1.7 KiB
1.7 KiB
Business Rules
Durable Rules
- Production data backend selection is explicit and fail-closed: a PostgreSQL configuration failure must never silently fall back to local JSON.
- Billing amounts use integer-fen arithmetic; wallet balance enforcement and ledger insertion happen inside the PostgreSQL
billing_post_wallet_entryfunction. - Job claiming uses the PostgreSQL
claim_generation_jobsfunction (FOR UPDATE SKIP LOCKED, lease, stale recovery); Go process-local locks must never replace it. - Ordinary members cannot submit generation when the organization balance is insufficient; submission is rejected before provider dispatch.
- Super administrators calculate and record generation cost without checking, freezing, or refunding organization quota.
- All new organization balance entries are organization-owned; generation charge/refund entries keep member attribution for consumption reporting.
- Logged-in users may change their own password; account management and organization member actions require admin roles.
- Public
/api/v1access authenticates with API keys and stays outside browser SSO middleware; API data is partitioned by the API account owner. - Database schema changes stay versioned and checksummed in
database/migrations/; the initial production schema is created by manually executing the SQL files plus application-role grants (no migration Job pod), and schema changes must never run inside long-lived pod startup. - Generated and uploaded assets remain runtime/object-storage state; PostgreSQL does not make them shared for horizontal scaling.
Open Questions
- The exact public
/api/v1compatibility promise to preserve for external consumers.
Last Reviewed
2026-08-14