Files
NianAIGC/.project-docs/30-worklog/tasks/20260812-runtime-config-audit-9b3e6d.md
T

3.8 KiB

Task: Audit current runtime configuration

Identity

  • Task ID: 20260812-runtime-config-audit-9b3e6d
  • Mode: Feature
  • Branch: main
  • Worktree: D:\Datas\OthersProjects\NianAIGC
  • Base commit: a235266bed
  • Owner: codex
  • Status: Complete

Scope

  • Audit every runtime environment variable consumed by the current main code, scripts, Docker image, and ACK manifests.
  • Reconcile the code contract with .env.example, deployment documentation, and the current ACK Web, Worker, Migration, Service, and Ingress resources.
  • Produce an ACK-oriented configuration list for RDS PostgreSQL without changing application or deployment files.

Intent And Constraints

  • Treat the current source code as authoritative when examples or documentation disagree.
  • Separate confirmed behavior, deployment recommendations, and facts that still require validation in the live ACK/RDS environment.
  • Separate non-sensitive ConfigMap values from Secret values and assign them only to the workload that consumes them.
  • Do not present dormant external OAuth configuration as an available production login path.

Outcome

  • Confirmed the existing ACK manifests cover the PostgreSQL, RDS CA, session, and internal Worker startup baseline, but not a complete real-generation production configuration.
  • Produced workload-specific configuration groups for Web, Worker, and the PostgreSQL migration Job, including conditional provider, OSS, Open API, webhook, billing, and organization settings.
  • Confirmed that production needs an explicit public HTTPS origin, an explicitly selected image/video engine, the selected provider credentials, and complete OSS configuration to avoid mock behavior or ephemeral Pod-local asset storage.
  • Identified current source-of-truth gaps: .env.example omits VIDEO_GENERATE_ENGINE, all Bailian settings, organization settings, directory overrides, Worker ID, and several compatibility settings.
  • Confirmed external OAuth/JWT variables are read by helpers but the current login route uses platform-owned PostgreSQL phone/password accounts; configured OAuth client IDs are also overridden by the hard-coded platform value.
  • Confirmed the obsolete Supabase variables are no longer consumed by runtime code.

Verification

  • Audited process.env reads across application and Node scripts, excluding tests and build output.
  • Inspected .env.example, Dockerfile, docker-compose.yml, PostgreSQL adapter and migration scripts, auth, storage, providers, Worker/task handling, billing, organization client, health/readiness routes, and all eight ACK manifests.
  • npm run deploy:check: passed for all 8 ACK manifests.
  • Independent configuration/security review: current ACK manifest completeness FAIL; configuration-list framing PASS when it distinguishes startup baseline from real-production requirements, includes provider and OSS configuration, and marks OAuth as not connected.
  • No live RDS connection, migration execution, provider/OSS request, Docker build, ACK server-side dry run, or rollout was performed.

Follow-ups

  • Update .env.example and ACK ConfigMap/Secret templates in a separate implementation task if the user wants the audited list applied to the repository.
  • Validate RDS TLS, roles, privileges, connection budget, ACR pulling, Ingress controller compatibility, provider credentials, OSS access, and the migration Job in the target ACK environment before production cutover.
  • Fix or remove the dormant OAuth configuration path before advertising external SSO support.
  • Decide whether application logs should move to stdout/log collection or a persistent volume; OSS only persists assets, not the current file log.

Promotion Candidates

  • None recorded. This audit refines deployment guidance but does not change the integrated architecture or accepted production boundaries.