Six of eight workloads had no readinessProbe, so a pod turned Ready the moment its process started. The verify job relies on `rollout status`, so it passed for images that crash-looped or served errors, which left the rollback safety net inert. Each probe targets the path the service is actually reached on: - homepages: / (verified 200) - error-pages: /404.html, the path Traefik's errorPages middleware requests. / returns 403 by design and would never pass. - webinar-checker: /health (verified 200). /metrics also answers, but it is a Prometheus endpoint, not a readiness signal. The two userbot deployments stay without probes: they expose no port and no session file, and the panel reaches Telegram through its own client. A truthful signal there needs a health endpoint in the app itself.
42 lines
813 B
YAML
42 lines
813 B
YAML
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: error-pages-service
|
|
namespace: error-pages
|
|
spec:
|
|
selector:
|
|
app: error-pages
|
|
ports:
|
|
- port: 80
|
|
targetPort: 80
|
|
---
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: error-pages-deployment
|
|
namespace: error-pages
|
|
spec:
|
|
replicas: 1
|
|
selector:
|
|
matchLabels:
|
|
app: error-pages
|
|
template:
|
|
metadata:
|
|
labels:
|
|
app: error-pages
|
|
spec:
|
|
containers:
|
|
- name: error-pages
|
|
image: gcr.forust.xyz/forust/error-pages:latest
|
|
imagePullPolicy: Always
|
|
ports:
|
|
- containerPort: 80
|
|
readinessProbe:
|
|
httpGet:
|
|
path: /404.html
|
|
port: 80
|
|
periodSeconds: 10
|
|
timeoutSeconds: 2
|
|
failureThreshold: 3
|
|
---
|