# Task: Simplify production database and deployment environment configuration ## Identity - Task ID: 20260816-simplify-prod-env-8a4c - Mode: Feature - Branch: codex/20260816-simplify-prod-env-8a4c-simplify-prod-env - Worktree: D:\Datas\OthersProjects\NianAIGC-simplify-prod-env-8a4c - Base commit: 8cb8b5e463b752230fc675f05de3d910f8c90332 - Owner: codex - Status: Ready for Integration ## Scope - Simplify PostgreSQL connection configuration so `DATABASE_URL` is the only database connection setting; allow `sslmode` and optional `sslrootcert` in that URL while retaining full certificate verification by default. - Remove non-essential production ACK environment and Secret injections while retaining the Go API, Next session, bootstrap, RDS CA mount, and runtime storage settings required by the first deployment. - Synchronize Go/Node clients, ACK checks, deployment documentation, README references, and configuration tests. ## Intent And Constraints - Do not weaken TLS verification or introduce `InsecureSkipVerify`. - Keep local JSON development behavior and existing database pool defaults. - Preserve the existing split topology: Next.js serves pages, Go owns the database and embedded WorkerLoop. - Feature mode may update task-scoped code/deployment/docs, but not canonical `.project-docs` memory. ## Outcome - Completed the single-variable database contract. Go, the legacy TypeScript adapter, and migration scripts now read TLS settings from `DATABASE_URL`; production defaults to `sslmode=verify-full`, and `sslrootcert` is optional in the URL when the RDS CA is mounted. Separate `DATABASE_SSL_MODE`/`DATABASE_CA_CERT_PATH` environment variables are no longer consumed. - Reduced ACK runtime configuration to startup essentials, added the missing `GO_BACKEND_HOST=0.0.0.0`, removed unused provider/webhook/API-key/legacy worker Secret injections, and retained the CA Secret as a file mount rather than an environment variable. - Updated `.env.example`, deployment docs, READMEs, ACK assertions, and database configuration tests. ## Verification - `go test ./...` passed in `backend/`. - `go test ./internal/postgres` passed after the final TLS assertion update. - `npm run deploy:check` passed (9 ACK manifests). - `node --check scripts/postgres-client.mjs` passed. - `node --check scripts/check-ack-manifests.mjs` passed. - `git diff --check` passed; only Git line-ending warnings were reported. - Full Vitest/Next typecheck was not run because this isolated worktree has no `node_modules` installation. ## Follow-ups - Replace all ACK placeholders, especially the RDS CA Secret and the `DATABASE_URL` values. For strict RDS verification, include `?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem` in both the Go and migration connection URLs. - Add provider/OSS/API-key/Webhook Secret references only when those optional capabilities are enabled. ## Promotion Candidates - None. The deployment simplification is task-scoped; canonical architecture already describes the same two-workload production topology.