Skip to content

fix(health): rule 6 is closed on the six vhosts that were missing it - #33

Merged
mikim merged 1 commit into
mainfrom
claude/rule6-exceptions-landed
Sep 10, 2026
Merged

mikim merged 1 commit into
mainfrom
claude/rule6-exceptions-landed

Conversation

@mikim

@mikim mikim commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

#32 shipped rule 6 as a recorded exception on seven of sixteen services rather than a failure, because a gate that is red on the day it ships is a gate nobody reads. Six of those are now fixed at the edge, so the entries come out — which the check itself demanded:

::error::ao now satisfies rule(s) [6] — remove them from EXCEPTIONS in this script
::error::bridge now satisfies rule(s) [6] — ...

That is the exception-rot detector doing its job on its first day.

What changed on the box (ssh mossland)

add_header Cache-Control "no-cache" always; with a preceding proxy_hide_header, inside each location = /api/health:

vhost before after
signal, npc, ao, algora, bridge no Cache-Control added to the existing health block
alpha no health block at all location = /api/health created

alpha needed the block created: its vhost is a bare location / and its Access-Control-Allow-Origin comes from the app, so that header is deliberately not touched there — no proxy_hide_header Access-Control-Allow-Origin, or it would delete the only source. The new block mirrors location /'s upstream and forwarding headers, minus the websocket Upgrade/Connection pair, which a plain health GET has no use for. ?strict=1 still routes into it — nginx location matching ignores the query string, verified live (200, worst_status: warn).

Each vhost backed up as .bak.rule6.20260910_051009; nginx -t clean; nginx -T | grep -c rule6 = 0, so the backups are not being loaded (this box's sites-enabled/* include has bitten before); every site's / still answers as it did.

Verified

alpha signal npc ao algora bridge
  -> access-control-allow-origin: *   cache-control: no-cache

city stays: it is cached on purpose by its own Next app (public, s-maxage=60, stale-while-revalidate=120), so it is an app change in a repo with no local checkout, not an nginx one.

Standing state

11 conformant · 4 known exceptions · 1 unreachable (not graded) · 0 failing

signalmap is the unreachable one — its box is mid-deploy and thrashing through next build (2.75 GB peak on a 1.9 GB box, which its deploy.sh documents as the expected path). The check reports it and moves on instead of going red, which is exactly the case it was written for.

🤖 Generated with Claude Code

#32 recorded rule 6 as an exception on seven of sixteen rather than failing
the build with it, because a gate that is red on the day it ships is a gate
nobody reads. Six are now fixed at the edge, so the entries come out — which
the check itself demanded, its exception-rot detector firing on day one.

On the box reachable as `ssh mossland`, each `location = /api/health` gained
`proxy_hide_header Cache-Control` followed by
`add_header Cache-Control "no-cache" always`. signal, npc, ao, algora and
bridge already had such a block; alpha had none at all, so one was created.

alpha is the careful one. Its vhost is a bare `location /`, and its
Access-Control-Allow-Origin comes from the app rather than nginx, so the new
block deliberately does not hide or set that header — doing so would delete
its only source. It mirrors `location /`'s upstream and forwarding headers,
minus the websocket Upgrade/Connection pair, which a plain health GET has no
use for. `?strict=1` still lands in it, since nginx location matching ignores
the query string; verified live.

Each vhost backed up as .bak.rule6.20260910_051009. `nginx -t` clean, and
`nginx -T | grep -c rule6` is 0, so the backups are not themselves being
served — this box includes `sites-enabled/*` and has been bitten by that
before. Every site's `/` still answers as it did.

city keeps its rule 6 exception: it is cached on purpose by its own Next app,
which makes it an app change in a repo with no local checkout rather than an
nginx one.

11 conformant, 4 known exceptions, 0 failing. signalmap is unreachable
mid-deploy and is reported rather than graded, which is the case the
unreachable branch was written for.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@mikim
mikim merged commit 3356caa into main Sep 10, 2026
9 checks passed
@mikim
mikim deleted the claude/rule6-exceptions-landed branch September 10, 2026 05:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant