docs: integrate plaintext PostgreSQL decision

This commit is contained in:
brother7 committed 2026-08-16 23:35:33 +08:00
1 parent ed978142eb
commit acd929c704
10 files changed
+146 -40

No files matched your search

+8 -4
View File
@@ -15,7 +15,8 @@ and are not a supported production path.
## Approved Target Flows
The implementation and desired ACK routing are present in `b14b4fc`.
The static implementation and desired ACK routing are present in `b14b4fc`;
`ed97814` adds the plaintext PostgreSQL transport correction.
Production is already online, but the static revision and exact live Service
ownership have not been confirmed from cluster configuration or logs:
@@ -24,7 +25,7 @@ ownership have not been confirmed from cluster configuration or logs:
| Browser UI | Browser | Same-origin Ingress -> Nginx static Web | Preserve current page URLs; Nginx performs no application logic. |
| Browser identity | Browser auth Module | Same-origin Ingress -> Go `GET /api/auth/me` | Browser automatically sends HttpOnly Cookie; validate anonymous/authenticated response shapes, keep no token in JavaScript, and use client guards only for UX. |
| Browser business/file requests | Browser components | Same-origin Ingress -> Go `/api`, `/uploads`, `/generated-results` | Go revalidates session/account/organization/sessionVersion and enforces every protected action. |
| Backend persistence | Go Modules | PostgreSQL Adapter -> RDS | Parameterized queries and transactions; fail closed in production. |
| Backend persistence | Go Modules | PostgreSQL Adapter -> internal RDS endpoint | Parameterized queries and transactions; fail closed in production; code-enforced plaintext (`sslmode=disable`) within VPC/security-group/allowlist isolation. |
| Task execution | Embedded Go WorkerLoop | RDS claim -> provider -> OSS -> RDS -> Webhook | Bounded concurrency, recoverable leases, one owner for external side effects. |
| Asset lifecycle | Go Assets | OSS plus RDS metadata | Shared storage required before horizontal scaling. |
| Schema rollout | Manual operator or dedicated CI | RDS | Execute immutable versioned SQL plus grants outside long-lived workloads; no Web-image migration Job. |
@@ -39,7 +40,9 @@ ownership have not been confirmed from cluster configuration or logs:
## External Interfaces
- Alibaba Cloud RDS PostgreSQL via its internal endpoint and verified TLS CA.
- Alibaba Cloud RDS PostgreSQL via its internal endpoint using code-enforced
plaintext; VPC, security-group, and RDS allowlist controls are the transport
isolation boundary.
- Alibaba Cloud ACK resources under `deploy/ack/`.
- Live production at `https://nianxxaigc.nianxx.cn`; public `/api/ready` has returned HTTP 200 with PostgreSQL configured, without proving the owning Service.
- The legacy internal Worker prefix is denied by Ingress; production uses the
@@ -47,7 +50,8 @@ ownership have not been confirmed from cluster configuration or logs:
The accepted production topology uses the embedded Go WorkerLoop. The current
live revision produces an RSC error for authenticated `/create`; the rollout
must deploy `b14b4fc` under immutable image references and smoke login,
must deploy `ed97814` under immutable image references and smoke PostgreSQL
bootstrap/readiness, login,
authenticated routes, logout, roles, `/healthz`, `/api/health`, and
`/api/ready`.