chore(dominio): o dominio antigo sai de tudo — Ingress, realms, Garmin, ArgoCD e Grafana

This commit is contained in:
deploy
2026-09-26 04:05:49 +00:00
parent f08f9c4141
commit 48668e1910
33 changed files with 58 additions and 388 deletions
+2 -2
View File
@@ -10,10 +10,10 @@ spec:
ingressClassName: traefik
tls:
- hosts:
- argocd.athleticmap.influxdigital.com.br
- argocd.athleticmap.com
secretName: argocd-tls
rules:
- host: argocd.athleticmap.influxdigital.com.br
- host: argocd.athleticmap.com
http:
paths:
- path: /
+2 -2
View File
@@ -79,11 +79,11 @@ spec:
cert-manager.io/cluster-issuer: letsencrypt-prod
traefik.ingress.kubernetes.io/router.middlewares: monitoring-redirect-https@kubernetescrd
hosts:
- grafana.athleticmap.influxdigital.com.br
- grafana.athleticmap.com
tls:
- secretName: grafana-tls
hosts:
- grafana.athleticmap.influxdigital.com.br
- grafana.athleticmap.com
resources:
requests:
cpu: 100m
+1 -28
View File
@@ -46,33 +46,10 @@ spec:
ingressClassName: traefik
tls:
- hosts:
- acme.athleticmap.influxdigital.com.br
- acme.athleticmap.com
- auth-acme.athleticmap.influxdigital.com.br
- auth-acme.athleticmap.com
secretName: acme-tls
rules:
- host: acme.athleticmap.influxdigital.com.br
http:
paths:
# P4.6: o nginx da SPA resolve /bff e /api/<contexto> por dentro.
#
# Ate 2026-09-22 havia UMA linha por contexto aqui, mais o /bff — catorze
# ao todo. Cada mudanca de topologia obrigava a editar o Ingress de todos
# os tenants; agora quem conhece a topologia interna e o
# `frontend/nginx.conf.template`, que viaja junto com a imagem.
#
# O destino deste /api mudou de `backend` (o legado) para `frontend-spa`.
# **O que o visitante ve NAO muda:** um caminho nao mapeado continua
# recebendo 401 — antes do backend legado, agora do BFF, para onde o
# nginx manda o /api que sobra. A decisao "401 ou 404" segue aberta e
# intacta; isto so tira o legado do caminho do trafego.
#
# ORDEM: `/api/public` e `/api/public/webhooks/asaas` vivem no
# `96-ingress-garmin-public.yaml` e tem prefixo MAIS LONGO, entao vencem
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: acme.athleticmap.com
http:
paths:
@@ -94,12 +71,8 @@ spec:
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: auth-acme.athleticmap.influxdigital.com.br
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
- host: auth-acme.athleticmap.com
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
+3 -3
View File
@@ -24,11 +24,11 @@ data:
"standardFlowEnabled": true,
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": ["https://acme.athleticmap.influxdigital.com.br/*", "https://acme.athleticmap.com/*"],
"webOrigins": ["https://acme.athleticmap.influxdigital.com.br", "https://acme.athleticmap.com"],
"redirectUris": ["https://acme.athleticmap.com/*"],
"webOrigins": ["https://acme.athleticmap.com"],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://acme.athleticmap.influxdigital.com.br/*##https://acme.athleticmap.com/*"
"post.logout.redirect.uris": "https://acme.athleticmap.com/*"
}
}
]
+2 -2
View File
@@ -44,9 +44,9 @@ spec:
- name: ATM_PLANO
value: institucional
- name: GARMIN_REDIRECT_URI
value: https://acme.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback
value: https://acme.athleticmap.com/api/public/integrations/garmin/callback
- name: GARMIN_FRONTEND_REDIRECT
value: https://acme.athleticmap.influxdigital.com.br/integracoes/garmin
value: https://acme.athleticmap.com/integracoes/garmin
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef:
+2 -2
View File
@@ -35,8 +35,8 @@ spec:
