6.0 KiB
Current State
This file is the integrated default-branch snapshot. Feature tasks record progress in 30-worklog/tasks/{task_id}.md and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.
Integrated Through
c44274f(rebased integration of84d84ba, task20260812-rds-postgres-adapter-7f2c1a)79d29bb(cross-platform ACK manifest validation fix)4485899(task-scoped Next.js frontend plus Go backend target design and explicit not-implemented progress record)064e155(canonical ADR-003, architecture, current-state, history, and commitment promotion)b8db39d(merge ofaef5a97— completed Go backend modules; tasks20260812-go-migration-foundation-b74c9e21,20260813-go-identity-vertical-c4e91a72,20260813-go-auth-me-http-8d6f3a21,20260813-go-auth-lifecycle-3f9a6c12,20260813-go-remaining-modules-7d3a9e42)d0fb346(merge ofc1cbd78— Go backend implementation, contract fixtures, migration 0002, and task-scoped records intomain; tasks20260813-go-remaining-modules-7d3a9e42and20260814-go-remaining-integration-5e7c9a1b)f10cdd9(record of completed task20260812-architecture-task-breakdown-a83f61c2)ff055c9(config-driven super-admin bootstrap in the Go backend, task20260814-go-bootstrap-admin-6e2b7d9c)4a8f2d5(Go workload deployment artifacts and split Ingress routing, task20260814-go-deploy-artifacts-2a5f8e1d)498c2fa(authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task20260816-fix-authenticated-ssr-6c3f8a21)
Current Focus
The first production deployment is live at https://nianxxaigc.nianxx.cn. Its deployed revision does not yet include 498c2fa: authenticated /create currently triggers a production RSC error, while the public /api/ready endpoint has been observed returning HTTP 200 with PostgreSQL configured. The repository now contains the authenticated Next.js SSR-to-Go identity bridge in lib/server/auth/current-user.ts; when ZHINIAN_GO_INTERNAL_BASE_URL is configured it refreshes identity through internal Go /api/auth/me, and without that environment variable local Next.js full-stack development retains the direct-store path. Current work is the production repair rollout: publish the updated Web image and ACK configuration, then complete an authenticated /create smoke test. The exact live Service owner for each request path remains unverified until confirmed from cluster configuration or logs.
Recently Completed
- 2026-08-12: Replaced the Supabase/PostgREST runtime path with a server-only
pgadapter across data, account, and billing stores. - 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, verified-CA TLS, database readiness, and ACK Web/Worker/migration manifests.
- 2026-08-12: Accepted and documented the Next.js frontend plus Go backend target, migration contracts, and acceptance criteria.
- 2026-08-14: Implemented and merged the Go backend (foundation, identity, administration, assets, billing, usage, jobs/providers/webhooks/worker loop, public and compatibility HTTP surfaces) with language-neutral contract fixtures and migration 0002.
- 2026-08-14: Reconciled canonical architecture, decision, history, commitment, and positioning memory with the merged Go implementation (task
20260814-go-memory-reconcile-7f2a9c41). - 2026-08-14: Added config-driven first-super-administrator bootstrap to the Go backend (task
20260814-go-bootstrap-admin-6e2b7d9c). - 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task
20260814-deploy-model-reconcile-9b4c2e7f). - 2026-08-14: Built the Go workload deployment artifacts:
backend/Dockerfile,deploy/ack/go-api.yaml, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task20260814-go-deploy-artifacts-2a5f8e1d). - 2026-08-16: Implemented authenticated production SSR identity refresh through Go
/api/auth/me, forwarding only enumeratedzhinian_sessionchunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task20260816-fix-authenticated-ssr-6c3f8a21, commit498c2fa; not yet deployed).
In Progress
- Release
498c2fato the existing production environment and verify authenticated/createSSR; the live revision still exhibits the RSC failure.
Next Recommended Steps
- Build and push the updated Web image containing
498c2fa, and validate the updated ACK configuration with a server-side dry run on the production cluster. - Apply the updated Web image and ACK configuration without assuming the current live Service ownership beyond what cluster configuration and logs confirm.
- Smoke-test an authenticated request to
/create, confirming the production RSC error is resolved and SSR refreshes the user through internal Go/api/auth/me. - Recheck public
/api/readyafter the rollout; it currently returns HTTP 200 with PostgreSQL configured. - Continue real RDS/OSS/provider/Webhook validation and confirm the public
/api/v1compatibility promise for external consumers.
Open Questions / Blockers
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
- Real OSS bucket/credential configuration is still needed for shared asset storage.
- Public
/api/v1support promises for external consumers need explicit confirmation.
Risky Areas
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
- The current image runs as root; moving to a non-root user requires an explicit writable-path ownership design.
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns those paths without cluster evidence.
Last Updated
2026-08-16