ce6228d6f2
++ trimspace kafka sasl mechanism, gitea var had trailing space
2026-08-11 15:18:38 +03:00
811c16a8b2
++ actually forward kafka/pg vars from gitea into job env, they were never wired
2026-08-11 15:11:27 +03:00
417772abdc
trigger ci in wb
2026-08-11 15:04:33 +03:00
7f6940b8ba
++ fix stale checkout skip, compare to GITHUB_SHA not just file presence
2026-08-11 14:56:52 +03:00
fcd6672ee2
++ kafka sasl mechanism none sentinel, gitea can't store empty vars
2026-08-11 14:46:45 +03:00
736d990ad0
fix wb test-namespace regcred key collision, image_pull_secret true was triggering the legacy auto-fanout regcred on top of the explicit v2 referenced record, same key test-namespace/regcred, matches how brusnika-stage avoids this by setting image_pull_secret false
...
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:33:17 +03:00
42c4e35291
revert the contracts-compiler wiring in live/rabbitmq/terragrunt.hcl, it broke the wb pipeline — locals cannot reference dependency in terragrunt, and live/contracts was never pushed anyway, this experiment isn't finished yet
...
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:29:35 +03:00
f57f154d83
add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
...
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:15:57 +03:00
370ce528d1
++ fix infrastructre.yaml
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-11 13:43:57 +03:00
867eed4052
++ fix infrastructre.yaml
2026-08-11 13:36:04 +03:00
d5a2d639ad
add wb environment, one test entity per resource type (namespace, rabbitmq vhost/user/queue, external postgres db/user, external minio bucket) plus matching v2 secret contracts
...
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 13:33:54 +03:00
ivan
d74baefa30
++
Terraform Terragrunt (contour) / validate (push) Successful in 53s
Terraform Terragrunt (contour) / plan (push) Successful in 55s
Terraform Terragrunt (contour) / apply (push) Successful in 55s
2026-08-09 14:16:10 +05:00
ivan
70895158fb
++
2026-08-09 13:40:53 +05:00
ivan
0907728217
++
2026-08-09 13:18:23 +05:00
ivan
d03f2efba2
++
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 54s
Terraform Terragrunt (contour) / apply (push) Successful in 59s
2026-08-08 16:01:03 +05:00
ivan
bb520d6980
++
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Successful in 54s
2026-08-08 13:14:46 +05:00
ivan
46b6c5f74e
++
2026-08-08 12:50:10 +05:00
94c4938547
align ugmk identity_components secrets with prod convention, connectors/operate/optimize/tasklist/zeebe now use the shared identity-secret-for-components value
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Successful in 54s
Terraform Terragrunt (contour) / apply (push) Successful in 56s
2026-08-07 16:49:17 +03:00
f9fca41c0c
fix cde CAMUNDA_CLIENT_SECRET to match current zeebe-secret
2026-08-07 14:53:06 +03:00
261b581508
fix camunda vault secrets: restore admin/firstuser/db passwords as explicit values, add identity-password/keycloak-password fields to camunda_postgresql secret
2026-08-07 14:38:52 +03:00
d642789448
++ bump brusnika-stage rabbitmq module to v1.0.3
Terraform Terragrunt (contour) / validate (push) Successful in 51s
Terraform Terragrunt (contour) / plan (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Successful in 54s
2026-08-07 12:49:28 +03:00
d99ba1989d
++ skip whole provider.tf block for brusnika-stage rabbitmq unit
Terraform Terragrunt (contour) / validate (push) Successful in 52s
Terraform Terragrunt (contour) / plan (push) Failing after 26s
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-07 12:26:15 +03:00
1d411af014
++ clear stale terragrunt-cache before each run
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-07 12:20:54 +03:00
044a0f7adf
++ fix duplicate required providers for brusnika-stage rabbitmq
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-07 12:13:33 +03:00
e6b02d42c5
++ fix module token auth format username colon token
Terraform Terragrunt (contour) / validate (push) Failing after 23s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-07 12:04:04 +03:00
f66f7839b9
++ gitignore all md except readme
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-07 11:53:53 +03:00
