17 KiB
17 KiB
Task: Verify ACK image build and middleware requirements
Identity
- Task ID: 20260828-ack-deploy-guide-8c1d
- Mode: Integration
- Branch: main
- Worktree: D:\Datas\OthersProjects\LWLT-AIBOT
- Base commit:
7b5d855b09 - Owner: codex
- Status: Completed
Scope
- Repair the repository's missing
.project-docstemplates with the official non-overwriting initializer after explicit user approval. - Read-only verification of the existing Docker build, runtime entrypoint, production configuration, persistence, artifact storage, health probes, and ACK/ACR deployment constraints.
- Provide a build-and-push command and a minimal middleware inventory; do not deploy, push an image, or read secrets.
- Follow up on the production deployment by fixing Chrome extension recognition and bridge injection for the user-confirmed control-plane origin
https://lwlt.nianxx.cn, then publish a synchronized versioned ZIP. - Fix the production follow-up where an interrupted Chrome MV3 ERP-link recovery leaves persisted
running, causing a permanent warning and blocking dispatch; publish a synchronized0.5.159ZIP without accessing ERP or mutating tasks. - Diagnose the Program live-submit blocker reported from production and publish
0.5.160, which identifies changed protected field names without persisting field values or relaxing the pre-write gate. - Fix the production-confirmed
xiaoshourendrift by waiting for native customer, OP and salesperson SelectBox lookup data before team-order preflight, then publish synchronized extension0.5.161. - Follow up on production
0.5.161, which still driftsxiaoshourenand inactive receivable customer/id fields, by waiting for the ERP page's full native jQuery Ajax idle signal and publishing synchronized extension0.5.162. - Follow up on production
0.5.162, where only numbered dynamic receivable fields still drift, by restoring the effective0.5.156protected-field scope at the production operator's explicit request and publishing synchronized extension0.5.163.
Intent And Constraints
- Preserve all existing work and do not read
.envorLianSyn-platform/.env. - Distinguish repository-confirmed requirements from deployment recommendations and unverified assumptions.
- Treat the Chrome ERP extension as a client-side component, not an ACK workload.
- Allow only the exact production control-plane origin; do not broaden content-script injection to arbitrary HTTPS sites.
- Do not reload the user's browser extension, deploy services, or access ERP as part of the source/release fix.
- Do not create sub-agents.
- Keep the approved protected-field projection only in ERP page memory; persistent diagnostics may contain field names and counts but no field values. Do not retry the failed task.
- Do not remove salesperson protection, silently rewrite it at the live gate, or add a fixed delay; use the ERP page's native lookup readiness signal.
- Through
0.5.162, preserve corrected dynamic receivable protection and usejQuery.active/ajaxStoprather than a fixed quiet sleep. After the production operator explicitly requested the0.5.156validation behavior, retain the Ajax stabilization but remove numbered dynamicys_*fields from the protected projection; core order fields remain fail-closed. - Reclaim the same task in Integration mode after the initialized canonical templates caused the Feature-mode drift check to block; the user explicitly approved the forced ownership recovery.
Outcome
- The official initializer added 34 previously missing
.project-docstemplate files without overwriting existing files, andcheck_project_docs.pypassed afterward. - The existing multi-stage
Dockerfilebuilds the TypeScript control plane and packages Node.js 22, LibreOffice Writer, Noto CJK fonts, compiled migrations, and the platform adapter into one runtime image exposing port 8786. - For ACK, the recommended image command is a
docker buildx build --platform <node-architecture> ... --push .command targeting ACR. ACR login and an ACK image-pull mechanism are separate prerequisites. - Required production state is PostgreSQL. The current production template selects OSS artifact storage; Redis, Kafka, RabbitMQ, MongoDB, Elasticsearch, and a separate platform-adapter service are not dependencies in the active code/configuration.
- Compose runs migrations before the server, while the image default
CMDstarts only the server. ACK therefore needs a single-run migration Job before the Deployment; starting an unmigrated Deployment fails closed on the required schema version. - Use an ACK Ingress/managed load balancer and TLS instead of the Compose-only Caddy service. Configure the long-lived HTTP path for SSE behavior.
- Start with one application replica: AgentBus listeners and SSE event emission are process-local, so horizontally scaling the current service would create multiple listeners and incomplete cross-pod event propagation without an explicit coordination design.
- The canonical templates remain neutral placeholders. Deployment findings were retained in this integration task record and were not promoted into accepted architecture without a separate architecture-memory decision.
- Reproduced the reported Popup symptom with an agent-runnable VM harness: localhost was recognized while
https://lwlt.nianxx.cnreturned未打开业务系统页面. - Updated Popup URL matching, background tab discovery, Manifest host permission/content script matching, extension/runtime version declarations, platform minimum version, lifecycle mapping, release gate, tests, and extension documentation to
0.5.158. - Archived the superseded
0.5.157ZIP and manifest snapshot underarchive/releases/2026-08-29/; generateddist/ltjt-order-assistant-0.5.158.zipwith SHA-25699ba7b29d1d4418cb02fcbb345aeaf8494877dbc397ae8592b4e3fdb68b4cf9d. - Verified the new archive contains exactly 19 source files and every entry matches the active extension source byte-for-byte.
