Commit Graph

421 Commits

Author SHA1 Message Date
f205274cf3 ++ first contour pipeline 2026-09-30 11:22:49 +03:00
1e344b29d5 ++ ugmk zitadel vault sa
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m11s
Terraform Terragrunt (contour) / plan (push) Successful in 1m11s
Terraform Terragrunt (contour) / apply (push) Successful in 1m13s
2026-09-29 21:41:10 +03:00
ivan
1faf40426c uralkal: drop cde-env for now — its extra_fields read rabbitmq/apps/cde and vault/common/rsa_keys, which vault-secrets hasn't created yet on a fresh apply, and secrets runs before vault-secrets alphabetically. Re-add once cde-env's real config is ready, via the STACKS=vault-secrets bootstrap run.
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m10s
Terraform Terragrunt (contour) / plan (push) Successful in 1m15s
Terraform Terragrunt (contour) / apply (push) Successful in 1m18s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 22:27:16 +03:00
ivan
04c8946b53 uralkal: rename databases to match the reference naming (django->sarex_db, documentations->documentations_db, notes->notes_db, flows->flow_db, pm->pm_db, workspaces_db->workspaces)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m14s
Terraform Terragrunt (contour) / apply (push) Successful in 1m11s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:55:07 +03:00
ivan
b0435647ac uralkal: order infra for the 36 business apps replicated in iac
namespaces/databases/buckets/rabbitmq vhosts for all app namespaces
(mirrors the vad set: workspaces, eav, notes, rfi, checklists, contracts,
django, documentations, processing, flows, issues, bim, attachments, bi,
comparisons, drawings, inspections, mapper, measurements, subscriptions,
system-log, transmittal, iam, pm, message-hub, cde).

vault: applications/read_paths for the 26 apps that need Vault secrets,
common.django_auth/rsa_keys/smtp_auth, minio.apps (admin creds tfstate/
09Eat4eiMcg5 via s3-proxy, matching the iac s3-proxy component), kafka.apps
(random creds, kafka users still need manual SCRAM creation like vad).

