AptLarder::Healthcheck
The probe the binary runs against itself.
It exists because the released image is distroless
(gcr.io/distroless/static-debian12): no shell, no curl, no wget. A
HEALTHCHECK CMD curl ... cannot work there, so the only thing able to
speak HTTP inside that container is apt-larder itself.
Deliberately a subcommand rather than a flag on the running server: Docker runs the check by exec'ing a second process into the container, and what it wants back is an exit code.
It probes the proxy, not the admin server. The admin server is optional
and off by default, and the baked HEALTHCHECK carries no --config, so a
probe pointed at the admin API reported unhealthy on every deployment whose
config lives outside the working directory — while the proxy was serving
packages perfectly. What the container exists to do is the only thing worth
gating its health on.
Constants
Short on purpose. A probe that hangs is a probe that reports nothing, and
Proxy::HEALTH_PATH is answered before any resolution, cache lookup or
upstream call — it never waits on anything.
Addresses that mean "every interface" when bound, and nothing routable
when dialled. The container binds 0.0.0.0 and the probe runs inside it,
so loopback is the address that actually reaches the listener.