docs: integrate plaintext PostgreSQL decision

This commit is contained in:
brother7 committed 2026-08-16 23:35:33 +08:00
1 parent ed978142eb
commit acd929c704
10 files changed
+146 -40

No files matched your search

+36 -18
View File
@@ -17,23 +17,28 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- `b14b4fc` (pure static Next.js export, browser-to-Go auth, Go-only runtime API
ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task
`20260816-static-frontend-go-api-4f8c2a7d`)
- `acf368b` (diagnosis of the production Go bootstrap failure against an RDS
endpoint that refuses PostgreSQL TLS)
- `ed97814` (code-enforced plaintext PostgreSQL for Go and retained Node
tooling, removal of the obsolete RDS CA deployment dependency, and protocol
regression coverage; task `20260816-disable-postgres-tls-d4a89c12`)
## Current Focus
The first production deployment is live at `https://nianxxaigc.nianxx.cn`; the
currently observed revision still fails authenticated `/create` with an RSC
error. Repository revision `b14b4fc` removes that request-time frontend seam:
Next.js now emits static `out/` files served by unprivileged Nginx, the browser
loads identity from same-origin Go `/api/auth/me`, and Ingress routes all
`/api`, `/uploads`, and `/generated-results` traffic directly to Go. Web has no
runtime ConfigMap, Secret, database credential, or internal Go URL. The new
images/manifests have not yet been deployed, and exact live Service ownership
still requires cluster evidence.
The first production deployment is live at `https://nianxxaigc.nianxx.cn`.
After a redeployment, the observed Go API process fails during super-admin
bootstrap because its RDS endpoint refuses a TLS negotiation. Repository
revision `ed97814` retains the static Web + Go-only runtime boundary from
`b14b4fc` and forces every maintained PostgreSQL client to plaintext
(`sslmode=disable`), without requiring an Alibaba Cloud RDS configuration
change. The fixed Go image and updated ACK manifest have not yet been verified
in the live cluster, and the exact deployed image revisions still require
cluster evidence.
## Recently Completed
- 2026-08-12: Replaced the Supabase/PostgREST runtime path with a server-only `pg` adapter across data, account, and billing stores.
- 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, verified-CA TLS, database readiness, and ACK Web/Worker/migration manifests.
- 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, database readiness, and ACK Web/Worker/migration manifests; the original verified-CA transport decision was amended on 2026-08-16.
- 2026-08-12: Accepted and documented the Next.js frontend plus Go backend target, migration contracts, and acceptance criteria.
- 2026-08-14: Implemented and merged the Go backend (foundation, identity, administration, assets, billing, usage, jobs/providers/webhooks/worker loop, public and compatibility HTTP surfaces) with language-neutral contract fixtures and migration 0002.
- 2026-08-14: Reconciled canonical architecture, decision, history, commitment, and positioning memory with the merged Go implementation (task `20260814-go-memory-reconcile-7f2a9c41`).
@@ -47,23 +52,30 @@ still requires cluster evidence.
Worker/migration manifests, and added static/deployment regressions (task
`20260816-static-frontend-go-api-4f8c2a7d`, commit `b14b4fc`; not yet
deployed).
- 2026-08-16: Diagnosed the Go bootstrap failure as a TLS negotiation against
an endpoint that refuses TLS, then changed Go and retained Node PostgreSQL
clients to enforce plaintext, removed the obsolete CA deployment dependency,
and added real wire-protocol regression coverage (task
`20260816-disable-postgres-tls-d4a89c12`, commit `ed97814`; live rollout not
yet verified).
## In Progress
- Build, publish, and deploy immutable Web and Go images for `b14b4fc`, then
verify the static Web + Go-only runtime boundary in the live ACK cluster.
- Build, publish, and deploy immutable Web and Go images containing `ed97814`,
then verify PostgreSQL readiness/bootstrap and the static Web + Go-only
runtime boundary in the live ACK cluster.
## Next Recommended Steps
1. Build and smoke the pinned unprivileged Nginx Web image in CI or another
host with Docker, then publish Web and Go images under new immutable tags or
digests.
1. Build and smoke Web and Go images from `ed97814` in CI or another host with
Docker, then publish them under new immutable tags or digests.
2. Create/verify the `zhinian` Namespace, run target-cluster server-side dry
runs, apply the production Go-owned Secret and six checked-in resource
manifests (not `secrets.example.yaml`), and confirm live Ingress/Service
ownership from cluster state.
3. Smoke anonymous login, authenticated `/create?mode=video`, logout, and each
admin role; verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
3. Confirm Go bootstrap completes without an SSLRequest, then smoke anonymous
login, authenticated `/create?mode=video`, logout, and each admin role;
verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
4. Configure OSS or another shared/persistent store before any Go Pod
replacement that must preserve current local uploads/generated results.
5. Continue real RDS/provider/Webhook validation and confirm the public
@@ -71,7 +83,10 @@ still requires cluster evidence.