- { name: ATM_TENANT, value: "acme" }
# Garmin: DNS devolve IPv6 primeiro e a rota IPv6 do cluster falha; forcar IPv4.
- { name: JAVA_TOOL_OPTIONS, value: "-Djava.net.preferIPv4Stack=true" }
- { name: GARMIN_REDIRECT_URI, value: "https://acme.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://acme.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_REDIRECT_URI, value: "https://acme.athleticmap.com/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://acme.athleticmap.com/integracoes/garmin" }
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef: { name: garmin-oauth, key: GARMIN_CLIENT_ID }
+1 -1
View File
@@ -43,7 +43,7 @@ spec:
valueFrom: { secretKeyRef: { name: consentimento-selo, key: segredo } }
- { name: ATM_TENANT, value: "acme" }
- { name: ATM_PLANO, value: "institucional" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://acme.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://acme.athleticmap.com/integracoes/garmin" }
resources:
requests: { cpu: 50m, memory: 256Mi }
limits: { cpu: 500m, memory: 512Mi }
+2 -36
View File
@@ -9,44 +9,9 @@ metadata:
spec:
ingressClassName: traefik
tls:
- hosts: [acme.athleticmap.influxdigital.com.br, acme.athleticmap.com]
- hosts: [acme.athleticmap.com]
secretName: acme-tls
rules:
- host: acme.athleticmap.influxdigital.com.br
http:
paths:
# O webhook de PAGAMENTO do Asaas, ANTES do /api/public generico.
#
# Aquele manda tudo de /api/public para o `servico-bff`, e o BFF NAO tem
# controlador para esta rota — so o financeiro tem
# (`WebhookAsaasController`). O BFF relaya o Garmin de proposito; o Asaas,
# nao. Sem esta linha o aviso de pagamento morre no BFF, e o sintoma e o
# pior possivel: **a cobranca e paga e nunca baixada**, sem erro do nosso
# lado — o provedor so registra uma entrega recusada.
#
# O Traefik ordena por TAMANHO do prefixo, entao esta (26 caracteres) vence
# `/api/public` (11) sozinha. Fica escrita primeiro mesmo assim, para
# ninguem reordenar sem perceber.
#
# `servico-financeiro` e o Service; num tenant consolidado ele aponta para
# o `runtime-operacao`, que e onde o financeiro roda de verdade.
#
# Quem autentica e o cabecalho `asaas-access-token`, no controlador.
- path: /api/public/webhooks/asaas
pathType: Prefix
backend:
service:
name: servico-financeiro
port:
number: 80
- path: /api/public
pathType: Prefix
backend:
service:
name: servico-bff
port:
number: 80
- host: acme.athleticmap.com
http:
paths:
@@ -81,3 +46,4 @@ spec:
name: servico-bff
port:
number: 80
+1 -3
View File
@@ -40,16 +40,14 @@
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": [
"https://acme.athleticmap.influxdigital.com.br/*",
"https://acme.athleticmap.com/*"
],
"webOrigins": [
"https://acme.athleticmap.influxdigital.com.br",
"https://acme.athleticmap.com"
],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://acme.athleticmap.influxdigital.com.br/*##https://acme.athleticmap.com/*"
"post.logout.redirect.uris": "https://acme.athleticmap.com/*"
}
}
]
+1 -28
View File
@@ -46,33 +46,10 @@ spec:
ingressClassName: traefik
tls:
- hosts:
- demo.athleticmap.influxdigital.com.br
- demo.athleticmap.com
- auth-demo.athleticmap.influxdigital.com.br
- auth-demo.athleticmap.com
secretName: demo-tls
rules:
- host: demo.athleticmap.influxdigital.com.br
http:
paths:
