docs: integrate plaintext PostgreSQL decision

This commit is contained in:
brother7 committed 2026-08-16 23:35:33 +08:00
1 parent ed978142eb
commit acd929c704
10 files changed
+146 -40

No files matched your search

@@ -28,6 +28,9 @@ The project exists to give organizations an Alibaba Cloud ACK-deployable AI crea
- Same-origin browser authentication through signed, chunked `zhinian_session` cookies with per-request account/organization/sessionVersion revalidation.
- Production persistence fails closed: explicit RDS PostgreSQL through the Go
PostgreSQL Adapter; local JSON is development/test only.
- PostgreSQL clients enforce plaintext (`sslmode=disable`) for the selected RDS
endpoint. Production database traffic must stay on the internal network and
be restricted by VPC, security-group, and RDS allowlist controls.
- Production Web is a static export on Nginx. Browser runtime requests stay
same-origin and all API/file/auth behavior belongs to Go.
- Cross-instance concurrency stays in PostgreSQL: `claim_generation_jobs` for job claims and `billing_post_wallet_entry` for wallet idempotency; no process-local lock replacements.