Commit Graph

113 Commits

Author SHA1 Message Date
ivan
fd31350ae0 ++ sarex-contour: databases (eav, bi) + bucket (eav)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-16 12:22:58 +05:00
ivan
6686dc9d44 ++ sarex-contour: databases (django)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:56:19 +05:00
ivan
b1e935b4f7 ++ sarex-contour: minio endpoint + bucket django
Тот же внешний MinIO, что уже используется под tfstate
(111.88.252.72:9000) — не отдельный in-cluster инстанс.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:50:16 +05:00
ivan
b774caedce ++ sarex-contour: databases (workspaces_db)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-15 12:28:54 +05:00
ivan
0cde523972 ++ sarex-contour: databases (zitadel)
environments.sarex-contour.databases в infrastructure.yaml (plaintext,
без sops) — для live/database stack. Postgres внешний, отдельная тачка
(111.88.255.180:5432), не наш in-cluster instance. Только новый
top-level ключ, остальные окружения не тронуты (чистый append, diff
подтверждён).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 18:09:36 +05:00
ivan
444e372749 ++ ugmk: bi postgres database + vault role, mirroring documentations
bi_db with ltree/pg_stat_statements/uuid-ossp extensions in
infrastructure.yaml; bi vault application role and bi-postgres secret
(apps/bi/postgres) in infrastructure-secrets.yaml, same shape as the
documentations app.
2026-08-31 15:59:21 +05:00
6d1e4fa861 ++ add postgresql namespace to regcred rollout list
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m2s
Terraform Terragrunt (contour) / plan (push) Successful in 1m5s
Terraform Terragrunt (contour) / apply (push) Successful in 1m13s
2026-08-26 14:49:21 +03:00
5d0844b4c5 ++ wire zitadel and camunda vault secrets from real postgres passwords 2026-08-26 11:58:30 +03:00
917151ec16 ++ generate camunda and zitadel vault secrets for vad, drop conflicting db entries 2026-08-26 11:37:41 +03:00
ebb54303ab ++ add kafka camunda zitadel namespaces and databases for vad 2026-08-26 11:33:32 +03:00
8d39c5d612 ++ align vad rabbitmq with brusnika-stage contract 2026-08-26 10:57:05 +03:00
c69704e250 ++ add vad test database
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m2s
Terraform Terragrunt (contour) / plan (push) Successful in 1m3s
Terraform Terragrunt (contour) / apply (push) Successful in 1m3s
2026-08-25 19:37:05 +03:00
a81c1776bd ++ add empty vad environment 2026-08-25 19:20:36 +03:00
511814cab8 ++ fix superset database grant
All checks were successful
Terraform Terragrunt (contour) / validate (push) Successful in 1m6s
Terraform Terragrunt (contour) / plan (push) Successful in 1m9s
Terraform Terragrunt (contour) / apply (push) Successful in 1m10s
2026-08-20 13:29:26 +03:00
280559e7c8 ++ add superset trino ugmk secrets 2026-08-20 13:08:10 +03:00
128cdf0958 ++ drop test-terraform and rabbitmq-module-test from brusnika-stage
Some checks failed
Terraform Terragrunt (contour) / plan (push) Failing after 27s
Terraform Terragrunt (contour) / validate (push) Successful in 53s
Terraform Terragrunt (contour) / apply (push) Has been skipped
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 15:44:43 +03:00
84454b41ae ++ point brusnika-stage at the shared rabbitmq
Some checks failed
Terraform Terragrunt (contour) / validate (push) Successful in 51s
Terraform Terragrunt (contour) / apply (push) Has been cancelled
Terraform Terragrunt (contour) / plan (push) Has been cancelled
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:24:06 +03:00
ed3aaaed49 ++ vault creds and regcred for the shared rabbitmq on brusnika-stage
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-12 12:10:44 +03:00
decffe42b1 ++ wire create_users flag and disable it for wb
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 2s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-11 16:37:24 +03:00
5b4b6084dd ++ drop wb kafka user and its secret, broker does not persist scram creds 2026-08-11 16:19:05 +03:00
fbf1f56362 ++ match wb test-queue arguments to what the broker actually set 2026-08-11 16:08:12 +03:00
e219da71ae ++ wb minio endpoint to a reachable node, nginx entrypoint is down 2026-08-11 15:57:17 +03:00
e9888d555e ++ disable kafka acls for wb, broker has no authorizer 2026-08-11 15:40:10 +03:00
d1337c38da ++ wb kafka to plaintext 9092, no tls no ca 2026-08-11 15:34:47 +03:00
417772abdc trigger ci in wb 2026-08-11 15:04:33 +03:00
736d990ad0 fix wb test-namespace regcred key collision, image_pull_secret true was triggering the legacy auto-fanout regcred on top of the explicit v2 referenced record, same key test-namespace/regcred, matches how brusnika-stage avoids this by setting image_pull_secret false
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:33:17 +03:00
f57f154d83 add kafka test topic/user to wb environment, wire kafka provider to work over TLS without SASL to match how production already connects to wb-prod-kafka-bootstrap:9093
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 14:15:57 +03:00
370ce528d1 ++ fix infrastructre.yaml
Some checks failed
Terraform Terragrunt (contour) / validate (push) Failing after 24s
Terraform Terragrunt (contour) / plan (push) Has been skipped
Terraform Terragrunt (contour) / apply (push) Has been skipped
2026-08-11 13:43:57 +03:00
867eed4052 ++ fix infrastructre.yaml 2026-08-11 13:36:04 +03:00
d5a2d639ad add wb environment, one test entity per resource type (namespace, rabbitmq vhost/user/queue, external postgres db/user, external minio bucket) plus matching v2 secret contracts
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-11 13:33:54 +03:00
cd14614538 ++ pilot external rabbitmq module on brusnika-stage only 2026-08-07 11:53:53 +03:00
d645e43de5 ++ add declarative secrets contract v2 (schema/ownership/targets/extra_fields)
module: optional schema/ownership/source_kind/source_ref/extra_fields fields,
backward compatible - legacy secrets keep resolving exactly as before.
ownership modes managed/referenced/observed/adopt_once replace ignore_changes
for v2 records; referenced reads a value straight from vault via a data
source; observed only verifies presence, writes nothing.

