Files
NianAIGC/.project-docs/30-worklog/tasks/20260816-simplify-prod-env-8a4c.md
T

3.0 KiB

Task: Simplify production database and deployment environment configuration

Identity

  • Task ID: 20260816-simplify-prod-env-8a4c
  • Mode: Feature
  • Branch: codex/20260816-simplify-prod-env-8a4c-simplify-prod-env
  • Worktree: D:\Datas\OthersProjects\NianAIGC-simplify-prod-env-8a4c
  • Base commit: 8cb8b5e463
  • Owner: codex
  • Status: Ready for Integration

Scope

  • Simplify PostgreSQL connection configuration so DATABASE_URL is the only database connection setting; allow sslmode and optional sslrootcert in that URL while retaining full certificate verification by default.
  • Remove non-essential production ACK environment and Secret injections while retaining the Go API, Next session, bootstrap, RDS CA mount, and runtime storage settings required by the first deployment.
  • Synchronize Go/Node clients, ACK checks, deployment documentation, README references, and configuration tests.

Intent And Constraints

  • Do not weaken TLS verification or introduce InsecureSkipVerify.
  • Keep local JSON development behavior and existing database pool defaults.
  • Preserve the existing split topology: Next.js serves pages, Go owns the database and embedded WorkerLoop.
  • Feature mode may update task-scoped code/deployment/docs, but not canonical .project-docs memory.

Outcome

  • Completed the single-variable database contract. Go, the legacy TypeScript adapter, and migration scripts now read TLS settings from DATABASE_URL; production defaults to sslmode=verify-full, and sslrootcert is optional in the URL when the RDS CA is mounted. Separate DATABASE_SSL_MODE/DATABASE_CA_CERT_PATH environment variables are no longer consumed.
  • Reduced ACK runtime configuration to startup essentials, added the missing GO_BACKEND_HOST=0.0.0.0, removed unused provider/webhook/API-key/legacy worker Secret injections, and retained the CA Secret as a file mount rather than an environment variable.
  • Updated .env.example, deployment docs, READMEs, ACK assertions, and database configuration tests.

Verification

  • go test ./... passed in backend/.
  • go test ./internal/postgres passed after the final TLS assertion update.
  • npm run deploy:check passed (9 ACK manifests).
  • node --check scripts/postgres-client.mjs passed.
  • node --check scripts/check-ack-manifests.mjs passed.
  • git diff --check passed; only Git line-ending warnings were reported.
  • Full Vitest/Next typecheck was not run because this isolated worktree has no node_modules installation.

Follow-ups

  • Replace all ACK placeholders, especially the RDS CA Secret and the DATABASE_URL values. For strict RDS verification, include ?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pem in both the Go and migration connection URLs.
  • Add provider/OSS/API-key/Webhook Secret references only when those optional capabilities are enabled.

Promotion Candidates

  • None. The deployment simplification is task-scoped; canonical architecture already describes the same two-workload production topology.