fix(health): rule 6 is closed on the six vhosts that were missing it - #33
Merged
Merged
Conversation
#32 recorded rule 6 as an exception on seven of sixteen rather than failing the build with it, because a gate that is red on the day it ships is a gate nobody reads. Six are now fixed at the edge, so the entries come out — which the check itself demanded, its exception-rot detector firing on day one. On the box reachable as `ssh mossland`, each `location = /api/health` gained `proxy_hide_header Cache-Control` followed by `add_header Cache-Control "no-cache" always`. signal, npc, ao, algora and bridge already had such a block; alpha had none at all, so one was created. alpha is the careful one. Its vhost is a bare `location /`, and its Access-Control-Allow-Origin comes from the app rather than nginx, so the new block deliberately does not hide or set that header — doing so would delete its only source. It mirrors `location /`'s upstream and forwarding headers, minus the websocket Upgrade/Connection pair, which a plain health GET has no use for. `?strict=1` still lands in it, since nginx location matching ignores the query string; verified live. Each vhost backed up as .bak.rule6.20260910_051009. `nginx -t` clean, and `nginx -T | grep -c rule6` is 0, so the backups are not themselves being served — this box includes `sites-enabled/*` and has been bitten by that before. Every site's `/` still answers as it did. city keeps its rule 6 exception: it is cached on purpose by its own Next app, which makes it an app change in a repo with no local checkout rather than an nginx one. 11 conformant, 4 known exceptions, 0 failing. signalmap is unreachable mid-deploy and is reported rather than graded, which is the case the unreachable branch was written for. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#32 shipped rule 6 as a recorded exception on seven of sixteen services rather than a failure, because a gate that is red on the day it ships is a gate nobody reads. Six of those are now fixed at the edge, so the entries come out — which the check itself demanded:
That is the exception-rot detector doing its job on its first day.
What changed on the box (
ssh mossland)add_header Cache-Control "no-cache" always;with a precedingproxy_hide_header, inside eachlocation = /api/health:Cache-Controllocation = /api/healthcreatedalphaneeded the block created: its vhost is a barelocation /and itsAccess-Control-Allow-Origincomes from the app, so that header is deliberately not touched there — noproxy_hide_header Access-Control-Allow-Origin, or it would delete the only source. The new block mirrorslocation /'s upstream and forwarding headers, minus the websocketUpgrade/Connectionpair, which a plain health GET has no use for.?strict=1still routes into it — nginx location matching ignores the query string, verified live (200,worst_status: warn).Each vhost backed up as
.bak.rule6.20260910_051009;nginx -tclean;nginx -T | grep -c rule6= 0, so the backups are not being loaded (this box'ssites-enabled/*include has bitten before); every site's/still answers as it did.Verified
citystays: it is cached on purpose by its own Next app (public, s-maxage=60, stale-while-revalidate=120), so it is an app change in a repo with no local checkout, not an nginx one.Standing state
signalmapis the unreachable one — its box is mid-deploy and thrashing throughnext build(2.75 GB peak on a 1.9 GB box, which itsdeploy.shdocuments as the expected path). The check reports it and moves on instead of going red, which is exactly the case it was written for.🤖 Generated with Claude Code