# Task: Integrate plaintext PostgreSQL decision ## Identity - Task ID: 20260816-integrate-plaintext-postgres-6e3b1a90 - Mode: Integration - Branch: main - Worktree: D:\Datas\OthersProjects\NianAIGC - Base commit: ed978142ebbea4ed8e4d3743f9ece42a334c6ea5 - Owner: codex - Status: Ready for Integration ## Scope - Promote the completed plaintext PostgreSQL implementation and decision into canonical project memory. - Reconcile stale verified-CA/TLS wording in current architecture, deployment commitments, and current-state guidance. - Do not change application code, Alibaba Cloud configuration, or historical task/proposal records. ## Intent And Constraints - The user explicitly requires a code-only correction and no Alibaba Cloud RDS configuration change. - PostgreSQL clients must enforce plaintext even when an existing Secret still contains TLS query parameters. - Canonical memory must disclose that transport confidentiality now depends on the internal endpoint plus VPC, security-group, and allowlist isolation. - Source feature task `20260816-disable-postgres-tls-d4a89c12` and commit `ed97814` are read-only inputs to this integration task. ## Outcome - Canonical `RDS-001` now records the plaintext transport amendment and its required private-network isolation boundary. - Current state, architecture, positioning, commitments, and history now point rollout at `ed97814` and no longer describe verified-CA TLS as the target. - No application code, cloud configuration, or deployment state was changed by this integration task. ## Verification - Source implementation final `sol_reviewer`: PASS for Standards and Spec after both identified gaps were fixed. - `check_project_docs.py --target .`: PASS. - `check_doc_drift.py --target . --task-id 20260816-integrate-plaintext-postgres-6e3b1a90`: PASS; only this integration task record and authorized canonical documents changed. - `git diff --check`: PASS (line-ending conversion warnings only). - First read-only integration review: FAIL on one stale TLS/CA maintenance item and this record's pending verification state; both findings were remediated. - Final read-only integration re-review: PASS; both initial documentation findings are closed and no residual Standards or Spec blocker remains. ## Follow-ups - Build, publish, and deploy immutable Web and Go images from `ed97814`. - Apply the checked-in Go manifest without the obsolete CA mount and verify bootstrap/readiness against the real internal RDS endpoint. - Record effective VPC, security-group, allowlist, database-role, and live request-path ownership evidence without exposing credentials. ## Promotion Candidates - None; this integration task directly updates canonical memory.