feat(health-check): post-apply health gate + validation/promotion docs (#107) #116
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!116
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/107-post-apply-health-gate"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Tier-2 of ADR 0030 — the last cheap piece of the pre-prod-validation epic (bitborg-docs#37). Turns the 2026-07-18 failure modes into an immediately-failing apply instead of a silent/lucky catch.
What it does
roles/health-checkruns as the final,always-tagged role in eachsite.ymlplay, so every apply (full or--tags-scoped) ends by asserting, on the host it ran against:active— the #94 dead-service class;--resolve, no NAT hairpin) — 2xx/3xx;*.promin the textfile dir is world-readable — the #96 0600-mode class.On any miss the apply fails loudly; no auto-rollback (fix-forward, per ADR 0030). All tasks are read-only (
changed_when: false) and skipped under--check, soansible-playbook site.yml --tags health-check --limit bitborgis a safe standalone probe.Design note: node_exporter listens only on the podman network, so the metric check is done on disk (file mode) rather than via its HTTP endpoint — simpler, host-local, and it targets the exact #96 property.
Verified on prod, both directions
.promfiles readable → 0 failed..promand passes at 0644.Docs
Operator action (not code)
Enable branch protection on
mainin Forgejo (Settings → Branches → protectmain, require thecistatus check). That's the merge-time half of ADR 0030 and can't be set from the repo.Closes #107.