simplify production database configuration

This commit is contained in:
brother7 committed 2026-08-16 12:40:43 +08:00
1 parent 8cb8b5e463
commit b26f9679ab
17 files changed
+199 -234

No files matched your search

+8 -49
View File
@@ -1,15 +1,16 @@
# Example only. Replace every placeholder and keep the populated file out of Git.
# Secrets marked "(local development only)" are not referenced by the first
# production deployment; keep or drop them as your local workflow requires.
# Provider, OSS, public API, and webhook secrets are optional add-ons and are
# intentionally not injected by the minimal production Deployment.
apiVersion: v1
kind: Secret
metadata:
name: zhinian-web-db
name: zhinian-rds-ca
namespace: zhinian
type: Opaque
stringData:
# Local development only: the production Web workload holds no RDS credentials.
DATABASE_URL: postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE
# Public CA certificate for the RDS endpoint used in DATABASE_URL.
ca.pem: |
REPLACE_WITH_RDS_CA_PEM
---
apiVersion: v1
kind: Secret
@@ -19,17 +20,7 @@ metadata:
type: Opaque
stringData:
# Manual schema execution only: run database/migrations/*.sql with this role.
DATABASE_URL: postgresql://MIGRATION_USER:MIGRATION_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE
---
apiVersion: v1
kind: Secret
metadata:
name: zhinian-worker-auth
namespace: zhinian
type: Opaque
stringData:
# Local development only: the Node Worker is not deployed in production.
ZHINIAN_INTERNAL_WORKER_TOKEN: REPLACE_WITH_A_LONG_RANDOM_VALUE
DATABASE_URL: "postgresql://MIGRATION_USER:MIGRATION_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem"
---
apiVersion: v1
kind: Secret
@@ -50,7 +41,7 @@ metadata:
type: Opaque
stringData:
# Application role (least privilege): grants applied manually after the SQL.
DATABASE_URL: postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE
DATABASE_URL: "postgresql://APP_USER:APP_PASSWORD@RDS_INTERNAL_HOST:5432/APP_DATABASE?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem"
---
apiVersion: v1
kind: Secret
@@ -63,35 +54,3 @@ stringData:
# administrator exists. Password must be at least 8 characters.
ZHINIAN_BOOTSTRAP_ADMIN_PHONE: REPLACE_WITH_ADMIN_PHONE
ZHINIAN_BOOTSTRAP_ADMIN_PASSWORD: REPLACE_WITH_STRONG_PASSWORD
ZHINIAN_BOOTSTRAP_ADMIN_NAME: 平台超级管理员
---
apiVersion: v1
kind: Secret
metadata:
name: zhinian-go-providers
namespace: zhinian
type: Opaque
stringData:
# Provider credentials. Delete keys for providers you do not use; the Go
# workload tolerates missing optional keys and fails closed when an enabled
# engine has no credentials.
VOLCENGINE_ACCESS_KEY_ID: REPLACE_OR_REMOVE
VOLCENGINE_SECRET_ACCESS_KEY: REPLACE_OR_REMOVE
JIMENG_IMAGE_GENERATE_46_REQ_KEY: REPLACE_OR_REMOVE
EVOLINK_API_KEY: REPLACE_OR_REMOVE
SEEDANCE_API_KEY: REPLACE_OR_REMOVE
BAILIAN_API_KEY: REPLACE_OR_REMOVE
DASHSCOPE_API_KEY: REPLACE_OR_REMOVE
ALI_OSS_ACCESS_KEY_ID: REPLACE_OR_REMOVE
ALI_OSS_ACCESS_KEY_SECRET: REPLACE_OR_REMOVE
---
apiVersion: v1
kind: Secret
metadata:
name: zhinian-go-secrets
namespace: zhinian
type: Opaque
stringData:
ZHINIAN_WEBHOOK_SECRET: REPLACE_WITH_A_LONG_RANDOM_VALUE
ZHINIAN_API_KEYS: REPLACE_WITH_PUBLIC_API_KEYS
ZHINIAN_INTERNAL_WORKER_TOKEN: REPLACE_OR_REMOVE