dev: leave /healthz outside the basic-auth boundary #113
1 changed files with 8 additions and 1 deletions
|
|
@ -75,7 +75,14 @@ dev.thermograph.org {
|
||||||
X-Robots-Tag "noindex, nofollow"
|
X-Robots-Tag "noindex, nofollow"
|
||||||
}
|
}
|
||||||
|
|
||||||
basic_auth {
|
# /healthz is deliberately OUTSIDE the auth boundary. It returns liveness and
|
||||||
|
# nothing else — no data, no version, no configuration — and Centralis polls
|
||||||
|
# it to report dev in `fleet_status`. Behind basic auth that poll gets a 401
|
||||||
|
# and dev reads as permanently down, which is how a monitoring blind spot
|
||||||
|
# gets created in the name of security.
|
||||||
|
@protected not path /healthz
|
||||||
|
|
||||||
|
basic_auth @protected {
|
||||||
dev $2a$14$LU5sNyxbop3HOsjhXB6ZrOQiveqhbcYVE6.Wi0bydAv4QhNpj4HMC
|
dev $2a$14$LU5sNyxbop3HOsjhXB6ZrOQiveqhbcYVE6.Wi0bydAv4QhNpj4HMC
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue