# Task: Build first-deployment artifacts for the Go stack ## Identity - Task ID: 20260814-go-deploy-artifacts-2a5f8e1d - Mode: Feature - Branch: main - Worktree: /Users/brother7/Documents/AI/NianAIGC - Base commit: ca019abb14859f7413214b2b6a11a8a07cebf5f7 - Owner: dsh - Status: Ready for Integration ## Scope - Build the deployment artifacts for the first production deployment of the ADR-003 split topology: Go container image build, ACK Deployment/Service for the Go API workload, split-path Ingress routing, and workload configuration updates. - Human direction (2026-08-14): first production deployment runs Next.js (pages/static/SSR) plus Go (backend paths) directly; no Node Worker and no migration Job pod in production. ## Intent And Constraints - Production Web workload holds no RDS/provider credentials and only needs the shared session secret for local cookie verification (its middleware already verifies the cookie with HMAC locally, no database access). - Go workload runs non-root, root filesystem read-only, with writable emptyDir mounts for runtime/logs/settings/temp. - Keep the manifest contract checker (`check-ack-manifests.mjs`) authoritative for the new topology. - Keep deprecated manifests (worker, migration Job) on disk with header comments. ## Outcome - Added `backend/Dockerfile` (multi-stage `golang:1.21-alpine` → `alpine:3.20`, static `CGO_ENABLED=0` build, non-root uid/gid 10001, ca-certificates + tzdata) and `backend/.dockerignore`. - Added `deploy/ack/go-api.yaml`: Deployment `zhinian-go-api` (1 replica, `/api/ready` database-aware readiness, runAsNonRoot, readOnlyRootFilesystem, RDS CA + data + tmp volumes, bootstrap/provider/webhook secrets, embedded WorkerLoop config) plus ClusterIP Service `zhinian-go-api:8080`. - Added `zhinian-go-runtime` ConfigMap to `deploy/ack/configmap.yaml` with the full Go runtime surface (DB/TLS settings, auth, embedded worker, billing, runtime/log/settings dirs). - Updated `deploy/ack/web.yaml`: removed RDS credentials, worker token, and RDS CA mount; readiness switched to process-level `/api/health` (Web is database-free in production). - Updated `deploy/ack/ingress.yaml`: `/api`, `/uploads`, `/generated-results` → `zhinian-go-api`; `/api/internal/worker` still → selectorless deny Service; pages/static → Web. - Updated `deploy/ack/secrets.example.yaml` with `zhinian-go-db`, `zhinian-go-bootstrap`, `zhinian-go-providers`, `zhinian-go-secrets` and notes that the session secret must match across workloads; marked local-only secrets. - Marked `deploy/ack/worker.yaml` deprecated (production uses the embedded WorkerLoop). - Updated `scripts/check-ack-manifests.mjs` assertions for the split topology (Web database-free, Go API non-root/database-aware readiness/bootstrap config, Ingress split routing). - Updated `docs/DEPLOYMENT.md`, `README.zh-CN.md`, and `README.md` deployment/tech-stack guidance (Go image build command, apply order, split topology). ## Verification - `npm run deploy:check` — PASS (9 manifest files, new assertions). - All `deploy/ack/*.yaml` parse as valid multi-document YAML. - `CGO_ENABLED=0 go build ./cmd/zhinian-api` — PASS. - Docker image build itself must run on a machine with Docker; the Dockerfile is static-checked against the build steps in `scripts/run-go-command.mjs` conventions. ## Follow-ups - Build and push the `zhinian-go-api` image, then validate the manifests with `kubectl apply --dry-run=server` on the target ACK cluster. - Validate the full stack against non-production RDS/OSS/provider/Webhook dependencies before the first rollout. - Decide whether to delete the deprecated `worker.yaml` and `migration-job.yaml`. ## Promotion Candidates - Canonical memory (current-state Next Steps, commitments) still lists "build the Go workload deployment artifacts" as open; promote completion there in the next integration pass.