6.6 KiB
Current State
This file is the integrated default-branch snapshot. Feature tasks record progress in 30-worklog/tasks/{task_id}.md and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.
Integrated Through
c44274f(rebased integration of84d84ba, task20260812-rds-postgres-adapter-7f2c1a)79d29bb(cross-platform ACK manifest validation fix)4485899(task-scoped Next.js frontend plus Go backend target design and explicit not-implemented progress record)064e155(canonical ADR-003, architecture, current-state, history, and commitment promotion)b8db39d(merge ofaef5a97— completed Go backend modules; tasks20260812-go-migration-foundation-b74c9e21,20260813-go-identity-vertical-c4e91a72,20260813-go-auth-me-http-8d6f3a21,20260813-go-auth-lifecycle-3f9a6c12,20260813-go-remaining-modules-7d3a9e42)d0fb346(merge ofc1cbd78— Go backend implementation, contract fixtures, migration 0002, and task-scoped records intomain; tasks20260813-go-remaining-modules-7d3a9e42and20260814-go-remaining-integration-5e7c9a1b)f10cdd9(record of completed task20260812-architecture-task-breakdown-a83f61c2)ff055c9(config-driven super-admin bootstrap in the Go backend, task20260814-go-bootstrap-admin-6e2b7d9c)4a8f2d5(Go workload deployment artifacts and split Ingress routing, task20260814-go-deploy-artifacts-2a5f8e1d)498c2fa(authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task20260816-fix-authenticated-ssr-6c3f8a21)b14b4fc(pure static Next.js export, browser-to-Go auth, Go-only runtime API ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task20260816-static-frontend-go-api-4f8c2a7d)
Current Focus
The first production deployment is live at https://nianxxaigc.nianxx.cn; the
currently observed revision still fails authenticated /create with an RSC
error. Repository revision b14b4fc removes that request-time frontend seam:
Next.js now emits static out/ files served by unprivileged Nginx, the browser
loads identity from same-origin Go /api/auth/me, and Ingress routes all
/api, /uploads, and /generated-results traffic directly to Go. Web has no
runtime ConfigMap, Secret, database credential, or internal Go URL. The new
images/manifests have not yet been deployed, and exact live Service ownership
still requires cluster evidence.
Recently Completed
- 2026-08-12: Replaced the Supabase/PostgREST runtime path with a server-only
pgadapter across data, account, and billing stores. - 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, verified-CA TLS, database readiness, and ACK Web/Worker/migration manifests.
- 2026-08-12: Accepted and documented the Next.js frontend plus Go backend target, migration contracts, and acceptance criteria.
- 2026-08-14: Implemented and merged the Go backend (foundation, identity, administration, assets, billing, usage, jobs/providers/webhooks/worker loop, public and compatibility HTTP surfaces) with language-neutral contract fixtures and migration 0002.
- 2026-08-14: Reconciled canonical architecture, decision, history, commitment, and positioning memory with the merged Go implementation (task
20260814-go-memory-reconcile-7f2a9c41). - 2026-08-14: Added config-driven first-super-administrator bootstrap to the Go backend (task
20260814-go-bootstrap-admin-6e2b7d9c). - 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task
20260814-deploy-model-reconcile-9b4c2e7f). - 2026-08-14: Built the Go workload deployment artifacts:
backend/Dockerfile,deploy/ack/go-api.yaml, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task20260814-go-deploy-artifacts-2a5f8e1d). - 2026-08-16: Implemented authenticated production SSR identity refresh through Go
/api/auth/me, forwarding only enumeratedzhinian_sessionchunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task20260816-fix-authenticated-ssr-6c3f8a21, commit498c2fa; not yet deployed). - 2026-08-16: Replaced production SSR/Middleware/Next Route Handlers with a
static export and browser auth Module, made Go the only runtime API owner,
replaced the Web runner with unprivileged Nginx, removed deprecated Node
Worker/migration manifests, and added static/deployment regressions (task
20260816-static-frontend-go-api-4f8c2a7d, commitb14b4fc; not yet deployed).
In Progress
- Build, publish, and deploy immutable Web and Go images for
b14b4fc, then verify the static Web + Go-only runtime boundary in the live ACK cluster.
Next Recommended Steps
- Build and smoke the pinned unprivileged Nginx Web image in CI or another host with Docker, then publish Web and Go images under new immutable tags or digests.
- Create/verify the
zhinianNamespace, run target-cluster server-side dry runs, apply the production Go-owned Secret and six checked-in resource manifests (notsecrets.example.yaml), and confirm live Ingress/Service ownership from cluster state. - Smoke anonymous login, authenticated
/create?mode=video, logout, and each admin role; verify Web/healthz, Go/api/health, and Go/api/ready. - Configure OSS or another shared/persistent store before any Go Pod replacement that must preserve current local uploads/generated results.
- Continue real RDS/provider/Webhook validation and confirm the public
/api/v1compatibility promise for external consumers.
Open Questions / Blockers
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
- Real OSS bucket/credential configuration is still needed for shared asset storage.
- Public
/api/v1support promises for external consumers need explicit confirmation. - The static Web Docker image has not been built or container-smoked in this workstation because its Docker daemon is unavailable.
Risky Areas
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
- Go currently stores local uploads/results on
emptyDirwhen OSS is absent; Pod replacement or rolling update loses them, not only horizontal scaling. - Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns paths without cluster evidence.
Last Updated
2026-08-16