Files
NianAIGC/.project-docs/30-worklog/tasks/20260814-go-deploy-artifacts-2a5f8e1d.md
T

3.8 KiB

Task: Build first-deployment artifacts for the Go stack

Identity

  • Task ID: 20260814-go-deploy-artifacts-2a5f8e1d
  • Mode: Feature
  • Branch: main
  • Worktree: /Users/brother7/Documents/AI/NianAIGC
  • Base commit: ca019abb14
  • Owner: dsh
  • Status: Ready for Integration

Scope

  • Build the deployment artifacts for the first production deployment of the ADR-003 split topology: Go container image build, ACK Deployment/Service for the Go API workload, split-path Ingress routing, and workload configuration updates.
  • Human direction (2026-08-14): first production deployment runs Next.js (pages/static/SSR) plus Go (backend paths) directly; no Node Worker and no migration Job pod in production.

Intent And Constraints

  • Production Web workload holds no RDS/provider credentials and only needs the shared session secret for local cookie verification (its middleware already verifies the cookie with HMAC locally, no database access).
  • Go workload runs non-root, root filesystem read-only, with writable emptyDir mounts for runtime/logs/settings/temp.
  • Keep the manifest contract checker (check-ack-manifests.mjs) authoritative for the new topology.
  • Keep deprecated manifests (worker, migration Job) on disk with header comments.

Outcome

  • Added backend/Dockerfile (multi-stage golang:1.21-alpine → alpine:3.20, static CGO_ENABLED=0 build, non-root uid/gid 10001, ca-certificates + tzdata) and backend/.dockerignore.
  • Added deploy/ack/go-api.yaml: Deployment zhinian-go-api (1 replica, /api/ready database-aware readiness, runAsNonRoot, readOnlyRootFilesystem, RDS CA + data + tmp volumes, bootstrap/provider/webhook secrets, embedded WorkerLoop config) plus ClusterIP Service zhinian-go-api:8080.
  • Added zhinian-go-runtime ConfigMap to deploy/ack/configmap.yaml with the full Go runtime surface (DB/TLS settings, auth, embedded worker, billing, runtime/log/settings dirs).
  • Updated deploy/ack/web.yaml: removed RDS credentials, worker token, and RDS CA mount; readiness switched to process-level /api/health (Web is database-free in production).
  • Updated deploy/ack/ingress.yaml: /api, /uploads, /generated-results → zhinian-go-api; /api/internal/worker still → selectorless deny Service; pages/static → Web.
  • Updated deploy/ack/secrets.example.yaml with zhinian-go-db, zhinian-go-bootstrap, zhinian-go-providers, zhinian-go-secrets and notes that the session secret must match across workloads; marked local-only secrets.
  • Marked deploy/ack/worker.yaml deprecated (production uses the embedded WorkerLoop).
  • Updated scripts/check-ack-manifests.mjs assertions for the split topology (Web database-free, Go API non-root/database-aware readiness/bootstrap config, Ingress split routing).
  • Updated docs/DEPLOYMENT.md, README.zh-CN.md, and README.md deployment/tech-stack guidance (Go image build command, apply order, split topology).

Verification

  • npm run deploy:check — PASS (9 manifest files, new assertions).
  • All deploy/ack/*.yaml parse as valid multi-document YAML.
  • CGO_ENABLED=0 go build ./cmd/zhinian-api — PASS.
  • Docker image build itself must run on a machine with Docker; the Dockerfile is static-checked against the build steps in scripts/run-go-command.mjs conventions.

Follow-ups

  • Build and push the zhinian-go-api image, then validate the manifests with kubectl apply --dry-run=server on the target ACK cluster.
  • Validate the full stack against non-production RDS/OSS/provider/Webhook dependencies before the first rollout.
  • Decide whether to delete the deprecated worker.yaml and migration-job.yaml.

Promotion Candidates

  • Canonical memory (current-state Next Steps, commitments) still lists "build the Go workload deployment artifacts" as open; promote completion there in the next integration pass.