Commit Graph

133 Commits

Author SHA1 Message Date
c7cbf7148c ++ uralkal environment 2026-09-25 11:04:36 +03:00
ivan
df5c8cf0b7 vad: pm uses the django bucket instead of its own
S3 bucket names must be at least 3 characters, so a bucket called "pm" cannot
be created (live/s3 apply failed on it). Drop the pm bucket and point the
minio/apps/pm secret at the existing django bucket.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:01:40 +05:00
ivan
690b9fb27b vad: stop generating regcred for the 20 newer namespaces
TF_VAR_secrets crossed the 128 KiB per-env-string kernel limit (each
regcred entry carries the full base64 dockerconfigjson, ~4.7 KiB), so
terraform init on live/secrets failed with "argument list too long" and
run_all_stacks aborted before any apply. Keep image_pull_secret only for
the 17 namespaces terraform already manages; the rest get regcred by hand.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 12:52:10 +05:00
ivan
6fd13c1290 vad: pm, message-hub, cde
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m8s
pm: postgres, rabbitmq, own kafka producer (self-contained
generate:true, message-hub reads the same credentials), S3.
message-hub: reads pm's postgres (same db/user, separate vault path)
and pm's kafka creds, own S3 bucket.
cde: single opaque vault/apps/cde blob per its CONFIGURATION.md.
Reused the real PUBLIC_KEY/CAMUNDA_CLIENT_SECRET/Telegram
token+group already shared identically between ugmk and yc-k8s-test.
AMQP creds pulled via secret_ref from the already-provisioned
rabbitmq/apps/cde secret. DATABASE_URL composed with the real
documentations postgres password.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:37:33 +05:00
ivan
766e5e6daf vad: iam, faas
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m11s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s
iam reads django's own postgres credentials (per explicit
instruction - same underlying database), written to its own
apps/iam/postgres vault path via a second dependency-based secrets
entry pointing at the same cluster/db/user as django-postgres. Kafka
and S3 follow the established self-contained/admin-creds patterns.
Also added django_zitadel_access_token to the shared django_auth
extra fields (placeholder, non-functional, only needs to be present).

faas has no vault dependencies at all - namespace only, for regcred.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:06:50 +05:00
ivan
e7ebdcd174 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal
Same shapes already proven for sarex-contour: kafka for
inspections/mapper/system-log via the self-contained generate:true
path (field shape mismatch with the v2 type), S3 via the eav/django
admin credentials. subscriptions gets postgis declared per explicit
instruction - not installed on vad's postgres yet, needs to be done
out of band since I have no SSH access there.

transmittal additionally needs a one-off opaque secret at
vault/apps/transmittal (mailgun API key) - a random placeholder via
the v2 secrets type=opaque/random_keys, since there's no real mailgun
account and the app only needs the field to be present.

5 pure-frontend apps also wired in this push (cross-section,
document-link, prescriptions, projects, stamp-verification) - no
vault dependencies, namespaces added for regcred only.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:00:48 +05:00
ivan
98d0e2ceb9 vad: processing, flows, issues, bim
processing needs smtp_auth (newly enabled, generate:true placeholder
- non-functional SMTP but structurally valid so the pod starts).
flows reads the already-existing apps/documentations/postgres secret
(read-only grant, no new database). issues' S3 uses the eav admin
creds like django/documentations; note the app itself hardcodes the
bucket name to "rfi" instead of "issues" - pre-existing bug, not
fixed here. bim only needs its own postgres, same as sarex-contour.

Pinned the shared vault/common/django_auth to the real sarex-backend
superuser (hagen013) so issues' API calls actually authenticate -
the other consumers (workspaces, django, documentations, notes,
contracts) only use the raw token for inter-service basic auth trust
and don't care about the specific value.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:49:11 +05:00
ivan
51fd8b275a vad: django + documentations
django and documentations get postgres, rabbitmq (django + a shared
cde vhost that documentations' hasher/marks depend on), and rsa_keys
(already enabled). Kafka for django uses the self-contained
generate:true path, same reasoning as notes/contracts.