# P4.6: o nginx da SPA resolve /bff e /api/<contexto> por dentro.
#
# Ate 2026-09-22 havia UMA linha por contexto aqui, mais o /bff — catorze
# ao todo. Cada mudanca de topologia obrigava a editar o Ingress de todos
# os tenants; agora quem conhece a topologia interna e o
# `frontend/nginx.conf.template`, que viaja junto com a imagem.
#
# O destino deste /api mudou de `backend` (o legado) para `frontend-spa`.
# **O que o visitante ve NAO muda:** um caminho nao mapeado continua
# recebendo 401 — antes do backend legado, agora do BFF, para onde o
# nginx manda o /api que sobra. A decisao "401 ou 404" segue aberta e
# intacta; isto so tira o legado do caminho do trafego.
#
# ORDEM: `/api/public` e `/api/public/webhooks/asaas` vivem no
# `96-ingress-garmin-public.yaml` e tem prefixo MAIS LONGO, entao vencem
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: demo.athleticmap.com
http:
paths:
@@ -94,12 +71,8 @@ spec:
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: auth-demo.athleticmap.influxdigital.com.br
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
- host: auth-demo.athleticmap.com
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
+3 -3
View File
@@ -24,11 +24,11 @@ data:
"standardFlowEnabled": true,
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": ["https://demo.athleticmap.influxdigital.com.br/*", "https://demo.athleticmap.com/*"],
"webOrigins": ["https://demo.athleticmap.influxdigital.com.br", "https://demo.athleticmap.com"],
"redirectUris": ["https://demo.athleticmap.com/*"],
"webOrigins": ["https://demo.athleticmap.com"],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://demo.athleticmap.influxdigital.com.br/*##https://demo.athleticmap.com/*"
"post.logout.redirect.uris": "https://demo.athleticmap.com/*"
}
}
]
+2 -2
View File
@@ -44,9 +44,9 @@ spec:
- name: ATM_PLANO
value: institucional
- name: GARMIN_REDIRECT_URI
value: https://demo.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback
value: https://demo.athleticmap.com/api/public/integrations/garmin/callback
- name: GARMIN_FRONTEND_REDIRECT
value: https://demo.athleticmap.influxdigital.com.br/integracoes/garmin
value: https://demo.athleticmap.com/integracoes/garmin
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef:
+2 -2
View File
@@ -35,8 +35,8 @@ spec:
- { name: ATM_TENANT, value: "demo" }
# Garmin: DNS devolve IPv6 primeiro e a rota IPv6 do cluster falha; forcar IPv4.
- { name: JAVA_TOOL_OPTIONS, value: "-Djava.net.preferIPv4Stack=true" }
- { name: GARMIN_REDIRECT_URI, value: "https://demo.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://demo.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_REDIRECT_URI, value: "https://demo.athleticmap.com/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://demo.athleticmap.com/integracoes/garmin" }
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef: { name: garmin-oauth, key: GARMIN_CLIENT_ID }
+1 -1
View File
@@ -43,7 +43,7 @@ spec:
valueFrom: { secretKeyRef: { name: consentimento-selo, key: segredo } }
- { name: ATM_TENANT, value: "demo" }
- { name: ATM_PLANO, value: "institucional" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://demo.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://demo.athleticmap.com/integracoes/garmin" }
resources:
requests: { cpu: 50m, memory: 256Mi }
limits: { cpu: 500m, memory: 512Mi }
+2 -36
View File
@@ -9,44 +9,9 @@ metadata:
spec:
ingressClassName: traefik
tls:
- hosts: [demo.athleticmap.influxdigital.com.br, demo.athleticmap.com]
- hosts: [demo.athleticmap.com]
secretName: demo-tls
rules:
- host: demo.athleticmap.influxdigital.com.br
http:
paths:
