false — держим
терраформ-модуль в синхроне с уже существующей БД, а не плодим
отдельный независимый пароль.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:12:26 +05:00
ivan
9741451e97 ++ sarex-contour: rabbitmq auth.username: sarex
Забыл перенести username при копировании из yc-k8s-test — ушёл пустой
default, из-за которого bitnami-образ засеял админа как литеральный
'user' вместо ожидаемого, а readiness-проба (читает vault-файл с пустым
именем) падала на invalid credentials.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:28:54 +05:00
ivan
1c6c0542fc ++ sarex-contour: vault env block (kafka + rabbitmq)
Новое окружение environments.sarex-contour.vault — только то, что уже
раскатано через iac: kafka (bootstrap, role по дефолту kafka-kafka-contour/
kafka) и rabbitmq (auth, role по дефолту rabbitmq/rabbitmq), пароли
generate: true. postgresql/minio/zitadel/camunda явно enabled:false —
этих сервисов в sarex-contour ещё нет, инфраструктурные дефолты модуля
иначе завели бы под них пустые secrets/roles.

Остальные environments (yc-k8s-test, ugmk, brusnika-stage, wb, vad) не
затронуты — проверено построчным diff расшифрованного содержимого.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:08:12 +05:00
ivan
1d85cab221 ++ ugmk: bi jwt secret (vault/apps/bi), mock value for now
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m11s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s
Adds bi-jwt (opaque, SUPERSET_JWT_SECRET) to the secrets list and
vault/apps/bi to bi's read_paths, so bi can drop the plain
superset-jwt-secret k8s secret and pull it from vault instead.
Value is a mock placeholder until the real one is known.
2026-08-31 16:31:05 +05:00
ivan
444e372749 ++ ugmk: bi postgres database + vault role, mirroring documentations
bi_db with ltree/pg_stat_statements/uuid-ossp extensions in
infrastructure.yaml; bi vault application role and bi-postgres secret
(apps/bi/postgres) in infrastructure-secrets.yaml, same shape as the
documentations app.
2026-08-31 15:59:21 +05:00
a66155e598 ++ remove stale v1 keys left on zitadel-postgresql v2 entry 2026-08-26 14:29:06 +03:00
9006521b68 ++ generate real zitadel postgres password via in-cluster postgres users secret 2026-08-26 14:22:02 +03:00
96ff8968e9 ++ compose keycloak-password into the policy-allowed camunda/postgresql secret 2026-08-26 14:17:25 +03:00
4b487e1fa0 ++ eliminate identity-password circular vault reference 2026-08-26 14:03:22 +03:00
e122f93749 ++ add missing camunda identity-components and identity-firstuser secrets 2026-08-26 13:51:44 +03:00
863c4896b0 ++ fix custom_keys misuse that overwrote real generated passwords 2026-08-26 13:44:22 +03:00
d2c2698765 ++ bind zitadel vault role to real service account name 2026-08-26 13:30:35 +03:00
17aede83c0 ++ drop circular keycloak-password ref from camunda-postgresql 2026-08-26 12:53:12 +03:00