Rogee and rogee
eb83d241fe
HH-547: allow cross-origin widget requests ( #126 )
...
* HH-547: allow cross-origin widget requests
* fix(HH-547): align production preflight with wildcard CORS
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 20:11:04 +08:00
rogee
25ef9ae494
fix(deploy): reuse shared redis and serve dashboard at root
2026-08-23 17:32:02 +08:00
Rogee and rogee
a5d244d293
HH-500: add reproducible production dist bundle ( #111 )
...
* HH-500: add reproducible production dist bundle
* HH-500: make production bundle builds reproducible
* HH-500: lock complete runtime APK closure
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-23 00:22:20 +08:00
Rogee and rogee
fb83285617
HH-445: deploy production observability and runbooks ( #96 )
...
* HH-445: deploy production observability and runbooks
* fix(ops): share production database DSN
* fix(HH-445): enforce database TLS gate
* fix(HH-445): preserve production serve command
* fix(prod): require external database dependencies
* fix(prod): unify database host rejection gates
* test(prod): enforce exact database TLS runbook contract
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 19:39:57 +08:00
Rogee and rogee
f719529d66
fix(security): harden auth and secret handling (HH-444) ( #101 )
...
* fix(security): harden auth and credential handling (HH-444)
* fix(security): address HH-444 review blockers
* fix(security): close remaining HH-444 review blockers
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 15:45:06 +08:00
Rogee and rogee
0e23ccc465
ci(HH-451): harden production Compose smoke ( #95 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 03:58:11 +08:00
Rogee and rogee
02a188dc29
HH-443: establish production CI and supply-chain evidence ( #93 )
...
* ci: enforce production release gates
* ci: close release gate review blockers
* ci: preserve verified digests during promotion
* ci: serialize and verify release cleanup
* ci: build govulncheck with Shangwutong toolchain
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 03:26:38 +08:00
Rogee and rogee
798ea43c2f
HH-442: isolate runtime processes and harden shutdown ( #90 )
...
* HH-442: isolate runtime processes and harden shutdown
* HH-442: harden worker shutdown races
* HH-442: gate dependency shutdown on active handlers
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 02:38:15 +08:00
Rogee and rogee
6d6d80dd86
HH-441: harden durable storage and recovery ( #92 )
...
* HH-441: harden durable storage and recovery
* HH-441: clear recovery review blockers
* HH-441: enforce offsite backup failure domain
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-22 02:16:02 +08:00
Rogee and rogee
7a9fec33c5
HH-439: harden production artifact pipeline ( #86 )
...
* HH-439: harden production artifact pipeline
* fix(HH-439): address production compose review
* fix(HH-439): preserve previous JWT secrets in production
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-21 20:20:00 +08:00
Rogee and rogee
2b182f9956
H-300: wire Captain Skills into Web runtime ( #48 )
...
* H-300: wire Captain Skills into Web runtime
* H-300: enforce effective model and conservative skill budget
* H-300: fix CI gosec step
* ci: extend golangci-lint timeout
* fix lint findings across backend
* fix(push): resolve delivery protocol blockers
* test(repository): close SQLite test databases
* test(repository): reuse SQLite schema per package
* H-307: restore backend Go cache in CI
* H-307: prefetch modules before cold lint
* H-307: resolve govulncheck security gate
* H-307: build lint with patched Go toolchain
* H-307: clear remaining security scan findings
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-19 07:08:14 +08:00
Rogee and rogee
21a9a6793d
H-162: serve built frontend from Go image ( #34 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-15 20:49:26 +08:00
Rogee and rogee
c922460649
H-97: fix Shangwutong conversation routing ( #16 )
...
* H-60: harden Captain migration rollback and concurrency
* chore(agent): baseline — uncommitted work from the local directory
* fix: route Shangwutong events by display id
---------
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-14 14:35:12 +08:00
Rogee and rogee
a5ceb0af93
H-47: unblock connector sandbox setup ( #11 )
...
Co-authored-by: Rogee <rogee@ipao.vip >
2026-08-13 18:25:19 +08:00
Rogee
3d7ff5a6b1
chore: complete Shangwutong connector integration
2026-08-04 18:00:10 +08:00
rogee
897b4e018f
feat(channels): add Shangwutong connector
2026-08-03 10:13:40 +08:00
Rogee
92f0d51375
refactor: 统一 DB/Redis 配置为 DSN 模式 + 移除 Helm/K8s 部署
...
- DatabaseConfig: Host/Port/User/Password/Name/DBName/SSLMode → 单个 DSN 字段
- RedisConfig: Host/Port/Password/DB/URL → 单个 DSN 字段
- 环境变量: GOCHAT_DATABASE_* (7个) → GOCHAT_DATABASE_DSN, GOCHAT_REDIS_* (5个) → GOCHAT_REDIS_DSN
- validator.go: DSN URL 解析校验 (scheme + host)
- redis.go: redis.ParseURL(cfg.DSN) 直连
- 所有 docker-compose / CI / shell 脚本 / .env 同步更新
- 删除 deploy/helm/ 整个目录 (20个文件)
- CI 删除 helm-validate / deploy-staging / deploy-production 三个 job
- 文档同步更新 (README, 架构设计, PRD, 滚动升级)
2026-07-29 20:58:10 +08:00
rogee
aeddedf2a3
Reorganize repo: backend/, deploy/, docs/ layout + AGENTS.md
...
Restructure the monorepo into clear top-level directories:
- backend/: Go module root (cmd, internal, pkg, configs, migrations,
docs/swagger, scripts, tests, go.mod, Makefile, .air.toml)
- deploy/: Docker (Dockerfile, docker-compose*), quickstart, fluentd
- docs/: project documentation + reports/ (moved from repo root)
- AGENTS.md: new AI coding-agent guide at repo root
Update all references to the new layout:
- Dockerfile: COPY backend/go.mod, COPY backend/ (context = repo root)
- docker-compose files: context ../.., dockerfile deploy/docker/Dockerfile,
env_file ../../.env, volume mounts ../../backend:/app
- deploy/quickstart/compose.yaml: dockerfile deploy/docker/Dockerfile
- CI: working-directory: backend for go commands, file deploy/docker/Dockerfile,
coverage path backend/coverage.out, health_check backend/scripts/
- backend/Makefile: docker target uses -f ../deploy/docker/Dockerfile ../
- README: architecture tree, quickstart, config paths updated
Move root stray scripts (rename_models.*, run_m11_tests.sh, verify_build.sh,
gorm_bool_main.go) to backend/scripts/legacy/. All moves via git mv to
preserve history. Build, vet, SQLite tests, and docker compose config verified.
2026-07-07 14:44:12 +08:00