# O webhook de PAGAMENTO do Asaas, ANTES do /api/public generico.
#
# Aquele manda tudo de /api/public para o `servico-bff`, e o BFF NAO tem
# controlador para esta rota — so o financeiro tem
# (`WebhookAsaasController`). O BFF relaya o Garmin de proposito; o Asaas,
# nao. Sem esta linha o aviso de pagamento morre no BFF, e o sintoma e o
# pior possivel: **a cobranca e paga e nunca baixada**, sem erro do nosso
# lado — o provedor so registra uma entrega recusada.
#
# O Traefik ordena por TAMANHO do prefixo, entao esta (26 caracteres) vence
# `/api/public` (11) sozinha. Fica escrita primeiro mesmo assim, para
# ninguem reordenar sem perceber.
#
# `servico-financeiro` e o Service; num tenant consolidado ele aponta para
# o `runtime-operacao`, que e onde o financeiro roda de verdade.
#
# Quem autentica e o cabecalho `asaas-access-token`, no controlador.
- path: /api/public/webhooks/asaas
pathType: Prefix
backend:
service:
name: servico-financeiro
port:
number: 80
- path: /api/public
pathType: Prefix
backend:
service:
name: servico-bff
port:
number: 80
- host: demo.athleticmap.com
http:
paths:
@@ -81,3 +46,4 @@ spec:
name: servico-bff
port:
number: 80
+1 -3
View File
@@ -40,16 +40,14 @@
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": [
"https://demo.athleticmap.influxdigital.com.br/*",
"https://demo.athleticmap.com/*"
],
"webOrigins": [
"https://demo.athleticmap.influxdigital.com.br",
"https://demo.athleticmap.com"
],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://demo.athleticmap.influxdigital.com.br/*##https://demo.athleticmap.com/*"
"post.logout.redirect.uris": "https://demo.athleticmap.com/*"
}
}
]
+1 -28
View File
@@ -46,33 +46,10 @@ spec:
ingressClassName: traefik
tls:
- hosts:
- escolinha.athleticmap.influxdigital.com.br
- escolinha.athleticmap.com
- auth-escolinha.athleticmap.influxdigital.com.br
- auth-escolinha.athleticmap.com
secretName: escolinha-tls
rules:
- host: escolinha.athleticmap.influxdigital.com.br
http:
paths:
# P4.6: o nginx da SPA resolve /bff e /api/<contexto> por dentro.
#
# Ate 2026-09-22 havia UMA linha por contexto aqui, mais o /bff — catorze
# ao todo. Cada mudanca de topologia obrigava a editar o Ingress de todos
# os tenants; agora quem conhece a topologia interna e o
# `frontend/nginx.conf.template`, que viaja junto com a imagem.
#
# O destino deste /api mudou de `backend` (o legado) para `frontend-spa`.
# **O que o visitante ve NAO muda:** um caminho nao mapeado continua
# recebendo 401 — antes do backend legado, agora do BFF, para onde o
# nginx manda o /api que sobra. A decisao "401 ou 404" segue aberta e
# intacta; isto so tira o legado do caminho do trafego.
#
# ORDEM: `/api/public` e `/api/public/webhooks/asaas` vivem no
# `96-ingress-garmin-public.yaml` e tem prefixo MAIS LONGO, entao vencem
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: escolinha.athleticmap.com
http:
paths:
@@ -94,12 +71,8 @@ spec:
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: auth-escolinha.athleticmap.influxdigital.com.br
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
- host: auth-escolinha.athleticmap.com
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
+3 -3
View File
@@ -41,11 +41,11 @@ data:
"standardFlowEnabled": true,
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": ["https://escolinha.athleticmap.influxdigital.com.br/*", "https://escolinha.athleticmap.com/*"],
"webOrigins": ["https://escolinha.athleticmap.influxdigital.com.br", "https://escolinha.athleticmap.com"],
"redirectUris": ["https://escolinha.athleticmap.com/*"],
"webOrigins": ["https://escolinha.athleticmap.com"],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://escolinha.athleticmap.influxdigital.com.br/*##https://escolinha.athleticmap.com/*"
"post.logout.redirect.uris": "https://escolinha.athleticmap.com/*"
}
}
]
+2 -2
View File
@@ -42,9 +42,9 @@ spec:
- name: ATM_TENANT
value: escolinha
- name: GARMIN_REDIRECT_URI
value: https://escolinha.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback
value: https://escolinha.athleticmap.com/api/public/integrations/garmin/callback
- name: GARMIN_FRONTEND_REDIRECT
value: https://escolinha.athleticmap.influxdigital.com.br/integracoes/garmin
value: https://escolinha.athleticmap.com/integracoes/garmin
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef:
+2 -2
View File
@@ -35,8 +35,8 @@ spec:
