module

AptLarder::Healthcheck

The probe the binary runs against itself.

It exists because the released image is distroless (gcr.io/distroless/static-debian12): no shell, no curl, no wget. A HEALTHCHECK CMD curl ... cannot work there, so the only thing able to speak HTTP inside that container is apt-larder itself.

Deliberately a subcommand rather than a flag on the running server: Docker runs the check by exec'ing a second process into the container, and what it wants back is an exit code.

It probes the proxy, not the admin server. The admin server is optional and off by default, and the baked HEALTHCHECK carries no --config, so a probe pointed at the admin API reported unhealthy on every deployment whose config lives outside the working directory — while the proxy was serving packages perfectly. What the container exists to do is the only thing worth gating its health on.

Constants

TIMEOUT = 2.seconds

Short on purpose. A probe that hangs is a probe that reports nothing, and Proxy::HEALTH_PATH is answered before any resolution, cache lookup or upstream call — it never waits on anything.

WILDCARD_HOSTS = {"0.0.0.0", "::", "[::]", ""}

Addresses that mean "every interface" when bound, and nothing routable when dialled. The container binds 0.0.0.0 and the probe runs inside it, so loopback is the address that actually reaches the listener.

Class methods

run(config : Config, io : IO = STDOUT) : Int32

0 when the proxy answers 2xx on Proxy::HEALTH_PATH, 1 otherwise — including when nothing is listening, which is itself the answer.

Source