docs: integrate plaintext PostgreSQL decision

This commit is contained in:
brother7 committed 2026-08-16 23:35:33 +08:00
1 parent ed978142eb
commit acd929c704
10 files changed
+146 -40

No files matched your search

+36 -18
View File
@@ -17,23 +17,28 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- `b14b4fc` (pure static Next.js export, browser-to-Go auth, Go-only runtime API
ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task
`20260816-static-frontend-go-api-4f8c2a7d`)
- `acf368b` (diagnosis of the production Go bootstrap failure against an RDS
endpoint that refuses PostgreSQL TLS)
- `ed97814` (code-enforced plaintext PostgreSQL for Go and retained Node
tooling, removal of the obsolete RDS CA deployment dependency, and protocol
regression coverage; task `20260816-disable-postgres-tls-d4a89c12`)
## Current Focus
The first production deployment is live at `https://nianxxaigc.nianxx.cn`; the
currently observed revision still fails authenticated `/create` with an RSC
error. Repository revision `b14b4fc` removes that request-time frontend seam:
Next.js now emits static `out/` files served by unprivileged Nginx, the browser
loads identity from same-origin Go `/api/auth/me`, and Ingress routes all
`/api`, `/uploads`, and `/generated-results` traffic directly to Go. Web has no
runtime ConfigMap, Secret, database credential, or internal Go URL. The new
images/manifests have not yet been deployed, and exact live Service ownership
still requires cluster evidence.
The first production deployment is live at `https://nianxxaigc.nianxx.cn`.
After a redeployment, the observed Go API process fails during super-admin
bootstrap because its RDS endpoint refuses a TLS negotiation. Repository
revision `ed97814` retains the static Web + Go-only runtime boundary from
`b14b4fc` and forces every maintained PostgreSQL client to plaintext
(`sslmode=disable`), without requiring an Alibaba Cloud RDS configuration
change. The fixed Go image and updated ACK manifest have not yet been verified
in the live cluster, and the exact deployed image revisions still require
cluster evidence.
## Recently Completed
- 2026-08-12: Replaced the Supabase/PostgREST runtime path with a server-only `pg` adapter across data, account, and billing stores.
- 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, verified-CA TLS, database readiness, and ACK Web/Worker/migration manifests.
- 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, database readiness, and ACK Web/Worker/migration manifests; the original verified-CA transport decision was amended on 2026-08-16.
- 2026-08-12: Accepted and documented the Next.js frontend plus Go backend target, migration contracts, and acceptance criteria.
- 2026-08-14: Implemented and merged the Go backend (foundation, identity, administration, assets, billing, usage, jobs/providers/webhooks/worker loop, public and compatibility HTTP surfaces) with language-neutral contract fixtures and migration 0002.
- 2026-08-14: Reconciled canonical architecture, decision, history, commitment, and positioning memory with the merged Go implementation (task `20260814-go-memory-reconcile-7f2a9c41`).
@@ -47,23 +52,30 @@ still requires cluster evidence.
Worker/migration manifests, and added static/deployment regressions (task
`20260816-static-frontend-go-api-4f8c2a7d`, commit `b14b4fc`; not yet
deployed).
- 2026-08-16: Diagnosed the Go bootstrap failure as a TLS negotiation against
an endpoint that refuses TLS, then changed Go and retained Node PostgreSQL
clients to enforce plaintext, removed the obsolete CA deployment dependency,
and added real wire-protocol regression coverage (task
`20260816-disable-postgres-tls-d4a89c12`, commit `ed97814`; live rollout not
yet verified).
## In Progress
- Build, publish, and deploy immutable Web and Go images for `b14b4fc`, then
verify the static Web + Go-only runtime boundary in the live ACK cluster.
- Build, publish, and deploy immutable Web and Go images containing `ed97814`,
then verify PostgreSQL readiness/bootstrap and the static Web + Go-only
runtime boundary in the live ACK cluster.
## Next Recommended Steps
1. Build and smoke the pinned unprivileged Nginx Web image in CI or another
host with Docker, then publish Web and Go images under new immutable tags or
digests.
1. Build and smoke Web and Go images from `ed97814` in CI or another host with
Docker, then publish them under new immutable tags or digests.
2. Create/verify the `zhinian` Namespace, run target-cluster server-side dry
runs, apply the production Go-owned Secret and six checked-in resource
manifests (not `secrets.example.yaml`), and confirm live Ingress/Service
ownership from cluster state.
3. Smoke anonymous login, authenticated `/create?mode=video`, logout, and each
admin role; verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
3. Confirm Go bootstrap completes without an SSLRequest, then smoke anonymous
login, authenticated `/create?mode=video`, logout, and each admin role;
verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
4. Configure OSS or another shared/persistent store before any Go Pod
replacement that must preserve current local uploads/generated results.
5. Continue real RDS/provider/Webhook validation and confirm the public
@@ -71,7 +83,10 @@ still requires cluster evidence.
## Open Questions / Blockers
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
- Canonical memory does not yet record the live RDS PostgreSQL version,
connection budget, exact internal endpoint, database roles, effective VPC /
security-group / allowlist controls, or confirmed request-path Service
ownership.
- Real OSS bucket/credential configuration is still needed for shared asset storage.
- Public `/api/v1` support promises for external consumers need explicit confirmation.
- The static Web Docker image has not been built or container-smoked in this
@@ -79,6 +94,9 @@ still requires cluster evidence.
## Risky Areas
- PostgreSQL transport is intentionally unencrypted. The RDS connection must
remain on the private network and be constrained by VPC, security-group, and
allowlist controls; those live controls still require recorded validation.
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
- Go currently stores local uploads/results on `emptyDir` when OSS is absent;
Pod replacement or rolling update loses them, not only horizontal scaling.