production runtime and mock removal
This commit is contained in:
@@ -39,6 +39,7 @@ assert(goApi.includes("name: zhinian-go-runtime"), "Go API must consume the Go r
|
||||
assert(goApi.includes("name: zhinian-go-auth"), "Go API must own the browser session signing Secret");
|
||||
assert(!goApi.includes("name: zhinian-web-auth"), "Go API must not reference the removed Web auth Secret");
|
||||
assert(goApi.includes("name: zhinian-go-bootstrap"), "Go API must receive bootstrap administrator credentials");
|
||||
assert(goApi.includes("name: zhinian-go-providers"), "Go API must receive real provider credentials");
|
||||
assert(!goApi.includes("rds-ca"), "Go API must not mount an RDS CA when PostgreSQL TLS is disabled");
|
||||
assert(!goApi.includes("/etc/zhinian/rds"), "Go API must not retain the removed RDS CA path");
|
||||
assert(!/\bTLS\b/i.test(goApi), "Go API manifest must not retain PostgreSQL TLS configuration");
|
||||
@@ -47,6 +48,7 @@ assert(!goApi.includes("DATABASE_CA_CERT_PATH"), "Go API must not receive a data
|
||||
|
||||
const secrets = read("secrets.example.yaml");
|
||||
assert(secrets.includes("name: zhinian-go-auth"), "Example secrets must name Go as the session Secret owner");
|
||||
assert(secrets.includes("name: zhinian-go-providers"), "Example secrets must define real provider credentials");
|
||||
assert(!secrets.includes("name: zhinian-web-auth"), "Example secrets must not retain the removed Web auth Secret");
|
||||
assert(!secrets.includes("zhinian-rds-ca"), "Example secrets must not define the removed RDS CA Secret");
|
||||
assert(!secrets.includes("sslrootcert"), "Example DATABASE_URL values must not reference an RDS CA");
|
||||
|
||||
@@ -23,7 +23,7 @@ if command -v node >/dev/null 2>&1; then
|
||||
elif [ ! -f .env.local ]; then
|
||||
cp .env.example .env.local
|
||||
echo "[deploy] Created .env.local from .env.example"
|
||||
echo "[deploy] Real generation requires API keys in .env.local. Empty keys keep mock/local flows available."
|
||||
echo "[deploy] Configure DATABASE_URL and all real provider credentials in .env.local before production use."
|
||||
fi
|
||||
|
||||
if ! grep -q '^ZHINIAN_INTERNAL_WORKER_TOKEN=' .env.local || grep -q '^ZHINIAN_INTERNAL_WORKER_TOKEN=$\|^ZHINIAN_INTERNAL_WORKER_TOKEN=change-me-worker-token$' .env.local; then
|
||||
@@ -66,12 +66,12 @@ if command -v curl >/dev/null 2>&1; then
|
||||
sleep 2
|
||||
done
|
||||
if ! curl -fsS "$HEALTH_URL" >/dev/null 2>&1; then
|
||||
echo "[deploy] Health check did not pass yet. Inspect logs with: ${COMPOSE[*]} logs -f zhinian-aigc"
|
||||
echo "[deploy] Health check did not pass yet. Inspect logs with: ${COMPOSE[*]} logs -f zhinian-go-api zhinian-web"
|
||||
fi
|
||||
fi
|
||||
|
||||
echo "[deploy] 智念AIGC平台 is available at http://127.0.0.1:${APP_PORT:-3000}"
|
||||
echo "[deploy] If this is a public server, set NEXT_PUBLIC_APP_URL in .env.local to your domain."
|
||||
echo "[deploy] Web service and zhinian-worker are both managed by Docker Compose."
|
||||
echo "[deploy] zhinian-web and zhinian-go-api are managed by Docker Compose; the Go API owns the embedded worker."
|
||||
echo "[deploy] API docs: docs/API.md"
|
||||
echo "[deploy] OpenAPI: ${HEALTH_URL%/api/health}/api/v1/openapi.json"
|
||||
|
||||
@@ -15,7 +15,7 @@ if (!existsSync(envPath)) {
|
||||
}
|
||||
copyFileSync(examplePath, envPath);
|
||||
console.log("[deploy] Created .env.local from .env.example");
|
||||
console.log("[deploy] Real generation requires API keys in .env.local. Empty keys keep mock/local flows available.");
|
||||
console.log("[deploy] Configure DATABASE_URL and all real provider credentials in .env.local before production use.");
|
||||
}
|
||||
|
||||
let envText = readFileSync(envPath, "utf8");
|
||||
|
||||
Reference in New Issue
Block a user