Repository navigation
fix(eks): health-check ALB targets on each service's readiness path - #2496
Merged
Merged
Conversation
With the network path fixed, every aws-dev ALB target reports Target.ResponseCodeMismatch: the controller defaulted the health check to "/" expecting 200, which the portal answers with a redirect and guacamole-client with not-found. GKE already health-checks the portal on /health/ through its BackendConfig. The AWS renderer now annotates the portal and guacamole-client Services with alb.ingress.kubernetes.io/healthcheck-path set to their readiness-probe paths (/health/, /guacamole/), so the load balancer and Kubernetes judge a pod by the same endpoint. A test pins the annotations to the chart's probe paths.
…ck-paths # Conflicts: # scripts/bootstrap/aws_eks.py
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Problem
Once ALB traffic can reach the pods (#2490), every aws-dev target reports
Target.ResponseCodeMismatch. The AWS Load Balancer Controller defaults the health check to/expecting200; the portal answers/with a redirect and guacamole-client with not-found. GKE already health-checks the portal on/health/through its BackendConfig; the AWS renderer set no health path.Change
scripts/bootstrap/aws_eks.pyannotates theportalandguacamoleClientServices withalb.ingress.kubernetes.io/healthcheck-pathset to their readiness-probe paths (/health/,/guacamole/), so the load balancer and Kubernetes judge a pod by the same endpoint. The chart already passesservices.*.annotationsthrough, and the values schema accepts them.Verification
scripts/bootstrap/tests/test_aws_eks.pypasses, including a new test that reads the readiness-probe paths from the chart'sweb-deployment.yamlandguacamole-client-deployment.yamland requires the annotations to match.helm templatewith the AWS dev values renders both annotations on the Services.