feat: add Go workload deployment artifacts and split Ingress routing

This commit is contained in:
2026-08-14 09:50:47 +08:00
parent ca019abb14
commit 4a8f2d56e2
13 changed files with 452 additions and 26 deletions

View File

@@ -0,0 +1,52 @@
# Task: Build first-deployment artifacts for the Go stack
## Identity
- Task ID: 20260814-go-deploy-artifacts-2a5f8e1d
- Mode: Feature
- Branch: main
- Worktree: /Users/brother7/Documents/AI/NianAIGC
- Base commit: ca019abb14859f7413214b2b6a11a8a07cebf5f7
- Owner: dsh
- Status: Ready for Integration
## Scope
- Build the deployment artifacts for the first production deployment of the ADR-003 split topology: Go container image build, ACK Deployment/Service for the Go API workload, split-path Ingress routing, and workload configuration updates.
- Human direction (2026-08-14): first production deployment runs Next.js (pages/static/SSR) plus Go (backend paths) directly; no Node Worker and no migration Job pod in production.
## Intent And Constraints
- Production Web workload holds no RDS/provider credentials and only needs the shared session secret for local cookie verification (its middleware already verifies the cookie with HMAC locally, no database access).
- Go workload runs non-root, root filesystem read-only, with writable emptyDir mounts for runtime/logs/settings/temp.
- Keep the manifest contract checker (`check-ack-manifests.mjs`) authoritative for the new topology.
- Keep deprecated manifests (worker, migration Job) on disk with header comments.
## Outcome
- Added `backend/Dockerfile` (multi-stage `golang:1.21-alpine` → `alpine:3.20`, static `CGO_ENABLED=0` build, non-root uid/gid 10001, ca-certificates + tzdata) and `backend/.dockerignore`.
- Added `deploy/ack/go-api.yaml`: Deployment `zhinian-go-api` (1 replica, `/api/ready` database-aware readiness, runAsNonRoot, readOnlyRootFilesystem, RDS CA + data + tmp volumes, bootstrap/provider/webhook secrets, embedded WorkerLoop config) plus ClusterIP Service `zhinian-go-api:8080`.
- Added `zhinian-go-runtime` ConfigMap to `deploy/ack/configmap.yaml` with the full Go runtime surface (DB/TLS settings, auth, embedded worker, billing, runtime/log/settings dirs).
- Updated `deploy/ack/web.yaml`: removed RDS credentials, worker token, and RDS CA mount; readiness switched to process-level `/api/health` (Web is database-free in production).
- Updated `deploy/ack/ingress.yaml`: `/api`, `/uploads`, `/generated-results` → `zhinian-go-api`; `/api/internal/worker` still → selectorless deny Service; pages/static → Web.
- Updated `deploy/ack/secrets.example.yaml` with `zhinian-go-db`, `zhinian-go-bootstrap`, `zhinian-go-providers`, `zhinian-go-secrets` and notes that the session secret must match across workloads; marked local-only secrets.
- Marked `deploy/ack/worker.yaml` deprecated (production uses the embedded WorkerLoop).
- Updated `scripts/check-ack-manifests.mjs` assertions for the split topology (Web database-free, Go API non-root/database-aware readiness/bootstrap config, Ingress split routing).
- Updated `docs/DEPLOYMENT.md`, `README.zh-CN.md`, and `README.md` deployment/tech-stack guidance (Go image build command, apply order, split topology).
## Verification
- `npm run deploy:check` — PASS (9 manifest files, new assertions).
- All `deploy/ack/*.yaml` parse as valid multi-document YAML.
- `CGO_ENABLED=0 go build ./cmd/zhinian-api` — PASS.
- Docker image build itself must run on a machine with Docker; the Dockerfile is static-checked against the build steps in `scripts/run-go-command.mjs` conventions.
## Follow-ups
- Build and push the `zhinian-go-api` image, then validate the manifests with `kubectl apply --dry-run=server` on the target ACK cluster.
- Validate the full stack against non-production RDS/OSS/provider/Webhook dependencies before the first rollout.
- Decide whether to delete the deprecated `worker.yaml` and `migration-job.yaml`.
## Promotion Candidates
- Canonical memory (current-state Next Steps, commitments) still lists "build the Go workload deployment artifacts" as open; promote completion there in the next integration pass.