- { name: ATM_TENANT, value: "escolinha" }
# Garmin: DNS devolve IPv6 primeiro e a rota IPv6 do cluster falha; forcar IPv4.
- { name: JAVA_TOOL_OPTIONS, value: "-Djava.net.preferIPv4Stack=true" }
- { name: GARMIN_REDIRECT_URI, value: "https://escolinha.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://escolinha.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_REDIRECT_URI, value: "https://escolinha.athleticmap.com/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://escolinha.athleticmap.com/integracoes/garmin" }
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef: { name: garmin-oauth, key: GARMIN_CLIENT_ID }
+1 -1
View File
@@ -43,7 +43,7 @@ spec:
valueFrom: { secretKeyRef: { name: consentimento-selo, key: segredo } }
- { name: ATM_TENANT, value: "escolinha" }
- { name: ATM_PLANO, value: "institucional" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://escolinha.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://escolinha.athleticmap.com/integracoes/garmin" }
resources:
requests: { cpu: 50m, memory: 256Mi }
limits: { cpu: 500m, memory: 512Mi }
@@ -9,44 +9,9 @@ metadata:
spec:
ingressClassName: traefik
tls:
- hosts: [escolinha.athleticmap.influxdigital.com.br, escolinha.athleticmap.com]
- hosts: [escolinha.athleticmap.com]
secretName: escolinha-tls
rules:
- host: escolinha.athleticmap.influxdigital.com.br
http:
paths:
# O webhook de PAGAMENTO do Asaas, ANTES do /api/public generico.
#
# Aquele manda tudo de /api/public para o `servico-bff`, e o BFF NAO tem
# controlador para esta rota — so o financeiro tem
# (`WebhookAsaasController`). O BFF relaya o Garmin de proposito; o Asaas,
# nao. Sem esta linha o aviso de pagamento morre no BFF, e o sintoma e o
# pior possivel: **a cobranca e paga e nunca baixada**, sem erro do nosso
# lado — o provedor so registra uma entrega recusada.
#
# O Traefik ordena por TAMANHO do prefixo, entao esta (26 caracteres) vence
# `/api/public` (11) sozinha. Fica escrita primeiro mesmo assim, para
# ninguem reordenar sem perceber.
#
# `servico-financeiro` e o Service; num tenant consolidado ele aponta para
# o `runtime-operacao`, que e onde o financeiro roda de verdade.
#
# Quem autentica e o cabecalho `asaas-access-token`, no controlador.
- path: /api/public/webhooks/asaas
pathType: Prefix
backend:
service:
name: servico-financeiro
port:
number: 80
- path: /api/public
pathType: Prefix
backend:
service:
name: servico-bff
port:
number: 80
- host: escolinha.athleticmap.com
http:
paths:
@@ -81,3 +46,4 @@ spec:
name: servico-bff
port:
number: 80
@@ -40,16 +40,14 @@
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": [
"https://escolinha.athleticmap.influxdigital.com.br/*",
"https://escolinha.athleticmap.com/*"
],
"webOrigins": [
"https://escolinha.athleticmap.influxdigital.com.br",
"https://escolinha.athleticmap.com"
],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://escolinha.athleticmap.influxdigital.com.br/*##https://escolinha.athleticmap.com/*"
"post.logout.redirect.uris": "https://escolinha.athleticmap.com/*"
}
}
]
+1 -28
View File
@@ -46,33 +46,10 @@ spec:
ingressClassName: traefik
tls:
- hosts:
- piloto.athleticmap.influxdigital.com.br
- piloto.athleticmap.com
- auth-piloto.athleticmap.influxdigital.com.br
- auth-piloto.athleticmap.com
secretName: piloto-tls
rules:
- host: piloto.athleticmap.influxdigital.com.br
http:
paths:
# P4.6: o nginx da SPA resolve /bff e /api/<contexto> por dentro.
#
# Ate 2026-09-22 havia UMA linha por contexto aqui, mais o /bff — catorze
# ao todo. Cada mudanca de topologia obrigava a editar o Ingress de todos
# os tenants; agora quem conhece a topologia interna e o
# `frontend/nginx.conf.template`, que viaja junto com a imagem.
#
# O destino deste /api mudou de `backend` (o legado) para `frontend-spa`.
# **O que o visitante ve NAO muda:** um caminho nao mapeado continua
# recebendo 401 — antes do backend legado, agora do BFF, para onde o
# nginx manda o /api que sobra. A decisao "401 ou 404" segue aberta e
# intacta; isto so tira o legado do caminho do trafego.
#
# ORDEM: `/api/public` e `/api/public/webhooks/asaas` vivem no
# `96-ingress-garmin-public.yaml` e tem prefixo MAIS LONGO, entao vencem
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: piloto.athleticmap.com
http:
paths:
@@ -94,12 +71,8 @@ spec:
