Files
NianAIGC/.project-docs/30-worklog/current-state.md
T

6.6 KiB

Current State

This file is the integrated default-branch snapshot. Feature tasks record progress in 30-worklog/tasks/{task_id}.md and propose canonical changes for the Integration Gate. Feature tasks must not rewrite this file; it changes only in integration mode.

Integrated Through

  • c44274f (rebased integration of 84d84ba, task 20260812-rds-postgres-adapter-7f2c1a)
  • 79d29bb (cross-platform ACK manifest validation fix)
  • 4485899 (task-scoped Next.js frontend plus Go backend target design and explicit not-implemented progress record)
  • 064e155 (canonical ADR-003, architecture, current-state, history, and commitment promotion)
  • b8db39d (merge of aef5a97 — completed Go backend modules; tasks 20260812-go-migration-foundation-b74c9e21, 20260813-go-identity-vertical-c4e91a72, 20260813-go-auth-me-http-8d6f3a21, 20260813-go-auth-lifecycle-3f9a6c12, 20260813-go-remaining-modules-7d3a9e42)
  • d0fb346 (merge of c1cbd78 — Go backend implementation, contract fixtures, migration 0002, and task-scoped records into main; tasks 20260813-go-remaining-modules-7d3a9e42 and 20260814-go-remaining-integration-5e7c9a1b)
  • f10cdd9 (record of completed task 20260812-architecture-task-breakdown-a83f61c2)
  • ff055c9 (config-driven super-admin bootstrap in the Go backend, task 20260814-go-bootstrap-admin-6e2b7d9c)
  • 4a8f2d5 (Go workload deployment artifacts and split Ingress routing, task 20260814-go-deploy-artifacts-2a5f8e1d)
  • 498c2fa (authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task 20260816-fix-authenticated-ssr-6c3f8a21)
  • b14b4fc (pure static Next.js export, browser-to-Go auth, Go-only runtime API ownership, unprivileged Nginx Web, and first-deployment ACK cleanup; task 20260816-static-frontend-go-api-4f8c2a7d)

Current Focus

The first production deployment is live at https://nianxxaigc.nianxx.cn; the currently observed revision still fails authenticated /create with an RSC error. Repository revision b14b4fc removes that request-time frontend seam: Next.js now emits static out/ files served by unprivileged Nginx, the browser loads identity from same-origin Go /api/auth/me, and Ingress routes all /api, /uploads, and /generated-results traffic directly to Go. Web has no runtime ConfigMap, Secret, database credential, or internal Go URL. The new images/manifests have not yet been deployed, and exact live Service ownership still requires cluster evidence.

Recently Completed

  • 2026-08-12: Replaced the Supabase/PostgREST runtime path with a server-only pg adapter across data, account, and billing stores.
  • 2026-08-12: Added versioned PostgreSQL migrations, strict backend selection, verified-CA TLS, database readiness, and ACK Web/Worker/migration manifests.
  • 2026-08-12: Accepted and documented the Next.js frontend plus Go backend target, migration contracts, and acceptance criteria.
  • 2026-08-14: Implemented and merged the Go backend (foundation, identity, administration, assets, billing, usage, jobs/providers/webhooks/worker loop, public and compatibility HTTP surfaces) with language-neutral contract fixtures and migration 0002.
  • 2026-08-14: Reconciled canonical architecture, decision, history, commitment, and positioning memory with the merged Go implementation (task 20260814-go-memory-reconcile-7f2a9c41).
  • 2026-08-14: Added config-driven first-super-administrator bootstrap to the Go backend (task 20260814-go-bootstrap-admin-6e2b7d9c).
  • 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task 20260814-deploy-model-reconcile-9b4c2e7f).
  • 2026-08-14: Built the Go workload deployment artifacts: backend/Dockerfile, deploy/ack/go-api.yaml, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task 20260814-go-deploy-artifacts-2a5f8e1d).
  • 2026-08-16: Implemented authenticated production SSR identity refresh through Go /api/auth/me, forwarding only enumerated zhinian_session chunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task 20260816-fix-authenticated-ssr-6c3f8a21, commit 498c2fa; not yet deployed).
  • 2026-08-16: Replaced production SSR/Middleware/Next Route Handlers with a static export and browser auth Module, made Go the only runtime API owner, replaced the Web runner with unprivileged Nginx, removed deprecated Node Worker/migration manifests, and added static/deployment regressions (task 20260816-static-frontend-go-api-4f8c2a7d, commit b14b4fc; not yet deployed).

In Progress

  • Build, publish, and deploy immutable Web and Go images for b14b4fc, then verify the static Web + Go-only runtime boundary in the live ACK cluster.
  1. Build and smoke the pinned unprivileged Nginx Web image in CI or another host with Docker, then publish Web and Go images under new immutable tags or digests.
  2. Create/verify the zhinian Namespace, run target-cluster server-side dry runs, apply the production Go-owned Secret and six checked-in resource manifests (not secrets.example.yaml), and confirm live Ingress/Service ownership from cluster state.
  3. Smoke anonymous login, authenticated /create?mode=video, logout, and each admin role; verify Web /healthz, Go /api/health, and Go /api/ready.
  4. Configure OSS or another shared/persistent store before any Go Pod replacement that must preserve current local uploads/generated results.
  5. Continue real RDS/provider/Webhook validation and confirm the public /api/v1 compatibility promise for external consumers.

Open Questions / Blockers

  • Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
  • Real OSS bucket/credential configuration is still needed for shared asset storage.
  • Public /api/v1 support promises for external consumers need explicit confirmation.
  • The static Web Docker image has not been built or container-smoked in this workstation because its Docker daemon is unavailable.

Risky Areas

  • Database grants and least-privilege roles still require documented validation against the live RDS instance.
  • Go currently stores local uploads/results on emptyDir when OSS is absent; Pod replacement or rolling update loses them, not only horizontal scaling.
  • Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns paths without cluster evidence.

Last Updated

2026-08-16