cd14614538
++ pilot external rabbitmq module on brusnika-stage only
2026-08-07 11:53:53 +03:00
d46f540a79
++ gitignore rabbitmq module pilot plan
2026-08-07 11:50:06 +03:00
c19bcac60a
++ gitignore almanac doc
2026-08-07 11:50:06 +03:00
ivan
b664a04688
++
Terraform Terragrunt (contour) / validate (push) Successful in 55s
Terraform Terragrunt (contour) / plan (push) Successful in 56s
Terraform Terragrunt (contour) / apply (push) Successful in 58s
2026-08-06 12:50:45 +05:00
ivan
bbe2b02e3c
++
Terraform Terragrunt (contour) / validate (push) Successful in 56s
Terraform Terragrunt (contour) / plan (push) Successful in 57s
Terraform Terragrunt (contour) / apply (push) Successful in 58s
2026-08-06 12:27:25 +05:00
3988c83ca4
++ enforce canonical field set for all v2 schemas, not just rabbitmq.v1
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m19s
Terraform Terragrunt (contour) / apply (push) Successful in 1m30s
2026-08-05 18:26:44 +03:00
e18bf1ce28
++ add STACKS filter bootstrap escape hatch for cross-stack read dependencies
2026-08-05 18:13:32 +03:00
573e8d04f6
++ fall back to in-cluster kubernetes auth when KUBECONFIG file doesn't exist
Terraform Terragrunt (contour) / validate (push) Successful in 1m14s
Terraform Terragrunt (contour) / plan (push) Successful in 1m35s
Terraform Terragrunt (contour) / apply (push) Successful in 1m19s
2026-08-05 18:02:44 +03:00
ivan
74f4e11b1d
++
2026-08-05 19:59:52 +05:00
47852a2170
++ fix inconsistent conditional result types in v2_source_ref_string
Terraform Terragrunt (contour) / validate (push) Successful in 1m7s
Terraform Terragrunt (contour) / plan (push) Failing after 1m8s
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-05 17:44:38 +03:00
ee8a64eb2e
++ forward SKIP_POSTGRES_ADMIN/SKIP_KAFKA_ADMIN/RABBITMQ_ENDPOINT vars into job env
Terraform Terragrunt (contour) / validate (push) Failing after 47s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-05 17:36:34 +03:00
ivan
8ee05e1dc6
++
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-05 19:25:32 +05:00
ivan
cf347a6a1a
++
2026-08-05 19:11:51 +05:00
ivan
6421953c73
++
2026-08-05 16:40:24 +05:00
964c718dc8
++ add SKIP_POSTGRES_ADMIN/SKIP_KAFKA_ADMIN flags, mirroring SKIP_MINIO_ADMIN
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / apply (push) Has been skipped
Terraform Terragrunt (contour) / plan (push) Has been skipped
2026-08-05 12:53:53 +03:00
7074281aba
++ add secrets-contract-probe test app for brusnika-stage acceptance test
2026-08-05 12:50:26 +03:00
9577ee8ad0
++ add verify_secret_contract.py for v2 secret acceptance testing
2026-08-05 12:43:30 +03:00
d645e43de5
++ add declarative secrets contract v2 (schema/ownership/targets/extra_fields)
...
module: optional schema/ownership/source_kind/source_ref/extra_fields fields,
backward compatible - legacy secrets keep resolving exactly as before.
ownership modes managed/referenced/observed/adopt_once replace ignore_changes
for v2 records; referenced reads a value straight from vault via a data
source; observed only verifies presence, writes nothing.
terragrunt: v1/v2 detection by marker keys, targets fan-out into the existing
flat secrets list (one entry per target, same resource-key scheme as today),
source.kind -> type/depends_on translation for the five documented kinds.
brusnika-stage: acceptance environment for the two test cases from the plan -
regcred (dockerconfigjson.v1, ownership=referenced, value from vault) and a
rabbitmq.v1 secret (ownership=managed) fanned out to both kubernetes and vault
targets from a single declaration.
2026-08-05 12:41:55 +03:00
8b98cee0a5
++ gitignore secrets contract plan
2026-08-05 12:02:03 +03:00
168f5d66ce
++ strip comments
2026-08-05 10:42:31 +03:00
b54fc6f29b
++ guard secrets/vault key typo at env top-level in contour terragrunt.hcl
2026-08-05 10:42:31 +03:00
ivan
631375d53f
++
2026-08-04 23:11:12 +05:00
1c232f7516
++ add dockerconfigjson contract check to k8s-secret module
2026-08-04 18:30:05 +03:00
9cde2dcab2
++ fail loudly on decrypt/env-lookup failure and secret key typos instead of silently empty
2026-08-04 18:30:05 +03:00