simplify production database configuration

This commit is contained in:
brother7 committed 2026-08-16 12:40:43 +08:00
1 parent 8cb8b5e463
commit b26f9679ab
17 files changed
+199 -234

No files matched your search

@@ -0,0 +1,71 @@
# Task: Simplify production database and deployment environment configuration
## Identity
- Task ID: 20260816-simplify-prod-env-8a4c
- Mode: Feature
- Branch: codex/20260816-simplify-prod-env-8a4c-simplify-prod-env
- Worktree: D:\Datas\OthersProjects\NianAIGC-simplify-prod-env-8a4c
- Base commit: 8cb8b5e463b752230fc675f05de3d910f8c90332
- Owner: codex
- Status: Ready for Integration
## Scope
- Simplify PostgreSQL connection configuration so `DATABASE_URL` is the only
database connection setting; allow `sslmode` and optional `sslrootcert` in
that URL while retaining full certificate verification by default.
- Remove non-essential production ACK environment and Secret injections while
retaining the Go API, Next session, bootstrap, RDS CA mount, and runtime
storage settings required by the first deployment.
- Synchronize Go/Node clients, ACK checks, deployment documentation, README
references, and configuration tests.
## Intent And Constraints
- Do not weaken TLS verification or introduce `InsecureSkipVerify`.
- Keep local JSON development behavior and existing database pool defaults.
- Preserve the existing split topology: Next.js serves pages, Go owns the
database and embedded WorkerLoop.
- Feature mode may update task-scoped code/deployment/docs, but not canonical
`.project-docs` memory.
## Outcome
- Completed the single-variable database contract. Go, the legacy TypeScript
adapter, and migration scripts now read TLS settings from `DATABASE_URL`;
production defaults to `sslmode=verify-full`, and `sslrootcert` is optional
in the URL when the RDS CA is mounted. Separate
`DATABASE_SSL_MODE`/`DATABASE_CA_CERT_PATH` environment variables are no
longer consumed.
- Reduced ACK runtime configuration to startup essentials, added the missing
`GO_BACKEND_HOST=0.0.0.0`, removed unused provider/webhook/API-key/legacy
worker Secret injections, and retained the CA Secret as a file mount rather
than an environment variable.
- Updated `.env.example`, deployment docs, READMEs, ACK assertions, and
database configuration tests.
## Verification
- `go test ./...` passed in `backend/`.
- `go test ./internal/postgres` passed after the final TLS assertion update.
- `npm run deploy:check` passed (9 ACK manifests).
- `node --check scripts/postgres-client.mjs` passed.
- `node --check scripts/check-ack-manifests.mjs` passed.
- `git diff --check` passed; only Git line-ending warnings were reported.
- Full Vitest/Next typecheck was not run because this isolated worktree has no
`node_modules` installation.
## Follow-ups
- Replace all ACK placeholders, especially the RDS CA Secret and the
`DATABASE_URL` values. For strict RDS verification, include
`?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem` in both the Go and
migration connection URLs.
- Add provider/OSS/API-key/Webhook Secret references only when those optional
capabilities are enabled.
## Promotion Candidates
- None. The deployment simplification is task-scoped; canonical architecture
already describes the same two-workload production topology.