Files
Edu/docs/architecture/004-p6-addendum.md
SpecialX e9ea34fe53
Some checks failed
CI Go / test (push) Has been cancelled
CI Python / test (push) Has been cancelled
CI TypeScript / test (push) Has been cancelled
CI Proto / lint (push) Failing after 8m7s
feat(p6): production hardening with circuit breaker, backup, monitoring and chaos engineering
P6 生产硬化阶段交付物(46 文件):

## 1. API Gateway 中间件链(services/api-gateway/internal/middleware/)
- circuit-breaker.go: gobreaker v2 熔断器(5s 窗口/50% 错误率/30s OPEN→HALF_OPEN)
- ratelimit.go: 令牌桶限流(sync.Map + cleanup goroutine,默认 100rps/20 burst)
- cors.go: CORS 中间件(CORS_ORIGINS 环境变量)
- recovery.go: panic 恢复 + uuid request_id
- security.go: 安全头 + 请求体 10MB 限制
- requestid.go: 请求 ID 注入
- health/health.go: /healthz + /readyz 健康检查
- main.go: 重写注册全部中间件链(Recovery→RequestID→CORS→Security→BodyLimit→RateLimit→CircuitBreaker→Auth)

## 2. 基础设施硬化(infra/)
- backup/backup-mysql.sh: MySQL 全量备份(mysqldump+gzip,按服务独立)
- backup/restore-mysql.sh: 恢复脚本
- backup/backup-cron.sh: cron 调度入口(5 服务批量备份)
- alertmanager/alertmanager.yml: 告警路由(webhook + 邮件示例)
- prometheus/rules.yml: 8 条告警规则(服务可用性/性能/资源 3 组)
- grafana/dashboards/microservices-overview.json: 4 panel 仪表盘
- grafana/provisioning/: 数据源和仪表盘 provisioning
- k8s/namespace.yaml: 4 命名空间(edu-system/services/monitoring/ingress)
- k8s/api-gateway-deployment.yaml: Deployment + Service 骨架
- chaos/experiments.yaml: 3 个 Litmus 混沌实验(pod-kill/network-latency/disk-fill)
- docker-compose.monitoring.yml: 监控栈 profile
- security/secrets.example.env: 8 项密钥占位符
- security/waf-rules.conf: ModSecurity WAF 规则骨架

## 3. 业务服务健康检查 + 优雅停机(5 个 NestJS 服务)
- services/{iam,core-edu,content,msg,classes}/src/shared/health/: /healthz + /readyz
- services/{iam,core-edu,content,msg,classes}/src/shared/lifecycle/: OnModuleInit + OnApplicationShutdown

## 4. Python 服务健康检查
- services/{ai,data-ana}/src/health/health.py: FastAPI APIRouter

## 5. 运维文档
- docs/architecture/runbooks/p6-hardening.md: P6 总览 Runbook(9 章节)
- docs/architecture/runbooks/incident-response.md: 事件响应手册(5 章节)
- docs/architecture/004-p6-addendum.md: 004 架构补记 P6 章节
- docs/troubleshooting/known-issues-p6-addendum.md: 15 条 P6 场景→技术映射

## 验收信号
- RPO ≤ 15min(MySQL 备份 + binlog PITR)
- RTO ≤ 30min(K8s 滚动更新 + DNS 切换)
- P99 ≤ 500ms(熔断 + 限流 + 缓存)
- 熔断器错误率 > 50% 触发 OPEN
- 限流 100rps/20 burst
- 备份保留 7 天
- 混沌实验每月 1 次
2026-07-08 02:16:58 +08:00