cde-env carries the same structure as vad's but without DATABASE_URL
(documentations DB creds not known until this DB is actually created) and
without a real Camunda/Zitadel-issued secret — those are follow-ups.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-28 14:44:49 +03:00
d9158a6b8a ++ uralkal zitadel bundled
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s
2026-09-25 17:27:14 +03:00
df13f562c0 ++ uralkal apps vault
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m7s
Terraform Terragrunt (contour) / plan (push) Successful in 1m13s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s
2026-09-25 16:46:07 +03:00
3696e4d675 ++ uralkal apps infra 2026-09-25 16:26:20 +03:00
b4522737fe ++ uralkal vault infra 2026-09-25 16:18:39 +03:00
f62e062ba3 ++ uralkal test only 2026-09-25 15:40:57 +03:00
f04ef68fdc ++ trigger uralkal 2026-09-25 15:16:08 +03:00
a590a37fb0 ++ uralkal vault block 2026-09-25 14:26:52 +03:00
1a33c9ec5d ++ uralkal test entities 2026-09-25 11:06:10 +03:00
c7cbf7148c ++ uralkal environment 2026-09-25 11:04:36 +03:00
f416ca5441 ++ offline-uralkal 2026-09-24 12:01:43 +03:00
0752ccc54e change camunda identity secrets for vad connectors optimize tasklist zeebe
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m10s
Terraform Terragrunt (contour) / plan (push) Successful in 1m10s
Terraform Terragrunt (contour) / apply (push) Successful in 1m18s
2026-09-23 12:46:55 +03:00
bb61d7c5f4 ++ trash commit to trigger workflow 2026-09-23 12:29:25 +03:00
d639dcd20b change camunda identity secret for vad 2026-09-23 12:17:51 +03:00
ivan
04de6df28a vad: minio credentials for notes (bucket notes, admin creds via s3-proxy)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 13:37:17 +05:00
ivan
4db9ed087c vad: minio credentials for rfi (bucket rfi, admin creds via s3-proxy)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-23 13:36:44 +05:00
ivan
f3e59c9ca2 vad: minio credentials for contracts (bucket contracts, admin creds via s3-proxy)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m5s
Terraform Terragrunt (contour) / plan (push) Successful in 1m6s
Terraform Terragrunt (contour) / apply (push) Successful in 1m7s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 17:30:43 +05:00
ivan
859075837e vad: processing task credentials in vault/common/django_auth (django-auth, pdm-api-db, bim-api-v2-db, yc-s3) and read access
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m11s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 16:59:47 +05:00
ivan
bd0e968a36 vad: fixed kafka credentials - user proc (flows, issues) and pm (pm, message-hub)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 16:15:39 +05:00
ivan
b643a4be6d vad: real zitadel service account key for documentations
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:51:33 +05:00
ivan
d23ce35d7b vad: real zitadel access token for django and iam
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:32:35 +05:00
ivan
df5c8cf0b7 vad: pm uses the django bucket instead of its own
S3 bucket names must be at least 3 characters, so a bucket called "pm" cannot
be created (live/s3 apply failed on it). Drop the pm bucket and point the
minio/apps/pm secret at the existing django bucket.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 13:01:40 +05:00
ivan
690b9fb27b vad: stop generating regcred for the 20 newer namespaces
TF_VAR_secrets crossed the 128 KiB per-env-string kernel limit (each
regcred entry carries the full base64 dockerconfigjson, ~4.7 KiB), so
terraform init on live/secrets failed with "argument list too long" and
run_all_stacks aborted before any apply. Keep image_pull_secret only for
the 17 namespaces terraform already manages; the rest get regcred by hand.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 12:52:10 +05:00
ivan
f868b8285a vad: fix cde-env secrets entry (v2 needs id/schema, data must be base64)
The entry used v2-only keys (ownership/targets/extra_fields) but was named
via `name`, so live/secrets failed on `secret.id`. Also v2 `data` values are
base64 in k8s-secret (base64decode), so the plaintext values are now encoded.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-21 12:38:00 +05:00
ivan
6fd13c1290 vad: pm, message-hub, cde
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m8s
Terraform Terragrunt (contour) / apply (push) Successful in 1m8s
pm: postgres, rabbitmq, own kafka producer (self-contained
generate:true, message-hub reads the same credentials), S3.
message-hub: reads pm's postgres (same db/user, separate vault path)
and pm's kafka creds, own S3 bucket.
cde: single opaque vault/apps/cde blob per its CONFIGURATION.md.
Reused the real PUBLIC_KEY/CAMUNDA_CLIENT_SECRET/Telegram
token+group already shared identically between ugmk and yc-k8s-test.
AMQP creds pulled via secret_ref from the already-provisioned
rabbitmq/apps/cde secret. DATABASE_URL composed with the real
documentations postgres password.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:37:33 +05:00
ivan
234039f2e3 vad: kafka for flows, issues
Needed by the env-override patches in the iac repo (flows/backend.yaml,
flows/celery.yaml, issues/backend-s3.yaml, issues/celery-s3.yaml) which
source a vault-agent kafka secret that didn't exist for these apps yet.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 02:16:19 +05:00
ivan
766e5e6daf vad: iam, faas
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m11s
Terraform Terragrunt (contour) / apply (push) Successful in 1m9s
iam reads django's own postgres credentials (per explicit
instruction - same underlying database), written to its own
apps/iam/postgres vault path via a second dependency-based secrets
entry pointing at the same cluster/db/user as django-postgres. Kafka
and S3 follow the established self-contained/admin-creds patterns.
Also added django_zitadel_access_token to the shared django_auth
extra fields (placeholder, non-functional, only needs to be present).

faas has no vault dependencies at all - namespace only, for regcred.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:06:50 +05:00
ivan
e7ebdcd174 vad: attachments, bi, comparisons, drawings, inspections, mapper, measurements, subscriptions, system-log, transmittal
Same shapes already proven for sarex-contour: kafka for
inspections/mapper/system-log via the self-contained generate:true
path (field shape mismatch with the v2 type), S3 via the eav/django
admin credentials. subscriptions gets postgis declared per explicit
instruction - not installed on vad's postgres yet, needs to be done
out of band since I have no SSH access there.

transmittal additionally needs a one-off opaque secret at
vault/apps/transmittal (mailgun API key) - a random placeholder via
the v2 secrets type=opaque/random_keys, since there's no real mailgun
account and the app only needs the field to be present.

5 pure-frontend apps also wired in this push (cross-section,
document-link, prescriptions, projects, stamp-verification) - no
vault dependencies, namespaces added for regcred only.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 20:00:48 +05:00
ivan
98d0e2ceb9 vad: processing, flows, issues, bim
processing needs smtp_auth (newly enabled, generate:true placeholder
- non-functional SMTP but structurally valid so the pod starts).
flows reads the already-existing apps/documentations/postgres secret
(read-only grant, no new database). issues' S3 uses the eav admin
creds like django/documentations; note the app itself hardcodes the
bucket name to "rfi" instead of "issues" - pre-existing bug, not
fixed here. bim only needs its own postgres, same as sarex-contour.

Pinned the shared vault/common/django_auth to the real sarex-backend
superuser (hagen013) so issues' API calls actually authenticate -
the other consumers (workspaces, django, documentations, notes,
contracts) only use the raw token for inter-service basic auth trust
and don't care about the specific value.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:49:11 +05:00
ivan
51fd8b275a vad: django + documentations
django and documentations get postgres, rabbitmq (django + a shared
cde vhost that documentations' hasher/marks depend on), and rsa_keys
(already enabled). Kafka for django uses the self-contained
generate:true path, same reasoning as notes/contracts.

