feat: add direct PostgreSQL and ACK deployment support
This commit is contained in:
20
progress.md
20
progress.md
@@ -1553,3 +1553,23 @@
|
||||
- Updated README/API billing semantics and added regression tests for insufficient balance, unbound super-admin image billing, super-admin Seedance settlement, usage cost recording, and ordinary unbound rejection.
|
||||
- Verification: focused billing tests 17/17, full Vitest 24 files / 96 tests, TypeScript, production build, and `git diff --check` passed.
|
||||
- The repository-local test/typecheck wrappers initially could not find `node`; reran the same checks with the bundled workspace Node runtime and they passed.
|
||||
|
||||
## Session: 2026-08-12 - Alibaba Cloud RDS PostgreSQL Adapter
|
||||
|
||||
### Phase 77: Planning and Gate - Complete
|
||||
- Initialized project-memory templates on an isolated `codex/rds-postgres-adapter-7f2c1a` worktree and committed only that baseline so feature drift can be enforced without touching the dirty `main` worktree.
|
||||
- Claimed task `20260812-rds-postgres-adapter-7f2c1a`; Concurrent Task Gate and Planning Gate passed.
|
||||
- Read the active task, project memory entry set, relevant architecture/domain/evidence/commitment files, peer Docker task, and existing task planning history.
|
||||
- Confirmed no semantic conflict with the peer task: it only verifies the Docker build command and does not authorize or perform application changes.
|
||||
- Chose one deep PostgreSQL module with stable store interfaces, explicit backend selection, fail-closed production behavior, versioned migrations, and ACK workload-specific secret boundaries.
|
||||
- **Status:** complete
|
||||
|
||||
### Phase 77: Implementation
|
||||
- Added the server-only PostgreSQL adapter and replaced Supabase access in data, account, and billing stores while preserving local JSON mode and public store contracts.
|
||||
- Added versioned migration tooling, application-role grants, direct PostgreSQL bootstrap/import scripts, Docker migration assets, `/api/ready`, and ACK workload templates.
|
||||
- Completed two independent read-only audits and fixed all findings, including migration Job backend selection, application grants, public Ingress isolation, wallet idempotency concurrency, failed-login concurrency, billing conflict mapping, and JSONB condition normalization.
|
||||
- The first mandated Sol final review returned FAIL. Fixed every reported code item and started a clean second Sol review: tenant-safe payload-bound wallet idempotency, fail-safe historical usage duplicate detection, precise/no-default grants, full runtime privilege readiness, atomic password changes, server-only module guards, and aligned npm/pnpm runtime versions.
|
||||
- Verification passes: `npm ci --ignore-scripts`, frozen pnpm lock validation, `npm run deploy:check` for 8 manifests, 31 Vitest files / 119 tests, `tsc --noEmit --incremental false`, Next production build (including `/api/ready`), script syntax, SQL static assertions, documentation drift, and `git diff --check`.
|
||||
- External validation remains unavailable: no live RDS credentials, ACK kubeconfig, Docker daemon, or `psql`; these are deployment prerequisites, not locally claimed results.
|
||||
- The second mandated Sol review and the post-fix incremental review both returned `PASS` with no blocking findings. The last regression found by the main-thread verification was corrected so wallet idempotency binds immutable accounting fields while allowing description/metadata audit details to evolve across a retry.
|
||||
- **Status:** complete
|
||||
|
||||
Reference in New Issue
Block a user