docs: integrate static frontend architecture

This commit is contained in:
brother7 committed 2026-08-16 21:02:42 +08:00
1 parent b14b4fced7
commit bb50d06d1d
13 files changed
+243 -82

No files matched your search

+39 -9
View File
@@ -14,10 +14,21 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
- `ff055c9` (config-driven super-admin bootstrap in the Go backend, task `20260814-go-bootstrap-admin-6e2b7d9c`)
- `4a8f2d5` (Go workload deployment artifacts and split Ingress routing, task `20260814-go-deploy-artifacts-2a5f8e1d`)
- `498c2fa` (authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task `20260816-fix-authenticated-ssr-6c3f8a21`)
- `b14b4fc` (pure static Next.js export, browser-to-Go auth, Go-only runtime API
ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task
`20260816-static-frontend-go-api-4f8c2a7d`)
## Current Focus
The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its deployed revision does not yet include `498c2fa`: authenticated `/create` currently triggers a production RSC error, while the public `/api/ready` endpoint has been observed returning HTTP 200 with PostgreSQL configured. The repository now contains the authenticated Next.js SSR-to-Go identity bridge in `lib/server/auth/current-user.ts`; when `ZHINIAN_GO_INTERNAL_BASE_URL` is configured it refreshes identity through internal Go `/api/auth/me`, and without that environment variable local Next.js full-stack development retains the direct-store path. Current work is the production repair rollout: publish the updated Web image and ACK configuration, then complete an authenticated `/create` smoke test. The exact live Service owner for each request path remains unverified until confirmed from cluster configuration or logs.
The first production deployment is live at `https://nianxxaigc.nianxx.cn`; the
currently observed revision still fails authenticated `/create` with an RSC
error. Repository revision `b14b4fc` removes that request-time frontend seam:
Next.js now emits static `out/` files served by unprivileged Nginx, the browser
loads identity from same-origin Go `/api/auth/me`, and Ingress routes all
`/api`, `/uploads`, and `/generated-results` traffic directly to Go. Web has no
runtime ConfigMap, Secret, database credential, or internal Go URL. The new
images/manifests have not yet been deployed, and exact live Service ownership
still requires cluster evidence.
## Recently Completed
@@ -30,30 +41,49 @@ The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its d
- 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task `20260814-deploy-model-reconcile-9b4c2e7f`).
- 2026-08-14: Built the Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task `20260814-go-deploy-artifacts-2a5f8e1d`).
- 2026-08-16: Implemented authenticated production SSR identity refresh through Go `/api/auth/me`, forwarding only enumerated `zhinian_session` chunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task `20260816-fix-authenticated-ssr-6c3f8a21`, commit `498c2fa`; not yet deployed).
- 2026-08-16: Replaced production SSR/Middleware/Next Route Handlers with a
static export and browser auth Module, made Go the only runtime API owner,
replaced the Web runner with unprivileged Nginx, removed deprecated Node
Worker/migration manifests, and added static/deployment regressions (task
`20260816-static-frontend-go-api-4f8c2a7d`, commit `b14b4fc`; not yet
deployed).
## In Progress
- Release `498c2fa` to the existing production environment and verify authenticated `/create` SSR; the live revision still exhibits the RSC failure.
- Build, publish, and deploy immutable Web and Go images for `b14b4fc`, then
verify the static Web + Go-only runtime boundary in the live ACK cluster.
## Next Recommended Steps
1. Build and push the updated Web image containing `498c2fa`, and validate the updated ACK configuration with a server-side dry run on the production cluster.
2. Apply the updated Web image and ACK configuration without assuming the current live Service ownership beyond what cluster configuration and logs confirm.
3. Smoke-test an authenticated request to `/create`, confirming the production RSC error is resolved and SSR refreshes the user through internal Go `/api/auth/me`.
4. Recheck public `/api/ready` after the rollout; it currently returns HTTP 200 with PostgreSQL configured.
5. Continue real RDS/OSS/provider/Webhook validation and confirm the public `/api/v1` compatibility promise for external consumers.
1. Build and smoke the pinned unprivileged Nginx Web image in CI or another
host with Docker, then publish Web and Go images under new immutable tags or
digests.
2. Create/verify the `zhinian` Namespace, run target-cluster server-side dry
runs, apply the production Go-owned Secret and six checked-in resource
manifests (not `secrets.example.yaml`), and confirm live Ingress/Service
ownership from cluster state.
3. Smoke anonymous login, authenticated `/create?mode=video`, logout, and each
admin role; verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
4. Configure OSS or another shared/persistent store before any Go Pod