# este — o Traefik ordena por tamanho. Conferido.
- { path: /api, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: auth-piloto.athleticmap.influxdigital.com.br
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
- host: auth-piloto.athleticmap.com
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
+3 -3
View File
@@ -24,11 +24,11 @@ data:
"standardFlowEnabled": true,
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": ["https://piloto.athleticmap.influxdigital.com.br/*", "https://piloto.athleticmap.com/*"],
"webOrigins": ["https://piloto.athleticmap.influxdigital.com.br", "https://piloto.athleticmap.com"],
"redirectUris": ["https://piloto.athleticmap.com/*"],
"webOrigins": ["https://piloto.athleticmap.com"],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://piloto.athleticmap.influxdigital.com.br/*##https://piloto.athleticmap.com/*"
"post.logout.redirect.uris": "https://piloto.athleticmap.com/*"
}
}
]
+2 -2
View File
@@ -44,9 +44,9 @@ spec:
- name: ATM_PLANO
value: institucional
- name: GARMIN_REDIRECT_URI
value: https://piloto.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback
value: https://piloto.athleticmap.com/api/public/integrations/garmin/callback
- name: GARMIN_FRONTEND_REDIRECT
value: https://piloto.athleticmap.influxdigital.com.br/integracoes/garmin
value: https://piloto.athleticmap.com/integracoes/garmin
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef:
+2 -2
View File
@@ -35,8 +35,8 @@ spec:
- { name: ATM_TENANT, value: "piloto" }
# Garmin: DNS devolve IPv6 primeiro e a rota IPv6 do cluster falha; forcar IPv4.
- { name: JAVA_TOOL_OPTIONS, value: "-Djava.net.preferIPv4Stack=true" }
- { name: GARMIN_REDIRECT_URI, value: "https://piloto.athleticmap.influxdigital.com.br/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://piloto.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_REDIRECT_URI, value: "https://piloto.athleticmap.com/api/public/integrations/garmin/callback" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://piloto.athleticmap.com/integracoes/garmin" }
- name: GARMIN_CLIENT_ID
valueFrom:
secretKeyRef: { name: garmin-oauth, key: GARMIN_CLIENT_ID }
+1 -1
View File
@@ -43,7 +43,7 @@ spec:
valueFrom: { secretKeyRef: { name: consentimento-selo, key: segredo } }
- { name: ATM_TENANT, value: "piloto" }
- { name: ATM_PLANO, value: "institucional" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://piloto.athleticmap.influxdigital.com.br/integracoes/garmin" }
- { name: GARMIN_FRONTEND_REDIRECT, value: "https://piloto.athleticmap.com/integracoes/garmin" }
resources:
requests: { cpu: 50m, memory: 256Mi }
limits: { cpu: 500m, memory: 512Mi }
+2 -36
View File
@@ -9,44 +9,9 @@ metadata:
spec:
ingressClassName: traefik
tls:
- hosts: [piloto.athleticmap.influxdigital.com.br, piloto.athleticmap.com]
- hosts: [piloto.athleticmap.com]
secretName: piloto-tls
rules:
- host: piloto.athleticmap.influxdigital.com.br
http:
paths:
