feat: P1 profile/portrait API and freeze local-dev environment

Add host-first environment contracts (Local vs CI vs Prod), deps-only
compose, and the Profile → Portrait → deep-access mock payment slice
with device identity and auto-migrate on API startup.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
jackyu66git
2026-08-02 16:24:57 +08:00
co-authored by Cursor
parent dd94e57277
commit 0f320e040b
49 changed files with 1907 additions and 191 deletions
+25
View File
@@ -0,0 +1,25 @@
# Production compose skeleton — NOT for daily local coding.
# Activate only when images/Dockerfiles exist for a release.
# Policy: .ai/deployment.md · .ai/docker.md
#
# Example (uncomment and set registry tags when shipping):
#
# services:
# api:
# image: registry.example.com/yuxingu-api:${TAG:-v0.0.0}
# env_file: [.env.prod]
# ports: ["8080:8080"]
# web:
# image: registry.example.com/yuxingu-user-h5:${TAG:-v0.0.0}
# ports: ["80:80"]
services:
# Keeps file valid; profile "prod" must be enabled explicitly — never default local.
postgres:
profiles: ["prod"]
image: postgres:16-alpine
environment:
POSTGRES_USER: yuxingu
POSTGRES_PASSWORD: change-me
POSTGRES_DB: yuxingu
# Do not expose 5432 publicly in real prod without network policy.