Commit Graph

94 Commits

Author SHA1 Message Date
5b4b6084dd ++ drop wb kafka user and its secret, broker does not persist scram creds 2026-08-11 16:19:05 +03:00
fbf1f56362 ++ match wb test-queue arguments to what the broker actually set 2026-08-11 16:08:12 +03:00
e219da71ae ++ wb minio endpoint to a reachable node, nginx entrypoint is down 2026-08-11 15:57:17 +03:00
e9888d555e ++ disable kafka acls for wb, broker has no authorizer 2026-08-11 15:40:10 +03:00
d1337c38da ++ wb kafka to plaintext 9092, no tls no ca 2026-08-11 15:34:47 +03:00
417772abdc trigger ci in wb 2026-08-11 15:04:33 +03:00
736d990ad0 fix wb test-namespace regcred key collision, image_pull_secret true was triggering the legacy auto-fanout regcred on top of the explicit v2 referenced record, same key test-namespace/regcred, matches how brusnika-stage avoids this by setting image_pull_secret false
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:33:17 +03:00
f57f154d83 add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:15:57 +03:00
370ce528d1 ++ fix infrastructre.yaml
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-11 13:43:57 +03:00
867eed4052 ++ fix infrastructre.yaml 2026-08-11 13:36:04 +03:00
d5a2d639ad add wb environment, one test entity per resource type (namespace, rabbitmq vhost/user/queue, external postgres db/user, external minio bucket) plus matching v2 secret contracts
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 13:33:54 +03:00
cd14614538 ++ pilot external rabbitmq module on brusnika-stage only 2026-08-07 11:53:53 +03:00
d645e43de5 ++ add declarative secrets contract v2 (schema/ownership/targets/extra_fields)
module: optional schema/ownership/source_kind/source_ref/extra_fields fields,
backward compatible - legacy secrets keep resolving exactly as before.
ownership modes managed/referenced/observed/adopt_once replace ignore_changes
for v2 records; referenced reads a value straight from vault via a data
source; observed only verifies presence, writes nothing.

terragrunt: v1/v2 detection by marker keys, targets fan-out into the existing
flat secrets list (one entry per target, same resource-key scheme as today),
source.kind -> type/depends_on translation for the five documented kinds.

brusnika-stage: acceptance environment for the two test cases from the plan -
regcred (dockerconfigjson.v1, ownership=referenced, value from vault) and a
rabbitmq.v1 secret (ownership=managed) fanned out to both kubernetes and vault
targets from a single declaration.
2026-08-05 12:41:55 +03:00
ivan
98750a048a ++ 2026-08-03 16:36:40 +05:00
ivan
3d69653667 ++ 2026-08-01 14:02:23 +05:00
ivan
f8ec3dac9f ++ 2026-08-01 13:46:23 +05:00
ivan
27f0770e07 ++ 2026-08-01 13:06:59 +05:00
ivan
d5dcdf44f0 ++ 2026-07-31 17:12:51 +05:00
ivan
b818f612f0 ++ 2026-07-31 13:04:40 +05:00
ivan
f0b086a60f ++ 2026-07-30 21:08:45 +05:00
ivan
25228040a8 ++ 2026-07-29 18:21:01 +05:00
ivan
b3502feae4 ++ 2026-07-29 18:11:19 +05:00
ivan
914abbe64f ++ 2026-07-28 19:24:32 +05:00
ivan
19e725fa3f ++ 2026-07-28 17:14:35 +05:00
ivan
bdd21c097f ++ 2026-07-28 15:24:05 +05:00
ivan
989c8feb04 ++ 2026-07-25 21:21:47 +05:00
ivan
054d542968 ++ 2026-07-25 20:44:15 +05:00
ivan
88e747fc9b ++ 2026-07-25 20:26:45 +05:00
ivan
1a7b67d506 ++ 2026-07-25 20:20:33 +05:00
610b2d9dc8 ++ 2026-07-21 15:17:00 +00:00
55b196d1ec ++ 2026-07-21 14:13:24 +00:00
9a3402b912 ++ fix ugmk rabbitmq queue drift 2026-07-21 15:17:06 +03:00
b2cdaab66e ++ skip kafka acls on ugmk broker without authorizer 2026-07-21 14:49:01 +03:00
9417c514c7 test ci 2026-07-20 17:25:05 +03:00
1f50e8533a ++ add ugmk test app kafka postgres rabbitmq vault examples 2026-07-20 17:15:41 +03:00
f1dfb90dba ++ add ugmk namespace database vault secrets 2026-07-20 16:52:16 +03:00
be5133a954 add regcred namespace propagation 2026-07-20 12:20:20 +03:00
c3f5a4285c add regcred namespace propagation 2026-07-20 12:08:06 +03:00
a47837d039 remove ns 2026-07-17 18:15:18 +03:00
gitlab-pusher
4271700e79 ++ test ci 2026-07-17 14:04:52 +00:00
973a9dc6a5 ++ minio host configurable in yaml, incluster runner 2026-07-17 16:05:40 +03:00
gitlab-pusher
76dca2b220 ++ add wf dispatch and test ci 2026-07-17 11:14:48 +00:00
gitlab-pusher
cd7fe0249b ++ test ci 2026-07-17 11:10:31 +00:00
gitlab-pusher
668bbbf76d ++ test ci 2026-07-17 10:49:35 +00:00
b8b77536c3 ++ contour: yc-k8s-test env — test bucket+user, db+extensions+user, kafka topic+user, rabbitmq exchange+user; 4 test secrets (k8s static/dynamic, vault static/dynamic); vault-platform inert 2026-07-16 16:35:59 +03:00
ca7332bfdc fix live and repo state discrepancies 2026-07-16 11:08:00 +03:00
dbfa8aa594 ++ planning ns: projects-backend pg+s3 dynamic secrets, projects_db/planning user, projects-backend-prod bucket 2026-07-16 10:42:28 +03:00
Vladislav Verezhnikov
a09315dba8 + 2026-07-14 13:06:06 +05:00
81f3eabcdd add premises storage s3 bucket + secret 2026-07-10 13:14:46 +03:00
15dc79196c fix user import vs create mechanic 2026-07-10 12:36:37 +03:00