2.3 KiB
2.3 KiB
Decision Index
Active Decisions
| ID | Decision | Status | Date | Applies To | Detail |
|---|---|---|---|---|---|
| RDS-001 | Production persistence uses explicit direct PostgreSQL through one server-only adapter; local JSON is explicit development/test mode. | Accepted; transport amended 2026-08-16 | 2026-08-12, amended 2026-08-16 | Server stores and scripts | ZHINIAN_DATA_BACKEND=postgres fails closed and never silently falls back. PostgreSQL clients enforce plaintext (sslmode=disable) because the selected RDS endpoint refuses TLS; production must use the internal endpoint with VPC, security-group, and allowlist isolation. |
| RDS-002 | Database changes use versioned, checksummed, advisory-locked migrations. | Accepted; execution amended 2026-08-14 | 2026-08-12 | Database schema and rollout | Initial production schema is executed manually from database/migrations/*.sql plus application-role grants; no migration Job manifest is shipped with the static Web image. |
| ADR-003 | Production is a same-origin static Next.js export on Nginx plus a Go modular-monolith backend with an embedded WorkerLoop. | Accepted; repository implementation complete in b14b4fc; production rollout pending |
2026-08-12, amended 2026-08-16 | Application and ACK architecture | Browser routes are static; all runtime API/file/auth responsibility belongs to Go. See adr-003-next-go-target.md. |
| DEP-001 | Production starts fresh with the ADR-003 static Web + Go topology, no legacy cutover or Node Worker, and manual SQL schema initialization. | Accepted; manifests updated 2026-08-16 | 2026-08-14 | Deployment model and schema initialization | No migration Job pod; Go bootstraps the super administrator, owns the session Secret, and receives all runtime/backend configuration. |
Superseded Decisions
| ID | Decision | Superseded By | Date |
|---|---|---|---|
| ACK-001 | Worker remains an HTTP poller and does not receive RDS credentials; Web owns database access. | DEP-001: production never deploys the Node Worker; the Go backend owns database access and embeds the WorkerLoop. |
2026-08-14 |
Decision Criteria
Create or update an ADR when a choice affects:
- project positioning
- architecture boundaries
- public behavior
- data model
- long-term maintenance
- user-facing workflow