docs: integrate static frontend architecture
This commit is contained in:
1 parent
b14b4fced7
commit
bb50d06d1d
13 files changed
+243
-82
No files matched your search
@@ -14,10 +14,21 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
- `ff055c9` (config-driven super-admin bootstrap in the Go backend, task `20260814-go-bootstrap-admin-6e2b7d9c`)
|
||||
- `4a8f2d5` (Go workload deployment artifacts and split Ingress routing, task `20260814-go-deploy-artifacts-2a5f8e1d`)
|
||||
- `498c2fa` (authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task `20260816-fix-authenticated-ssr-6c3f8a21`)
|
||||
- `b14b4fc` (pure static Next.js export, browser-to-Go auth, Go-only runtime API
|
||||
ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task
|
||||
`20260816-static-frontend-go-api-4f8c2a7d`)
|
||||
|
||||
## Current Focus
|
||||
|
||||
The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its deployed revision does not yet include `498c2fa`: authenticated `/create` currently triggers a production RSC error, while the public `/api/ready` endpoint has been observed returning HTTP 200 with PostgreSQL configured. The repository now contains the authenticated Next.js SSR-to-Go identity bridge in `lib/server/auth/current-user.ts`; when `ZHINIAN_GO_INTERNAL_BASE_URL` is configured it refreshes identity through internal Go `/api/auth/me`, and without that environment variable local Next.js full-stack development retains the direct-store path. Current work is the production repair rollout: publish the updated Web image and ACK configuration, then complete an authenticated `/create` smoke test. The exact live Service owner for each request path remains unverified until confirmed from cluster configuration or logs.
|
||||
The first production deployment is live at `https://nianxxaigc.nianxx.cn`; the
|
||||
currently observed revision still fails authenticated `/create` with an RSC
|
||||
error. Repository revision `b14b4fc` removes that request-time frontend seam:
|
||||
Next.js now emits static `out/` files served by unprivileged Nginx, the browser
|
||||
loads identity from same-origin Go `/api/auth/me`, and Ingress routes all
|
||||
`/api`, `/uploads`, and `/generated-results` traffic directly to Go. Web has no
|
||||
runtime ConfigMap, Secret, database credential, or internal Go URL. The new
|
||||
images/manifests have not yet been deployed, and exact live Service ownership
|
||||
still requires cluster evidence.
|
||||
|
||||
## Recently Completed
|
||||
|
||||
@@ -30,30 +41,49 @@ The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its d
|
||||
- 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task `20260814-deploy-model-reconcile-9b4c2e7f`).
|
||||
- 2026-08-14: Built the Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task `20260814-go-deploy-artifacts-2a5f8e1d`).
|
||||
- 2026-08-16: Implemented authenticated production SSR identity refresh through Go `/api/auth/me`, forwarding only enumerated `zhinian_session` chunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task `20260816-fix-authenticated-ssr-6c3f8a21`, commit `498c2fa`; not yet deployed).
|
||||
- 2026-08-16: Replaced production SSR/Middleware/Next Route Handlers with a
|
||||
static export and browser auth Module, made Go the only runtime API owner,
|
||||
replaced the Web runner with unprivileged Nginx, removed deprecated Node
|
||||
Worker/migration manifests, and added static/deployment regressions (task
|
||||
`20260816-static-frontend-go-api-4f8c2a7d`, commit `b14b4fc`; not yet
|
||||
deployed).
|
||||
|
||||
## In Progress
|
||||
|
||||
- Release `498c2fa` to the existing production environment and verify authenticated `/create` SSR; the live revision still exhibits the RSC failure.
|
||||
- Build, publish, and deploy immutable Web and Go images for `b14b4fc`, then
|
||||
verify the static Web + Go-only runtime boundary in the live ACK cluster.
|
||||
|
||||
## Next Recommended Steps
|
||||
|
||||
1. Build and push the updated Web image containing `498c2fa`, and validate the updated ACK configuration with a server-side dry run on the production cluster.
|
||||
2. Apply the updated Web image and ACK configuration without assuming the current live Service ownership beyond what cluster configuration and logs confirm.
|
||||
3. Smoke-test an authenticated request to `/create`, confirming the production RSC error is resolved and SSR refreshes the user through internal Go `/api/auth/me`.
|
||||
4. Recheck public `/api/ready` after the rollout; it currently returns HTTP 200 with PostgreSQL configured.
|
||||
5. Continue real RDS/OSS/provider/Webhook validation and confirm the public `/api/v1` compatibility promise for external consumers.
|
||||
1. Build and smoke the pinned unprivileged Nginx Web image in CI or another
|
||||
host with Docker, then publish Web and Go images under new immutable tags or
|
||||
digests.
|
||||
2. Create/verify the `zhinian` Namespace, run target-cluster server-side dry
|
||||
runs, apply the production Go-owned Secret and six checked-in resource
|
||||
manifests (not `secrets.example.yaml`), and confirm live Ingress/Service
|
||||
ownership from cluster state.
|
||||
3. Smoke anonymous login, authenticated `/create?mode=video`, logout, and each
|
||||
admin role; verify Web `/healthz`, Go `/api/health`, and Go `/api/ready`.
|
||||
4. Configure OSS or another shared/persistent store before any Go Pod
|
||||
replacement that must preserve current local uploads/generated results.
|
||||
5. Continue real RDS/provider/Webhook validation and confirm the public
|
||||
`/api/v1` compatibility promise for external consumers.
|
||||
|
||||
## Open Questions / Blockers
|
||||
|
||||
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
|
||||
- Real OSS bucket/credential configuration is still needed for shared asset storage.
|
||||
- Public `/api/v1` support promises for external consumers need explicit confirmation.
|
||||
- The static Web Docker image has not been built or container-smoked in this
|
||||
workstation because its Docker daemon is unavailable.
|
||||
|
||||
## Risky Areas
|
||||
|
||||
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
|
||||
- The current image runs as root; moving to a non-root user requires an explicit writable-path ownership design.
|
||||
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns those paths without cluster evidence.
|
||||
- Go currently stores local uploads/results on `emptyDir` when OSS is absent;
|
||||
Pod replacement or rolling update loses them, not only horizontal scaling.
|
||||
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not
|
||||
infer which live workload owns paths without cluster evidence.
|
||||
|
||||
## Last Updated
|
||||
|
||||
|
||||
Reference in new issue
Block a user