docs: integrate RDS and ACK architecture memory
This commit is contained in:
1 parent
c44274f098
commit
bb004f02b3
8 files changed
+97
-19
No files matched your search
@@ -4,33 +4,37 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
|
||||
## Integrated Through
|
||||
|
||||
- {source task or merge commit}
|
||||
- `84d84ba94f136f10624700e8d34ed19fc6fe7fe7` (`20260812-rds-postgres-adapter-7f2c1a`)
|
||||
|
||||
## Current Focus
|
||||
|
||||
The project is currently focused on {current focus}.
|
||||
The application now has a production deployment path for Alibaba Cloud ACK backed by direct Alibaba Cloud RDS PostgreSQL access. Local JSON remains an explicit development/test backend.
|
||||
|
||||
## Recently Completed
|
||||
|
||||
- {YYYY-MM-DD}: {completed work summary}
|
||||
- 2026-08-12: Replaced the Supabase/PostgREST runtime path with a server-only `pg` adapter across data, account, and billing stores.
|
||||
- 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, verified-CA TLS, database readiness, and ACK Web/Worker/migration manifests.
|
||||
|
||||
## In Progress
|
||||
|
||||
- {in-progress item}
|
||||
- Production environment values and the real RDS/ACK rollout are not yet validated in this repository environment.
|
||||
|
||||
## Next Recommended Steps
|
||||
|
||||
1. {next recommended step}
|
||||
2. {next recommended step}
|
||||
1. Back up the target database; create separate migration and application roles; verify the RDS internal endpoint, VPC connectivity, whitelist, TLS mode, and CA certificate.
|
||||
2. Build and push the reviewed image, run the one-shot migration Job, confirm `/api/ready`, then roll out Web and Worker.
|
||||
3. Keep Web at one replica until generated assets are externalized to OSS or another shared object store.
|
||||
|
||||
## Open Questions / Blockers
|
||||
|
||||
- {open question or blocker}
|
||||
- Target RDS PostgreSQL version, connection budget, endpoint, TLS enforcement, CA bundle, database roles, and ACK network policy remain deployment inputs.
|
||||
|
||||
## Risky Areas
|
||||
|
||||
- {risky area}
|
||||
- Database migrations and least-privilege grants must be tested against the actual RDS instance before production cutover.
|
||||
- Web pods still own runtime files; PostgreSQL does not make local uploads/generated assets safe for horizontal Web scaling.
|
||||
- The current image runs as root; moving to a non-root user requires an explicit writable-path ownership design.
|
||||
|
||||
## Last Updated
|
||||
|
||||
{YYYY-MM-DD}
|
||||
2026-08-12
|
||||
Reference in new issue
Block a user