terraform-contour-mirror/infrastructure.yaml

92 lines
2.6 KiB
YAML

current_environment: yc-k8s-test
# Contour branch — one declarative source for ALL closed contours. The concrete
# contour is selected by INFRA_ENV (falls back to current_environment). Entities
# use the SAME schema/contract as the product master branch; only the backend is
# in-cluster (see live/terragrunt.hcl providers). ++ ++ ++
environments:
yc-k8s-test:
namespaces:
- name: contour
labels:
environment: yc-k8s-test
project: contour
istio-injection: enabled
annotations:
managed-by: terraform
# MinIO endpoint (declarative). Exposed externally on this contour; scheme
# decides TLS. Admin creds are injected from Vault (secrets/minio/admin).
minio:
endpoint: https://minio.contour.infra.sarex.tech
# In-cluster MinIO. Bucket + dedicated access user (access_key/secret_key).
buckets:
- name: test-bucket
acl: private
# In-cluster PostgreSQL server (single instance in ns postgresql).
postgresql:
default_host: postgresql.postgresql.svc.cluster.local
default_port: 5432
databases:
- cluster_id: incluster
database:
name: test_db
extensions:
- uuid-ossp
- pg_stat_statements
user:
name: test_user
password_length: 32
password_special: false
conn_limit: 20
# In-cluster Kafka (Bitnami). clusterRef carries the bootstrap endpoint.
kafka:
kafka_cluster_refs:
contour:
bootstrap_servers: kafka-kafka-contour.kafka.svc.cluster.local:9092
sasl_mechanism: SCRAM-SHA-512
security_protocol: SASL_PLAINTEXT
tls_enabled: false
default_partitions: 3
default_replication_factor: 1
max_replication_factor: 1
topics:
- name: contour.test.event.v1
owner: contour-test
clusterRef: contour
partitions: 3
replicationFactor: 1
users:
- name: contour-test
clusterRef: contour
permissions:
- topic: contour.test.event.v1
roles:
- PRODUCER
# In-cluster RabbitMQ.
rabbitmq:
amqp_host: rabbitmq.rabbitmq.svc.cluster.local
amqp_port: 5672
vhosts:
- name: test-vhost
users:
- name: test-rmq
password_length: 32
password_special: false
permissions:
- user: test-rmq
vhost: test-vhost
configure: ".*"
write: ".*"
read: ".*"
exchanges:
- name: test.exchange
vhost: test-vhost
type: topic
durable: true