docs: accept central extension update architecture

This commit is contained in:
inman committed 2026-09-03 16:17:11 +08:00
1 parent 322475860a
commit efc342c626
10 files changed
+132 -16

No files matched your search

@@ -0,0 +1,43 @@
# EXT-001: Central-service orchestration for Windows extension updates
## Status
Accepted
## Date
2026-09-03
## Context
The production control plane runs on a separate Node server while ERP work runs in multiple Chrome profiles across multiple Alibaba ECS Windows Server hosts. The profiles use an unpacked extension and are not managed through AD, Chrome Enterprise policy, or the Chrome Web Store. Maintaining every profile by logging in to each Windows host does not scale, but a remote web page cannot itself install an extension or write silently to a Windows extension directory.
The user selected an architecture that keeps release and update logic in the existing control plane, stores packages in OSS, and uses Alibaba Cloud Assistant only as the bounded remote-execution boundary. A separately maintained LTJT updater service on each Windows host is not introduced.
## Decision
- The central control plane owns approved extension releases, version comparison, update state, retry policy, host safety, and post-update verification. Private OSS owns immutable, content-addressed package bytes.
- Each non-administrator account may map to one Alibaba ECS region and instance. Accounts on the same instance share one host update row and one idle gate, while every Chrome profile continues to report its actually loaded extension version.
- The updater may start only while every mapped account is safe: no live ERP lease, accepted/running execution, write-started/submitted/uncertain attempt, reconciliation task, or recent browser worker reporting an unsafe extension state. The same organization serialization boundary protects both update start and ERP task claim.
- The control plane sends one bounded `RunPowerShellScript` command through ECS Cloud Assistant. The Windows command downloads through a short-lived organization/release/host-bound control-plane capability, verifies byte count, SHA-256, Manifest identity and target version, stages the package beneath the configured `ProgramData\LTJT` subtree, retains one `.previous` directory, rolls back a failed switch, and refuses downgrade.
- Cloud Assistant completion requires a successful exit code and an explicit completion marker. Ambiguous dispatch reuses the same persisted attempt identity and client token; definite failures may retry at most three total attempts.
- File deployment alone is not success. Each installed profile performs its own idle recheck and `chrome.runtime.reload()`, and a target-version heartbeat is required before that profile can receive new ERP work.
- Extension `0.5.167` is the one-time bootstrap release for the safety and reload protocol. Before enabling automatic updates, every existing profile must manually load the shared `C:\ProgramData\LTJT\chrome-extension\ltjt-order-assistant` directory once.
- Automatic updates remain disabled by default. Production activation requires HTTPS `APP_ORIGIN`, private OSS configuration, a least-privilege ECS RAM identity, verified ECS account mappings, Cloud Assistant connectivity, completed bootstrap, backup, migration `019`, and a canary rollout.
## Consequences
- Routine releases no longer require logging in to every Windows account after bootstrap; one host file deployment can serve multiple profiles, while each profile remains independently version-gated and verified.
- The update path does not depend on Google services or Chrome Web Store review, but it does depend on Alibaba ECS Cloud Assistant and Windows-to-control-plane HTTPS reachability.
- An offline profile does not block deployment. It remains unable to claim new ERP work until it starts, reloads from the shared directory, and reports the required version.
- Disabling the feature is a kill switch for new update work, not permission to bypass an unfinished host update or an active higher-version claim gate.
- This mechanism externally replaces trusted unpacked-extension files; it does not claim Chrome-native installation or enterprise-policy distribution. Removing Cloud Assistant without another host execution boundary would reduce the workflow to a manual download/install procedure.
## Related
- `.project-docs/30-worklog/tasks/20260903-adaptive-wait-auto-update-7b3e9a2c.md`
- `.project-docs/30-worklog/tasks/20260903-service-extension-update-8d42c6f1.md`
- `.project-docs/30-worklog/tasks/20260903-finalize-extension-update-a6c4e192.md`
- `control-plane/src/extension-updates.ts`
- `control-plane/migrations/019_extension_host_updates.sql`
- `chrome-extension/ltjt-order-assistant/background.js`
@@ -12,6 +12,7 @@
| NETWORK-001 | In the trusted internal deployment, AgentBus roster attachment URLs may resolve to internal/private addresses; HTTPS, credential rejection, DNS pinning, redirect validation, bounds, and digest checks remain. | Active | 2026-08-31 | AgentBus attachment ingress | [Reply contract](../../agent设计规范/agentbus-reply-contract.md) |
| AUTH-001 | The fixed deployment scope uses administrator-managed `admin`, `team_lead`, and `user` accounts, owner-isolated normal tasks, display-only leadership metrics with explicit filtering, explicit non-admin route grants, and assignee-bound AgentBus/browser/ERP execution. | Active except clauses superseded by AUTH-002 | 2026-09-01 | Authentication, authorization, audit, AgentBus workers, and operations oversight | [ADR](AUTH-001-fixed-scope-account-authorization.md) |
| AUTH-002 | ERP execution is serialized per immutable assigned account, administrator visibility is never execution routing, and explicit force delete physically removes authorized tasks regardless of lifecycle state. | Active | 2026-09-03 | ERP claim queues, executable events/results, and task removal | [ADR](AUTH-002-account-scoped-execution-and-force-delete.md) |
| EXT-001 | The separate central control plane publishes private OSS extension releases and uses bounded ECS Cloud Assistant commands to update shared unpacked-extension files only while every mapped account is idle; target-version browser heartbeats are required before ERP execution resumes. | Active | 2026-09-03 | Chrome extension release, Windows host update, and ERP claim safety | [ADR](EXT-001-central-service-host-extension-updates.md) |
## Superseded Decisions