terragrunt: v1/v2 detection by marker keys, targets fan-out into the existing
flat secrets list (one entry per target, same resource-key scheme as today),
source.kind -> type/depends_on translation for the five documented kinds.

brusnika-stage: acceptance environment for the two test cases from the plan -
regcred (dockerconfigjson.v1, ownership=referenced, value from vault) and a
rabbitmq.v1 secret (ownership=managed) fanned out to both kubernetes and vault
targets from a single declaration.
2026-08-05 12:41:55 +03:00
ivan
98750a048a ++ 2026-08-03 16:36:40 +05:00
ivan
3d69653667 ++ 2026-08-01 14:02:23 +05:00
ivan
f8ec3dac9f ++ 2026-08-01 13:46:23 +05:00
ivan
27f0770e07 ++ 2026-08-01 13:06:59 +05:00
ivan
d5dcdf44f0 ++ 2026-07-31 17:12:51 +05:00
ivan
b818f612f0 ++ 2026-07-31 13:04:40 +05:00
ivan
f0b086a60f ++ 2026-07-30 21:08:45 +05:00
ivan
25228040a8 ++ 2026-07-29 18:21:01 +05:00
ivan
b3502feae4 ++ 2026-07-29 18:11:19 +05:00
ivan
914abbe64f ++ 2026-07-28 19:24:32 +05:00
ivan
19e725fa3f ++ 2026-07-28 17:14:35 +05:00
ivan
bdd21c097f ++ 2026-07-28 15:24:05 +05:00
ivan
989c8feb04 ++ 2026-07-25 21:21:47 +05:00
ivan
054d542968 ++ 2026-07-25 20:44:15 +05:00
ivan
88e747fc9b ++ 2026-07-25 20:26:45 +05:00
ivan
1a7b67d506 ++ 2026-07-25 20:20:33 +05:00
610b2d9dc8 ++ 2026-07-21 15:17:00 +00:00
55b196d1ec ++ 2026-07-21 14:13:24 +00:00