G1: stop probing the tunnel from inside a container
cloudflared binds 127.0.0.1:2000 on the HOST. This process runs in a container whose only route to the host is the bridge gateway (172.17.0.1), where nothing is listening — so the check was permanently red regardless of what the tunnel was actually doing. Binding the metrics endpoint wider would have fixed the probe and made a metrics bind failure capable of taking down ingress. That is a worse trade than losing one row on a dashboard. The check is not silently dropped: /health/full now carries a 'not_checked_here' map naming the tunnel and where its health actually lives (systemd windygit-tunnel). An observer should never have to wonder whether a missing check means healthy or means forgotten. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
@@ -24,9 +24,6 @@ services:
|
||||
# nothing needs to be reachable from the LAN, let alone the internet (G1.6).
|
||||
ports: ["127.0.0.1:${API_PORT:-8600}:8600"]
|
||||
depends_on: {db: {condition: service_healthy}}
|
||||
# cloudflared runs on the host, not in this network. Without this the tunnel
|
||||
# probe is permanently red and stops meaning anything.
|
||||
extra_hosts: ["host.docker.internal:host-gateway"]
|
||||
restart: unless-stopped
|
||||
|
||||
gitea:
|
||||
|
||||
Reference in New Issue
Block a user