kanidm: no container health probe is possible with the upstream image #475

Öppen
öppnade 2026-09-08 23:22:01 +00:00 av supernaut · 0 kommentarer
Ägare

roles/kanidm/templates/kanidm.container.j2 has no HealthCmd. Kanidm is the sole identity provider for Forgejo, the portal and Grafana; a hung-but-running container is invisible to podman, systemd and the ContainerUnhealthy alert.

The upstream image (docker.io/kanidm/server) ships only /sbin/kanidmd: no shell, no curl, and kanidmd has no healthcheck subcommand, so a container-side probe cannot be written against it.

Options: probe from outside the container (a blackbox target on https://127.0.0.1:<port>/status from the services host, with an alert on failure), or build a derived image that adds a static probe binary. Decide and implement; the external probe is the smaller change.

`roles/kanidm/templates/kanidm.container.j2` has no `HealthCmd`. Kanidm is the sole identity provider for Forgejo, the portal and Grafana; a hung-but-running container is invisible to podman, systemd and the `ContainerUnhealthy` alert. The upstream image (`docker.io/kanidm/server`) ships only `/sbin/kanidmd`: no shell, no curl, and `kanidmd` has no healthcheck subcommand, so a container-side probe cannot be written against it. Options: probe from outside the container (a blackbox target on `https://127.0.0.1:<port>/status` from the services host, with an alert on failure), or build a derived image that adds a static probe binary. Decide and implement; the external probe is the smaller change.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#475
Ingen beskrivning angiven.