refactor: serve static frontend with Go APIs

This commit is contained in:
brother7 committed 2026-08-16 20:47:45 +08:00
1 parent 763d2f0648
commit b14b4fced7
101 files changed
+963 -3928

No files matched your search

+21 -27
View File
@@ -1,16 +1,11 @@
# Next.js frontend workload for the first production deployment: serves pages,
# static assets, and SSR only. All /api, /uploads, and /generated-results
# traffic is routed to zhinian-go-api by the Ingress, so this workload holds no
# RDS credentials and needs only the shared session secret for local cookie
# verification in the middleware.
# Stateless static frontend. Nginx serves the exported Next.js files only; all
# /api, /uploads, and /generated-results traffic belongs to zhinian-go-api.
apiVersion: apps/v1
kind: Deployment
metadata:
name: zhinian-web
namespace: zhinian
spec:
# Keep one replica until uploaded/generated files are stored in OSS or another
# shared object store. PostgreSQL alone does not make local runtime files shared.
replicas: 1
strategy:
type: RollingUpdate
@@ -29,6 +24,11 @@ spec:
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 101
runAsGroup: 101
fsGroup: 101
fsGroupChangePolicy: OnRootMismatch
seccompProfile:
type: RuntimeDefault
containers:
@@ -38,47 +38,41 @@ spec:
ports:
- name: http
containerPort: 3000
envFrom:
- configMapRef:
name: zhinian-runtime
env:
# The session secret must be the same value the Go backend uses so
# the frontend middleware and the Go backend verify the same cookies.
- name: ZHINIAN_AUTH_SESSION_SECRET
valueFrom:
secretKeyRef:
name: zhinian-web-auth
key: ZHINIAN_AUTH_SESSION_SECRET
startupProbe:
httpGet:
path: /api/health
path: /healthz
port: http
periodSeconds: 5
failureThreshold: 24
readinessProbe:
httpGet:
path: /api/health
path: /healthz
port: http
periodSeconds: 10
timeoutSeconds: 5
failureThreshold: 3
livenessProbe:
httpGet:
path: /api/health
path: /healthz
port: http
periodSeconds: 20
timeoutSeconds: 3
failureThreshold: 3
resources:
requests:
cpu: 250m
memory: 512Mi
cpu: 25m
memory: 32Mi
limits:
cpu: "1"
memory: 1Gi
cpu: 250m
memory: 128Mi
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
# The current image runs as root. Add a fixed non-root image user and
# verify /app/.runtime permissions before enabling runAsNonRoot.
volumeMounts:
- name: nginx-tmp
mountPath: /tmp
volumes:
- name: nginx-tmp
emptyDir: {}