feat: add Go workload deployment artifacts and split Ingress routing
This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
# Task: Build first-deployment artifacts for the Go stack
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260814-go-deploy-artifacts-2a5f8e1d
|
||||
- Mode: Feature
|
||||
- Branch: main
|
||||
- Worktree: /Users/brother7/Documents/AI/NianAIGC
|
||||
- Base commit: ca019abb14859f7413214b2b6a11a8a07cebf5f7
|
||||
- Owner: dsh
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Build the deployment artifacts for the first production deployment of the ADR-003 split topology: Go container image build, ACK Deployment/Service for the Go API workload, split-path Ingress routing, and workload configuration updates.
|
||||
- Human direction (2026-08-14): first production deployment runs Next.js (pages/static/SSR) plus Go (backend paths) directly; no Node Worker and no migration Job pod in production.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Production Web workload holds no RDS/provider credentials and only needs the shared session secret for local cookie verification (its middleware already verifies the cookie with HMAC locally, no database access).
|
||||
- Go workload runs non-root, root filesystem read-only, with writable emptyDir mounts for runtime/logs/settings/temp.
|
||||
- Keep the manifest contract checker (`check-ack-manifests.mjs`) authoritative for the new topology.
|
||||
- Keep deprecated manifests (worker, migration Job) on disk with header comments.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Added `backend/Dockerfile` (multi-stage `golang:1.21-alpine` → `alpine:3.20`, static `CGO_ENABLED=0` build, non-root uid/gid 10001, ca-certificates + tzdata) and `backend/.dockerignore`.
|
||||
- Added `deploy/ack/go-api.yaml`: Deployment `zhinian-go-api` (1 replica, `/api/ready` database-aware readiness, runAsNonRoot, readOnlyRootFilesystem, RDS CA + data + tmp volumes, bootstrap/provider/webhook secrets, embedded WorkerLoop config) plus ClusterIP Service `zhinian-go-api:8080`.
|
||||
- Added `zhinian-go-runtime` ConfigMap to `deploy/ack/configmap.yaml` with the full Go runtime surface (DB/TLS settings, auth, embedded worker, billing, runtime/log/settings dirs).
|
||||
- Updated `deploy/ack/web.yaml`: removed RDS credentials, worker token, and RDS CA mount; readiness switched to process-level `/api/health` (Web is database-free in production).
|
||||
- Updated `deploy/ack/ingress.yaml`: `/api`, `/uploads`, `/generated-results` → `zhinian-go-api`; `/api/internal/worker` still → selectorless deny Service; pages/static → Web.
|
||||
- Updated `deploy/ack/secrets.example.yaml` with `zhinian-go-db`, `zhinian-go-bootstrap`, `zhinian-go-providers`, `zhinian-go-secrets` and notes that the session secret must match across workloads; marked local-only secrets.
|
||||
- Marked `deploy/ack/worker.yaml` deprecated (production uses the embedded WorkerLoop).
|
||||
- Updated `scripts/check-ack-manifests.mjs` assertions for the split topology (Web database-free, Go API non-root/database-aware readiness/bootstrap config, Ingress split routing).
|
||||
- Updated `docs/DEPLOYMENT.md`, `README.zh-CN.md`, and `README.md` deployment/tech-stack guidance (Go image build command, apply order, split topology).
|
||||
|
||||
## Verification
|
||||
|
||||
- `npm run deploy:check` — PASS (9 manifest files, new assertions).
|
||||
- All `deploy/ack/*.yaml` parse as valid multi-document YAML.
|
||||
- `CGO_ENABLED=0 go build ./cmd/zhinian-api` — PASS.
|
||||
- Docker image build itself must run on a machine with Docker; the Dockerfile is static-checked against the build steps in `scripts/run-go-command.mjs` conventions.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Build and push the `zhinian-go-api` image, then validate the manifests with `kubectl apply --dry-run=server` on the target ACK cluster.
|
||||
- Validate the full stack against non-production RDS/OSS/provider/Webhook dependencies before the first rollout.
|
||||
- Decide whether to delete the deprecated `worker.yaml` and `migration-job.yaml`.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- Canonical memory (current-state Next Steps, commitments) still lists "build the Go workload deployment artifacts" as open; promote completion there in the next integration pass.
|
||||
Reference in New Issue
Block a user