Skip to main content

Infraestrutura e Cloud

Propósito

Esta secção documenta a topologia Kubernetes, a gestão de segredos e os recursos de infraestrutura que suportam o Returns Manager.

Namespaces Kubernetes

NamespaceWorkloads
ingressIngress Controller, API Gateway (YARP/Kong)
rm-frontendPortal Cliente, App Instore, BackOffice Web (React SPAs)
rm-bffBFF Web, BFF Instore, BFF External (.NET 8, HPA)
rm-servicesReturns Service, Policy Engine, BackOffice Service, Integration Service
rm-workersRefund, Pickup, Notify, Case Workers (KEDA)
rm-infraPostgreSQL HA, Redis Sentinel, RabbitMQ cluster

Segurança

  • mTLS: Istio STRICT mode em todos os namespaces
  • Segredos: External Secrets Operator + Vault (multi-version key rotation)
  • Autenticação: OAuth2/OIDC via Identity Manager; API Gateway valida JWT

Vaults

AmbienteURL
PRDhttps://vault-gcp.corp.mc.pt:8200/
PPhttps://vault-gcp-pp.corp.mc.pt:8200/
DEVhttps://vault-gcp-dev.corp.mc.pt:8200/

ArgoCD

AmbienteURL
DEVhttps://gitops-gke-app-d1-dev.corp.mc.pt/
DEV-DBhttps://gitops-gke-data-d1-dev.corp.mc.pt/
PP-DBhttps://gitops-gke-data-s1-pp.corp.mc.pt/applications

Diagrama de Infraestrutura

Diagrama de Infraestrutura

Documentos Relacionados