docs: integrate plaintext PostgreSQL decision

This commit is contained in:
brother7 committed 2026-08-16 23:35:33 +08:00
1 parent ed978142eb
commit acd929c704
10 files changed
+146 -40

No files matched your search

@@ -0,0 +1,66 @@
# Task: Integrate plaintext PostgreSQL decision
## Identity
- Task ID: 20260816-integrate-plaintext-postgres-6e3b1a90
- Mode: Integration
- Branch: main
- Worktree: D:\Datas\OthersProjects\NianAIGC
- Base commit: ed978142ebbea4ed8e4d3743f9ece42a334c6ea5
- Owner: codex
- Status: Ready for Integration
## Scope
- Promote the completed plaintext PostgreSQL implementation and decision into
canonical project memory.
- Reconcile stale verified-CA/TLS wording in current architecture, deployment
commitments, and current-state guidance.
- Do not change application code, Alibaba Cloud configuration, or historical
task/proposal records.
## Intent And Constraints
- The user explicitly requires a code-only correction and no Alibaba Cloud RDS
configuration change.
- PostgreSQL clients must enforce plaintext even when an existing Secret still
contains TLS query parameters.
- Canonical memory must disclose that transport confidentiality now depends on
the internal endpoint plus VPC, security-group, and allowlist isolation.
- Source feature task `20260816-disable-postgres-tls-d4a89c12` and commit
`ed97814` are read-only inputs to this integration task.
## Outcome
- Canonical `RDS-001` now records the plaintext transport amendment and its
required private-network isolation boundary.
- Current state, architecture, positioning, commitments, and history now point
rollout at `ed97814` and no longer describe verified-CA TLS as the target.
- No application code, cloud configuration, or deployment state was changed by
this integration task.
## Verification
- Source implementation final `sol_reviewer`: PASS for Standards and Spec after
both identified gaps were fixed.
- `check_project_docs.py --target .`: PASS.
- `check_doc_drift.py --target . --task-id
20260816-integrate-plaintext-postgres-6e3b1a90`: PASS; only this integration
task record and authorized canonical documents changed.
- `git diff --check`: PASS (line-ending conversion warnings only).
- First read-only integration review: FAIL on one stale TLS/CA maintenance item
and this record's pending verification state; both findings were remediated.
- Final read-only integration re-review: PASS; both initial documentation
findings are closed and no residual Standards or Spec blocker remains.
## Follow-ups
- Build, publish, and deploy immutable Web and Go images from `ed97814`.
- Apply the checked-in Go manifest without the obsolete CA mount and verify
bootstrap/readiness against the real internal RDS endpoint.
- Record effective VPC, security-group, allowlist, database-role, and live
request-path ownership evidence without exposing credentials.
## Promotion Candidates
- None; this integration task directly updates canonical memory.