dev: leave /healthz outside the basic-auth boundary #113

Merged
admin_emi merged 1 commit from fix/dev-healthz-unauthed into dev 2026-07-26 08:28:19 +00:00
Showing only changes of commit 492f64a581 - Show all commits

View file

@ -75,7 +75,14 @@ dev.thermograph.org {
X-Robots-Tag "noindex, nofollow"
}
basic_auth {
# /healthz is deliberately OUTSIDE the auth boundary. It returns liveness and
# nothing else — no data, no version, no configuration — and Centralis polls
# it to report dev in `fleet_status`. Behind basic auth that poll gets a 401
# and dev reads as permanently down, which is how a monitoring blind spot
# gets created in the name of security.
@protected not path /healthz
basic_auth @protected {
dev $2a$14$LU5sNyxbop3HOsjhXB6ZrOQiveqhbcYVE6.Wi0bydAv4QhNpj4HMC
}