S3 for both uses the eav admin credentials directly (per explicit
instruction) rather than the two-push bucket dance - buckets are
still ordered via live/s3 so they physically exist, but the vault
secret is wired with the admin key/secret right away.

documentations also needs two extra django_auth fields it reads as
raw JSON (documentations_s3_service_account_json and
_zitadel_account_json - a structurally-valid but non-functional
placeholder RSA key, same approach used for sarex-contour, since the
app only needs a decodable PEM at startup, not a working Zitadel
integration).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:26:02 +05:00
ivan
92216914d8 vad: fix rabbitmq secret depends_on field names
k8s-secret's contract check and its rabbitmq_outputs_map lookup both
only honor depends_on.rabbitmq_vhost/rabbitmq_user - the vhost/user
fallback never fires because the primary keys default to "" rather
than being absent, so try() never falls through to them.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 19:10:46 +05:00
ivan
6d1817ee02 vad: notes, rfi, checklists, contracts postgres/rabbitmq/kafka (stage 1)
checklists needs only postgres + the already-enabled rsa_keys, fully
wired in one push. notes/rfi/contracts also get real rabbitmq
vhosts/users (v2 secrets type, field shapes match app templates) and
self-contained kafka creds via the legacy generate:true path (same
precedent as sarex-contour - the v2 kafka type writes flat fields but
these apps read a nested auth.* object, so it doesn't fit).

S3 for notes/rfi/contracts is deliberately left out: same nested
client.endpoint shape mismatch as eav. Buckets ordered via live/s3;
vault.data.infrastructure.minio.apps entries follow in stage 2 once
the real generated credentials are known.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:52:07 +05:00
ivan
5c257ad1b7 vad: eav S3 credentials (stage 2 of 2)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:38:21 +05:00
ivan
e657596ec6 vad: eav postgres db + role/policy (stage 1 of 2)
Adds the eav database and app policy/role/rsa_keys wiring. The minio
S3 secret for eav is deliberately left unset here: the new v2 secrets
contract writes flat s3 fields that don't match eav's expected nested
client.endpoint shape, so that secret has to be hand-populated with
the real live/s3-generated credentials in a follow-up commit. Until
then eav's pod will not start (agent-pre-populate-only needs every
declared secret path to resolve).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 18:17:24 +05:00
d756a89697 ++ vad kafka: disable acl creation, broker has no authorizer 2026-09-17 15:39:17 +03:00
ivan
79144bed98 vad: workspaces postgres db + vault wiring
Enables app-level policy/role creation for vad (was fully disabled),
adds the workspaces database and a v2 secrets entry that pulls the
generated password from live/database via dependency block.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 17:22:33 +05:00
a632f98a9a ++ add vad kafka test topic and user 2026-09-17 15:12:13 +03:00
69efede7b6 ++ offline provider mirror for contour runner 2026-09-17 15:11:41 +03:00
ivan
57ec941046 sarex-contour: fix zitadel k8s-auth role losing bound_service_account_namespaces
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m8s
Terraform Terragrunt (contour) / plan (push) Successful in 1m9s
Terraform Terragrunt (contour) / apply (push) Successful in 1m10s
The module's top-level infra merge replaces the role block wholesale
rather than deep-merging, so overriding only service_account_names
silently dropped the default service_account_namespaces on apply.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:15:09 +05:00
ivan
60d5fe3fce sarex-contour: bim, comparisons, drawings, inspections, mapper, measurements, notes, rfi, subscriptions, system-log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-17 15:10:28 +05:00
ivan
97fef103a3 sarex-contour: django_auth -> hagen013/zealot096 (реальный суперюзер django)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m16s
Terraform Terragrunt (contour) / plan (push) Successful in 1m13s
Terraform Terragrunt (contour) / apply (push) Successful in 1m12s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 15:14:17 +05:00
ivan
9f35b79310 sarex-contour: django_auth.token = base64(username:password)
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m13s
Terraform Terragrunt (contour) / plan (push) Successful in 1m12s
Terraform Terragrunt (contour) / apply (push) Successful in 1m13s
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 15:01:31 +05:00
ivan
51cff0eb7c sarex-contour: documentations_zitadel_account_json — валидный RSA PEM вместо заглушки
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:55:55 +05:00
ivan
ffd36826f3 sarex-contour: documentations db extension (timescaledb) — установлен на сервере
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:49:43 +05:00
ivan
b5df31a4f5 sarex-contour: revert timescaledb (extension not installed on postgres server)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:44:07 +05:00
ivan
2a2a61038e sarex-contour: documentations db extension (timescaledb)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 14:42:23 +05:00