3.8 KiB
3.8 KiB
Task: Audit current runtime configuration
Identity
- Task ID: 20260812-runtime-config-audit-9b3e6d
- Mode: Feature
- Branch: main
- Worktree: D:\Datas\OthersProjects\NianAIGC
- Base commit:
a235266bed - Owner: codex
- Status: Complete
Scope
- Audit every runtime environment variable consumed by the current
maincode, scripts, Docker image, and ACK manifests. - Reconcile the code contract with
.env.example, deployment documentation, and the current ACK Web, Worker, Migration, Service, and Ingress resources. - Produce an ACK-oriented configuration list for RDS PostgreSQL without changing application or deployment files.
Intent And Constraints
- Treat the current source code as authoritative when examples or documentation disagree.
- Separate confirmed behavior, deployment recommendations, and facts that still require validation in the live ACK/RDS environment.
- Separate non-sensitive ConfigMap values from Secret values and assign them only to the workload that consumes them.
- Do not present dormant external OAuth configuration as an available production login path.
Outcome
- Confirmed the existing ACK manifests cover the PostgreSQL, RDS CA, session, and internal Worker startup baseline, but not a complete real-generation production configuration.
- Produced workload-specific configuration groups for Web, Worker, and the PostgreSQL migration Job, including conditional provider, OSS, Open API, webhook, billing, and organization settings.
- Confirmed that production needs an explicit public HTTPS origin, an explicitly selected image/video engine, the selected provider credentials, and complete OSS configuration to avoid mock behavior or ephemeral Pod-local asset storage.
- Identified current source-of-truth gaps:
.env.exampleomitsVIDEO_GENERATE_ENGINE, all Bailian settings, organization settings, directory overrides, Worker ID, and several compatibility settings. - Confirmed external OAuth/JWT variables are read by helpers but the current login route uses platform-owned PostgreSQL phone/password accounts; configured OAuth client IDs are also overridden by the hard-coded
platformvalue. - Confirmed the obsolete Supabase variables are no longer consumed by runtime code.
Verification
- Audited
process.envreads across application and Node scripts, excluding tests and build output. - Inspected
.env.example,Dockerfile,docker-compose.yml, PostgreSQL adapter and migration scripts, auth, storage, providers, Worker/task handling, billing, organization client, health/readiness routes, and all eight ACK manifests. npm run deploy:check: passed for all 8 ACK manifests.- Independent configuration/security review: current ACK manifest completeness
FAIL; configuration-list framingPASSwhen it distinguishes startup baseline from real-production requirements, includes provider and OSS configuration, and marks OAuth as not connected. - No live RDS connection, migration execution, provider/OSS request, Docker build, ACK server-side dry run, or rollout was performed.
Follow-ups
- Update
.env.exampleand ACK ConfigMap/Secret templates in a separate implementation task if the user wants the audited list applied to the repository. - Validate RDS TLS, roles, privileges, connection budget, ACR pulling, Ingress controller compatibility, provider credentials, OSS access, and the migration Job in the target ACK environment before production cutover.
- Fix or remove the dormant OAuth configuration path before advertising external SSO support.
- Decide whether application logs should move to stdout/log collection or a persistent volume; OSS only persists assets, not the current file log.
Promotion Candidates
- None recorded. This audit refines deployment guidance but does not change the integrated architecture or accepted production boundaries.