模块 4 · 生产认知

审计只 INSERT
Redis 6380 与 fail-open

共用底座课讲了双栈鉴权与 input_guard,这模块补生产环境行为和画像/cache 接缝—— 指挥 AI 改「吊销 fail-closed」或「审计可改」前必看。

G-02:审计表只 INSERT

audit_log · input_guard_log · risk_suitability_log 等合规留痕表禁止 UPDATE/DELETE。任何「改历史审计」需求都应被拒绝,改为追加更正记录。

input_guard 命中: fail-fast,不建会话——和 LangGraph 内 fallback 不同,没有 reply 回合入库。

fail-open 与 debug 双闸门

①

Redis 会话窗口 fail-open — Redis 挂了对话仍能回,只是少短期记忆(客服线同样策略)。

②

jti 吊销 fail-open — 吊销服务异常时 token 仍可能通过;生产要监控 Redis。

③

debug 头 — 仅 APP_ENV=development 且无 RS256 公钥;生产有公钥时 debug 头失效。

④

Redis 6380 + RESP2 — Docker 映射 6380;Windows 本机 6379 旧 Redis 3 不兼容。

L1/L2 热缓存:谁接了谁没接

接缝快照
客服 profile_maybe_extract → L1 抽槽 ✓
ProfileHotCache → 部分读 ✓
L2 Repository / 全量 Redis L1 → 开放项
宿主 POST /api/chat 非 customer → 未全接 L1 热缓存
白话

指挥 AI「全 Agent 统一画像 Redis」前,先对 FRAMEWORK 实现状态表。

Bearer 全环境优先——pytest 仍用 dev token,但生产必须 RS256 + 禁 debug 头冒充。

运维说「把 audit_log 里错的那条改成正确 decision」,你怎么回?