S3 for both uses the eav admin credentials directly (per explicit
instruction) rather than the two-push bucket dance - buckets are
still ordered via live/s3 so they physically exist, but the vault
secret is wired with the admin key/secret right away.

documentations also needs two extra django_auth fields it reads as
raw JSON (documentations_s3_service_account_json and
_zitadel_account_json - a structurally-valid but non-functional
placeholder RSA key, same approach used for sarex-contour, since the
app only needs a decodable PEM at startup, not a working Zitadel
integration).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:26:02 +05:00
ivan
6d1817ee02 vad: notes, rfi, checklists, contracts postgres/rabbitmq/kafka (stage 1)
checklists needs only postgres + the already-enabled rsa_keys, fully
wired in one push. notes/rfi/contracts also get real rabbitmq
vhosts/users (v2 secrets type, field shapes match app templates) and
self-contained kafka creds via the legacy generate:true path (same
precedent as sarex-contour - the v2 kafka type writes flat fields but
these apps read a nested auth.* object, so it doesn't fit).

S3 for notes/rfi/contracts is deliberately left out: same nested
client.endpoint shape mismatch as eav. Buckets ordered via live/s3;
vault.data.infrastructure.minio.apps entries follow in stage 2 once
the real generated credentials are known.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:52:07 +05:00
ivan
e657596ec6 vad: eav postgres db + role/policy (stage 1 of 2)
Adds the eav database and app policy/role/rsa_keys wiring. The minio
S3 secret for eav is deliberately left unset here: the new v2 secrets
contract writes flat s3 fields that don't match eav's expected nested
client.endpoint shape, so that secret has to be hand-populated with
the real live/s3-generated credentials in a follow-up commit. Until
then eav's pod will not start (agent-pre-populate-only needs every
declared secret path to resolve).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:17:24 +05:00
d756a89697 ++ vad kafka: disable acl creation, broker has no authorizer 2026-09-17 15:39:17 +03:00
ivan
79144bed98 vad: workspaces postgres db + vault wiring
Enables app-level policy/role creation for vad (was fully disabled),
adds the workspaces database and a v2 secrets entry that pulls the
generated password from live/database via dependency block.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:22:33 +05:00
a632f98a9a ++ add vad kafka test topic and user 2026-09-17 15:12:13 +03:00
ivan
60d5fe3fce sarex-contour: bim, comparisons, drawings, inspections, mapper, measurements, notes, rfi, subscriptions, system-log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:10:28 +05:00
ivan
ffd36826f3 sarex-contour: documentations db extension (timescaledb) — установлен на сервере
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:49:43 +05:00
ivan
b5df31a4f5 sarex-contour: revert timescaledb (extension not installed on postgres server)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:44:07 +05:00
ivan
2a2a61038e sarex-contour: documentations db extension (timescaledb)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:42:23 +05:00
ivan
ad599b180e sarex-contour: documentations db extensions (ltree, uuid-ossp, pg_stat_statements)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:37:49 +05:00
ivan
2b8f5449a7 sarex-contour: databases (attachments) + buckets (attachments, documentations)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:26:04 +05:00
ivan
68cdd58196 ++ sarex-contour: databases (flows, issues, checklists, contracts, documentations) + buckets (issues, contracts)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:45:18 +05:00
ivan
fd31350ae0 ++ sarex-contour: databases (eav, bi) + bucket (eav)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:22:58 +05:00
ivan
6686dc9d44 ++ sarex-contour: databases (django)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:56:19 +05:00
ivan
b1e935b4f7 ++ sarex-contour: minio endpoint + bucket django
Тот же внешний MinIO, что уже используется под tfstate
(111.88.252.72:9000) — не отдельный in-cluster инстанс.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:50:16 +05:00
ivan
b774caedce ++ sarex-contour: databases (workspaces_db)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:28:54 +05:00
ivan
0cde523972 ++ sarex-contour: databases (zitadel)
