production runtime and mock removal

This commit is contained in:
inman
2026-08-17 23:44:14 +08:00
parent 2ef3da7af5
commit 6480e503eb
55 changed files with 581 additions and 540 deletions

View File

@@ -39,6 +39,7 @@ assert(goApi.includes("name: zhinian-go-runtime"), "Go API must consume the Go r
assert(goApi.includes("name: zhinian-go-auth"), "Go API must own the browser session signing Secret");
assert(!goApi.includes("name: zhinian-web-auth"), "Go API must not reference the removed Web auth Secret");
assert(goApi.includes("name: zhinian-go-bootstrap"), "Go API must receive bootstrap administrator credentials");
assert(goApi.includes("name: zhinian-go-providers"), "Go API must receive real provider credentials");
assert(!goApi.includes("rds-ca"), "Go API must not mount an RDS CA when PostgreSQL TLS is disabled");
assert(!goApi.includes("/etc/zhinian/rds"), "Go API must not retain the removed RDS CA path");
assert(!/\bTLS\b/i.test(goApi), "Go API manifest must not retain PostgreSQL TLS configuration");
@@ -47,6 +48,7 @@ assert(!goApi.includes("DATABASE_CA_CERT_PATH"), "Go API must not receive a data
const secrets = read("secrets.example.yaml");
assert(secrets.includes("name: zhinian-go-auth"), "Example secrets must name Go as the session Secret owner");
assert(secrets.includes("name: zhinian-go-providers"), "Example secrets must define real provider credentials");
assert(!secrets.includes("name: zhinian-web-auth"), "Example secrets must not retain the removed Web auth Secret");
assert(!secrets.includes("zhinian-rds-ca"), "Example secrets must not define the removed RDS CA Secret");
assert(!secrets.includes("sslrootcert"), "Example DATABASE_URL values must not reference an RDS CA");

View File

@@ -23,7 +23,7 @@ if command -v node >/dev/null 2>&1; then
elif [ ! -f .env.local ]; then
cp .env.example .env.local
echo "[deploy] Created .env.local from .env.example"
echo "[deploy] Real generation requires API keys in .env.local. Empty keys keep mock/local flows available."
echo "[deploy] Configure DATABASE_URL and all real provider credentials in .env.local before production use."
fi
if ! grep -q '^ZHINIAN_INTERNAL_WORKER_TOKEN=' .env.local || grep -q '^ZHINIAN_INTERNAL_WORKER_TOKEN=$\|^ZHINIAN_INTERNAL_WORKER_TOKEN=change-me-worker-token$' .env.local; then
@@ -66,12 +66,12 @@ if command -v curl >/dev/null 2>&1; then
sleep 2
done
if ! curl -fsS "$HEALTH_URL" >/dev/null 2>&1; then
echo "[deploy] Health check did not pass yet. Inspect logs with: ${COMPOSE[*]} logs -f zhinian-aigc"
echo "[deploy] Health check did not pass yet. Inspect logs with: ${COMPOSE[*]} logs -f zhinian-go-api zhinian-web"
fi
fi
echo "[deploy] 智念AIGC平台 is available at http://127.0.0.1:${APP_PORT:-3000}"
echo "[deploy] If this is a public server, set NEXT_PUBLIC_APP_URL in .env.local to your domain."
echo "[deploy] Web service and zhinian-worker are both managed by Docker Compose."
echo "[deploy] zhinian-web and zhinian-go-api are managed by Docker Compose; the Go API owns the embedded worker."
echo "[deploy] API docs: docs/API.md"
echo "[deploy] OpenAPI: ${HEALTH_URL%/api/health}/api/v1/openapi.json"

View File

@@ -15,7 +15,7 @@ if (!existsSync(envPath)) {
}
copyFileSync(examplePath, envPath);
console.log("[deploy] Created .env.local from .env.example");
console.log("[deploy] Real generation requires API keys in .env.local. Empty keys keep mock/local flows available.");
console.log("[deploy] Configure DATABASE_URL and all real provider credentials in .env.local before production use.");
}
let envText = readFileSync(envPath, "utf8");