3.5 KiB
Data Flow
Local Full-Stack Flows
These repository flows remain available for local development and do not establish which Service currently owns a path in the live production cluster.
| Flow | Source | Destination | Notes |
|---|---|---|---|
| Web persistence | Routes/services/stores | PostgreSQL adapter -> RDS | Parameterized SQL; related statements share one Pool client transaction. |
| Worker processing | Worker process | Internal Web Service /api/internal/worker/tick |
Authenticated by internal token; Worker has no RDS credentials. |
| Schema rollout | Manual SQL execution by the deployment operator | RDS PostgreSQL | Versioned checksummed files under database/migrations/; 0001 then 0002, then application-role grants. |
| Readiness | ACK probe | Web /api/ready -> RDS |
Verifies connection, 11 runtime tables, required privileges, and 2 functions. |
Approved Target Flows
The Go implementation and desired ACK routing for these flows are present in the repository. Production is already online, but its exact live Service ownership has not been confirmed from cluster configuration or logs:
| Flow | Source | Destination | Required behavior |
|---|---|---|---|
| Browser UI | Browser | Same-origin Ingress -> Next.js or Go by path | Preserve current URLs; avoid cross-origin Cookie/CORS changes. |
| SSR identity | Next.js getOptionalAuthSession() |
Internal Go GET /api/auth/me |
Implemented in 498c2fa when ZHINIAN_GO_INTERNAL_BASE_URL is configured: forward only enumerated zhinian_session Cookie chunks, use no-store transport, strictly validate authenticated/anonymous response shape and identity binding, and fail closed on bridge errors. No unrelated Cookie or origin forwarding. Without the URL, local full-stack mode keeps direct-store authorization. The live revision does not yet contain this fix. |
| Backend persistence | Go Modules | PostgreSQL Adapter -> RDS | Parameterized queries and transactions; fail closed in production. |
| Task execution | Embedded Go WorkerLoop | RDS claim -> provider -> OSS -> RDS -> Webhook | Bounded concurrency, recoverable leases, one owner for external side effects. |
| Asset lifecycle | Go Assets | OSS plus RDS metadata | Shared storage required before horizontal scaling. |
| Schema rollout | Migration Job | RDS | Existing version/checksum/advisory-lock contract remains unchanged. |
State Ownership
- Production relational state belongs to RDS PostgreSQL when
ZHINIAN_DATA_BACKEND=postgres. - Local JSON under the runtime directory is an explicit development/test backend, not a production fallback.
- Uploads/generated files remain runtime/object-storage state and are not made shared by the PostgreSQL migration.
External Interfaces
- Alibaba Cloud RDS PostgreSQL via its internal endpoint and verified TLS CA.
- Alibaba Cloud ACK resources under
deploy/ack/. - Live production at
https://nianxxaigc.nianxx.cn; public/api/readyhas returned HTTP 200 with PostgreSQL configured, without proving the owning Service. - Internal Worker HTTP endpoint is cluster-internal and blocked from public Ingress routing.
The accepted production topology uses the embedded Go WorkerLoop rather than the local-development Node Worker. The exact live workload set remains to be confirmed from the cluster.
The SSR identity bridge and ACK internal URL are merged but not yet deployed. The current live revision produces a production RSC error for authenticated /create; the repair rollout must deploy 498c2fa and verify the flow with an authenticated smoke test.
Last Updated
2026-08-16