3.8 KiB
3.8 KiB
Task: Build first-deployment artifacts for the Go stack
Identity
- Task ID: 20260814-go-deploy-artifacts-2a5f8e1d
- Mode: Feature
- Branch: main
- Worktree: /Users/brother7/Documents/AI/NianAIGC
- Base commit:
ca019abb14 - Owner: dsh
- Status: Ready for Integration
Scope
- Build the deployment artifacts for the first production deployment of the ADR-003 split topology: Go container image build, ACK Deployment/Service for the Go API workload, split-path Ingress routing, and workload configuration updates.
- Human direction (2026-08-14): first production deployment runs Next.js (pages/static/SSR) plus Go (backend paths) directly; no Node Worker and no migration Job pod in production.
Intent And Constraints
- Production Web workload holds no RDS/provider credentials and only needs the shared session secret for local cookie verification (its middleware already verifies the cookie with HMAC locally, no database access).
- Go workload runs non-root, root filesystem read-only, with writable emptyDir mounts for runtime/logs/settings/temp.
- Keep the manifest contract checker (
check-ack-manifests.mjs) authoritative for the new topology. - Keep deprecated manifests (worker, migration Job) on disk with header comments.
Outcome
- Added
backend/Dockerfile(multi-stagegolang:1.21-alpine→alpine:3.20, staticCGO_ENABLED=0build, non-root uid/gid 10001, ca-certificates + tzdata) andbackend/.dockerignore. - Added
deploy/ack/go-api.yaml: Deploymentzhinian-go-api(1 replica,/api/readydatabase-aware readiness, runAsNonRoot, readOnlyRootFilesystem, RDS CA + data + tmp volumes, bootstrap/provider/webhook secrets, embedded WorkerLoop config) plus ClusterIP Servicezhinian-go-api:8080. - Added
zhinian-go-runtimeConfigMap todeploy/ack/configmap.yamlwith the full Go runtime surface (DB/TLS settings, auth, embedded worker, billing, runtime/log/settings dirs). - Updated
deploy/ack/web.yaml: removed RDS credentials, worker token, and RDS CA mount; readiness switched to process-level/api/health(Web is database-free in production). - Updated
deploy/ack/ingress.yaml:/api,/uploads,/generated-results→zhinian-go-api;/api/internal/workerstill → selectorless deny Service; pages/static → Web. - Updated
deploy/ack/secrets.example.yamlwithzhinian-go-db,zhinian-go-bootstrap,zhinian-go-providers,zhinian-go-secretsand notes that the session secret must match across workloads; marked local-only secrets. - Marked
deploy/ack/worker.yamldeprecated (production uses the embedded WorkerLoop). - Updated
scripts/check-ack-manifests.mjsassertions for the split topology (Web database-free, Go API non-root/database-aware readiness/bootstrap config, Ingress split routing). - Updated
docs/DEPLOYMENT.md,README.zh-CN.md, andREADME.mddeployment/tech-stack guidance (Go image build command, apply order, split topology).
Verification
npm run deploy:check— PASS (9 manifest files, new assertions).- All
deploy/ack/*.yamlparse as valid multi-document YAML. CGO_ENABLED=0 go build ./cmd/zhinian-api— PASS.- Docker image build itself must run on a machine with Docker; the Dockerfile is static-checked against the build steps in
scripts/run-go-command.mjsconventions.
Follow-ups
- Build and push the
zhinian-go-apiimage, then validate the manifests withkubectl apply --dry-run=serveron the target ACK cluster. - Validate the full stack against non-production RDS/OSS/provider/Webhook dependencies before the first rollout.
- Decide whether to delete the deprecated
worker.yamlandmigration-job.yaml.
Promotion Candidates
- Canonical memory (current-state Next Steps, commitments) still lists "build the Go workload deployment artifacts" as open; promote completion there in the next integration pass.