feat: add Go workload deployment artifacts and split Ingress routing

This commit is contained in:
zn-admin committed 2026-08-14 09:50:47 +08:00
1 parent ca019abb14
commit 4a8f2d56e2
13 files changed
+452 -26

No files matched your search

+9 -20
View File
@@ -1,3 +1,8 @@
# Next.js frontend workload for the first production deployment: serves pages,
# static assets, and SSR only. All /api, /uploads, and /generated-results
# traffic is routed to zhinian-go-api by the Ingress, so this workload holds no
# RDS credentials and needs only the shared session secret for local cookie
# verification in the middleware.
apiVersion: apps/v1
kind: Deployment
metadata:
@@ -10,7 +15,7 @@ spec:
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 1 # Budget RDS connections for (replicas + maxSurge) * DATABASE_POOL_MAX.
maxSurge: 1
maxUnavailable: 0
selector:
matchLabels:
@@ -37,25 +42,13 @@ spec:
- configMapRef:
name: zhinian-runtime
env:
- name: DATABASE_URL
valueFrom:
secretKeyRef:
name: zhinian-web-db
key: DATABASE_URL
- name: ZHINIAN_INTERNAL_WORKER_TOKEN
valueFrom:
secretKeyRef:
name: zhinian-worker-auth
key: ZHINIAN_INTERNAL_WORKER_TOKEN
# The session secret must be the same value the Go backend uses so
# the frontend middleware and the Go backend verify the same cookies.
- name: ZHINIAN_AUTH_SESSION_SECRET
valueFrom:
secretKeyRef:
name: zhinian-web-auth
key: ZHINIAN_AUTH_SESSION_SECRET
volumeMounts:
- name: rds-ca
mountPath: /etc/zhinian/rds
readOnly: true
startupProbe:
httpGet:
path: /api/health
@@ -64,7 +57,7 @@ spec:
failureThreshold: 24
readinessProbe:
httpGet:
path: /api/ready
path: /api/health
port: http
periodSeconds: 10
timeoutSeconds: 5
@@ -89,7 +82,3 @@ spec:
drop: ["ALL"]
# The current image runs as root. Add a fixed non-root image user and
# verify /app/.runtime permissions before enabling runAsNonRoot.
volumes:
- name: rds-ca
secret:
secretName: zhinian-rds-ca