fix: disable PostgreSQL TLS for refusing RDS endpoint

This commit is contained in:
brother7 committed 2026-08-16 23:26:03 +08:00
1 parent acf368b6fe
commit ed978142eb
17 files changed
+340 -180

No files matched your search

+8 -5
View File
@@ -20,9 +20,10 @@ Implemented Modules:
tenant-scoped reports.
- `templates`, `prompt`, `settings`, and `logging`: the remaining compatibility
modules used by the HTTP surface.
- `postgres`: fail-closed configuration, verified-CA TLS, readiness, atomic
account mutations, and calls to the existing claim and wallet PostgreSQL
functions. PostgreSQL is the production relational source of truth.
- `postgres`: fail-closed configuration, code-enforced plaintext
`sslmode=disable`, readiness, atomic account mutations, and calls to the
existing claim and wallet PostgreSQL functions. PostgreSQL is the production
relational source of truth.
- `localstore`: a mutex-protected, non-durable, single-process development
store covering the same business Module ports.
- `httpapi`: the complete checked-in route compatibility surface.
@@ -107,5 +108,7 @@ bootstrap-creates accounts.
Production routing, Secret ownership, probes, and rollout commands are defined
in [`../docs/DEPLOYMENT.md`](../docs/DEPLOYMENT.md) and `../deploy/ack/`. Go owns
the session signing Secret and backend runtime configuration; the static Web
workload receives neither. Validate RDS/CA, OSS, providers, Webhooks, embedded
Worker recovery, and rollback behavior for each production release.
workload receives neither. PostgreSQL does not use TLS, so production must use
the RDS internal endpoint and restrict access with VPC boundaries, security
groups, and allowlists. Validate RDS connectivity, OSS, providers, Webhooks,
embedded Worker recovery, and rollback behavior for each production release.