Skip to content

feat: GET /api/health with a database check - #298

Merged
ralyodio merged 1 commit into
masterfrom
ops/health-endpoint
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
ops/health-endpoint

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Adds GET /api/health for status.profullstack.com (Gatus).

  • 200 {"status":"ok","db":"ok"} after one PostgREST HEAD query on users (limit 1, 3s AbortSignal.timeout) via getServiceRoleClient.
  • 503 {"status":"error","db":"down"} on any failure; no error details, env or keys in the body.
  • Cache-Control: no-store, no auth. src/middleware.js returns early for /api/health so the per-IP API rate limiter can never 429 the monitor.
  • Verified: eslint clean on both files.

🤖 Generated with Claude Code

Returns 200 {"status":"ok","db":"ok"} after one PostgREST HEAD query
(3s timeout) through the shared service-role client, or 503
{"status":"error","db":"down"} without error details. For the
status.profullstack.com Gatus check; the middleware lets it past the
per-IP API rate limiter.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

13 finding(s)

MEDIUM: 9 | LOW: 4

Severity Rule Location
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:38
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:66
MEDIUM js-unescaped-html-sink src/app/faq/page.jsx:57
MEDIUM js-unescaped-html-sink src/app/layout.jsx:137
MEDIUM js-unescaped-html-sink src/app/layout.jsx:141
MEDIUM js-unescaped-html-sink src/app/page.jsx:47
MEDIUM redos-nested-quantifier src/lib/auth/dns-name.js:88
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:85
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:130
LOW secret-generic-credential src/app/api/auth/register-anon/route.test.js:32
LOW secret-jwt tests/debug-sms.js:10
LOW secret-generic-credential tests/private-key-import-export.test.js:252
LOW secret-generic-credential tests/private-key-import-export.test.js:264

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 8840da6 into master Oct 6, 2026
11 checks passed
@ralyodio
ralyodio deleted the ops/health-endpoint branch October 6, 2026 18:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant