You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(deploy): health checks probed localhost regardless of the bind address
Docker publishes a container on exactly the address it is given, so an app
with a specific `bind:` is not reachable at localhost — but every health probe
dialled localhost anyway. The probe therefore never connected, retried to the
timeout, and failed the deploy while the container was perfectly healthy.
`ingress: host` deploys by recreate, stopping the old container first, so the
failure was not a no-op: the deploy tears down the new container and nothing
is left running. Setting a bind address turned every subsequent deploy into a
full outage. Found by doing it — dash went down moving from 0.0.0.0 to its
tailnet address, with "timeout after 30s" as the only clue.
The probe now resolves the address from the bind host (0.0.0.0/:: still mean
localhost, as does an empty value, which is caddy/external ingress publishing
on 127.0.0.1). Both the HTTP probe and the TCP fallback were affected.
The same bug sat on the rollback and start/restart paths, where it would have
been worse — a rollback that cannot health-check its target aborts and stops
what it started, so the escape hatch failed exactly when it was needed. Those
read the address back from the running container (docker.HostBindIP) since
they have no config in hand.
Verified live: the failing dash deploy now passes its health check, and dash
answers on the tailnet while the LAN gets nothing.
0 commit comments