- Repaired Windows-reachable verification gaps encountered by the mandated gates:
.project-docsis now an allowed governed root, text artifact comparison normalizes CRLF/LF only for explicit text extensions,ajvandajv-formatsare declared direct dev dependencies, URL fixtures usefileURLToPath, and Unix fake-converter success tests are explicitly skipped on Windows while remaining active on Linux/Docker. - Reproduced the production warning with the real platform state function:
session_ready=trueplus persistedrecovery_status=runningrendered已连接,有告警and blocked dispatch. - Added a behavioral keepalive regression. A real in-memory recovery Promise preserves
running; a service-worker-interrupted persisted state is normalized tointerrupted; a later successful read-only keepalive with no recovery in flight sets the recovery state toidle. - Advanced the extension/runtime contract to
0.5.159, updated the platform cache key, lifecycle mapping, release gate and tests, archived0.5.158, and generateddist/ltjt-order-assistant-0.5.159.zipwith SHA-256dcb44f1a6e3336ed1876753c658e664eaf224f55c3d0c792bb2e83b1c8398276. - Confirmed from the user's service-worker evidence that the approved preflight form/request protected hashes matched, the live form retained the same 822-field count, and only the live protected hash changed; the blocker remained pre-network with
write_attempted=falseandno_erp_write=true. - Added page-memory-only approved protected projections and structured drift diagnostics containing only changed field names, count, baseline integrity, and
values_redacted=true; the existing fail-closed blocker and zero-write behavior remain unchanged. - Fixed the dynamic receivable protection regex so real numeric fields such as
ys_jine0andys_shuliang0are included in the protected projection. - Advanced the synchronized extension/runtime contract to
0.5.160, archived0.5.159, and generateddist/ltjt-order-assistant-0.5.160.zipwith SHA-256e331d3d63967ae7278ce0ded35de6210c09555b5e69374c9190e8e7b380c2a70. - Production use of
0.5.160identifiedxiaoshourenas the sole changed protected field. Read-only diagnosis found that the team-order frame probe declares readiness from form element count alone, while the ERP page asynchronously fetches staff data and reinitializes the salesperson SelectBox afterward; the plugin performs no second salesperson write between the approved baseline and live gate. - A VM harness over the real
lightweightOrderFrameProbereturnedorder_frame_readywith all three native lookup-data attributes absent, providing a deterministic red signal for the readiness gap. The analogous shared-child flow already waits forzutuanshe,gendanren, andxiaoshourenlookup data. This diagnosis did not change execution code or produce a new release. - After user authorization, locked that harness into
tools/operation-timing.test.mjs; it first failed withactual=order_frame_ready / expected=order_frame_loading, then passed after both the inline background probe and exported page probe required nativezutuanshe,gendanren, andxiaoshourenlookup data. - Advanced the synchronized extension/runtime contract to
0.5.161, archived0.5.160, and generateddist/ltjt-order-assistant-0.5.161.zipwith SHA-2564a5f680bfe7524f8215ef80b83c681076602e3f59e3a9c7f33005698256809cb. The archive contains exactly 19 files and matches active extension source byte-for-byte. - Production handshake confirmed
0.5.161, but the same route still reportedxiaoshourenand thenxiaoshourenplus inactiveys_danwei*/ys_danweiid*fields. The user's known-good0.5.156comparison showed salesperson protection already existed there, while the old dynamic-receivable regex did not actually match numbered fields. - A second real-probe VM regression returned
order_frame_readywith all three lookup data attributes present but two native jQuery Ajax requests still active. The probe now remains loading untiljQuery.activereaches zero, and preflight waits for the page's nativeajaxStopafterGetProductbefore applying final business fields. - Advanced the synchronized extension/runtime contract to
0.5.162, archived0.5.161, and generateddist/ltjt-order-assistant-0.5.162.zipwith SHA-2562b257fd61610e8cb6f21c99441b6072246ce06397e2ea05e96488ef414926f12. The archive contains exactly 19 files and matches active extension source byte-for-byte. - Confirmed by archived-source differential that
0.5.156did not protect real numbered dynamic receivable fields because its regex matched a literal backslash sequence. A deterministic regression first reporteddarenshu,ys_danwei1,ys_danweiid1, andys_jine0; after restoring the old effective scope it reports only the still-protecteddarenshu. - Advanced the synchronized extension/runtime contract to
0.5.163, archived0.5.162, and generateddist/ltjt-order-assistant-0.5.163.zipwith SHA-25690c550054cdf747aa9c2c80bca5ee5fba0d13f126acfd4779f85400764379bf0. Core protected-field drift still blocks before network; numbered dynamic receivable drift is allowed through the native submit gate by explicit production request.
Verification
- Read:
README.md, root planning files, business registry,Dockerfile,.dockerignore,docker-compose.yml,package.json,.env.production.example, infrastructure scripts, control-plane README, configuration, database, migration, server, artifact-store, and AgentBus-related source. - Confirmed
.dockerignoreexcludes.envand.env.*from the image build context. - Confirmed health endpoints
/health/liveand/health/ready, service port 8786, required migration014_task_input_attachments, PostgreSQL pool usage, OSS production configuration, bundled document conversion, and lack of Redis/MQ/search dependencies. - The production-origin regression first failed with
false !== true, then passed after the fix; the original Popup black-box no longer produced未打开业务系统页面forhttps://lwlt.nianxx.cn. - Final release verification includes repository hygiene 9/9, TypeScript check, control-plane tests, legacy tests, build, JavaScript syntax checks, package/source byte comparison, and
git diff --check. - Final gate counts: repository hygiene 9/9; control-plane 123 passed, 0 failed, 4 Windows-only skips for Unix fake-converter fixtures; legacy 249/249; TypeScript check and build both exited 0.
- Cross-checked current ACR build/push, private image pull, ACK ALB/Nginx Ingress, and long-connection guidance against Alibaba Cloud official documentation on 2026-08-28.
- The Feature-mode boundary check correctly blocked on initialized canonical templates; after explicit approval, official
release --forceandstart --mode integration --adopt-existingcommands established matching Integration ownership and lock. - No Docker build, image push, Kubernetes mutation, database migration, browser-extension reload, ERP access/write, or deployment was executed.
- The stale-recovery regression failed before the implementation because no state normalizer existed, then passed after the fix; the combined background-normalizer/platform-UI harness now reports
已连接for an interrupted recovery and retains已连接,有告警for a real in-flight recovery. 0.5.159release verification: keepalive tests 6/6; repository hygiene 9/9; TypeScript check; control-plane 123 passed with 4 Windows-only skips; legacy 250/250; build; package/source comparison 19/19;git diff --check. The initial legacy rerun exposed only four escaped old-version regex assertions, which were synchronized before the clean rerun.0.5.160diagnostics verification: focused drift tests 3/3; package/source comparison 19/19; repository hygiene 9/9; TypeScript check; control-plane 123 passed with 4 Windows-only skips; legacy 252/252; build. The first legacy run found one stale0.5.159assertion and the PowerShell PATH omitted Git'sunzip; after synchronizing the assertion and supplying the existing tool path, the clean rerun passed.0.5.161readiness verification: focused readiness tests 2/2; JavaScript syntax checks; package/source comparison 19/19; repository hygiene 9/9; TypeScript check; control-plane 123 passed with 4 Windows-only skips; legacy 253/253; build. No ERP access/write, failed-task retry, extension reload, service restart, or deployment was performed.0.5.162verification: the new pending-Ajax probe failed before implementation withactual=order_frame_ready / expected=order_frame_loading; afterward operation timing/native-idle tests passed 11/11, drift tests passed 2/2, JavaScript syntax passed, and package/source comparison passed 19/19. Final gates passed: repository hygiene 9/9, TypeScript check, control-plane 123 passed with 4 Windows-only skips, legacy 254/254, and build.0.5.163verification: the core-scope differential regression failed before implementation with actual changed fieldsdarenshu, ys_danwei1, ys_danweiid1, ys_jine0versus expecteddarenshu; afterward focused tests passed 3/3 and Ajax timing tests passed 11/11. Final gates passed: repository hygiene 9/9, TypeScript check, control-plane 123 passed with 4 Windows-only skips, legacy 255/255, build, and release package/source verification.
Follow-ups
- If requested, create task-scoped ACK manifests or a Helm chart containing Namespace, Secret/ConfigMap references, migration Job, single-replica Deployment, ClusterIP Service, Ingress, probes, and ACR pull configuration.
- Load or distribute
dist/ltjt-order-assistant-0.5.163.zip, refresh ERP andhttps://lwlt.nianxx.cn, and confirm the live handshake reports0.5.163. Then use a new task to verify numbered dynamic receivable drift no longer blocks while core protected-field drift still does; runtime reload and task execution remain separate user/operations actions. - Reconcile stable project facts from the populated root project-memory files into canonical
.project-docsonly through an explicitly scoped architecture-memory integration task.
Promotion Candidates
- Target:
.project-docs/20-architecture/system-overview.mdand.project-docs/30-worklog/current-state.mdthrough a separately confirmed architecture-memory integration. Proposal: record PostgreSQL as the sole required database/state middleware, OSS as the production artifact backend, the client-side Chrome extension boundary, the migration-before-start requirement, and the current single-replica constraint. Evidence: active Docker, Compose, production config, control-plane source, and README. Future impact: prevents incomplete ACK deployments and unsafe horizontal scaling. Semantic conflicts: canonical files are newly initialized placeholders; root project memory is populated but has not been reconciled into.project-docs. Human confirmation: required before promotion because this would establish canonical architecture memory.