docs: integrate plaintext PostgreSQL decision
This commit is contained in:
1 parent
ed978142eb
commit
acd929c704
10 files changed
+146
-40
No files matched your search
@@ -0,0 +1,66 @@
|
||||
# Task: Integrate plaintext PostgreSQL decision
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260816-integrate-plaintext-postgres-6e3b1a90
|
||||
- Mode: Integration
|
||||
- Branch: main
|
||||
- Worktree: D:\Datas\OthersProjects\NianAIGC
|
||||
- Base commit: ed978142ebbea4ed8e4d3743f9ece42a334c6ea5
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Promote the completed plaintext PostgreSQL implementation and decision into
|
||||
canonical project memory.
|
||||
- Reconcile stale verified-CA/TLS wording in current architecture, deployment
|
||||
commitments, and current-state guidance.
|
||||
- Do not change application code, Alibaba Cloud configuration, or historical
|
||||
task/proposal records.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- The user explicitly requires a code-only correction and no Alibaba Cloud RDS
|
||||
configuration change.
|
||||
- PostgreSQL clients must enforce plaintext even when an existing Secret still
|
||||
contains TLS query parameters.
|
||||
- Canonical memory must disclose that transport confidentiality now depends on
|
||||
the internal endpoint plus VPC, security-group, and allowlist isolation.
|
||||
- Source feature task `20260816-disable-postgres-tls-d4a89c12` and commit
|
||||
`ed97814` are read-only inputs to this integration task.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Canonical `RDS-001` now records the plaintext transport amendment and its
|
||||
required private-network isolation boundary.
|
||||
- Current state, architecture, positioning, commitments, and history now point
|
||||
rollout at `ed97814` and no longer describe verified-CA TLS as the target.
|
||||
- No application code, cloud configuration, or deployment state was changed by
|
||||
this integration task.
|
||||
|
||||
## Verification
|
||||
|
||||
- Source implementation final `sol_reviewer`: PASS for Standards and Spec after
|
||||
both identified gaps were fixed.
|
||||
- `check_project_docs.py --target .`: PASS.
|
||||
- `check_doc_drift.py --target . --task-id
|
||||
20260816-integrate-plaintext-postgres-6e3b1a90`: PASS; only this integration
|
||||
task record and authorized canonical documents changed.
|
||||
- `git diff --check`: PASS (line-ending conversion warnings only).
|
||||
- First read-only integration review: FAIL on one stale TLS/CA maintenance item
|
||||
and this record's pending verification state; both findings were remediated.
|
||||
- Final read-only integration re-review: PASS; both initial documentation
|
||||
findings are closed and no residual Standards or Spec blocker remains.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Build, publish, and deploy immutable Web and Go images from `ed97814`.
|
||||
- Apply the checked-in Go manifest without the obsolete CA mount and verify
|
||||
bootstrap/readiness against the real internal RDS endpoint.
|
||||
- Record effective VPC, security-group, allowlist, database-role, and live
|
||||
request-path ownership evidence without exposing credentials.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None; this integration task directly updates canonical memory.
|
||||
Reference in new issue
Block a user