docs: integrate static frontend architecture
This commit is contained in:
1 parent
b14b4fced7
commit
bb50d06d1d
13 files changed
+243
-82
No files matched your search
@@ -14,10 +14,21 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
- `ff055c9` (config-driven super-admin bootstrap in the Go backend, task `20260814-go-bootstrap-admin-6e2b7d9c`)
|
||||
- `4a8f2d5` (Go workload deployment artifacts and split Ingress routing, task `20260814-go-deploy-artifacts-2a5f8e1d`)
|
||||
- `498c2fa` (authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task `20260816-fix-authenticated-ssr-6c3f8a21`)
|
||||
- `b14b4fc` (pure static Next.js export, browser-to-Go auth, Go-only runtime API
|
||||
ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task
|
||||
`20260816-static-frontend-go-api-4f8c2a7d`)
|
||||
|
||||
## Current Focus
|
||||
|
||||
The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its deployed revision does not yet include `498c2fa`: authenticated `/create` currently triggers a production RSC error, while the public `/api/ready` endpoint has been observed returning HTTP 200 with PostgreSQL configured. The repository now contains the authenticated Next.js SSR-to-Go identity bridge in `lib/server/auth/current-user.ts`; when `ZHINIAN_GO_INTERNAL_BASE_URL` is configured it refreshes identity through internal Go `/api/auth/me`, and without that environment variable local Next.js full-stack development retains the direct-store path. Current work is the production repair rollout: publish the updated Web image and ACK configuration, then complete an authenticated `/create` smoke test. The exact live Service owner for each request path remains unverified until confirmed from cluster configuration or logs.
|
||||
The first production deployment is live at `https://nianxxaigc.nianxx.cn`; the
|
||||
currently observed revision still fails authenticated `/create` with an RSC
|
||||
error. Repository revision `b14b4fc` removes that request-time frontend seam:
|
||||
Next.js now emits static `out/` files served by unprivileged Nginx, the browser
|
||||
loads identity from same-origin Go `/api/auth/me`, and Ingress routes all
|
||||
`/api`, `/uploads`, and `/generated-results` traffic directly to Go. Web has no
|
||||
runtime ConfigMap, Secret, database credential, or internal Go URL. The new
|
||||
images/manifests have not yet been deployed, and exact live Service ownership
|
||||
still requires cluster evidence.
|
||||
|
||||
## Recently Completed
|
||||
|
||||
@@ -30,30 +41,49 @@ The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its d
|
||||
- 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task `20260814-deploy-model-reconcile-9b4c2e7f`).
|
||||
- 2026-08-14: Built the Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task `20260814-go-deploy-artifacts-2a5f8e1d`).
|
||||
- 2026-08-16: Implemented authenticated production SSR identity refresh through Go `/api/auth/me`, forwarding only enumerated `zhinian_session` chunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task `20260816-fix-authenticated-ssr-6c3f8a21`, commit `498c2fa`; not yet deployed).
|
||||
- 2026-08-16: Replaced production SSR/Middleware/Next Route Handlers with a
|
||||
static export and browser auth Module, made Go the only runtime API owner,
|
||||
replaced the Web runner with unprivileged Nginx, removed deprecated Node
|
||||
Worker/migration manifests, and added static/deployment regressions (task
|
||||
`20260816-static-frontend-go-api-4f8c2a7d`, commit `b14b4fc`; not yet
|
||||
deployed).
|
||||
|
||||
## In Progress
|
||||
|
||||
- Release `498c2fa` to the existing production environment and verify authenticated `/create` SSR; the live revision still exhibits the RSC failure.
|
||||
- Build, publish, and deploy immutable Web and Go images for `b14b4fc`, then
|
||||
verify the static Web + Go-only runtime boundary in the live ACK cluster.
|
||||
|
||||
## Next Recommended Steps
|
||||
|
||||
1. Build and push the updated Web image containing `498c2fa`, and validate the updated ACK configuration with a server-side dry run on the production cluster.
|
||||
2. Apply the updated Web image and ACK configuration without assuming the current live Service ownership beyond what cluster configuration and logs confirm.
|
||||
3. Smoke-test an authenticated request to `/create`, confirming the production RSC error is resolved and SSR refreshes the user through internal Go `/api/auth/me`.
|
||||
4. Recheck public `/api/ready` after the rollout; it currently returns HTTP 200 with PostgreSQL configured.
|
||||
5. Continue real RDS/OSS/provider/Webhook validation and confirm the public `/api/v1` compatibility promise for external consumers.
|
||||
1. Build and smoke the pinned unprivileged Nginx Web image in CI or another
|
||||
host with Docker, then publish Web and Go images under new immutable tags or
|
||||
digests.
|
||||
2. Create/verify the `zhinian` Namespace, run target-cluster server-side dry
|
||||
runs, apply the production Go-owned Secret and six checked-in resource
|
||||
manifests (not `secrets.example.yaml`), and confirm live Ingress/Service
|
||||
ownership from cluster state.
|
||||
3. Smoke anonymous login, authenticated `/create?mode=video`, logout, and each
|
||||
admin role; verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
|
||||
4. Configure OSS or another shared/persistent store before any Go Pod
|
||||
replacement that must preserve current local uploads/generated results.