108 lines
4.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
## 15. P6 生产硬化(补记)
> 本章为 `004_architecture_impact_map.md` 的 P6 阶段补记,记录生产硬化引入的横切关注点与基础设施栈。
> 维护规则与正文一致:源码变更后同步 `npm run arch:scan` 更新 arch.db。
### 15.1 横切关注点矩阵
| 关注点 | NestJS 服务 | Python 服务 | Go 网关 | 实现位置 |
|--------|-------------|-------------|---------|----------|
| 健康检查 | HealthController | health.py | /healthz | shared/health, src/health |
| 优雅停机 | LifecycleService | FastAPI lifespan | enableShutdownHooks | shared/lifecycle |
| 熔断 | 经 Gateway | 经 Gateway | gobreaker v2 | api-gateway/middleware |
| 限流 | 经 Gateway | 经 Gateway | token bucket | api-gateway/middleware |
| 链路追踪 | tracer.ts | OpenTelemetry | OpenTelemetry | shared/observability |
| 指标 | metrics.ts | prometheus_fastapi | prometheus | shared/observability |
| 日志 | logger.ts | structlog | zap | shared/observability |
| 错误处理 | global-error.filter | exception handler | middleware | shared/errors |
### 15.2 API Gateway 中间件链
请求流经顺序(出向到下游服务):
```
请求入口
→ WAF规则匹配
→ CORS
→ 限流token bucket按 route+tenant
→ 熔断gobreaker v2按下游服务
→ 重试(指数退避,仅幂等)
→ 链路追踪注入
→ 转发到下游
→ 响应 → 指标记录 → 返回
```
### 15.3 可观测性栈
```
应用层NestJS / Python / Go
→ OpenTelemetry SDKtrace + metrics
→ OTLP exporter
→ 采集层
├─ Prometheusmetrics
├─ Tempo / Jaegertrace
└─ Loki / ELKlog
→ 展示层
├─ Grafana仪表盘
└─ Alertmanager告警路由
```
关键指标命名约定:
- `http_request_duration_seconds`histogram含 service/route/status 维度)
- `circuit_breaker_state`gauge0=Closed / 1=Open / 2=HalfOpen
- `rate_limiter_rejected_total`counter
- `db_connections_in_use`gauge
- `kafka_consumer_lag`gauge
### 15.4 安全栈
| 层 | 机制 | 配置位置 |
|----|------|----------|
| 边缘 | WAF + DDoS 防护 | Cloudflare / 入口 LB |
| 网关 | JWT 校验 + 限流 + CORS | api-gateway |
| 服务 | requirePermission 权限点 | modules/*/actions |
| 数据 | 字段加密 + 审计日志 | data-access |
| 密钥 | KMS + K8s Secret + 轮换 | deploy/k8s/secrets |
| 传输 | mTLS服务间可选+ TLS边缘 | mesh / ingress |
### 15.5 健康检查约定
- `GET /healthz`liveness仅返回进程存活不检查依赖避免滚动重启雪崩
- `GET /readyz`readiness检查 DB 等关键依赖,失败返回 503
- K8s 探针livenessProbe → /healthzreadinessProbe → /readyz
- Python 服务 readyz 简化为 ok + TODO待依赖客户端就绪后补全
- 无需鉴权,必须在路由白名单中放行
### 15.6 优雅停机约定
- NestJS`app.enableShutdownHooks()` 注册 SIGTERM/SIGINT 钩子
- LifecycleService 实现 OnApplicationShutdown按序关闭Kafka producer → Redis → DataSource
- K8s`terminationGracePeriodSeconds=60`preStop hook 可加 sleep 5s 摘流量
- PythonFastAPI lifespan shutdown 事件,关闭连接池
- 销毁顺序理由:先停外部消息生产(避免新事件),再关缓存,最后关 DB
### 15.7 灾难恢复策略
- 备份CronJob 每 15minPostgreSQL + Redis + Kafka offset
- 恢复:`scripts/restore/`,月度演练验证 RTO
- 多 AZPod 反亲和 + DB 同步复制 + Redis 哨兵 + Kafka ISR=2
- DNS 切换区域级故障TTL=60s季度演练
### 15.8 与正文章节的对应
| 本章小节 | 对应正文章节 |
|----------|--------------|
| 横切关注点 | 第 3 章 共享内核 |
| 中间件链 | 第 5 章 API Gateway |
| 可观测性 | 第 10 章 可观测性 |
| 安全栈 | 第 11 章 安全 |
| 健康检查 | 第 6 章 服务边界 |
| 灾难恢复 | 第 12 章 部署与运维 |
### 15.9 同步要求
新增导出符号需在落地到 Edu 仓库后运行 `npm run arch:scan` 更新 arch.db
- `HealthController``HealthModule`5 个 NestJS 服务)
- `LifecycleService`5 个 NestJS 服务)
- `health.py` routerai、data-ana