#!/bin/sh # Container health for the `serve` role: readiness, not liveness (US08-02). # # /api/v1/health/ready is 503 until the database is reachable, migrated, and in WAL # mode with foreign keys on, so an unmigrated or misconfigured container never reports # healthy. Health endpoints need no session and no access secret, which is what lets an # orchestrator restart a container it holds no credentials for (US08-01). set -eu role="$(cat "${PHOTO_PIPELINE_ROLE_FILE:-/tmp/photo-pipeline-role}" 2>/dev/null || echo unknown)" if [ "${role}" != "serve" ]; then # ponytail: the worker has no endpoint to probe; its liveness is its lease and job # heartbeat in the database. Add a `worker --health` command if a restart policy # ever needs to act on it. exit 0 fi port="${PHOTO_PIPELINE_PORT:-8000}" exec python - "${port}" <<'PY' import sys import urllib.error import urllib.request url = f"http://127.0.0.1:{sys.argv[1]}/api/v1/health/ready" try: with urllib.request.urlopen(url, timeout=5) as response: # noqa: S310 — loopback sys.exit(0 if response.status == 200 else 1) except urllib.error.HTTPError as error: print(f"not ready: HTTP {error.code}", file=sys.stderr) sys.exit(1) except OSError as error: print(f"not ready: {error}", file=sys.stderr) sys.exit(1) PY