docs: reconcile authenticated SSR production state
This commit is contained in:
1 parent
498c2fa242
commit
ca12cc88da
7 files changed
+101
-38
No files matched your search
@@ -2,9 +2,9 @@
|
||||
|
||||
## Current Architecture
|
||||
|
||||
There is no deployed production architecture yet. Local development keeps the Next.js full-stack Web workload plus the HTTP-polling Node Worker; production server state is stored directly in PostgreSQL through a shared server-only adapter, and development/tests can explicitly use local JSON.
|
||||
The first production deployment is online at `https://nianxxaigc.nianxx.cn`. The public `/api/ready` endpoint has been observed returning HTTP 200 with PostgreSQL configured. The exact live Service owner for each path has not been confirmed through cluster configuration or logs, so the deployed routing shape is not inferred here.
|
||||
|
||||
The first production deployment will run the ADR-003 split topology directly: Next.js serves pages/static/SSR, and the merged Go backend under `backend/` owns `/api`, `/uploads`, and `/generated-results`. There is no legacy production instance, so there is no cutover and no Node Worker in production — the Go process embeds the WorkerLoop from day one. The deployment artifacts are checked in: `backend/Dockerfile` (non-root static Go image), `deploy/ack/go-api.yaml` (Deployment plus Service), and the split-path Ingress in `deploy/ack/ingress.yaml`; the image build/push and target-cluster validation remain.
|
||||
The live revision predates `498c2fa` and authenticated `/create` currently triggers a production RSC error. The fixed repository revision implements the ADR-003 boundary: Next.js serves pages/static/SSR without database credentials and refreshes authenticated SSR through internal Go `/api/auth/me`; the checked-in production topology assigns backend routes, database-backed authorization, RDS access, and the embedded WorkerLoop to Go. The updated Web image and ACK configuration have not yet been deployed, and the authenticated smoke test remains open. Local development remains a separate Next.js full-stack shape with explicit PostgreSQL or local JSON stores and the HTTP-polling Node Worker.
|
||||
|
||||
## Approved Target Architecture
|
||||
|
||||
@@ -13,24 +13,24 @@ The accepted target in ADR-003 is a same-origin Next.js frontend plus Go modular
|
||||
| Target component | Responsibility | Constraint | Implementation state |
|
||||
|---|---|---|---|
|
||||
| Next.js frontend | Pages, static assets, SSR, browser UI | Calls Go over HTTP; no RDS/provider/OSS/business Secret. | Local dev also runs its API routes; production serves pages only. |
|
||||
| Go backend | Existing HTTP/file contracts, identity, administration, assets, jobs, billing, usage, providers, storage, Webhooks, readiness | Owns relational access and embeds the WorkerLoop. | Implemented in `backend/` and merged; first production deployment pending. |
|
||||
| Go backend | Existing HTTP/file contracts, identity, administration, assets, jobs, billing, usage, providers, storage, Webhooks, readiness | Owns relational access and embeds the WorkerLoop in the approved topology. | Implemented in `backend/`; production is online, but exact live path ownership is not asserted without cluster evidence. |
|
||||
| RDS PostgreSQL | Relational state and cross-instance concurrency | Retains versioned migrations and both concurrency-sensitive database functions. | Schema initialized by manual SQL (migrations 0001/0002) plus role grants. |
|
||||
| Migration Job | Schema and application-role grants | Remains one-shot and separate from long-lived workloads. | Manifest retained but not used; initial schema is executed manually. |
|
||||
| Alibaba Cloud OSS | Shared generated/uploaded assets | Must be production-ready before horizontal workload scaling. | Still behind a storage Adapter; not validated against real OSS. |
|
||||
|
||||
Ingress will route page/static paths to Next.js and `/api`, `/uploads`, and `/generated-results` to Go from the first deployment. The initial target is two long-lived Pods (`Next x1 + Go x1`).
|
||||
The checked-in Ingress routes page/static paths to Next.js and `/api`, `/uploads`, and `/generated-results` to Go. Production is already online; confirming that the live cluster matches this desired state is part of the repair rollout. The approved initial target is two long-lived Pods (`Next x1 + Go x1`).
