kanidm: no container health probe is possible with the upstream image #475
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#475
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
roles/kanidm/templates/kanidm.container.j2has noHealthCmd. Kanidm is the sole identity provider for Forgejo, the portal and Grafana; a hung-but-running container is invisible to podman, systemd and theContainerUnhealthyalert.The upstream image (
docker.io/kanidm/server) ships only/sbin/kanidmd: no shell, no curl, andkanidmdhas no healthcheck subcommand, so a container-side probe cannot be written against it.Options: probe from outside the container (a blackbox target on
https://127.0.0.1:<port>/statusfrom the services host, with an alert on failure), or build a derived image that adds a static probe binary. Decide and implement; the external probe is the smaller change.