5.2 KiB
5.2 KiB
Task: Persist provider settings in PostgreSQL
Identity
- Task ID: 20260818-db-provider-settings-4f6a2c9d
- Mode: Feature
- Branch: main
- Worktree: /Users/andy/IdeaProjects/NianAIGC
- Base commit:
22b504e - Owner: Codex /root
- Status: Ready for Integration
Scope
- Replace production file persistence for the four provider setting groups (Volcengine visual, EvoLink, Seedance, and Bailian) plus image/video engine assignments with PostgreSQL-backed runtime settings.
- Keep environment variables as fallback values and leave authentication, database, billing, and OSS deployment configuration outside this migration.
- Make provider submission, job construction, capability reporting, and health reporting observe successful setting changes without a process restart.
- Change the settings UI to submit only edited fields and accurately report that a successful save is immediately effective.
- Add migration and regression coverage for persistence, precedence, secret preservation, and runtime consumption.
Intent And Constraints
- Preserve the accepted static Web plus Go-only API architecture and the
existing super-administrator authorization boundary on
/api/settings. - PostgreSQL is the production source of truth; saved database values override environment fallback values, while unset values continue to use environment configuration and existing defaults.
- Store values in plaintext for this first functional delivery, as explicitly requested; encryption and secret rotation remain follow-up hardening.
- Do not modify the pre-existing untracked
.idea/directory. - The repository-required
task_context.pycoordination helper is not present in this checkout, and.gitis read-only in this environment, so this task records ownership here and works in the user-authorized current worktree without creating a feature branch. - Feature work updates only this task-scoped record; canonical architecture and decision documents remain integration-owned.
Outcome
- Added migration
0003_platform_runtime_settings.sqland explicit application-role/readiness coverage for the new PostgreSQL table. Provider settings are upserted transactionally with a revision and update timestamp. - The production settings service now persists the four provider groups plus image/video engine assignments in PostgreSQL. Database rows override environment and legacy file fallback values; blank secret submissions still preserve the existing value and secret values remain blank in API payloads.
- Provider configuration is refreshed at both runtime seams: quote/job construction resolves current engine/model/defaults, and Worker submit/query resolves a fresh adapter with the current credential and Base URL. Capability and health projections also observe the mutable provider state.
- Removed the production startup credential gate and obsolete bootstrap flag. The API can start before providers are configured, while a request selecting an unconfigured provider still fails with 503 and never falls back to Mock.
- The settings client tracks dirty keys and posts only edited values, preventing a provider save from also attempting writes for unrelated file-backed groups. Successful provider saves report immediate application without a restart.
- Provider Secret injection is now an optional environment fallback in ACK; deployment guidance documents migration 0003, database precedence, and the no-restart behavior. Values are intentionally plaintext for this delivery.
Verification
- RED:
npx vitest run tests/settings-go-contract.test.tsfailed because the compatibility fixture still required restart and migration 0003 did not yet exist. - PASS: official Go 1.26.6 archive checksum matched the published SHA-256;
the toolchain was extracted only under
/private/tmpand removed after verification. - PASS:
gofmt -l backendreturned no files. - PASS:
go test ./...across all Go packages. - PASS:
go vet ./.... - PASS:
go build -o /private/tmp/nianaigc-zhinian-api ./cmd/zhinian-api. - PASS: affected Go package regression rerun for
postgres,settings,application,jobs, andhttpapiafter final transaction cleanup. - PASS:
npm test(55files,176tests). - PASS:
npx tsc --noEmit --incremental false. - PASS:
npm run build(all routes statically exported). - PASS:
npm run deploy:check(7ACK manifest files). - PASS:
git diff --check. - The repository-referenced
check_project_docs.py,check_doc_drift.py, andtask_context.pyhelpers are not present in this checkout, so those specific project-document/coordination commands could not be run.
Follow-ups
- Consider encrypting provider secrets at rest and recording secret-access audit metadata after functional persistence is deployed and verified.
- Before rolling out the new Go image, execute migration 0003 and re-provision application-role grants, then smoke save each provider group and submit one real request through every configured engine against the target RDS/ACK environment. No live database or cluster mutation was performed in this task.
Promotion Candidates
- Record PostgreSQL-backed mutable provider settings and the database-over-env precedence rule in canonical architecture during integration.