docs: integrate plaintext PostgreSQL decision
This commit is contained in:
1 parent
ed978142eb
commit
acd929c704
10 files changed
+146
-40
No files matched your search
@@ -15,7 +15,8 @@ and are not a supported production path.
|
||||
|
||||
## Approved Target Flows
|
||||
|
||||
The implementation and desired ACK routing are present in `b14b4fc`.
|
||||
The static implementation and desired ACK routing are present in `b14b4fc`;
|
||||
`ed97814` adds the plaintext PostgreSQL transport correction.
|
||||
Production is already online, but the static revision and exact live Service
|
||||
ownership have not been confirmed from cluster configuration or logs:
|
||||
|
||||
@@ -24,7 +25,7 @@ ownership have not been confirmed from cluster configuration or logs:
|
||||
| Browser UI | Browser | Same-origin Ingress -> Nginx static Web | Preserve current page URLs; Nginx performs no application logic. |
|
||||
| Browser identity | Browser auth Module | Same-origin Ingress -> Go `GET /api/auth/me` | Browser automatically sends HttpOnly Cookie; validate anonymous/authenticated response shapes, keep no token in JavaScript, and use client guards only for UX. |
|
||||
| Browser business/file requests | Browser components | Same-origin Ingress -> Go `/api`, `/uploads`, `/generated-results` | Go revalidates session/account/organization/sessionVersion and enforces every protected action. |
|
||||
| Backend persistence | Go Modules | PostgreSQL Adapter -> RDS | Parameterized queries and transactions; fail closed in production. |
|
||||
| Backend persistence | Go Modules | PostgreSQL Adapter -> internal RDS endpoint | Parameterized queries and transactions; fail closed in production; code-enforced plaintext (`sslmode=disable`) within VPC/security-group/allowlist isolation. |
|
||||
| Task execution | Embedded Go WorkerLoop | RDS claim -> provider -> OSS -> RDS -> Webhook | Bounded concurrency, recoverable leases, one owner for external side effects. |
|
||||
| Asset lifecycle | Go Assets | OSS plus RDS metadata | Shared storage required before horizontal scaling. |
|
||||
| Schema rollout | Manual operator or dedicated CI | RDS | Execute immutable versioned SQL plus grants outside long-lived workloads; no Web-image migration Job. |
|
||||
@@ -39,7 +40,9 @@ ownership have not been confirmed from cluster configuration or logs:
|
||||
|
||||
## External Interfaces
|
||||
|
||||
- Alibaba Cloud RDS PostgreSQL via its internal endpoint and verified TLS CA.
|
||||
- Alibaba Cloud RDS PostgreSQL via its internal endpoint using code-enforced
|
||||
plaintext; VPC, security-group, and RDS allowlist controls are the transport
|
||||
isolation boundary.
|
||||
- Alibaba Cloud ACK resources under `deploy/ack/`.
|
||||
- Live production at `https://nianxxaigc.nianxx.cn`; public `/api/ready` has returned HTTP 200 with PostgreSQL configured, without proving the owning Service.
|
||||
- The legacy internal Worker prefix is denied by Ingress; production uses the
|
||||
@@ -47,7 +50,8 @@ ownership have not been confirmed from cluster configuration or logs:
|
||||
|
||||
The accepted production topology uses the embedded Go WorkerLoop. The current
|
||||
live revision produces an RSC error for authenticated `/create`; the rollout
|
||||
must deploy `b14b4fc` under immutable image references and smoke login,
|
||||
must deploy `ed97814` under immutable image references and smoke PostgreSQL
|
||||
bootstrap/readiness, login,
|
||||
authenticated routes, logout, roles, `/healthz`, `/api/health`, and
|
||||
`/api/ready`.
|
||||
|
||||
|
||||
Reference in new issue
Block a user