G1: stop probing the tunnel from inside a container
cloudflared binds 127.0.0.1:2000 on the HOST. This process runs in a container whose only route to the host is the bridge gateway (172.17.0.1), where nothing is listening — so the check was permanently red regardless of what the tunnel was actually doing. Binding the metrics endpoint wider would have fixed the probe and made a metrics bind failure capable of taking down ingress. That is a worse trade than losing one row on a dashboard. The check is not silently dropped: /health/full now carries a 'not_checked_here' map naming the tunnel and where its health actually lives (systemd windygit-tunnel). An observer should never have to wonder whether a missing check means healthy or means forgotten. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -66,6 +66,14 @@ async def health_full(request: Request, response: Response) -> dict:
|
||||
"status": status,
|
||||
"commit_sha": info.commit_sha,
|
||||
"checks": checks,
|
||||
# Named, not hidden. An observer should never have to wonder whether a
|
||||
# missing check means healthy or means forgotten.
|
||||
"not_checked_here": {
|
||||
"tunnel": (
|
||||
"host-scoped: cloudflared binds host loopback and is supervised "
|
||||
"by systemd (windygit-tunnel). Verify with `systemctl status`."
|
||||
)
|
||||
},
|
||||
# Grandma-words, and the D-9 vocabulary law binds this string.
|
||||
"speak": (
|
||||
"Everything is working."
|
||||
|
||||
Reference in New Issue
Block a user