3.0 KiB
3.0 KiB
Task: Simplify production database and deployment environment configuration
Identity
- Task ID: 20260816-simplify-prod-env-8a4c
- Mode: Feature
- Branch: codex/20260816-simplify-prod-env-8a4c-simplify-prod-env
- Worktree: D:\Datas\OthersProjects\NianAIGC-simplify-prod-env-8a4c
- Base commit:
8cb8b5e463 - Owner: codex
- Status: Ready for Integration
Scope
- Simplify PostgreSQL connection configuration so
DATABASE_URLis the only database connection setting; allowsslmodeand optionalsslrootcertin that URL while retaining full certificate verification by default. - Remove non-essential production ACK environment and Secret injections while retaining the Go API, Next session, bootstrap, RDS CA mount, and runtime storage settings required by the first deployment.
- Synchronize Go/Node clients, ACK checks, deployment documentation, README references, and configuration tests.
Intent And Constraints
- Do not weaken TLS verification or introduce
InsecureSkipVerify. - Keep local JSON development behavior and existing database pool defaults.
- Preserve the existing split topology: Next.js serves pages, Go owns the database and embedded WorkerLoop.
- Feature mode may update task-scoped code/deployment/docs, but not canonical
.project-docsmemory.
Outcome
- Completed the single-variable database contract. Go, the legacy TypeScript
adapter, and migration scripts now read TLS settings from
DATABASE_URL; production defaults tosslmode=verify-full, andsslrootcertis optional in the URL when the RDS CA is mounted. SeparateDATABASE_SSL_MODE/DATABASE_CA_CERT_PATHenvironment variables are no longer consumed. - Reduced ACK runtime configuration to startup essentials, added the missing
GO_BACKEND_HOST=0.0.0.0, removed unused provider/webhook/API-key/legacy worker Secret injections, and retained the CA Secret as a file mount rather than an environment variable. - Updated
.env.example, deployment docs, READMEs, ACK assertions, and database configuration tests.
Verification
go test ./...passed inbackend/.go test ./internal/postgrespassed after the final TLS assertion update.npm run deploy:checkpassed (9 ACK manifests).node --check scripts/postgres-client.mjspassed.node --check scripts/check-ack-manifests.mjspassed.git diff --checkpassed; only Git line-ending warnings were reported.- Full Vitest/Next typecheck was not run because this isolated worktree has no
node_modulesinstallation.
Follow-ups
- Replace all ACK placeholders, especially the RDS CA Secret and the
DATABASE_URLvalues. For strict RDS verification, include?sslmode=verify-full&sslrootcert=/etc/zhinian/rds/ca.pemin both the Go and migration connection URLs. - Add provider/OSS/API-key/Webhook Secret references only when those optional capabilities are enabled.
Promotion Candidates
- None. The deployment simplification is task-scoped; canonical architecture already describes the same two-workload production topology.