refactor: serve static frontend with Go APIs

This commit is contained in:
2026-08-16 20:47:45 +08:00
parent 763d2f0648
commit b14b4fced7
101 changed files with 963 additions and 3928 deletions

View File

@@ -1,15 +1,3 @@
apiVersion: v1
kind: ConfigMap
metadata:
name: zhinian-runtime
namespace: zhinian
data:
NODE_ENV: production
PORT: "3000"
ZHINIAN_AUTH_REQUIRED: "1"
ZHINIAN_PUBLIC_BASE_URL: https://REPLACE_WITH_PUBLIC_HOST
ZHINIAN_GO_INTERNAL_BASE_URL: http://zhinian-go-api:8080
---
# Go API runtime settings. Provider endpoints/models use code defaults unless
# optional provider/OSS credentials are added to the Deployment.
apiVersion: v1

View File

@@ -45,12 +45,12 @@ spec:
secretKeyRef:
name: zhinian-go-db
key: DATABASE_URL
# The session secret must be the same value Next.js uses so the
# frontend middleware and the Go backend verify the same cookies.
# Go alone creates and verifies the browser session cookie. The
# static Web workload must never receive this signing secret.
- name: ZHINIAN_AUTH_SESSION_SECRET
valueFrom:
secretKeyRef:
name: zhinian-web-auth
name: zhinian-go-auth
key: ZHINIAN_AUTH_SESSION_SECRET
- name: ZHINIAN_BOOTSTRAP_ADMIN_PHONE
valueFrom:

View File

@@ -43,7 +43,7 @@ spec:
name: zhinian-go-api
port:
number: 8080
# Pages and static assets stay with Next.js.
# Exported pages and static assets stay with the stateless Web Nginx.
- path: /
pathType: Prefix
backend:

View File

@@ -1,60 +0,0 @@
# DEPRECATED (2026-08-14): the initial production schema is executed manually
# from database/migrations/*.sql plus application-role grants. This Job is not
# part of the first-deployment path; keep the manifest only as an optional
# automation reference.
apiVersion: batch/v1
kind: Job
metadata:
name: zhinian-db-migrate
namespace: zhinian
spec:
backoffLimit: 2
ttlSecondsAfterFinished: 86400
template:
metadata:
labels:
app.kubernetes.io/name: zhinian
app.kubernetes.io/component: database-migration
spec:
restartPolicy: Never
automountServiceAccountToken: false
securityContext:
seccompProfile:
type: RuntimeDefault
containers:
- name: migrate
image: REGISTRY/PROJECT/zhinian-aigc:REPLACE_TAG
imagePullPolicy: IfNotPresent
command: ["node", "scripts/migrate-postgres.mjs"]
env:
- name: NODE_ENV
value: production
- name: ZHINIAN_DATA_BACKEND
value: postgres
# Must match the username in zhinian-go-db/DATABASE_URL.
- name: DATABASE_APP_ROLE
value: REPLACE_WITH_RDS_APP_ROLE
- name: DATABASE_URL
valueFrom:
secretKeyRef:
name: zhinian-migration-db
key: DATABASE_URL
volumeMounts:
- name: rds-ca
mountPath: /etc/zhinian/rds
readOnly: true
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 512Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
volumes:
- name: rds-ca
secret:
secretName: zhinian-rds-ca

View File

@@ -25,12 +25,12 @@ stringData:
apiVersion: v1
kind: Secret
metadata:
name: zhinian-web-auth
name: zhinian-go-auth
namespace: zhinian
type: Opaque
stringData:
# Shared by the Next.js middleware and the Go backend so both verify the
# same session cookies. Keep identical across workloads.
# Go is the sole owner of session creation and verification. Static Web never
# receives this signing secret.
ZHINIAN_AUTH_SESSION_SECRET: REPLACE_WITH_A_DIFFERENT_LONG_RANDOM_VALUE
---
apiVersion: v1