environments.sarex-contour.databases в infrastructure.yaml (plaintext,
без sops) — для live/database stack. Postgres внешний, отдельная тачка
(111.88.255.180:5432), не наш in-cluster instance. Только новый
top-level ключ, остальные окружения не тронуты (чистый append, diff
подтверждён).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:09:36 +05:00
ivan
444e372749 ++ ugmk: bi postgres database + vault role, mirroring documentations
bi_db with ltree/pg_stat_statements/uuid-ossp extensions in
infrastructure.yaml; bi vault application role and bi-postgres secret
(apps/bi/postgres) in infrastructure-secrets.yaml, same shape as the
documentations app.
2026-08-31 15:59:21 +05:00
6d1e4fa861 ++ add postgresql namespace to regcred rollout list
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m2s
Terraform Terragrunt (contour) / plan (push) Successful in 1m5s
Terraform Terragrunt (contour) / apply (push) Successful in 1m13s
2026-08-26 14:49:21 +03:00
5d0844b4c5 ++ wire zitadel and camunda vault secrets from real postgres passwords 2026-08-26 11:58:30 +03:00
917151ec16 ++ generate camunda and zitadel vault secrets for vad, drop conflicting db entries 2026-08-26 11:37:41 +03:00
ebb54303ab ++ add kafka camunda zitadel namespaces and databases for vad 2026-08-26 11:33:32 +03:00
8d39c5d612 ++ align vad rabbitmq with brusnika-stage contract 2026-08-26 10:57:05 +03:00
c69704e250 ++ add vad test database
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m2s
Terraform Terragrunt (contour) / plan (push) Successful in 1m3s
Terraform Terragrunt (contour) / apply (push) Successful in 1m3s
2026-08-25 19:37:05 +03:00
a81c1776bd ++ add empty vad environment 2026-08-25 19:20:36 +03:00
511814cab8 ++ fix superset database grant
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m6s
Terraform Terragrunt (contour) / plan (push) Successful in 1m9s
Terraform Terragrunt (contour) / apply (push) Successful in 1m10s
2026-08-20 13:29:26 +03:00
280559e7c8 ++ add superset trino ugmk secrets 2026-08-20 13:08:10 +03:00
128cdf0958 ++ drop test-terraform and rabbitmq-module-test from brusnika-stage
Some checks failed
Terraform Terragrunt (contour) / plan (push) Failing after 27s
Terraform Terragrunt (contour) / validate (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Has been skipped
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 15:44:43 +03:00
84454b41ae ++ point brusnika-stage at the shared rabbitmq
Some checks failed
Terraform Terragrunt (contour) / validate (push) Successful in 51s
Terraform Terragrunt (contour) / apply (push) Has been cancelled
Terraform Terragrunt (contour) / plan (push) Has been cancelled
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:24:06 +03:00
ed3aaaed49 ++ vault creds and regcred for the shared rabbitmq on brusnika-stage
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:10:44 +03:00
decffe42b1 ++ wire create_users flag and disable it for wb
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-11 16:37:24 +03:00
5b4b6084dd ++ drop wb kafka user and its secret, broker does not persist scram creds 2026-08-11 16:19:05 +03:00
fbf1f56362 ++ match wb test-queue arguments to what the broker actually set 2026-08-11 16:08:12 +03:00
e219da71ae ++ wb minio endpoint to a reachable node, nginx entrypoint is down 2026-08-11 15:57:17 +03:00
e9888d555e ++ disable kafka acls for wb, broker has no authorizer 2026-08-11 15:40:10 +03:00
d1337c38da ++ wb kafka to plaintext 9092, no tls no ca 2026-08-11 15:34:47 +03:00
417772abdc trigger ci in wb 2026-08-11 15:04:33 +03:00
736d990ad0 fix wb test-namespace regcred key collision, image_pull_secret true was triggering the legacy auto-fanout regcred on top of the explicit v2 referenced record, same key test-namespace/regcred, matches how brusnika-stage avoids this by setting image_pull_secret false
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:33:17 +03:00
f57f154d83 add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:15:57 +03:00
370ce528d1 ++ fix infrastructre.yaml
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-11 13:43:57 +03:00
867eed4052 ++ fix infrastructre.yaml 2026-08-11 13:36:04 +03:00
d5a2d639ad add wb environment, one test entity per resource type (namespace, rabbitmq vhost/user/queue, external postgres db/user, external minio bucket) plus matching v2 secret contracts
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 13:33:54 +03:00