# O webhook de PAGAMENTO do Asaas, ANTES do /api/public generico.
#
# Aquele manda tudo de /api/public para o `servico-bff`, e o BFF NAO tem
# controlador para esta rota — so o financeiro tem
# (`WebhookAsaasController`). O BFF relaya o Garmin de proposito; o Asaas,
# nao. Sem esta linha o aviso de pagamento morre no BFF, e o sintoma e o
# pior possivel: **a cobranca e paga e nunca baixada**, sem erro do nosso
# lado — o provedor so registra uma entrega recusada.
#
# O Traefik ordena por TAMANHO do prefixo, entao esta (26 caracteres) vence
# `/api/public` (11) sozinha. Fica escrita primeiro mesmo assim, para
# ninguem reordenar sem perceber.
#
# `servico-financeiro` e o Service; num tenant consolidado ele aponta para
# o `runtime-operacao`, que e onde o financeiro roda de verdade.
#
# Quem autentica e o cabecalho `asaas-access-token`, no controlador.
- path: /api/public/webhooks/asaas
pathType: Prefix
backend:
service:
name: servico-financeiro
port:
number: 80
- path: /api/public
pathType: Prefix
backend:
service:
name: servico-bff
port:
number: 80
- host: piloto.athleticmap.com
http:
paths:
@@ -81,3 +46,4 @@ spec:
name: servico-bff
port:
number: 80
+1 -3
View File
@@ -40,16 +40,14 @@
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": [
"https://piloto.athleticmap.influxdigital.com.br/*",
"https://piloto.athleticmap.com/*"
],
"webOrigins": [
"https://piloto.athleticmap.influxdigital.com.br",
"https://piloto.athleticmap.com"
],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://piloto.athleticmap.influxdigital.com.br/*##https://piloto.athleticmap.com/*"
"post.logout.redirect.uris": "https://piloto.athleticmap.com/*"
}
}
]
+2 -78
View File
@@ -29,7 +29,7 @@
# - cert-manager usa desafio HTTP-01, entao sem o host resolvindo para o
# cluster o certificado nao e emitido, e sem certificado nao ha login.
#
# Ja `*.athleticmap.influxdigital.com.br` e wildcard para o cluster (conferido:
# Ja `*.athleticmap.com` e wildcard para o cluster (conferido:
# ate um subdominio inventado resolve para 187.77.37.184). Entao este tenant
# sobe hoje e atravessa o corte de dominio junto com os demais, no passo 5 do
# `docs/p09-plano-de-corte-dominio.md` — e nao numa migracao propria.
@@ -60,85 +60,12 @@ spec:
ingressClassName: traefik
tls:
- hosts:
- plataforma.athleticmap.influxdigital.com.br
- plataforma.athleticmap.com
- auth-plataforma.athleticmap.influxdigital.com.br
- auth-plataforma.athleticmap.com
# O host de autenticacao DOS TENANTS. Ver a regra la embaixo.
- auth.athleticmap.com
secretName: plataforma-tls
rules:
- host: plataforma.athleticmap.influxdigital.com.br
http:
paths:
# PUBLICA — sem token, por desenho. Vem primeiro porque o Traefik
# ordena por tamanho do prefixo, mas deixar explicito evita que alguem
# reordene sem perceber.
- { path: /api/public/leads, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
# A CONTRATACAO pela landing page: escolher o plano e receber o link
# por e-mail. Prefixo cobre tambem `/contratacoes/planos`, que a
# pagina le para mostrar o MESMO preco que o checkout vai cobrar.
#
# Aqui nao ha catch-all: caminho que nao esta escrito nao existe. Foi
# por isso que o endpoint respondeu vazio quando a imagem ja estava no
# ar — o servico tinha a rota e o Ingress nao.
- { path: /api/public/contratacoes, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
# PUBLICA — a tela de espera depois do pagamento (P5.8). Quem acabou de
# pagar AINDA NAO TEM CONTA, logo nao tem token: se esta rota exigisse
# um, a tela que existe para tranquilizar quem pagou seria a primeira a
# recusa-lo.
#
# O que ela entrega e deliberadamente pouco: se a conta ficou pronta e
# o endereco do tenant. Nem nome, nem e-mail, nem plano, nem realm — o
# id da assinatura na URL e a unica "credencial" da tela, e ha teste
# guardando esse limite. Acrescentar um campo aqui e acrescentar o que
# um link vazado entrega.
#
# Estava PREPARADA e nao publicada desde 2026-09-19: o controlador
# existe (`EstadoDaContaController`) e a cadeia ja a liberava
# (`SecurityConfig`, permitAll), mas sem esta linha o Ingress devolvia
# 404 — nao ha catch-all aqui, por desenho.
- { path: /api/public/conta, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