View File

@@ -1,16 +1,11 @@
# Next.js frontend workload for the first production deployment: serves pages,
# static assets, and SSR only. All /api, /uploads, and /generated-results
# traffic is routed to zhinian-go-api by the Ingress, so this workload holds no
# RDS credentials and needs only the shared session secret for local cookie
# verification in the middleware.
# Stateless static frontend. Nginx serves the exported Next.js files only; all
# /api, /uploads, and /generated-results traffic belongs to zhinian-go-api.
apiVersion: apps/v1
kind: Deployment
metadata:
name: zhinian-web
namespace: zhinian
spec:
# Keep one replica until uploaded/generated files are stored in OSS or another
# shared object store. PostgreSQL alone does not make local runtime files shared.
replicas: 1
strategy:
type: RollingUpdate
@@ -29,6 +24,11 @@ spec:
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 101
runAsGroup: 101
fsGroup: 101
fsGroupChangePolicy: OnRootMismatch
seccompProfile:
type: RuntimeDefault
containers:
@@ -38,47 +38,41 @@ spec:
ports:
- name: http
containerPort: 3000
envFrom:
- configMapRef:
name: zhinian-runtime
env:
# The session secret must be the same value the Go backend uses so
# the frontend middleware and the Go backend verify the same cookies.
- name: ZHINIAN_AUTH_SESSION_SECRET
valueFrom:
secretKeyRef:
name: zhinian-web-auth
key: ZHINIAN_AUTH_SESSION_SECRET
startupProbe:
httpGet:
path: /api/health
path: /healthz
port: http
periodSeconds: 5
failureThreshold: 24
readinessProbe:
httpGet:
path: /api/health
path: /healthz
port: http
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
livenessProbe:
httpGet:
path: /api/health
path: /healthz
port: http
periodSeconds: 20
timeoutSeconds: 3
failureThreshold: 3
resources:
requests:
cpu: 250m
memory: 512Mi
cpu: 25m
memory: 32Mi
limits:
cpu: "1"
memory: 1Gi
cpu: 250m
memory: 128Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
# The current image runs as root. Add a fixed non-root image user and
# verify /app/.runtime permissions before enabling runAsNonRoot.
volumeMounts:
- name: nginx-tmp
mountPath: /tmp
volumes:
- name: nginx-tmp
emptyDir: {}

View File

@@ -1,52 +0,0 @@
# DEPRECATED (2026-08-14): production deploys the Go API workload with the
# embedded WorkerLoop (ZHINIAN_GO_EMBEDDED_WORKER=true). The Node Worker is
# local-development only; do not apply this manifest in production.
apiVersion: apps/v1
kind: Deployment
metadata:
name: zhinian-worker
namespace: zhinian
spec:
replicas: 1
selector:
matchLabels:
app.kubernetes.io/name: zhinian
app.kubernetes.io/component: worker
template:
metadata:
labels:
app.kubernetes.io/name: zhinian
app.kubernetes.io/component: worker
spec:
automountServiceAccountToken: false
securityContext:
seccompProfile:
type: RuntimeDefault
containers:
- name: worker
image: REGISTRY/PROJECT/zhinian-aigc:REPLACE_TAG
imagePullPolicy: IfNotPresent
command: ["node", "scripts/worker.mjs"]
env:
- name: NODE_ENV
value: production
- name: ZHINIAN_WORKER_BASE_URL
value: http://zhinian-web:3000
- name: ZHINIAN_WORKER_REQUEST_TIMEOUT_MS
value: "120000"
- name: ZHINIAN_INTERNAL_WORKER_TOKEN
valueFrom:
secretKeyRef:
name: zhinian-worker-auth
key: ZHINIAN_INTERNAL_WORKER_TOKEN
resources:
requests:
cpu: 100m
memory: 128Mi
limits:
cpu: 500m
memory: 256Mi
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]