## Open Questions / Blockers
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
- Canonical memory does not yet record the live RDS PostgreSQL version,
connection budget, exact internal endpoint, database roles, effective VPC /
security-group / allowlist controls, or confirmed request-path Service
ownership.
- Real OSS bucket/credential configuration is still needed for shared asset storage.
- Public `/api/v1` support promises for external consumers need explicit confirmation.
- The static Web Docker image has not been built or container-smoked in this
@@ -79,6 +94,9 @@ still requires cluster evidence.
## Risky Areas
- PostgreSQL transport is intentionally unencrypted. The RDS connection must
remain on the private network and be constrained by VPC, security-group, and
allowlist controls; those live controls still require recorded validation.
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
- Go currently stores local uploads/results on `emptyDir` when OSS is absent;
Pod replacement or rolling update loses them, not only horizontal scaling.
+2
View File
@@ -20,6 +20,8 @@
| 2026-08-16 | `20260816-integrate-auth-ssr-9d7e4c2a` | Serialized integration of source commit `498c2fa` and canonical reconciliation for the authenticated SSR-to-Go identity bridge. No live deployment was performed. | Current state, task history, system overview, module map, data flow, commitments |
| 2026-08-16 | `20260816-static-frontend-go-api-4f8c2a7d` | Revision `b14b4fc` replaces production SSR/Middleware/Next APIs with a static export on unprivileged Nginx; browser runtime traffic goes directly to the Go-owned same-origin API/file surface. | Task record, proposal, application/deployment docs |
| 2026-08-16 | `20260816-integrate-static-frontend-2c7e91b4` | Serialized canonical promotion of the user-approved static Web + Go-only runtime architecture. | Positioning, success criteria, ADR-003, decision index, current state, architecture, domain rules, commitments, task history |
| 2026-08-16 | `20260816-disable-postgres-tls-d4a89c12` | Revision `ed97814` forces plaintext PostgreSQL in Go and retained Node clients, removes the obsolete RDS CA deployment dependency, and adds wire-level regression coverage for an endpoint that refuses TLS. No live deployment was performed. | Task record, application/deployment docs |
| 2026-08-16 | `20260816-integrate-plaintext-postgres-6e3b1a90` | Serialized canonical promotion of the user-approved plaintext PostgreSQL transport decision and its private-network security boundary. | Positioning, decision index, current state, architecture, commitments, task history |
## Notes
@@ -0,0 +1,66 @@
# Task: Integrate plaintext PostgreSQL decision
## Identity
- Task ID: 20260816-integrate-plaintext-postgres-6e3b1a90
- Mode: Integration
- Branch: main
- Worktree: D:\Datas\OthersProjects\NianAIGC
- Base commit: ed978142ebbea4ed8e4d3743f9ece42a334c6ea5
- Owner: codex
- Status: Ready for Integration
## Scope
- Promote the completed plaintext PostgreSQL implementation and decision into
canonical project memory.
- Reconcile stale verified-CA/TLS wording in current architecture, deployment
commitments, and current-state guidance.
- Do not change application code, Alibaba Cloud configuration, or historical
task/proposal records.
## Intent And Constraints
- The user explicitly requires a code-only correction and no Alibaba Cloud RDS
configuration change.
- PostgreSQL clients must enforce plaintext even when an existing Secret still
contains TLS query parameters.
- Canonical memory must disclose that transport confidentiality now depends on
the internal endpoint plus VPC, security-group, and allowlist isolation.
- Source feature task `20260816-disable-postgres-tls-d4a89c12` and commit
`ed97814` are read-only inputs to this integration task.
## Outcome
- Canonical `RDS-001` now records the plaintext transport amendment and its
required private-network isolation boundary.
- Current state, architecture, positioning, commitments, and history now point
rollout at `ed97814` and no longer describe verified-CA TLS as the target.
- No application code, cloud configuration, or deployment state was changed by
this integration task.
## Verification
- Source implementation final `sol_reviewer`: PASS for Standards and Spec after
both identified gaps were fixed.
- `check_project_docs.py --target .`: PASS.
- `check_doc_drift.py --target . --task-id
20260816-integrate-plaintext-postgres-6e3b1a90`: PASS; only this integration
task record and authorized canonical documents changed.
- `git diff --check`: PASS (line-ending conversion warnings only).
- First read-only integration review: FAIL on one stale TLS/CA maintenance item
and this record's pending verification state; both findings were remediated.
- Final read-only integration re-review: PASS; both initial documentation
findings are closed and no residual Standards or Spec blocker remains.
## Follow-ups
- Build, publish, and deploy immutable Web and Go images from `ed97814`.
- Apply the checked-in Go manifest without the obsolete CA mount and verify
bootstrap/readiness against the real internal RDS endpoint.
- Record effective VPC, security-group, allowlist, database-role, and live
request-path ownership evidence without exposing credentials.
## Promotion Candidates
- None; this integration task directly updates canonical memory.