|
||||
|
||||
## Main Components
|
||||
|
||||
| Component | Responsibility | Notes |
|
||||
|---|---|---|
|
||||
| Next.js Web | Browser/API routes, domain services, persistence calls, internal Worker tick endpoint | Owns the PostgreSQL pool and `/api/ready` until cutover. |
|
||||
| Next.js Web | Local full-stack browser/API routes and stores; fixed production revision serves pages/static/SSR plus the internal Go identity bridge | Local development may use direct stores. The database-free production configuration in `498c2fa` is not yet deployed. |
|
||||
| Worker | Periodically invokes the internal Worker tick endpoint | Local development only; production uses the embedded Go WorkerLoop. |
|
||||
| PostgreSQL adapter | Backend selection, Pool lifecycle, TLS, parameterized queries, transactions, readiness | Server-only module at `lib/server/database.ts`. |
|
||||
| Go backend | `cmd/zhinian-api` plus 18 `internal/` packages: identity, administration, assets, billing, usage, jobs, providers, webhook, httpapi, publicapi, application, orchestration, postgres, localstore, logging, settings, templates, prompt | Merged into `main`; locally runnable and contract-tested; unrouted in production. |
|
||||
| Go backend | `cmd/zhinian-api` plus 18 `internal/` packages: identity, administration, assets, billing, usage, jobs, providers, webhook, httpapi, publicapi, application, orchestration, postgres, localstore, logging, settings, templates, prompt | Merged and contract-tested; checked-in manifests route backend paths to Go, while exact live routing remains to be confirmed from the cluster. |
|
||||
| Contract fixtures | Language-neutral JSON contracts for auth, admin, assets, billing, http, jobs, logs, providers, settings, usage, webhook under `contracts/` | Shared executable acceptance source for TypeScript and Go consumers. |
|
||||
| RDS PostgreSQL | Accounts, assets, jobs, usage, templates, billing state | Schema managed by versioned migrations (0001, 0002). |
|
||||
| Migration Job | Applies migrations and exact application-role privileges | Must complete before Web rollout. |
|
||||
| Migration Job | Retained one-shot migration artifact | Not used for the first production deployment; the operator executes versioned SQL and grants manually. |
|
||||
| Runtime/object storage | Uploads, generated assets, and logs | Container-local/PVC by default; use OSS/shared storage before scaling horizontally. |
|
||||
|
||||
## Important Boundaries
|
||||
@@ -38,15 +38,15 @@ Ingress will route page/static paths to Next.js and `/api`, `/uploads`, and `/ge
|
||||
- Production backend selection is explicit and fail-closed; never turn a PostgreSQL configuration failure into local JSON fallback.
|
||||
- Store callers depend on stable store interfaces, not `pg` or SQL details.
|
||||
- Multi-statement consistency uses one transaction client; atomic job claim and wallet posting remain database functions.
|
||||
- Database credentials are injected only into Web and migration workloads; Worker uses the internal HTTP boundary.
|
||||
- The Go implementation must be validated against non-production RDS/OSS/provider/Webhook dependencies before the first production rollout; Next Route Handlers stay in the repository for local development.
|
||||
- In the approved production split topology, database credentials belong to Go and the manual migration operator; the fixed Next.js Web configuration and any local-only Node Worker do not receive them.
|
||||
- The live production environment requires post-deployment validation against RDS/OSS/provider/Webhook dependencies; Next Route Handlers stay in the repository for local development.
|
||||
|
||||
## Related Decisions
|
||||
|
||||
- Current implementation: `RDS-001` and `RDS-002` (schema execution now manual SQL per `DEP-001`).
|
||||
- Accepted target: `ADR-003`; it supersedes ACK-001 once the first production deployment runs the Go stack.
|
||||
- Accepted target: `ADR-003`; production is online, but its exact live realization must be confirmed from cluster evidence.
|
||||
- First-deployment model: `DEP-001`.
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-08-14
|
||||
2026-08-16
|
||||
Reference in new issue
Block a user