replacement that must preserve current local uploads/generated results.
5. Continue real RDS/provider/Webhook validation and confirm the public
`/api/v1` compatibility promise for external consumers.
## Open Questions / Blockers
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
- Real OSS bucket/credential configuration is still needed for shared asset storage.
- Public `/api/v1` support promises for external consumers need explicit confirmation.
- The static Web Docker image has not been built or container-smoked in this
workstation because its Docker daemon is unavailable.
## Risky Areas
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
- The current image runs as root; moving to a non-root user requires an explicit writable-path ownership design.
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns those paths without cluster evidence.
- Go currently stores local uploads/results on `emptyDir` when OSS is absent;
Pod replacement or rolling update loses them, not only horizontal scaling.
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not
infer which live workload owns paths without cluster evidence.
## Last Updated
+2
View File
@@ -18,6 +18,8 @@
| 2026-08-14 | `20260814-go-deploy-artifacts-2a5f8e1d` | Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress, database-free Web workload, updated manifest assertions. | Task record, deployment docs, READMEs |
| 2026-08-16 | `20260816-fix-authenticated-ssr-6c3f8a21` | Revision `498c2fa` implements authenticated SSR identity refresh through internal Go `/api/auth/me` using only enumerated session Cookie chunks; strict response validation, local direct-store behavior, and a database-free ACK Web configuration are preserved. The task performed no live deployment. | Task record |
| 2026-08-16 | `20260816-integrate-auth-ssr-9d7e4c2a` | Serialized integration of source commit `498c2fa` and canonical reconciliation for the authenticated SSR-to-Go identity bridge. No live deployment was performed. | Current state, task history, system overview, module map, data flow, commitments |
| 2026-08-16 | `20260816-static-frontend-go-api-4f8c2a7d` | Revision `b14b4fc` replaces production SSR/Middleware/Next APIs with a static export on unprivileged Nginx; browser runtime traffic goes directly to the Go-owned same-origin API/file surface. | Task record, proposal, application/deployment docs |
| 2026-08-16 | `20260816-integrate-static-frontend-2c7e91b4` | Serialized canonical promotion of the user-approved static Web + Go-only runtime architecture. | Positioning, success criteria, ADR-003, decision index, current state, architecture, domain rules, commitments, task history |
## Notes
@@ -0,0 +1,60 @@
# Task: Integrate static frontend architecture into project memory
## Identity
- Task ID: 20260816-integrate-static-frontend-2c7e91b4
- Mode: Integration
- Branch: codex/20260816-integrate-static-frontend-2c7e91b4
- Worktree: D:\Datas\OthersProjects\NianAIGC-integrate-static-frontend-2c7e91b4
- Base commit: b14b4fced70775eb50fde5b83192b72b09e3d86f
- Owner: codex
- Status: Ready for Integration
## Scope
- Promote the accepted static Web + Go API architecture from source task
`20260816-static-frontend-go-api-4f8c2a7d` into canonical project memory.
- Reconcile current state, architecture, domain language, decisions, success
criteria, commitments, and task history with implementation commit
`b14b4fc`.
## Intent And Constraints
- Preserve historical task/proposal records while making canonical documents
describe the implemented target unambiguously.
- Record deployment as pending; do not infer live ACK routing or workload
revisions from the public endpoint.
- Keep Go authorization authoritative and record client guards as UX only.
- Preserve the one-replica Go constraint until file storage is shared.
## Outcome
- Canonical memory now describes a statically exported Next.js frontend served
by unprivileged Nginx, with all runtime API, file, authentication,
authorization, database, and WorkerLoop responsibilities in Go.
- ADR-003, DEP-001, module/data-flow documentation, domain terminology,
commitments, and current-state rollout guidance are aligned with `b14b4fc`.
- The deployment gap is explicit: immutable image publication, target-cluster
validation, and live authentication/file smoke tests remain outstanding.
## Verification
- `check_project_docs.py`: PASS.
- `check_doc_drift.py --task-id 20260816-integrate-static-frontend-2c7e91b4`:
PASS.
- `git diff --check`: PASS.
- Read-only `sol_reviewer` verdict: PASS after resolving the two identified
documentation inconsistencies.
## Follow-ups
- Publish immutable Web and Go image tags/digests, update ACK manifests, and
run server-side dry-run before rollout.
- Verify login, `/api/auth/me`, role boundaries, deep links, file routes, and
health/readiness probes against the deployed revision.
- Configure OSS/shared storage before Go Pod replacement or horizontal scale
if uploads and generated results must persist.
## Promotion Candidates
- None; canonical promotion is applied directly by this integration task.