|
||||
5. Continue real RDS/provider/Webhook validation and confirm the public
|
||||
`/api/v1` compatibility promise for external consumers.
|
||||
|
||||
## Open Questions / Blockers
|
||||
|
||||
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
|
||||
- Real OSS bucket/credential configuration is still needed for shared asset storage.
|
||||
- Public `/api/v1` support promises for external consumers need explicit confirmation.
|
||||
- The static Web Docker image has not been built or container-smoked in this
|
||||
workstation because its Docker daemon is unavailable.
|
||||
|
||||
## Risky Areas
|
||||
|
||||
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
|
||||
- The current image runs as root; moving to a non-root user requires an explicit writable-path ownership design.
|
||||
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns those paths without cluster evidence.
|
||||
- Go currently stores local uploads/results on `emptyDir` when OSS is absent;
|
||||
Pod replacement or rolling update loses them, not only horizontal scaling.
|
||||
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not
|
||||
infer which live workload owns paths without cluster evidence.
|
||||
|
||||
## Last Updated
|
||||
|
||||
|
||||
@@ -18,6 +18,8 @@
|
||||
| 2026-08-14 | `20260814-go-deploy-artifacts-2a5f8e1d` | Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress, database-free Web workload, updated manifest assertions. | Task record, deployment docs, READMEs |
|
||||
| 2026-08-16 | `20260816-fix-authenticated-ssr-6c3f8a21` | Revision `498c2fa` implements authenticated SSR identity refresh through internal Go `/api/auth/me` using only enumerated session Cookie chunks; strict response validation, local direct-store behavior, and a database-free ACK Web configuration are preserved. The task performed no live deployment. | Task record |
|
||||
| 2026-08-16 | `20260816-integrate-auth-ssr-9d7e4c2a` | Serialized integration of source commit `498c2fa` and canonical reconciliation for the authenticated SSR-to-Go identity bridge. No live deployment was performed. | Current state, task history, system overview, module map, data flow, commitments |
|
||||
| 2026-08-16 | `20260816-static-frontend-go-api-4f8c2a7d` | Revision `b14b4fc` replaces production SSR/Middleware/Next APIs with a static export on unprivileged Nginx; browser runtime traffic goes directly to the Go-owned same-origin API/file surface. | Task record, proposal, application/deployment docs |
|
||||
| 2026-08-16 | `20260816-integrate-static-frontend-2c7e91b4` | Serialized canonical promotion of the user-approved static Web + Go-only runtime architecture. | Positioning, success criteria, ADR-003, decision index, current state, architecture, domain rules, commitments, task history |
|
||||
|
||||
## Notes
|
||||
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
# Task: Integrate static frontend architecture into project memory
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260816-integrate-static-frontend-2c7e91b4
|
||||
- Mode: Integration
|
||||
- Branch: codex/20260816-integrate-static-frontend-2c7e91b4
|
||||
- Worktree: D:\Datas\OthersProjects\NianAIGC-integrate-static-frontend-2c7e91b4
|
||||
- Base commit: b14b4fced70775eb50fde5b83192b72b09e3d86f
|
||||
- Owner: codex
|
||||
- Status: Ready for Integration
|
||||
|
||||
## Scope
|
||||
|
||||
- Promote the accepted static Web + Go API architecture from source task
|
||||
`20260816-static-frontend-go-api-4f8c2a7d` into canonical project memory.
|
||||
- Reconcile current state, architecture, domain language, decisions, success
|
||||
criteria, commitments, and task history with implementation commit
|
||||
`b14b4fc`.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Preserve historical task/proposal records while making canonical documents
|
||||
describe the implemented target unambiguously.
|
||||
- Record deployment as pending; do not infer live ACK routing or workload
|
||||
revisions from the public endpoint.
|
||||
- Keep Go authorization authoritative and record client guards as UX only.
|
||||
- Preserve the one-replica Go constraint until file storage is shared.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Canonical memory now describes a statically exported Next.js frontend served
|
||||
by unprivileged Nginx, with all runtime API, file, authentication,
|
||||
authorization, database, and WorkerLoop responsibilities in Go.
|
||||
- ADR-003, DEP-001, module/data-flow documentation, domain terminology,
|
||||
commitments, and current-state rollout guidance are aligned with `b14b4fc`.
|
||||
- The deployment gap is explicit: immutable image publication, target-cluster
|
||||
validation, and live authentication/file smoke tests remain outstanding.
|
||||
|
||||
## Verification
|
||||
|
||||
- `check_project_docs.py`: PASS.
|
||||
- `check_doc_drift.py --task-id 20260816-integrate-static-frontend-2c7e91b4`:
|
||||
PASS.
|
||||
- `git diff --check`: PASS.
|
||||
- Read-only `sol_reviewer` verdict: PASS after resolving the two identified
|
||||
documentation inconsistencies.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Publish immutable Web and Go image tags/digests, update ACK manifests, and
|
||||
run server-side dry-run before rollout.
|
||||
- Verify login, `/api/auth/me`, role boundaries, deep links, file routes, and
|
||||
health/readiness probes against the deployed revision.
|
||||
- Configure OSS/shared storage before Go Pod replacement or horizontal scale
|
||||
if uploads and generated results must persist.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None; canonical promotion is applied directly by this integration task.
|
||||
Reference in new issue
Block a user