# O PAINEL DO COMPRADOR e o PAINEL DO DONO. Sem estas duas linhas as
# chamadas caiam no `/` do front, que as repassava a OUTRO servico — o
# 401 que voltava parecia o validador de JWT do captacao funcionando, e
# era de outro lugar (2026-09-25). A seguranca de cada uma esta no
# captacao: JWT do realm `clientes` numa, token de admin na outra.
- { path: /api/cliente, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
- { path: /api/plataforma/painel, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
# PUBLICA — o aviso de ASSINATURA do Asaas (P5.1), que e outra coisa do
# `/api/public/webhooks/asaas` logo abaixo: aquele avisa que uma COBRANCA
# de cliente foi paga e vai para o financeiro do tenant; este avisa que
# alguem assinou a Athletic Map, e e o que dispara o provisionamento de
# um tenant NOVO. Contas diferentes no Asaas, servicos diferentes aqui.
#
# Chega da internet sem token nosso; quem autentica e o
# `PLATAFORMA_WEBHOOK_TOKEN`, conferido no `WebhookDeAssinatura`. Sem o
# segredo selado, o endpoint RECUSA tudo de proposito, e o log diz isso.
#
# Sem esta linha o Ingress devolvia 404: alguem assinaria, pagaria, e
# nenhum tenant seria criado — sem erro em lugar nenhum do nosso lado.
- { path: /api/public/webhooks/assinatura, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
- { path: /api/public/webhooks/subconta, pathType: Prefix, backend: { service: { name: servico-captacao, port: { number: 80 } } } }
# PUBLICA — o aviso de pagamento do Asaas, que chega da internet sem
# token nenhum (P3.3). NAO casa com /api/financeiro: o controlador
# atende em /api/public/webhooks/asaas, e como aqui nao ha catch-all,
# a ausencia desta linha daria 404 em todo aviso — a cobranca seria
# paga e nunca baixada. Quem autentica e o cabecalho
# `asaas-access-token`, conferido no WebhookAsaasController.
- { path: /api/public/webhooks/asaas, pathType: Prefix, backend: { service: { name: servico-financeiro, port: { number: 80 } } } }
# O resto exige token, como em qualquer tenant.
- { path: /api/configuracao, pathType: Prefix, backend: { service: { name: servico-configuracao, port: { number: 80 } } } }
- { path: /api/cadastro, pathType: Prefix, backend: { service: { name: servico-cadastro, port: { number: 80 } } } }
- { path: /api/financeiro, pathType: Prefix, backend: { service: { name: servico-financeiro, port: { number: 80 } } } }
- { path: /bff, pathType: Prefix, backend: { service: { name: servico-bff, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: plataforma.athleticmap.com
http:
paths:
@@ -210,15 +137,12 @@ spec:
- { path: /bff, pathType: Prefix, backend: { service: { name: servico-bff, port: { number: 80 } } } }
- { path: /, pathType: Prefix, backend: { service: { name: frontend-spa, port: { number: 80 } } } }
- host: auth-plataforma.athleticmap.influxdigital.com.br
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
- host: auth-plataforma.athleticmap.com
http:
paths:
- { path: /, pathType: Prefix, backend: { service: { name: keycloak, port: { number: 8080 } } } }
# O HOST DE AUTENTICACAO DOS TENANTS.
#
# O mesmo Keycloak, outro nome. O molde do tenant ja apontava para ca — a
+3 -3
View File
@@ -28,11 +28,11 @@ data:
"standardFlowEnabled": true,
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": ["https://plataforma.athleticmap.influxdigital.com.br/*", "https://plataforma.athleticmap.com/*"],
"webOrigins": ["https://plataforma.athleticmap.influxdigital.com.br", "https://plataforma.athleticmap.com"],
"redirectUris": ["https://plataforma.athleticmap.com/*"],
"webOrigins": ["https://plataforma.athleticmap.com"],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://plataforma.athleticmap.influxdigital.com.br/*##https://plataforma.athleticmap.com/*"
"post.logout.redirect.uris": "https://plataforma.athleticmap.com/*"
}
}
]
@@ -44,16 +44,14 @@
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"redirectUris": [
"https://plataforma.athleticmap.influxdigital.com.br/*",
"https://plataforma.athleticmap.com/*"
],
"webOrigins": [
"https://plataforma.athleticmap.influxdigital.com.br",
"https://plataforma.athleticmap.com"
],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "https://plataforma.athleticmap.influxdigital.com.br/*##https://plataforma.athleticmap.com/*"
"post.logout.redirect.uris": "https://plataforma.athleticmap.com/*"
},
"protocolMappers": [
{