v0.292.0: cloudflared readiness health check (R-841) — tunnel --metrics localhost:20241 run + Docker healthcheck on cloudflared's own /ready; the host agent reports running/not_running/unknown from State.Health
gates / gates (push) Successful in 28s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 13:16:26 +02:00
parent badc9c2a0c
commit 09e634de31
6 changed files with 55 additions and 10 deletions
+14
View File
@@ -1,3 +1,17 @@
## v0.292.0 — cloudflared says whether the tunnel is CONNECTED (R-841) (2026-10-04)
**MinAgent: 0.131.0** (unchanged). No new household string. Agent v0.141.0 reads the result; an older agent ignores it.
- **R-841.** The cloudflared stack now runs `tunnel --metrics localhost:20241 run` and has a Docker health check,
`cloudflared tunnel --metrics localhost:20241 ready` (every 30 s, 3 retries, 30 s start period). `/ready` answers
200 only with at least one connection to Cloudflare. Measured 2026-10-04: with a wrong token the container stays
`running` while `/ready` answers 503 — the container state alone said "up" for a dead tunnel. The host agent reads
`State.Health` through its existing `docker inspect` sudoers line and reports `running` / `not_running` / `unknown`.
- Delivery: the infra reconcile (v0.286.0) sees the changed compose and recreates cloudflared once on upgrade; the
tunnel reconnects in seconds.
- Tests: `TestRenderCloudflared_HasAReadinessHealthcheck`; `TestCloudflaredRender` expects the new command.
Red-proof: `felhom.eu/documentation/audits/os-host-lane-2026-10-04/partA/controller-redproof.txt`.
## v0.291.0 — a returning household's first night makes an off-site copy (decision 78, R-726); the built-in images raised and a release now moves them (R-838) (2026-10-04)
**MinAgent: 0.131.0** (unchanged). No new household string.